Nikolaj02 | 09.06.2014 13:04 | ADWCleaner log: Code:
# AdwCleaner v3.212 - Bericht erstellt am 09/06/2014 um 13:42:32
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : olga müller - OLGAMÜLLER-PC
# Gestartet von : C:\Users\olga müller\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Program Files (x86)\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Users\olga müller\AppData\Local\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Users\OLGAML~1\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\olga müller\AppData\LocalLow\AVG SafeGuard toolbar
Datei Gelöscht : C:\Users\olga müller\AppData\Roaming\Mozilla\Firefox\Profiles\1xfda83j.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKCU\Software\AVG SafeGuard toolbar
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\AVG SafeGuard toolbar
Schlüssel Gelöscht : HKLM\Software\AVG Secure Search
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\olga müller\AppData\Roaming\Mozilla\Firefox\Profiles\1xfda83j.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "AVG Secure Search");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [6381 octets] - [02/04/2014 18:42:28]
AdwCleaner[R1].txt - [952 octets] - [03/04/2014 18:03:34]
AdwCleaner[R2].txt - [1071 octets] - [03/04/2014 18:43:10]
AdwCleaner[R3].txt - [1192 octets] - [07/04/2014 11:10:46]
AdwCleaner[R4].txt - [1312 octets] - [07/04/2014 11:27:07]
AdwCleaner[R5].txt - [6579 octets] - [08/05/2014 11:18:24]
AdwCleaner[R6].txt - [1551 octets] - [17/05/2014 11:26:40]
AdwCleaner[R7].txt - [1671 octets] - [17/05/2014 12:42:48]
AdwCleaner[R8].txt - [6329 octets] - [09/06/2014 13:40:11]
AdwCleaner[S0].txt - [6266 octets] - [02/04/2014 18:43:57]
AdwCleaner[S1].txt - [1012 octets] - [03/04/2014 18:28:13]
AdwCleaner[S2].txt - [1133 octets] - [03/04/2014 18:43:51]
AdwCleaner[S3].txt - [1254 octets] - [07/04/2014 11:12:03]
AdwCleaner[S4].txt - [1374 octets] - [07/04/2014 11:27:38]
AdwCleaner[S5].txt - [6464 octets] - [08/05/2014 11:19:42]
AdwCleaner[S6].txt - [1612 octets] - [17/05/2014 11:27:58]
AdwCleaner[S7].txt - [1732 octets] - [17/05/2014 12:44:00]
AdwCleaner[S8].txt - [6002 octets] - [09/06/2014 13:42:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S8].txt - [6062 octets] ##########
JRT log: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by olga mller on 09.06.2014 at 13:48:36,66
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{293F8BD8-8333-45CC-99EC-C7C995852711}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{29543A8E-F588-4E9F-BA70-31839F7042CC}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{46F0117C-693B-4FD6-994F-B7352FC10BAC}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{47FF5744-3620-4CF5-BA1E-C6CE28B4DD24}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{4F1B405C-C678-4E6C-B226-6DD7940E0428}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{609F03B0-EA99-4F44-AE5B-45FC28CC3681}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{66A740DE-4AF8-4C14-BA5A-B53F848E5433}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{6A3AC4BB-14F5-4792-AC08-5364B5FAEB5B}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{727C6942-1037-4EE9-802B-F8B06CCF36D2}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{77D80A3C-C902-4D3D-82DA-F0560EC71A4D}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{87094220-36D5-489A-A4F2-A892525F862A}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{88521F78-D735-495A-8088-308C54D1005C}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{BBA53F06-757E-4BC2-8E6E-BD5793B1150C}
Successfully deleted: [Empty Folder] C:\Users\olga mller\appdata\local\{D372691E-2F4C-4C77-B547-B4A571191267}
~~~ FireFox
Successfully deleted the following from C:\Users\olga mller\AppData\Roaming\mozilla\firefox\profiles\1xfda83j.default\prefs.js
user_pref("browser.startup.homepage", "hxxp://mysearch.avg.com/?cid={296DBE24-C7EC-4C8D-A920-248414188F4D}&mid=3dc24f59b91d49a9b15acff09fe33f75-fce9ca809ad4cc5f69d3b70b40facf6
user_pref("keyword.URL", "hxxp://mysearch.avg.com/search?cid={296DBE24-C7EC-4C8D-A920-248414188F4D}&mid=3dc24f59b91d49a9b15acff09fe33f75-fce9ca809ad4cc5f69d3b70b40facf6c259723
Emptied folder: C:\Users\olga mller\AppData\Roaming\mozilla\firefox\profiles\1xfda83j.default\minidumps [7 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.06.2014 at 13:53:42,72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-06-2014
Ran by olga müller (administrator) on OLGAMÜLLER-PC on 09-06-2014 13:55:09
Running from C:\Users\olga müller\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Sphinx Software) C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallService.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Sphinx Software) C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallControl.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [Windows7FirewallControl] => C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallControl.exe [802816 2012-04-12] (Sphinx Software)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1057920 2012-07-31] (SEIKO EPSON CORPORATION)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoComputersNearMe] 0
HKU\.DEFAULT\...\Run: [Advanced SystemCare 7] => "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\Policies\Explorer: [NoNetHood] 0
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\Policies\Explorer: [NoComputersNearMe] 0
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: F - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {05baa77b-fa26-11e2-8109-0022192d7826} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {511a24be-8641-11e2-857e-0022192d7826} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {511a24cc-8641-11e2-857e-0022192d7826} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {56bb9e79-965f-11e2-a5ba-0022192d7826} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {65602795-ed58-11e3-9668-001e101f859f} - I:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {656027a4-ed58-11e3-9668-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {656027b5-ed58-11e3-9668-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {656027c2-ed58-11e3-9668-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {656027d3-ed58-11e3-9668-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {656027e1-ed58-11e3-9668-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {656027ec-ed58-11e3-9668-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {8d07f3f9-8a8b-11e2-8488-0022192d7826} - F:\AutoRun.exe
HKU\S-1-5-21-4158558861-3850249873-1972377515-1000\...\MountPoints2: {a6bf979a-97cd-11e2-b276-0022192d7826} - F:\AutoRun.exe
==================== Internet (Whitelisted) ====================
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Ads Removal - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll No File
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\olga müller\AppData\Roaming\Mozilla\Firefox\Profiles\1xfda83j.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Ads Removal) - C:\Users\olga müller\AppData\Local\Google\Chrome\User Data\Default\Extensions\fopdddcinljmpmioaklghcalngfhbaen [2014-04-02]
==================== Services (Whitelisted) =================
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [671744 2013-02-05] ()
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [174088 2014-05-29] (Sandboxie Holdings, LLC)
R2 Windows7FirewallService; C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallService.exe [495616 2012-04-12] (Sphinx Software)
S2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [X]
S2 vToolbarUpdater14.0.1; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [37720 2014-06-02] (AVG Technologies)
S3 dc21x4vm; C:\Windows\System32\DRIVERS\dc21x4vm.sys [57344 2009-06-10] (Microsoft Corp.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-06] (DT Soft Ltd)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [245248 2013-04-10] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-09] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [185352 2014-05-29] (Sandboxie Holdings, LLC)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
S4 FileMonitor; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [X]
S3 RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [X]
S3 UrlFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-09 13:55 - 2014-06-09 13:55 - 00011846 _____ () C:\Users\olga müller\Desktop\FRST.txt
2014-06-09 13:53 - 2014-06-09 13:53 - 00002823 _____ () C:\Users\olga müller\Desktop\JRT.txt
2014-06-09 13:48 - 2014-06-09 13:48 - 00000000 ____D () C:\Windows\ERUNT
2014-06-09 13:46 - 2014-06-09 13:46 - 01016261 _____ (Thisisu) C:\Users\olga müller\Desktop\JRT.exe
2014-06-09 13:44 - 2014-06-09 13:44 - 00006158 _____ () C:\Users\olga müller\Desktop\AdwCleaner[S8].txt
2014-06-09 13:38 - 2014-06-09 13:38 - 01333465 _____ () C:\Users\olga müller\Desktop\adwcleaner_3.212.exe
2014-06-09 13:27 - 2014-06-09 13:27 - 00000000 ____D () C:\Users\olga müller\AppData\Roaming\EurekaLog
2014-06-09 13:26 - 2014-06-09 13:26 - 00000000 ____D () C:\Users\olga müller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2014-06-09 13:26 - 2014-06-09 13:26 - 00000000 ____D () C:\Program Files\Unlocker
2014-06-09 13:25 - 2014-06-09 13:25 - 01078591 _____ () C:\Users\olga müller\Downloads\Unlocker1.9.2.exe
2014-06-09 13:11 - 2014-06-09 13:11 - 00000000 ____D () C:\Windows\Tasks\ImCleanDisabled
2014-06-08 16:43 - 2014-06-09 13:55 - 00000000 ____D () C:\FRST
2014-06-08 16:42 - 2014-06-08 16:42 - 02072576 _____ (Farbar) C:\Users\olga müller\Desktop\FRST64.exe
2014-06-08 16:38 - 2014-06-09 13:43 - 00001766 _____ () C:\Windows\PFRO.log
2014-06-08 16:38 - 2014-06-09 13:43 - 00000336 _____ () C:\Windows\setupact.log
2014-06-08 16:38 - 2014-06-08 16:38 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-08 16:35 - 2014-06-08 16:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\olga müller\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-08 16:33 - 2013-03-05 14:49 - 00002697 _____ () C:\Users\olga müller\Desktop\Microsoft Office Word 2007.lnk
2014-06-08 16:17 - 2014-06-08 16:30 - 00000255 _____ () C:\Users\olga müller\Desktop\Trojaner-Board info.txt
2014-06-07 23:18 - 2014-06-07 23:22 - 00000000 ____D () C:\ProgramData\ProductData
2014-06-07 23:18 - 2014-06-07 23:18 - 00000000 ____D () C:\Users\olga müller\AppData\Roaming\Apple Computer
2014-06-07 23:18 - 2014-06-07 23:18 - 00000000 ____D () C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-06-06 15:48 - 2014-06-06 15:48 - 00001212 _____ () C:\Users\Public\Desktop\Internet Manager.lnk
2014-06-06 15:48 - 2014-06-06 15:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager
2014-06-06 15:48 - 2014-06-06 15:48 - 00000000 ____D () C:\ProgramData\Internet Manager
2014-06-06 15:48 - 2013-04-10 10:47 - 00245248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys
2014-06-06 15:48 - 2013-03-21 03:57 - 00453632 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys
2014-06-06 15:48 - 2013-03-04 10:32 - 00110592 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys
2014-06-06 15:48 - 2013-03-04 10:32 - 00091648 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys
2014-06-06 15:48 - 2013-03-04 10:32 - 00077312 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys
2014-06-06 15:48 - 2013-03-04 10:32 - 00030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys
2014-06-06 15:48 - 2013-03-04 10:21 - 00226048 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys
2014-06-06 15:48 - 2013-01-25 03:16 - 00109568 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys
2014-06-06 15:48 - 2012-12-22 03:46 - 00014976 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys
2014-06-06 15:48 - 2010-10-08 10:59 - 00032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys
2014-06-06 15:48 - 2010-09-26 12:09 - 00022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys
2014-06-06 15:48 - 2010-08-06 01:43 - 01001472 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys
2014-06-06 13:37 - 2014-06-06 13:37 - 00000000 ____D () C:\Program Files (x86)\T-Mobile
2014-06-06 13:33 - 2014-06-06 13:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf
2014-06-06 13:33 - 2014-06-06 13:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf
2014-06-05 18:35 - 2013-03-15 12:14 - 00001312 _____ () C:\Users\olga müller\Desktop\PlantsVsZombies - Verknüpfung.lnk
2014-06-05 18:29 - 2014-06-05 18:29 - 05718872 _____ (Microsoft Corporation) C:\Users\olga müller\Downloads\vcredist_x64.exe
2014-06-05 18:25 - 2014-06-05 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2014-06-05 18:23 - 2014-06-05 18:23 - 02656264 _____ (Sandboxie Holdings, LLC) C:\Users\olga müller\Downloads\SandboxieInstall.exe
2014-06-04 10:43 - 2014-06-04 10:43 - 00000000 __SHD () C:\Users\olga müller\AppData\Local\EmieUserList
2014-06-04 10:43 - 2014-06-04 10:43 - 00000000 __SHD () C:\Users\olga müller\AppData\Local\EmieSiteList
2014-05-28 14:09 - 2014-05-28 14:09 - 00000000 ____D () C:\Users\olga müller\AppData\Local\Apps\2.0
2014-05-19 12:13 - 2014-06-03 00:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-17 18:54 - 2014-06-09 13:47 - 01604514 _____ () C:\Windows\WindowsUpdate.log
2014-05-16 17:12 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-16 17:12 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-16 17:12 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-16 17:12 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-16 17:12 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-16 17:12 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-16 11:23 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-16 11:23 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-16 11:23 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-16 11:23 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-16 11:23 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-16 11:22 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-16 11:22 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-16 11:22 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-16 11:22 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-16 11:22 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-16 11:22 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-16 11:22 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-16 11:22 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-16 11:22 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-16 11:22 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-16 11:22 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-16 11:22 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-16 11:22 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-16 11:22 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-16 11:22 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-16 11:22 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-16 11:22 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-16 11:22 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-16 11:22 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-16 11:22 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-16 11:22 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-16 11:22 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-16 11:22 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-16 11:22 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-16 11:22 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-16 11:14 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-16 11:14 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
==================== One Month Modified Files and Folders =======
2014-06-09 13:55 - 2014-06-09 13:55 - 00011846 _____ () C:\Users\olga müller\Desktop\FRST.txt
2014-06-09 13:55 - 2014-06-08 16:43 - 00000000 ____D () C:\FRST
2014-06-09 13:55 - 2013-03-05 17:59 - 00000000 ____D () C:\Users\olga müller\AppData\Local\Temp
2014-06-09 13:53 - 2014-06-09 13:53 - 00002823 _____ () C:\Users\olga müller\Desktop\JRT.txt
2014-06-09 13:50 - 2009-07-14 06:45 - 00021696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-09 13:50 - 2009-07-14 06:45 - 00021696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-09 13:48 - 2014-06-09 13:48 - 00000000 ____D () C:\Windows\ERUNT
2014-06-09 13:48 - 2011-04-12 09:43 - 00696620 _____ () C:\Windows\system32\perfh007.dat
2014-06-09 13:48 - 2011-04-12 09:43 - 00147916 _____ () C:\Windows\system32\perfc007.dat
2014-06-09 13:48 - 2009-07-14 07:13 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-09 13:47 - 2014-05-17 18:54 - 01604514 _____ () C:\Windows\WindowsUpdate.log
2014-06-09 13:46 - 2014-06-09 13:46 - 01016261 _____ (Thisisu) C:\Users\olga müller\Desktop\JRT.exe
2014-06-09 13:44 - 2014-06-09 13:44 - 00006158 _____ () C:\Users\olga müller\Desktop\AdwCleaner[S8].txt
2014-06-09 13:43 - 2014-06-08 16:38 - 00001766 _____ () C:\Windows\PFRO.log
2014-06-09 13:43 - 2014-06-08 16:38 - 00000336 _____ () C:\Windows\setupact.log
2014-06-09 13:43 - 2014-03-31 13:10 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-09 13:43 - 2013-11-17 13:14 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-09 13:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-09 13:42 - 2014-04-02 18:42 - 00000000 ____D () C:\AdwCleaner
2014-06-09 13:38 - 2014-06-09 13:38 - 01333465 _____ () C:\Users\olga müller\Desktop\adwcleaner_3.212.exe
2014-06-09 13:34 - 2013-03-06 11:54 - 00000000 ____D () C:\ProgramData\TEMP
2014-06-09 13:34 - 2013-03-06 11:29 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-06-09 13:27 - 2014-06-09 13:27 - 00000000 ____D () C:\Users\olga müller\AppData\Roaming\EurekaLog
2014-06-09 13:27 - 2013-03-06 11:54 - 00000000 ____D () C:\Program Files (x86)\Your Uninstaller! 7
2014-06-09 13:26 - 2014-06-09 13:26 - 00000000 ____D () C:\Users\olga müller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2014-06-09 13:26 - 2014-06-09 13:26 - 00000000 ____D () C:\Program Files\Unlocker
2014-06-09 13:25 - 2014-06-09 13:25 - 01078591 _____ () C:\Users\olga müller\Downloads\Unlocker1.9.2.exe
2014-06-09 13:24 - 2013-05-19 16:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-09 13:19 - 2013-11-17 13:14 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-09 13:18 - 2013-03-06 11:35 - 00000000 ____D () C:\Program Files (x86)\CCleaner Professional
2014-06-09 13:16 - 2013-03-06 11:30 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-06-09 13:11 - 2014-06-09 13:11 - 00000000 ____D () C:\Windows\Tasks\ImCleanDisabled
2014-06-09 13:02 - 2014-01-05 15:02 - 00000911 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Update {DE4E382B-0006-4483-9119-FABAB407EA92}.job
2014-06-09 13:02 - 2014-01-05 15:02 - 00000725 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Invitation {DE4E382B-0006-4483-9119-FABAB407EA92}.job
2014-06-09 13:02 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-06-08 16:42 - 2014-06-08 16:42 - 02072576 _____ (Farbar) C:\Users\olga müller\Desktop\FRST64.exe
2014-06-08 16:38 - 2014-06-08 16:38 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-08 16:38 - 2014-03-31 13:09 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-08 16:37 - 2013-03-06 13:06 - 00001073 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-08 16:35 - 2014-06-08 16:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\olga müller\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-08 16:30 - 2014-06-08 16:17 - 00000255 _____ () C:\Users\olga müller\Desktop\Trojaner-Board info.txt
2014-06-07 23:22 - 2014-06-07 23:18 - 00000000 ____D () C:\ProgramData\ProductData
2014-06-07 23:21 - 2013-03-05 17:50 - 00000000 ____D () C:\Windows\Panther
2014-06-07 23:18 - 2014-06-07 23:18 - 00000000 ____D () C:\Users\olga müller\AppData\Roaming\Apple Computer
2014-06-07 23:18 - 2014-06-07 23:18 - 00000000 ____D () C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-06-07 23:18 - 2014-04-02 18:40 - 00000000 ____D () C:\Users\olga müller\AppData\Roaming\IObit
2014-06-07 23:18 - 2013-03-06 11:29 - 00000000 ____D () C:\ProgramData\IObit
2014-06-06 15:48 - 2014-06-06 15:48 - 00001212 _____ () C:\Users\Public\Desktop\Internet Manager.lnk
2014-06-06 15:48 - 2014-06-06 15:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager
2014-06-06 15:48 - 2014-06-06 15:48 - 00000000 ____D () C:\ProgramData\Internet Manager
2014-06-06 15:48 - 2013-03-06 12:37 - 00000000 ____D () C:\ProgramData\DatacardService
2014-06-06 15:45 - 2013-03-06 12:37 - 00000000 ____D () C:\Program Files (x86)\Mobile Partner
2014-06-06 13:37 - 2014-06-06 13:37 - 00000000 ____D () C:\Program Files (x86)\T-Mobile
2014-06-06 13:34 - 2013-03-06 11:20 - 00002446 _____ () C:\Windows\Sandboxie.ini
2014-06-06 13:33 - 2014-06-06 13:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf
2014-06-06 13:33 - 2014-06-06 13:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf
2014-06-06 12:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-05 18:43 - 2013-08-31 12:07 - 00000000 ____D () C:\Users\olga müller\Desktop\mbar
2014-06-05 18:29 - 2014-06-05 18:29 - 05718872 _____ (Microsoft Corporation) C:\Users\olga müller\Downloads\vcredist_x64.exe
2014-06-05 18:25 - 2014-06-05 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2014-06-05 18:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-05 18:23 - 2014-06-05 18:23 - 02656264 _____ (Sandboxie Holdings, LLC) C:\Users\olga müller\Downloads\SandboxieInstall.exe
2014-06-04 10:49 - 2013-03-06 17:17 - 00000000 ____D () C:\Users\olga müller\Documents\WB Games
2014-06-04 10:43 - 2014-06-04 10:43 - 00000000 __SHD () C:\Users\olga müller\AppData\Local\EmieUserList
2014-06-04 10:43 - 2014-06-04 10:43 - 00000000 __SHD () C:\Users\olga müller\AppData\Local\EmieSiteList
2014-06-03 11:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-06-03 00:09 - 2014-05-19 12:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-03 00:09 - 2013-03-05 17:59 - 00000000 ____D () C:\Users\olga müller\Tracing
2014-06-02 11:28 - 2013-06-06 16:50 - 00037720 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-06-02 11:25 - 2013-05-19 16:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 11:25 - 2013-03-23 17:58 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 11:25 - 2013-03-23 17:58 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 11:09 - 2013-06-13 13:30 - 00007597 _____ () C:\Users\olga müller\AppData\Local\resmon.resmoncfg
2014-05-28 14:09 - 2014-05-28 14:09 - 00000000 ____D () C:\Users\olga müller\AppData\Local\Apps\2.0
2014-05-20 15:27 - 2013-03-29 17:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-17 10:52 - 2013-06-06 16:50 - 00003242 _____ () C:\Windows\System32\Tasks\SidebarExecute
2014-05-16 17:12 - 2013-03-05 14:47 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-16 17:11 - 2013-08-08 15:23 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-16 17:10 - 2013-03-16 13:03 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-16 14:51 - 2013-03-05 17:59 - 00000000 ___RD () C:\Users\olga müller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 14:51 - 2013-03-05 17:59 - 00000000 ___RD () C:\Users\olga müller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 14:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-12 07:26 - 2014-03-31 13:09 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-03-31 13:09 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2013-03-06 11:33 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
Some content of TEMP:
====================
C:\Users\olga müller\AppData\Local\Temp\Quarantine.exe
C:\Users\olga müller\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-06-08 19:28
==================== End Of Log ============================ --- --- ---
Ich habe soweit alles deinstalliert bis auf microsoft security essentials und malwarebytes, wieso war da mse zweimal gelistet??
Wieso sind iobit Produkte so schlimm, ich hatte immer einen sehr guten Eindruck, aber Advanced System Care hatte jetzt schon viel Müll installiert, Surfing Protection, LiveUpdate...bei LiveUpdate z.B. weiss ich garnicht wie ich es wieder wegbekomme, und für was es überhaupt gut sein soll. |