Ich habe doch gar keinen Google Chrom Browser. Nutze Mozilla Firefox.
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=a549ec4d5d412a47b5483f23585cc11e
# engine=18753
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=false
# utc_time=2014-06-17 01:42:13
# local_time=2014-06-17 03:42:13 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 100 92 760839 167433023 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 760921 43558932 0 0
# scanned=227687
# found=17
# cleaned=0
# scan_time=11577
sh=E0814D0F17EE1122F6D3507DC676030F8E1CC133 ft=1 fh=0e0f46db8e6ee8c4 vn="Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Renchen72\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir"
sh=25B9F4013FB34153FFA27E460D4B8594C79FE337 ft=1 fh=15384691e6094ee0 vn="Variante von Win32/HiddenStart.A potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\hstart.exe"
sh=7DE60A3AEAC96F7FA559D468D852FBDDA731391F ft=1 fh=3d20769bd48072ca vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\ApnIC.dll"
sh=DBA4D7540C69C6492D48E688A00B51387685F8A6 ft=1 fh=fb092140bceb8039 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\ApnStub.exe"
sh=140308EF85F243BA4D2AAC012B1017B47E52B89E ft=1 fh=ffd7fdcd47cd63f7 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\ApnToolbarInstaller.exe"
sh=44554E882D1DD6FBF71B6550B0687E3D9FD73711 ft=1 fh=b0638f029680e22d vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\AskPIP_FF_.exe"
sh=24EACADAF8910146B00A3B6146FAD19E11BFF03B ft=1 fh=5e1dc8d93e2d8e01 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-egypt.exe"
sh=34D77A23AA7C7648948E4BFAB31F33F517A785DC ft=1 fh=11cdaad78b073df2 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-japan.exe"
sh=D6AE522FF8806F7589D0FD0CC5D70B65B0B5E390 ft=1 fh=1211e94886f9a591 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-saudi-forf.exe"
sh=E5A3C100D2D0FD94482783AF2B2FF94CDFC9923F ft=1 fh=a0ddd0619a504a2e vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe"
sh=2860D062EC1AE1D58870818B4459F01E67541BFB ft=1 fh=1424bb462488f869 vn="Variante von Win32/ELEX.AJ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Renchen72\AppData\Local\Temp\29c2217fff8359d2c648e0ce94c6c82b\sweetpage294wld_n2.exe"
sh=44554E882D1DD6FBF71B6550B0687E3D9FD73711 ft=1 fh=b0638f029680e22d vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Users\Renchen72\AppData\Local\Temp\AskPIP_FF_.exe"
sh=2860D062EC1AE1D58870818B4459F01E67541BFB ft=1 fh=1424bb462488f869 vn="Variante von Win32/ELEX.AJ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Renchen72\AppData\Local\Temp\sweetpage294wld_n2.exe"
sh=6D259E8B7FC2A5CA3A960E76EC15A39B242F94F0 ft=1 fh=4a984638c41edfed vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Renchen72\Downloads\FFSetup3.2.1.0.exe"
sh=1447092BA29779C726829611180994E17718C412 ft=1 fh=23f22b72eb3a5b90 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Renchen72\Downloads\PDFCreator-1_7_2_setup_offline.exe"
sh=3D43A8D789987686A919F8DE25FE86D6C1024B2B ft=1 fh=21dcd790bca1e78e vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Renchen72\Downloads\Recuva-lnstall.exe"
sh=8BE4C277A62F2400C3B0A20F39297D310774E2AC ft=1 fh=d69c639933d87dfe vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Renchen72\Downloads\Setup21_FreeConverter.exe"
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-06-2014
Ran by Renchen72 (administrator) on RENCHEN on 17-06-2014 15:47:02
Running from C:\Users\Renchen72\Downloads
Platform: Windows 8 Pro (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\CxUtilSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpAgent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\SmartAudio3.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
(Farbar) C:\Users\Renchen72\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2780048 2012-11-01] (ELAN Microelectronics Corp.)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5757328 2012-10-19] (Dell Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SA3\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-04] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [143888 2012-06-01] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637528 2012-10-09] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-06] (AVAST Software)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3133595154-2642610443-1825705747-1001\...\Run: [LG LinkAir] => [X]
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com?fr=hp-avast&type=avastbcl
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://de.yahoo.com?fr=hp-avast&type=avastbcl
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com?fr=hp-avast&type=avastbcl
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {9F07D8F6-05C1-4997-9190-622A3BE0650C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDSJS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM-x32 - {9F07D8F6-05C1-4997-9190-622A3BE0650C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDSJS
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKCU - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKCU - {9F07D8F6-05C1-4997-9190-622A3BE0650C} URL =
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: HistoryTriggerBHO Class - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: No Name - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - No File
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM-x32 - No Name - {553891B7-A0D5-4526-BE18-D3CE461D6310} - No File
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Renchen72\AppData\Roaming\Mozilla\Firefox\Profiles\l8ruh2za.default-1402728366372
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Keyword.URL: https://de.search.yahoo.com/yhs/search
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent - C:\Program Files (x86)\DigitalPersona\Bin\ChromeExt\components\npChromeDPAgent.dll (DigitalPersona, Inc.)
FF SearchPlugin: C:\Users\Renchen72\AppData\Roaming\Mozilla\Firefox\Profiles\l8ruh2za.default-1402728366372\searchplugins\yahoo-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-05-07]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-12-27]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\DigitalPersona\Bin\ChromeExt\dpchrome.crx [2012-05-24]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-18] (AVAST Software)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2247992 2012-07-19] (Broadcom Corporation.)
R2 CxUtilSvc; C:\Program Files\Conexant\SA3\CxUtilSvc.exe [109184 2012-08-07] (Conexant Systems, Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
S2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-25] ()
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1915408 2013-10-10] (SoftThinks SAS)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S3 AndNetDiag; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\system32\DRIVERS\lgandnetndis64.sys [93696 2013-04-23] (LG Electronics Inc.)
S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-18] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-18] ()
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [164152 2012-07-19] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6824520 2012-07-10] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2012-08-05] (OSR Open Systems Resources, Inc.)
R3 LgBttPort; C:\Windows\system32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\Windows\System32\drivers\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\Windows\system32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-17] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 ST_ACCEL; C:\Windows\system32\DRIVERS\ST_Accel.sys [71832 2012-07-13] (STMicroelectronics)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2013-02-12] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-17 12:26 - 2014-06-17 12:26 - 02347384 _____ (ESET) C:\Users\Renchen72\Downloads\esetsmartinstaller_deu.exe
2014-06-17 10:43 - 2014-06-17 10:43 - 02081280 _____ (Farbar) C:\Users\Renchen72\Downloads\FRST64(1).exe
2014-06-17 10:40 - 2014-06-17 10:40 - 00001146 _____ () C:\Users\Renchen72\Desktop\mbam.txt
2014-06-17 10:16 - 2014-06-17 10:16 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-17 10:15 - 2014-06-17 10:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Renchen72\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-06-17 10:13 - 2014-06-17 10:13 - 00001163 _____ () C:\Users\Renchen72\Desktop\JRT.txt
2014-06-17 09:58 - 2014-06-17 09:58 - 01016261 _____ (Thisisu) C:\Users\Renchen72\Downloads\JRT.exe
2014-06-17 09:58 - 2014-06-17 09:58 - 00000000 ____D () C:\windows\ERUNT
2014-06-17 09:57 - 2014-06-17 09:57 - 00016381 _____ () C:\Users\Renchen72\Desktop\AdwCleaner[S0].txt
2014-06-17 09:49 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-06-17 09:48 - 2014-06-17 09:53 - 00000000 ____D () C:\AdwCleaner
2014-06-17 09:48 - 2014-06-17 09:48 - 01333465 _____ () C:\Users\Renchen72\Downloads\adwcleaner_3.212.exe
2014-06-17 09:39 - 2014-06-17 09:39 - 00001270 _____ () C:\Users\Renchen72\Desktop\Revo Uninstaller.lnk
2014-06-17 09:39 - 2014-06-17 09:39 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-17 09:38 - 2014-06-17 09:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Renchen72\Downloads\revosetup95.exe
2014-06-16 21:43 - 2014-06-16 21:44 - 00033996 _____ () C:\Users\Renchen72\Downloads\Addition.txt
2014-06-16 21:42 - 2014-06-17 15:47 - 00018034 _____ () C:\Users\Renchen72\Downloads\FRST.txt
2014-06-16 21:40 - 2014-06-17 15:47 - 00000000 ____D () C:\FRST
2014-06-16 21:39 - 2014-06-16 21:39 - 02081280 _____ (Farbar) C:\Users\Renchen72\Downloads\FRST64.exe
2014-06-16 20:38 - 2014-06-17 14:40 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-16 20:38 - 2014-06-17 10:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-16 20:38 - 2014-06-17 10:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-16 20:38 - 2014-06-16 20:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-16 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-06-16 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-06-16 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-06-16 20:37 - 2014-06-16 20:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Renchen72\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-16 09:56 - 2013-10-15 00:51 - 00000118 ____H () C:\DBAR_Ver.txt
2014-06-16 09:54 - 2014-06-16 09:54 - 00000000 ____D () C:\Users\Renchen72\AppData\Local\Adobe
2014-06-14 09:02 - 2014-06-14 09:02 - 00001165 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-14 09:02 - 2014-06-14 09:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-13 13:41 - 2014-06-13 13:41 - 01062800 _____ () C:\Users\Renchen72\Downloads\Recuva-lnstall.exe
2014-06-11 17:59 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-06-11 17:59 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-06-11 17:58 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-11 17:58 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-11 17:58 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-11 17:58 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2014-06-11 17:58 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\UXInit.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-11 17:58 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-11 17:58 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-11 17:58 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-11 17:58 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-11 17:58 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-11 17:58 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-11 17:58 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-11 17:58 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-11 17:58 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2014-06-11 17:58 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-11 17:58 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-11 17:58 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-11 17:58 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-11 17:58 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-06-11 17:58 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-11 17:58 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-11 17:58 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-11 17:58 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-11 17:58 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-11 17:58 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\uxtheme.dll
2014-06-11 17:58 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2014-06-11 17:58 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2014-06-11 17:58 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Classpnp.sys
2014-06-11 17:58 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2014-06-11 17:58 - 2014-04-01 00:08 - 00387268 _____ () C:\windows\system32\ApnDatabase.xml
2014-06-11 17:58 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\windows\SysWOW64\wusa.exe
2014-06-11 17:58 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\wusa.exe
2014-06-11 17:57 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-11 17:57 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-11 17:57 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-11 17:57 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-11 17:57 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-11 17:57 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-11 17:57 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-06-11 17:57 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-11 17:57 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-11 17:57 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-05-18 07:28 - 2014-05-18 07:28 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-05-18 07:28 - 2014-05-18 07:28 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
==================== One Month Modified Files and Folders =======
2014-06-17 15:47 - 2014-06-16 21:42 - 00018034 _____ () C:\Users\Renchen72\Downloads\FRST.txt
2014-06-17 15:47 - 2014-06-16 21:40 - 00000000 ____D () C:\FRST
2014-06-17 15:47 - 2013-05-03 12:55 - 00000000 ____D () C:\Users\Renchen72\AppData\Local\Temp
2014-06-17 15:44 - 2013-10-15 17:09 - 00000000 ____D () C:\Users\Renchen72\AppData\Roaming\ClassicShell
2014-06-17 15:22 - 2013-09-16 09:04 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-06-17 15:02 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\sru
2014-06-17 14:40 - 2014-06-16 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-17 12:26 - 2014-06-17 12:26 - 02347384 _____ (ESET) C:\Users\Renchen72\Downloads\esetsmartinstaller_deu.exe
2014-06-17 12:09 - 2013-05-03 18:57 - 00000000 ____D () C:\Users\Renchen72\Desktop\Pflegeplanungen Diakonie
2014-06-17 11:12 - 2013-05-03 12:54 - 01314329 _____ () C:\windows\WindowsUpdate.log
2014-06-17 10:43 - 2014-06-17 10:43 - 02081280 _____ (Farbar) C:\Users\Renchen72\Downloads\FRST64(1).exe
2014-06-17 10:40 - 2014-06-17 10:40 - 00001146 _____ () C:\Users\Renchen72\Desktop\mbam.txt
2014-06-17 10:16 - 2014-06-17 10:16 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-17 10:16 - 2014-06-16 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-17 10:16 - 2014-06-16 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-17 10:15 - 2014-06-17 10:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Renchen72\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-06-17 10:13 - 2014-06-17 10:13 - 00001163 _____ () C:\Users\Renchen72\Desktop\JRT.txt
2014-06-17 10:02 - 2013-01-29 04:36 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
2014-06-17 10:00 - 2012-07-26 12:27 - 00754172 _____ () C:\windows\system32\perfh007.dat
2014-06-17 10:00 - 2012-07-26 12:27 - 00156362 _____ () C:\windows\system32\perfc007.dat
2014-06-17 10:00 - 2012-07-26 09:28 - 01748838 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-17 09:58 - 2014-06-17 09:58 - 01016261 _____ (Thisisu) C:\Users\Renchen72\Downloads\JRT.exe
2014-06-17 09:58 - 2014-06-17 09:58 - 00000000 ____D () C:\windows\ERUNT
2014-06-17 09:57 - 2014-06-17 09:57 - 00016381 _____ () C:\Users\Renchen72\Desktop\AdwCleaner[S0].txt
2014-06-17 09:54 - 2013-01-29 04:09 - 00355130 _____ () C:\windows\PFRO.log
2014-06-17 09:54 - 2012-07-26 09:22 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-17 09:53 - 2014-06-17 09:48 - 00000000 ____D () C:\AdwCleaner
2014-06-17 09:53 - 2013-05-03 12:55 - 00001005 _____ () C:\Users\Renchen72\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-17 09:48 - 2014-06-17 09:48 - 01333465 _____ () C:\Users\Renchen72\Downloads\adwcleaner_3.212.exe
2014-06-17 09:46 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\AUInstallAgent
2014-06-17 09:46 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\BBI
2014-06-17 09:39 - 2014-06-17 09:39 - 00001270 _____ () C:\Users\Renchen72\Desktop\Revo Uninstaller.lnk
2014-06-17 09:39 - 2014-06-17 09:39 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-17 09:38 - 2014-06-17 09:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Renchen72\Downloads\revosetup95.exe
2014-06-16 21:44 - 2014-06-16 21:43 - 00033996 _____ () C:\Users\Renchen72\Downloads\Addition.txt
2014-06-16 21:39 - 2014-06-16 21:39 - 02081280 _____ (Farbar) C:\Users\Renchen72\Downloads\FRST64.exe
2014-06-16 20:38 - 2014-06-16 20:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-16 20:37 - 2014-06-16 20:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Renchen72\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-16 09:54 - 2014-06-16 09:54 - 00000000 ____D () C:\Users\Renchen72\AppData\Local\Adobe
2014-06-14 13:21 - 2013-05-03 14:42 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3133595154-2642610443-1825705747-1001
2014-06-14 09:02 - 2014-06-14 09:02 - 00001165 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-14 09:02 - 2014-06-14 09:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-14 09:02 - 2014-05-10 13:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-13 13:41 - 2014-06-13 13:41 - 01062800 _____ () C:\Users\Renchen72\Downloads\Recuva-lnstall.exe
2014-06-12 18:53 - 2013-09-16 09:04 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-06-11 21:43 - 2012-07-26 09:59 - 00000000 ____D () C:\windows\CbsTemp
2014-06-11 21:41 - 2013-08-18 20:57 - 00000000 ____D () C:\windows\system32\MRT
2014-06-11 21:38 - 2013-05-03 21:57 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-11 17:55 - 2013-05-07 19:25 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-06-08 20:20 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-08 20:20 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-08 20:20 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-06-08 20:20 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-06-04 18:37 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\NDF
2014-05-31 15:48 - 2013-05-03 19:06 - 02560512 _____ () C:\Users\Renchen72\Desktop\2014_SN_a_Excel.xls
2014-05-31 15:07 - 2013-05-03 19:06 - 00000000 ____D () C:\Users\Renchen72\Documents\Diakonie
2014-05-31 07:16 - 2013-11-15 23:21 - 00703992 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-05-31 07:16 - 2013-11-15 23:21 - 00105464 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-24 04:48 - 2014-06-11 17:58 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-24 04:47 - 2014-06-11 17:58 - 02239488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-24 04:47 - 2014-06-11 17:58 - 01366016 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-24 04:47 - 2014-06-11 17:58 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2014-05-24 04:47 - 2014-06-11 17:58 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\UXInit.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 19290112 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 15368704 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-24 04:46 - 2014-06-11 17:58 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-24 04:46 - 2014-06-11 17:57 - 03958784 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-24 04:46 - 2014-06-11 17:57 - 02650112 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-24 04:45 - 2014-06-11 17:58 - 01508864 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-24 04:45 - 2014-06-11 17:58 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-24 04:45 - 2014-06-11 17:58 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-24 03:26 - 2014-06-11 17:58 - 01766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-24 03:26 - 2014-06-11 17:58 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-24 03:26 - 2014-06-11 17:58 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-24 03:26 - 2014-06-11 17:58 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-24 03:26 - 2014-06-11 17:58 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2014-05-24 03:26 - 2014-06-11 17:57 - 14365696 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-24 03:26 - 2014-06-11 17:57 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-24 03:25 - 2014-06-11 17:58 - 13731328 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-24 03:25 - 2014-06-11 17:58 - 01440768 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-24 03:25 - 2014-06-11 17:58 - 00357888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-24 03:25 - 2014-06-11 17:58 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-24 03:25 - 2014-06-11 17:58 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-05-24 03:25 - 2014-06-11 17:58 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-24 03:25 - 2014-06-11 17:58 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-24 03:25 - 2014-06-11 17:58 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-24 03:25 - 2014-06-11 17:57 - 02862080 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-24 03:25 - 2014-06-11 17:57 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-24 03:25 - 2014-06-11 17:57 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-05-24 03:09 - 2014-06-11 17:58 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-24 03:03 - 2014-06-11 17:58 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-24 00:37 - 2014-06-11 17:58 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\uxtheme.dll
2014-05-19 09:45 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\ELAM
2014-05-18 19:45 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\rescache
2014-05-18 08:32 - 2013-05-03 19:06 - 00000000 ____D () C:\Users\Renchen72\Documents\Kinderstunde
2014-05-18 07:49 - 2013-05-03 12:55 - 00000000 ___RD () C:\Users\Renchen72\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-18 07:49 - 2013-05-03 12:55 - 00000000 ___RD () C:\Users\Renchen72\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-18 07:46 - 2012-07-26 10:12 - 00000000 ___RD () C:\windows\ToastData
2014-05-18 07:46 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\SecureBootUpdates
2014-05-18 07:46 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-05-18 07:45 - 2013-05-03 19:06 - 00000000 ____D () C:\Users\Renchen72\Documents\Word-Dokumente
2014-05-18 07:29 - 2014-02-20 15:54 - 00085328 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2014-05-18 07:29 - 2013-05-07 19:25 - 01039096 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2014-05-18 07:29 - 2013-05-07 19:25 - 00423240 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys
2014-05-18 07:28 - 2014-05-18 07:28 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-05-18 07:28 - 2014-05-18 07:28 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2014-05-18 07:28 - 2013-05-07 19:25 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-05-18 07:28 - 2013-05-07 19:25 - 00208416 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-05-18 07:28 - 2013-05-07 19:25 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-05-18 07:28 - 2013-05-07 19:25 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-05-18 07:28 - 2013-05-07 19:25 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
Some content of TEMP:
====================
C:\Users\Renchen72\AppData\Local\Temp\AskPIP_FF_.exe
C:\Users\Renchen72\AppData\Local\Temp\Execute2App.exe
C:\Users\Renchen72\AppData\Local\Temp\msvcp90.dll
C:\Users\Renchen72\AppData\Local\Temp\msvcr90.dll
C:\Users\Renchen72\AppData\Local\Temp\Quarantine.exe
C:\Users\Renchen72\AppData\Local\Temp\rcsetup151_slim.exe
C:\Users\Renchen72\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Renchen72\AppData\Local\Temp\sdapskill.exe
C:\Users\Renchen72\AppData\Local\Temp\sdaspwn.exe
C:\Users\Renchen72\AppData\Local\Temp\sweetpage294wld_n2.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-13 13:52
==================== End Of Log ============================
--- --- ---