[CMalwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 01.07.2014
Suchlauf-Zeit: 15:30:50
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.03.04.09
Rootkit Datenbank: v2014.07.01.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Marita
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 233540
Verstrichene Zeit: 22 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\updateBetterBrowse.exe, 312, Löschen bei Neustart, [5ced6d92e496c96d61a19402926fd52b]
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\utilBetterBrowse.exe, 1888, Löschen bei Neustart, [bf8a8a7562185bdbea184155e31e23dd]
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowse.BrowserAdapter.exe, 7512, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be]
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowse.PurBrowse64.exe, 2288, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be]
Module: 5
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowseBAApp.dll, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowseBAApp.dll, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\{d1377c30-1cf3-4e6f-ae8b-e1fab3664710}.dll, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\{d1377c30-1cf3-4e6f-ae8b-e1fab3664710}.dll, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\{d1377c30-1cf3-4e6f-ae8b-e1fab3664710}.dll, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
Registrierungsschlüssel: 45
PUP.Optional.BetterBrowse.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update BetterBrowse, In Quarantäne, [5ced6d92e496c96d61a19402926fd52b],
PUP.Optional.BetterBrowse.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util BetterBrowse, In Quarantäne, [bf8a8a7562185bdbea184155e31e23dd],
PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselive, In Quarantäne, [ab9ed32cc3b7c37352f356390ff232ce],
PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselivem, In Quarantäne, [ab9ed32cc3b7c37352f356390ff232ce],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SAVESENSELIVE.EXE, In Quarantäne, [ab9ed32cc3b7c37352f356390ff232ce],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SAVESENSELIVE.EXE, In Quarantäne, [ab9ed32cc3b7c37352f356390ff232ce],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [46036b94661458deb527b38c9e649a66],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [46036b94661458deb527b38c9e649a66],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [46036b94661458deb527b38c9e649a66],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [46036b94661458deb527b38c9e649a66],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [46036b94661458deb527b38c9e649a66],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [46036b94661458deb527b38c9e649a66],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [46036b94661458deb527b38c9e649a66],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [be8bc936daa05ed89f84e3912ed42ad6],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [be8bc936daa05ed89f84e3912ed42ad6],
PUP.Optional.SaveSense, HKU\S-1-5-21-4060787532-3131775629-3680099422-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{0F21B1E5-5AFC-43C9-9C66-515046E92EC2}, In Quarantäne, [eb5e936cf08a3cfa9aea55216c96b050],
PUP.Optional.SaveSense, HKU\S-1-5-21-4060787532-3131775629-3680099422-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{0F21B1E5-5AFC-43C9-9C66-515046E92EC2}, In Quarantäne, [eb5e936cf08a3cfa9aea55216c96b050],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\BetterBrowse, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass, In Quarantäne, [a5a4a45b6614fe3871626f4a58ab6799],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass.1, In Quarantäne, [f3565ba4bbbf063070634b6e7e85cf31],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService, In Quarantäne, [3f0a7887f5853cfac80b437608fb23dd],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [df6a98674634e3539f3488314db609f7],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc, In Quarantäne, [3a0ff00f7bff0c2ac013edcc28db17e9],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [0049fb04ee8ca690dcf73089ca39e21e],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\SaveSenseLive.exe, In Quarantäne, [32176c93d6a4979febe7befb30d3ef11],
PUP.Optional.BetterBrowse.A, HKLM\SOFTWARE\WOW6432NODE\BetterBrowse, In Quarantäne, [c78256a9e694de58e3ce7a3f7d86fc04],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\SaveSenseLive, In Quarantäne, [3217887753270a2c489006b3a85b09f7],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreClass, In Quarantäne, [53f6e8176812b284a72c2297bd469868],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreClass.1, In Quarantäne, [331642bd0773ef476b680dacea19d927],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService, In Quarantäne, [e267639c83f73afc399aae0ba65de21e],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [f257817e7dfdb18530a39d1c5da6b24e],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc, In Quarantäne, [3a0ff6097dfd89ad24af7f3a689bcc34],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [1633956a06745cda15bebcfdf70c33cd],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\SaveSenseLive.exe, In Quarantäne, [7ecb7b84e694a492706233865ba813ed],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=3, In Quarantäne, [14352ed19cdea19504d23f7a92712dd3],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=9, In Quarantäne, [6fda0ef114667fb7f9dd398010f3e41c],
PUP.Optional.BetterBrowse.A, HKU\S-1-5-21-4060787532-3131775629-3680099422-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BetterBrowse, In Quarantäne, [ab9e5ba48ded6fc7d2ded0e912f1a35d],
PUP.Optional.SaveSense.A, HKU\S-1-5-21-4060787532-3131775629-3680099422-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SaveSenseLive, In Quarantäne, [86c34eb1314953e352837d3c6b9805fb],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 20
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\TEMP, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\CrashReports, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Download, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Install, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Offline, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Offline\{84A9D62C-9C2A-4347-91F5-D7D12402E6B6}, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive, In Quarantäne, [8bbe08f7730749ed12ed93f43ac8f30d],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update, In Quarantäne, [8bbe08f7730749ed12ed93f43ac8f30d],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log, In Quarantäne, [8bbe08f7730749ed12ed93f43ac8f30d],
PUP.Optional.SaveSense, C:\Users\Marita\AppData\Roaming\SaveSense, In Quarantäne, [58f1699666144fe7956b790fd1314ab6],
PUP.Optional.SaveSense.A, C:\Users\Marita\AppData\Local\SaveSenseLive, In Quarantäne, [2d1c88773e3cdc5a70946820df2339c7],
PUP.Optional.SaveSense.A, C:\Users\Marita\AppData\Local\SaveSenseLive\CrashReports, In Quarantäne, [2d1c88773e3cdc5a70946820df2339c7],
PUP.Optional.NextLive.A, C:\Users\Marita\AppData\Roaming\newnext.me, In Quarantäne, [0148cf30bbbff244db6a444417eba957],
PUP.Optional.NextLive.A, C:\Users\Marita\AppData\Roaming\newnext.me\cache, In Quarantäne, [0148cf30bbbff244db6a444417eba957],
Dateien: 117
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\updateBetterBrowse.exe, Löschen bei Neustart, [5ced6d92e496c96d61a19402926fd52b],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\utilBetterBrowse.exe, Löschen bei Neustart, [bf8a8a7562185bdbea184155e31e23dd],
PUP.Optional.SaveSense.A, C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe, In Quarantäne, [ab9ed32cc3b7c37352f356390ff232ce],
PUP.Optional.NextLive.A, C:\Users\Marita\AppData\Local\Temp\Mobogenie_Setup_2.1.35_122100041.exe, In Quarantäne, [f85122dda9d175c1df886135d829bd43],
PUP.Optional.BetterBrowse.A, C:\Users\Marita\AppData\Local\Temp\BetterBrowseSetup.exe, In Quarantäne, [47025ea16e0cdb5be058c05e986cd62a],
PUP.Optional.SearchProtect.A, C:\Users\Marita\AppData\Local\Temp\nsz79AA.exe, In Quarantäne, [7ccdd52a205a51e593c1f972857cba46],
PUP.Optional.SearchProtect.A, C:\Users\Marita\AppData\Local\Temp\nsb71D9.exe, In Quarantäne, [c08934cb1f5bc96d351f3b30ad54db25],
PUP.Optional.SearchProtect.A, C:\Users\Marita\AppData\Local\Temp\nscC58.exe, In Quarantäne, [10399f60d1a95adcada7ef7cb150b54b],
PUP.Optional.SearchProtect.A, C:\Users\Marita\AppData\Local\Temp\nscF42B.exe, In Quarantäne, [3316e51aa4d6d561f85c145706fb58a8],
PUP.Optional.SearchProtect.A, C:\Users\Marita\AppData\Local\Temp\nss2753.exe, In Quarantäne, [f2575ea13e3ca98d58fcbdaee61b01ff],
PUP.Optional.SearchProtect.A, C:\Users\Marita\AppData\Local\Temp\nsx81C9.exe, In Quarantäne, [95b409f6e79332047adaa8c3e61bbc44],
PUP.Optional.SaveSense.A, C:\Users\Marita\AppData\Local\Temp\sas.exe, In Quarantäne, [41086c93700a1125c5b2acd84db427d9],
PUP.Optional.SaveSense.A, C:\Users\Marita\AppData\Local\Temp\SaveSenseUpdateVer.exe, In Quarantäne, [fe4bb24d02787abca356ceb112eed62a],
PUP.Optional.Conduit.A, C:\Users\Marita\AppData\Local\Temp\SPSetup.exe, In Quarantäne, [5beeb24d304a46f0b38dd98732cfd62a],
PUP.Optional.Conduit.A, C:\Users\Marita\AppData\Local\Temp\sp_downloader.exe, In Quarantäne, [5fea6699abcff6406e0e60fe4bb69b65],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nseEFDD.exe, In Quarantäne, [1f2a748b91e9d2645cf88fdca55cc040],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nso6510.exe, In Quarantäne, [8cbd5ca36b0fc076450fe784f20f44bc],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nst6445.exe, In Quarantäne, [66e367981c5e71c5b69ec3a8b34ee21e],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsuF20F.exe, In Quarantäne, [ea5f699601797db9c1933734728fed13],
PUP.Optional.BundleInstaller.A, C:\Users\Marita\Downloads\openoffice setup (1).exe, In Quarantäne, [42074ab5621878be35495f1b3ec341bf],
PUP.Optional.BundleInstaller.A, C:\Users\Marita\Downloads\openoffice setup.exe, In Quarantäne, [d27720df5129191d90ee93e758a9ef11],
PUP.Optional.RegCleanPro, C:\Users\Marita\Downloads\sysrc_trial_9407_german01.exe, In Quarantäne, [0d3c6b9455250c2a4234542ecc3428d8],
PUP.Optional.BundleInstaller.A, C:\Users\Marita\Downloads\windows live messenger formerly msn messenger setup.exe, In Quarantäne, [03467689394173c399e5fa8061a043bd],
PUP.Optional.NextLive.A, C:\Users\Marita\AppData\Local\genienext\nengine.dll, In Quarantäne, [163300ff5a20bc7a86e18d09d32ee818],
PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job, In Quarantäne, [0c3dda25215963d39cf5f5c47b8807f9],
PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job, In Quarantäne, [2e1bcc33bcbe082ea9e87346659e7888],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\BetterBrowse.ico, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\BetterBrowseUninstall.exe, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\updateBetterBrowse.InstallState, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\7za.exe, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowse.BrowserAdapter.exe, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowse.PurBrowse.zip, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowse.PurBrowse64.exe, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BetterBrowseBAApp.dll, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\BrowserAdapterS.7z, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\sqlite3.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\utilBetterBrowse.InstallState, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\{d1377c30-1cf3-4e6f-ae8b-e1fab3664710}.dll, Löschen bei Neustart, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.Bromon.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.BroStats.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.BrowserAdapterS.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.CompatibilityChecker.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.FFUpdate.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.GCUpdate.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.IEUpdate.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.OfSvc.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.PurBrowse.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\plugins\BetterBrowse.Repmon.dll, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\TEMP\mfs25DB.tmp, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.BetterBrowse.A, C:\Program Files (x86)\BetterBrowse\bin\TEMP\mfs25EC.tmp, In Quarantäne, [b495ca3505750f278c23675217ec42be],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_de.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_el.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_en-GB.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_en.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_es-419.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_es.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_et.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fa.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fi.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fil.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fr.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_gu.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hi.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hr.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hu.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_id.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_it.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_iw.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ja.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_kn.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ko.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_lt.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_lv.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ml.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_mr.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ms.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_nl.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_no.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pl.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-BR.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-PT.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ro.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdate.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_am.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ar.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_bg.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_bn.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ca.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_cs.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sk.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sl.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sr.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sv.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sw.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ta.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_te.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_th.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_tr.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_uk.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ur.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_vi.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-CN.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-TW.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psuser.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHelper.msi, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_da.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_is.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ru.dll, In Quarantäne, [5aef4bb45624f1455ca2e7a0738fbd43],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log\SaveSenseLive.log, In Quarantäne, [8bbe08f7730749ed12ed93f43ac8f30d],
PUP.Optional.NextLive.A, C:\Users\Marita\AppData\Roaming\newnext.me\nengine.cookie, In Quarantäne, [0148cf30bbbff244db6a444417eba957],
PUP.Optional.NextLive.A, C:\Users\Marita\AppData\Roaming\newnext.me\cache\spark.bin, In Quarantäne, [0148cf30bbbff244db6a444417eba957],
Physische Sektoren: 0
(No malicious items detected)
(end)ODE][/CODE]
[COAdwCleaner Logfile:
Code:
# AdwCleaner v3.214 - Bericht erstellt am 01/07/2014 um 16:18:48
# Aktualisiert 29/06/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Marita - MARITAPC
# Gestartet von : C:\Users\Marita\AppData\Local\Microsoft\Windows\INetCache\IE\2M2E6CW0\adwcleaner_3.214[1].exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Users\Marita\AppData\Local\genienext
Ordner Gelöscht : C:\Users\Marita\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Marita\AppData\Local\SearchProtect
Datei Gelöscht : C:\Users\Marita\daemonprocess.txt
Datei Gelöscht : C:\Users\Marita\AppData\Roaming\Mozilla\Firefox\Profiles\004v85vo.default\searchplugins\conduit-search.xml
Datei Gelöscht : C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKCU\Software\WEDLMNGR
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Marita\AppData\Roaming\Mozilla\Firefox\Profiles\004v85vo.default\prefs.js ]
-\\ Google Chrome v35.0.1916.114
[ Datei : C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.trovigo.com/Results.aspx?q={searchTerms}&Suggest=runk&stype=Homepage&useHistory=0&UP=SP1F7BAA3D-84A1-4CB1-B036-5D4D5F2A760C&UM=2&SelfSearch=1&SearchType=SearchWeb&SearchSource=55&ctid=CT3314759&octid=EB_ORIGINAL_CTID
Gelöscht [Startup_urls] : hxxp://search.conduit.com/?ctid=CT3314759&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP1F7BAA3D-84A1-4CB1-B036-5D4D5F2A760C&SSPV=
Gelöscht [Homepage] : hxxp://search.conduit.com/?ctid=CT3314759&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP1F7BAA3D-84A1-4CB1-B036-5D4D5F2A760C&SSPV=
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
*************************
AdwCleaner[R0].txt - [3267 octets] - [01/07/2014 16:15:09]
AdwCleaner[S0].txt - [3269 octets] - [01/07/2014 16:18:48]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3329 octets] ##########
--- --- ---
DE][/CODE]
[C~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Marita on 01.07.2014 at 16:29:48,14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Marita\AppData\Roaming\mozilla\firefox\profiles\004v85vo.default\minidumps [30 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.07.2014 at 17:03:05,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ODE][/CODE]
[C
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-06-2014
Ran by Marita (administrator) on MARITAPC on 01-07-2014 17:08:10
Running from C:\Users\Marita\Downloads
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\PHotkey\Atouch64.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\livecomm.exe
() C:\Program Files (x86)\PHotkey\POsd.exe
() C:\Program Files (x86)\PHotkey\GPMTray.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Dolby Laboratories Inc.) C:\Program Files\Dolby Digital Plus\ddp.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13653208 2013-09-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-30] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [280576 2013-09-29] (Realtek Semiconductor Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2777840 2013-08-14] (Synaptics Incorporated)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111576 2013-08-05] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [490760 2013-09-23] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-11] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2013-09-18] (CyberLink Corp.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-06-30] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1
HKU\S-1-5-21-4060787532-3131775629-3680099422-1001\...\Run: [GoogleChromeAutoLaunch_26FCAD50FEA4D2144FF64E2847F340EA] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-05-14] (Google Inc.)
HKU\S-1-5-21-4060787532-3131775629-3680099422-1001\...\Run: [Google Update] => C:\Users\Marita\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-12-14] (Google Inc.)
HKU\S-1-5-21-4060787532-3131775629-3680099422-1001\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
HKU\S-1-5-21-4060787532-3131775629-3680099422-1001\...\Run: [Yahoo! Search] => C:\Users\Marita\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.8.2\dsrlte.exe
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://rts.dsrlte.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {46F7DB3D-32D9-4EF6-BB40-577D4AEC6921} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB
SearchScopes: HKCU - {5A4594FC-845C-459F-B170-E3C42298628D} URL = hxxp://rts.dsrlte.com/?q={searchTerms}&r=377
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Marita\AppData\Roaming\Mozilla\Firefox\Profiles\004v85vo.default
FF NewTab: hxxp://rts.dsrlte.com/?m=tab
FF DefaultSearchEngine: Yahoo! Search
FF SearchEngineOrder.1: Microsoft (Bing)
FF SelectedSearchEngine: Yahoo! Search
FF Homepage: https://www.google.de/
FF Keyword.URL: hxxp://rts.dsrlte.com/?q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Marita\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Marita\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Marita\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Marita\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marita\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Marita\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\Marita\AppData\Roaming\Mozilla\Firefox\Profiles\004v85vo.default\searchplugins\bing-avast.xml
FF SearchPlugin: C:\Users\Marita\AppData\Roaming\Mozilla\Firefox\Profiles\004v85vo.default\searchplugins\keepmysearch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-12-15]
Chrome:
=======
CHR HomePage: hxxp://search.conduit.com/?ctid=CT3314759&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP1F7BAA3D-84A1-4CB1-B036-5D4D5F2A760C&SSPV=
CHR StartupUrls: "hxxp://search.conduit.com/?ctid=CT3314759&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP1F7BAA3D-84A1-4CB1-B036-5D4D5F2A760C&SSPV=", "hxxp://www.msn.com/?pc=AV01", "hxxp://rts.dsrlte.com"
CHR DefaultSearchKeyword: pay-by-ads.com
CHR DefaultSearchProvider: Yahoo! Search
CHR DefaultSearchURL: hxxp://rts.dsrlte.com/?q={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-14]
CHR Extension: (Google Drive) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-14]
CHR Extension: (YouTube) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-14]
CHR Extension: (Google-Suche) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-14]
CHR Extension: (avast! Online Security) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-12-16]
CHR Extension: (Hangouts) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2013-12-14]
CHR Extension: (Google Wallet) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-14]
CHR Extension: (Google Mail) - C:\Users\Marita\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-30]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-30] (AVAST Software)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [61440 2013-09-26] () [File not signed]
R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [74712 2013-03-11] (CyberLink)
R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [316376 2013-03-11] (CyberLink)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [160768 2013-06-27] () [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2013-03-06] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-30] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-30] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-06-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [426848 2014-06-30] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-06-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-06-30] ()
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-01] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 PegaRadioSwitch; C:\Windows\System32\drivers\PegaRadioSwitch.sys [23552 2013-08-22] (Windows (R) Win 7 DDK provider)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2013-10-22] ()
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [548056 2013-09-05] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-08-14] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-14] (Synaptics Incorporated)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [87568 2013-07-01] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
R1 {d1377c30-1cf3-4e6f-ae8b-e1fab3664710}w64; C:\Windows\System32\drivers\{d1377c30-1cf3-4e6f-ae8b-e1fab3664710}w64.sys [61120 2014-04-24] (StdLib)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-01 17:07 - 2014-07-01 17:07 - 00000000 ____D () C:\Users\Marita\Downloads\FRST-OlderVersion
2014-07-01 17:03 - 2014-07-01 17:03 - 00000882 _____ () C:\Users\Marita\Desktop\JRT.txt
2014-07-01 16:29 - 2014-07-01 16:29 - 00000000 ____D () C:\Windows\ERUNT
2014-07-01 16:16 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-01 16:09 - 2014-07-01 16:09 - 00029205 _____ () C:\Users\Marita\Desktop\mbam.txt
2014-07-01 15:29 - 2014-07-01 16:19 - 00000000 ____D () C:\AdwCleaner
2014-07-01 15:23 - 2014-07-01 16:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-01 15:23 - 2014-07-01 15:23 - 00001122 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-01 15:23 - 2014-07-01 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-01 15:23 - 2014-07-01 15:23 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-01 15:23 - 2014-07-01 15:23 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-01 15:23 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-01 15:23 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-01 15:23 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-01 14:54 - 2014-07-01 14:54 - 00001288 _____ () C:\Users\Marita\Desktop\Revo Uninstaller.lnk
2014-07-01 14:54 - 2014-07-01 14:54 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-01 14:52 - 2014-07-01 14:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2014-07-01 14:46 - 2014-07-01 14:47 - 17257912 _____ (Malwarebytes Corporation ) C:\Users\Marita\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-01 14:33 - 2014-07-01 14:33 - 02619300 _____ (VS Revo Group Ltd.) C:\Users\Marita\Downloads\revosetup95.exe
2014-06-30 18:03 - 2014-06-30 18:06 - 04875056 _____ (WinZip International LLC ) C:\Users\Marita\Downloads\wzmp_8.exe
2014-06-30 17:57 - 2014-06-30 17:57 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-29 12:32 - 2014-06-29 12:32 - 00003538 _____ () C:\Windows\System32\Tasks\Yahoo! Search
2014-06-29 12:32 - 2014-06-29 12:32 - 00000000 ____D () C:\Users\Marita\AppData\Local\Pay-By-Ads
2014-06-29 12:08 - 2014-06-29 12:08 - 00001151 _____ () C:\Users\Marita\Desktop\FRST.txt - Verknüpfung.lnk
2014-06-29 12:06 - 2014-06-29 12:06 - 00001191 _____ () C:\Users\Marita\Desktop\Addition.txt - Verknüpfung.lnk
2014-06-28 05:58 - 2014-06-28 05:58 - 00001872 _____ () C:\Users\Marita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! antivirus.lnk
2014-06-26 15:14 - 2014-06-26 15:16 - 00028086 _____ () C:\Users\Marita\Downloads\Addition.txt
2014-06-26 15:10 - 2014-07-01 17:08 - 00016751 _____ () C:\Users\Marita\Downloads\FRST.txt
2014-06-26 15:08 - 2014-07-01 17:08 - 00000000 ____D () C:\FRST
2014-06-26 15:07 - 2014-07-01 17:07 - 02083328 _____ (Farbar) C:\Users\Marita\Downloads\FRST64.exe
2014-06-23 19:57 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll
2014-06-23 19:57 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-06-23 19:57 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-06-23 19:57 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\energyprov.dll
2014-06-23 19:57 - 2014-04-18 11:32 - 13287936 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-06-23 19:57 - 2014-04-18 10:58 - 11792384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-06-23 19:57 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-06-23 19:57 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-06-23 19:57 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-06-23 19:57 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-06-23 19:57 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-06-23 19:57 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2014-06-23 19:57 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2014-06-23 19:57 - 2014-04-11 08:13 - 01200128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2014-06-23 19:57 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-06-23 19:57 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2014-06-23 19:57 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\defragsvc.dll
2014-06-23 19:57 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-23 19:57 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-06-23 19:57 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2014-06-23 19:57 - 2014-04-09 06:35 - 01411584 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-06-23 19:57 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2014-06-23 19:57 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-06-23 19:57 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-06-23 19:57 - 2014-04-06 18:34 - 00275800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-06-23 19:57 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2014-06-23 19:57 - 2014-04-06 18:31 - 21268952 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-06-23 19:57 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2014-06-23 19:57 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2014-06-23 19:57 - 2014-04-06 18:20 - 02140888 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-06-23 19:57 - 2014-04-06 18:20 - 00233912 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-06-23 19:57 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-06-23 19:57 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2014-06-23 19:57 - 2014-04-06 17:22 - 18755672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-06-23 19:57 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVideoDSP.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 02144984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-06-23 19:57 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-06-23 19:57 - 2014-04-06 16:10 - 04190720 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-06-23 19:57 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-06-23 19:57 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-06-23 19:57 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2014-06-23 19:57 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-06-23 19:57 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-06-23 19:57 - 2014-04-06 13:55 - 16872448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-06-23 19:57 - 2014-04-06 13:54 - 12711424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-06-23 19:57 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2014-06-23 19:57 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2014-06-23 19:57 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-06-23 19:57 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2014-06-23 19:57 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2014-06-23 19:57 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2014-06-23 19:57 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2014-06-23 19:57 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2014-06-23 19:57 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2014-06-23 19:57 - 2014-04-03 10:12 - 02124840 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-06-23 19:57 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-06-23 19:57 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2014-06-23 19:57 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-06-23 19:57 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2014-06-23 19:57 - 2014-04-03 05:53 - 01797896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2014-06-23 19:57 - 2014-04-03 04:53 - 04269056 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-06-23 19:57 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-23 19:57 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
2014-06-23 19:57 - 2014-04-03 04:23 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-06-23 19:57 - 2014-04-03 04:23 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-06-23 19:57 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tlscsp.dll
2014-06-23 19:57 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2014-06-23 19:57 - 2014-04-01 08:23 - 00384856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2014-06-23 19:57 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-06-23 19:57 - 2014-03-31 02:41 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d8thk.dll
2014-06-23 19:57 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersShell.dll
2014-06-23 19:57 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\Windows\system32\WorkfoldersControl.dll
2014-06-23 19:57 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2014-06-23 19:57 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2014-06-23 19:57 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2014-06-23 19:57 - 2014-03-31 00:11 - 00721408 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-06-23 19:57 - 2014-03-30 23:47 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-06-23 19:57 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2014-06-23 19:57 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-06-23 19:57 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2014-06-23 19:57 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2014-06-23 19:57 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2014-06-23 19:57 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2014-06-23 19:57 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-06-23 19:57 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll
2014-06-23 19:57 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2014-06-23 19:57 - 2014-03-25 00:58 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-06-23 19:57 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2014-06-23 19:57 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-06-23 19:57 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-06-23 19:57 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2014-06-23 19:57 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2014-06-23 19:57 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-06-23 19:57 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2014-06-23 19:57 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-06-23 19:57 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-06-23 19:57 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2014-06-23 19:57 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2014-06-23 19:57 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-06-23 19:57 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2014-06-23 19:57 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2014-06-23 19:57 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2014-06-23 19:57 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2014-06-23 19:57 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2014-06-23 19:57 - 2014-03-18 10:19 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-06-23 19:57 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2014-06-23 19:57 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2014-06-23 19:57 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-06-23 19:57 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-06-23 19:57 - 2014-03-17 05:01 - 00486912 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2014-06-23 19:57 - 2014-03-17 04:47 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-06-23 19:57 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2014-06-23 19:57 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\GeofenceMonitorService.dll
2014-06-23 19:57 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GeofenceMonitorService.dll
2014-06-23 19:57 - 2014-03-06 14:42 - 00310616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-06-23 19:56 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-23 19:56 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-23 19:56 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-23 19:56 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-23 19:56 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-23 19:56 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-23 19:56 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-23 19:56 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-23 19:56 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-23 19:56 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-23 19:56 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-23 19:56 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-23 19:56 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-23 19:56 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-23 19:56 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-23 19:56 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-23 19:56 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-23 19:56 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-23 19:56 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-23 19:56 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-23 19:56 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-23 19:56 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-23 19:56 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-23 19:56 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-23 19:56 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-23 19:56 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-23 19:56 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-23 19:56 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-23 19:56 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-23 15:42 - 2014-06-23 15:42 - 00000000 ____D () C:\Users\Marita\AppData\Local\Adobe
2014-06-20 15:14 - 2014-06-23 19:43 - 00000000 ____D () C:\Users\Marita\Downloads\Win81U
2014-06-20 15:11 - 2014-06-20 14:46 - 807793968 _____ () C:\Users\Marita\Downloads\Win81U.zip
2014-06-20 14:49 - 2014-06-20 14:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-06-17 17:10 - 2014-06-17 17:10 - 00000000 __SHD () C:\Users\Marita\AppData\Local\EmieUserList
2014-06-17 17:10 - 2014-06-17 17:10 - 00000000 __SHD () C:\Users\Marita\AppData\Local\EmieSiteList
2014-06-15 14:21 - 2014-06-15 14:21 - 04536336 _____ () C:\Users\Marita\Downloads\avira_de_av___ws.exe
2014-06-15 14:13 - 2014-06-15 14:14 - 29671984 _____ (Mozilla) C:\Users\Marita\Downloads\Firefox-Setup-30.0.exe
2014-06-14 13:02 - 2014-06-14 13:02 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-06-14 06:48 - 2014-04-03 09:59 - 02518872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-14 06:48 - 2014-04-03 09:59 - 00428888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-14 05:58 - 2014-05-01 15:31 - 03048904 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2014-06-14 05:58 - 2014-05-01 15:31 - 00055328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wpcfltr.sys
2014-06-14 05:58 - 2014-05-01 09:14 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-06-14 05:58 - 2014-05-01 09:05 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2014-06-14 05:58 - 2014-05-01 08:51 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-06-14 05:58 - 2014-05-01 07:24 - 02834944 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2014-06-13 17:36 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-13 17:17 - 2014-06-13 17:17 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-13 17:17 - 2014-06-13 17:17 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-13 17:17 - 2014-06-13 17:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-13 17:16 - 2014-06-13 17:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 20:56 - 2014-05-09 01:06 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-06-12 20:46 - 2014-04-30 06:43 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-06-12 20:46 - 2014-04-30 06:26 - 01345536 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-06-12 20:46 - 2014-04-30 05:47 - 01509888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-06-12 20:31 - 2014-05-10 05:46 - 02151424 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 20:31 - 2014-05-10 05:22 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 20:31 - 2014-05-03 09:14 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe
2014-06-12 20:31 - 2014-05-03 06:21 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-06-12 20:31 - 2014-05-03 06:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-06-12 20:31 - 2014-05-03 05:41 - 00921088 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-06-12 20:31 - 2014-05-03 05:38 - 00754688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-06-12 20:26 - 2014-04-30 13:16 - 01336648 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-12 20:26 - 2014-04-30 05:51 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-12 20:17 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\drvcfg.exe
2014-06-12 20:17 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe
2014-06-12 20:17 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
==================== One Month Modified Files and Folders =======
2014-07-01 17:08 - 2014-06-26 15:10 - 00016751 _____ () C:\Users\Marita\Downloads\FRST.txt
2014-07-01 17:08 - 2014-06-26 15:08 - 00000000 ____D () C:\FRST
2014-07-01 17:07 - 2014-07-01 17:07 - 00000000 ____D () C:\Users\Marita\Downloads\FRST-OlderVersion
2014-07-01 17:07 - 2014-06-26 15:07 - 02083328 _____ (Farbar) C:\Users\Marita\Downloads\FRST64.exe
2014-07-01 17:03 - 2014-07-01 17:03 - 00000882 _____ () C:\Users\Marita\Desktop\JRT.txt
2014-07-01 17:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-07-01 16:58 - 2013-12-14 16:23 - 00001142 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4060787532-3131775629-3680099422-1001UA.job
2014-07-01 16:57 - 2013-12-12 20:17 - 00003934 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0F1CE9E0-BBD0-4D75-93AA-2B513D5EF18D}
2014-07-01 16:45 - 2013-12-12 20:10 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4060787532-3131775629-3680099422-1001
2014-07-01 16:43 - 2013-12-14 16:13 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-01 16:40 - 2013-12-12 20:04 - 00952101 _____ () C:\Users\Marita\AppData\Local\BTServer.log
2014-07-01 16:34 - 2014-02-23 08:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-01 16:29 - 2014-07-01 16:29 - 00000000 ____D () C:\Windows\ERUNT
2014-07-01 16:22 - 2013-12-14 16:14 - 00002199 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-01 16:22 - 2013-12-12 20:06 - 00000000 ____D () C:\Users\Marita\Documents\Youcam
2014-07-01 16:21 - 2013-12-14 16:13 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-01 16:21 - 2013-12-12 20:08 - 00000000 __RDO () C:\Users\Marita\SkyDrive
2014-07-01 16:20 - 2014-07-01 15:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-01 16:20 - 2013-10-07 07:06 - 00046832 _____ () C:\Windows\PFRO.log
2014-07-01 16:20 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-01 16:19 - 2014-07-01 15:29 - 00000000 ____D () C:\AdwCleaner
2014-07-01 16:19 - 2013-12-12 20:02 - 00000000 ____D () C:\Users\Marita
2014-07-01 16:19 - 2013-12-12 19:56 - 01723979 _____ () C:\Windows\WindowsUpdate.log
2014-07-01 16:19 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-07-01 16:14 - 2013-08-22 16:46 - 00065923 _____ () C:\Windows\setupact.log
2014-07-01 16:12 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-07-01 16:09 - 2014-07-01 16:09 - 00029205 _____ () C:\Users\Marita\Desktop\mbam.txt
2014-07-01 15:23 - 2014-07-01 15:23 - 00001122 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-01 15:23 - 2014-07-01 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-01 15:23 - 2014-07-01 15:23 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-01 15:23 - 2014-07-01 15:23 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-01 15:20 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-07-01 14:58 - 2013-12-14 16:23 - 00001090 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4060787532-3131775629-3680099422-1001Core.job
2014-07-01 14:54 - 2014-07-01 14:54 - 00001288 _____ () C:\Users\Marita\Desktop\Revo Uninstaller.lnk
2014-07-01 14:54 - 2014-07-01 14:54 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-01 14:52 - 2014-07-01 14:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2014-07-01 14:47 - 2014-07-01 14:46 - 17257912 _____ (Malwarebytes Corporation ) C:\Users\Marita\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-01 14:33 - 2014-07-01 14:33 - 02619300 _____ (VS Revo Group Ltd.) C:\Users\Marita\Downloads\revosetup95.exe
2014-07-01 05:34 - 2013-08-22 15:25 - 00000292 _____ () C:\Windows\win.ini
2014-06-30 18:06 - 2014-06-30 18:03 - 04875056 _____ (WinZip International LLC ) C:\Users\Marita\Downloads\wzmp_8.exe
2014-06-30 17:58 - 2013-12-15 08:16 - 00001986 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-06-30 17:57 - 2014-06-30 17:57 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-30 17:57 - 2014-05-02 19:21 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-30 17:57 - 2014-01-04 16:38 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-06-30 17:57 - 2013-12-15 08:16 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-06-30 17:57 - 2013-12-15 08:16 - 00426848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-06-30 17:57 - 2013-12-15 08:16 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-30 17:57 - 2013-12-15 08:16 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-30 17:57 - 2013-12-15 08:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-30 17:57 - 2013-12-15 08:16 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-30 17:57 - 2013-12-15 08:16 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-30 17:57 - 2013-12-15 08:16 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-29 12:32 - 2014-06-29 12:32 - 00003538 _____ () C:\Windows\System32\Tasks\Yahoo! Search
2014-06-29 12:32 - 2014-06-29 12:32 - 00000000 ____D () C:\Users\Marita\AppData\Local\Pay-By-Ads
2014-06-29 12:08 - 2014-06-29 12:08 - 00001151 _____ () C:\Users\Marita\Desktop\FRST.txt - Verknüpfung.lnk
2014-06-29 12:06 - 2014-06-29 12:06 - 00001191 _____ () C:\Users\Marita\Desktop\Addition.txt - Verknüpfung.lnk
2014-06-28 07:40 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-28 05:58 - 2014-06-28 05:58 - 00001872 _____ () C:\Users\Marita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! antivirus.lnk
2014-06-27 15:38 - 2013-12-14 16:13 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-27 15:38 - 2013-12-14 16:13 - 00003864 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-26 19:40 - 2013-12-15 08:20 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 19:40 - 2013-12-15 08:20 - 00001155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 15:16 - 2014-06-26 15:14 - 00028086 _____ () C:\Users\Marita\Downloads\Addition.txt
2014-06-23 20:20 - 2014-01-18 20:19 - 00056832 ___SH () C:\Users\Marita\Downloads\Thumbs.db
2014-06-23 20:13 - 2013-10-07 07:32 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2014-06-23 20:13 - 2013-10-07 07:32 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2014-06-23 20:13 - 2013-10-07 07:11 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-23 20:07 - 2013-08-22 16:44 - 00380720 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-23 20:05 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-06-23 20:05 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2014-06-23 20:05 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\system32\oobe
2014-06-23 19:43 - 2014-06-20 15:14 - 00000000 ____D () C:\Users\Marita\Downloads\Win81U
2014-06-23 15:42 - 2014-06-23 15:42 - 00000000 ____D () C:\Users\Marita\AppData\Local\Adobe
2014-06-22 14:53 - 2013-12-14 16:23 - 00004090 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4060787532-3131775629-3680099422-1001UA
2014-06-22 14:53 - 2013-12-14 16:23 - 00003710 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4060787532-3131775629-3680099422-1001Core
2014-06-20 14:49 - 2014-06-20 14:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-06-20 14:46 - 2014-06-20 15:11 - 807793968 _____ () C:\Users\Marita\Downloads\Win81U.zip
2014-06-19 16:04 - 2014-02-15 16:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-18 19:44 - 2013-12-14 15:54 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-18 19:40 - 2013-10-07 08:12 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-17 17:10 - 2014-06-17 17:10 - 00000000 __SHD () C:\Users\Marita\AppData\Local\EmieUserList
2014-06-17 17:10 - 2014-06-17 17:10 - 00000000 __SHD () C:\Users\Marita\AppData\Local\EmieSiteList
2014-06-15 14:21 - 2014-06-15 14:21 - 04536336 _____ () C:\Users\Marita\Downloads\avira_de_av___ws.exe
2014-06-15 14:14 - 2014-06-15 14:13 - 29671984 _____ (Mozilla) C:\Users\Marita\Downloads\Firefox-Setup-30.0.exe
2014-06-14 13:02 - 2014-06-14 13:02 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-06-14 05:53 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2014-06-13 17:17 - 2014-06-13 17:17 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-13 17:17 - 2014-06-13 17:17 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-13 17:17 - 2014-06-13 17:17 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-13 17:17 - 2014-06-13 17:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-13 17:17 - 2014-06-13 17:17 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-13 17:17 - 2014-06-13 17:16 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-09 05:53 - 2013-12-14 16:24 - 00000000 ____D () C:\Users\Marita\AppData\Roaming\Mozilla
2014-06-04 18:25 - 2014-05-07 18:26 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-06-04 18:22 - 2013-12-12 20:04 - 00000000 ____D () C:\Users\Marita\AppData\Roaming\Adobe
2014-06-01 06:15 - 2014-05-07 18:24 - 00000000 ____D () C:\ProgramData\Adobe
Some content of TEMP:
====================
C:\Users\Marita\AppData\Local\Temp\AppLauncher.exe
C:\Users\Marita\AppData\Local\Temp\icqsetup.exe
C:\Users\Marita\AppData\Local\Temp\ntdll.dll
C:\Users\Marita\AppData\Local\Temp\obexpf.dll
C:\Users\Marita\AppData\Local\Temp\Quarantine.exe
C:\Users\Marita\AppData\Local\Temp\{1E3015E6-B1C4-421F-AE8E-5E92BB2E7064}-35.0.1916.153_chrome_installer.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-28 07:26
==================== End Of Log ============================
--- --- ---
--- --- ---
ODE][/CODE]