Hallo,
ich habe alles befolgt und hoffentlich richtig gemacht. Jetzt kommen die ganzen Berichte.
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 09.07.2014 12:47:29, SYSTEM, RAMONA-HP, Protection, Malware Protection, Starting,
Protection, 09.07.2014 12:47:29, SYSTEM, RAMONA-HP, Protection, Malware Protection, Started,
Protection, 09.07.2014 12:47:30, SYSTEM, RAMONA-HP, Protection, Malicious Website Protection, Starting,
Protection, 09.07.2014 12:47:36, SYSTEM, RAMONA-HP, Protection, Malicious Website Protection, Started,
Update, 09.07.2014 12:47:50, SYSTEM, RAMONA-HP, Manual, Rootkit Database, 2014.2.20.1, 2014.7.7.1,
Update, 09.07.2014 12:48:00, SYSTEM, RAMONA-HP, Manual, Malware Database, 2014.3.4.9, 2014.7.9.3,
Protection, 09.07.2014 12:48:22, SYSTEM, RAMONA-HP, Protection, Refresh, Starting,
Protection, 09.07.2014 12:48:22, SYSTEM, RAMONA-HP, Protection, Malicious Website Protection, Stopping,
Protection, 09.07.2014 12:48:23, SYSTEM, RAMONA-HP, Protection, Malicious Website Protection, Stopped,
Protection, 09.07.2014 12:48:31, SYSTEM, RAMONA-HP, Protection, Refresh, Success,
Protection, 09.07.2014 12:48:31, SYSTEM, RAMONA-HP, Protection, Malicious Website Protection, Starting,
Protection, 09.07.2014 12:48:31, SYSTEM, RAMONA-HP, Protection, Malicious Website Protection, Started,
Detection, 09.07.2014 12:48:42, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, C:\Program Files\SupTab\SearchProtect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Detection, 09.07.2014 12:48:46, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files\suptab\searchprotect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Protection, 09.07.2014 12:48:47, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Error, 09.07.2014 12:48:47, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Detection, 09.07.2014 12:50:42, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files\suptab\searchprotect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Protection, 09.07.2014 12:50:42, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Error, 09.07.2014 12:50:42, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Detection, 09.07.2014 12:50:50, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files\suptab\searchprotect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Protection, 09.07.2014 12:50:50, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Error, 09.07.2014 12:50:50, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Detection, 09.07.2014 13:03:46, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files\suptab\searchprotect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Protection, 09.07.2014 13:03:47, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Error, 09.07.2014 13:03:47, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Detection, 09.07.2014 13:10:03, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files\suptab\searchprotect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Protection, 09.07.2014 13:10:03, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Error, 09.07.2014 13:10:03, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Detection, 09.07.2014 13:14:16, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files\suptab\searchprotect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Protection, 09.07.2014 13:14:16, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Error, 09.07.2014 13:14:16, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Detection, 09.07.2014 13:16:26, SYSTEM, RAMONA-HP, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files\suptab\searchprotect32.dll, Quarantine, [d5a249549edd76c03ffa9bf1e41de51b]
Protection, 09.07.2014 13:16:26, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
Error, 09.07.2014 13:16:26, SYSTEM, RAMONA-HP, Protection, SDKQuarantine, 1, Failed, c:\program files\suptab\searchprotect32.dll,
(end)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x86
Ran by Ramona on 09.07.2014 at 13:48:24,41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4256409248-1071207549-3705033787-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E58CDA9-3B21-4611-A859-26EE28950E61}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{75b4241f-171e-44a3-bf44-23613b6e3e03}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.07.2014 at 14:01:36,64
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AdwCleaner Logfile:
Code:
# AdwCleaner v3.215 - Bericht erstellt am 09/07/2014 um 13:29:01
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Ramona - RAMONA-HP
# Gestartet von : C:\Users\Ramona\Downloads\adwcleaner_3.215.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : ca82e1a5
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\END
Datei Gefunden : C:\windows\system32\roboot.exe
Ordner Gefunden : C:\Program Files\Ask.com
Ordner Gefunden : C:\Program Files\globalUpdate
Ordner Gefunden : C:\Program Files\Optimizer Pro
Ordner Gefunden : C:\Program Files\predm
Ordner Gefunden : C:\ProgramData\Babylon
Ordner Gefunden : C:\ProgramData\BitGuard
Ordner Gefunden : C:\ProgramData\eSafe
Ordner Gefunden : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Ordner Gefunden : C:\Users\Ramona\AppData\Local\globalUpdate
Ordner Gefunden : C:\Users\Ramona\AppData\Local\Temp\AirInstaller
Ordner Gefunden : C:\Users\Ramona\AppData\Local\Temp\AskSearch
Ordner Gefunden : C:\Users\Ramona\AppData\LocalLow\iac
Ordner Gefunden : C:\Users\Ramona\AppData\Roaming\Babylon
Ordner Gefunden : C:\Users\Ramona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Ordner Gefunden : C:\Users\Ramona\AppData\Roaming\Optimizer Pro
Ordner Gefunden : C:\Users\Ramona\AppData\Roaming\SupTab
Ordner Gefunden : C:\Users\Ramona\AppData\Roaming\Systweak
Ordner Gefunden : C:\Users\Ramona\Documents\Optimizer Pro
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Daten Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\SupTab\SEARCH~1.DLL
Schlüssel Gefunden : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\lyricsparty
Schlüssel Gefunden : HKCU\Software\BABSOLUTION
Schlüssel Gefunden : HKCU\Software\Delta
Schlüssel Gefunden : HKCU\Software\fe8a8be13deb44
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Schlüssel Gefunden : HKCU\Software\Optimizer Pro
Schlüssel Gefunden : HKCU\Software\TutoTag
Schlüssel Gefunden : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gefunden : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gefunden : HKLM\Software\aartemisSoftware
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{889F49D2-6CEA-40BE-BE5F-7217485F9745}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2561FD25-FE31-4E56-A120-AF7FEAAE3124}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gefunden : HKLM\Software\Delta
Schlüssel Gefunden : HKLM\Software\eSafeSecControl
Schlüssel Gefunden : HKLM\SOFTWARE\fe8a8be13deb44
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayerUpdater_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayerUpdater_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gefunden : HKLM\Software\SupDp
Schlüssel Gefunden : HKLM\Software\SupTab
Schlüssel Gefunden : HKLM\Software\systweak
Schlüssel Gefunden : HKLM\Software\Tutorials
Schlüssel Gefunden : HKLM\Software\Wpm
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Wert Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://istart.webssearches.com/web/?type=ds&ts=1403976004&from=tugs&uid=HitachiXHTS725025A9A364_100915PCK204VJJLVM5JX&q={searchTerms}
*************************
AdwCleaner[R0].txt - [9889 octets] - [09/07/2014 13:29:01]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [9949 octets] ##########
--- --- ---
AdwCleaner Logfile:
Code:
# AdwCleaner v3.215 - Bericht erstellt am 09/07/2014 um 13:30:36
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Ramona - RAMONA-HP
# Gestartet von : C:\Users\Ramona\Downloads\adwcleaner_3.215.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : ca82e1a5
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\ProgramData\eSafe
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Ordner Gelöscht : C:\Program Files\Ask.com
Ordner Gelöscht : C:\Program Files\globalUpdate
Ordner Gelöscht : C:\Program Files\Optimizer Pro
Ordner Gelöscht : C:\Program Files\predm
Ordner Gelöscht : C:\Users\Ramona\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Ramona\AppData\Local\Temp\AirInstaller
Ordner Gelöscht : C:\Users\Ramona\AppData\Local\Temp\AskSearch
Ordner Gelöscht : C:\Users\Ramona\AppData\LocalLow\iac
Ordner Gelöscht : C:\Users\Ramona\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Ramona\AppData\Roaming\Optimizer Pro
Ordner Gelöscht : C:\Users\Ramona\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Ramona\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Ramona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Ordner Gelöscht : C:\Users\Ramona\Documents\Optimizer Pro
Datei Gelöscht : C:\END
Datei Gelöscht : C:\windows\system32\roboot.exe
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayerUpdater_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayerUpdater_RASMANCS
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gelöscht : HKCU\Software\fe8a8be13deb44
Schlüssel Gelöscht : HKLM\SOFTWARE\fe8a8be13deb44
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{889F49D2-6CEA-40BE-BE5F-7217485F9745}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2561FD25-FE31-4E56-A120-AF7FEAAE3124}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Schlüssel Gelöscht : HKCU\Software\BABSOLUTION
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyricsparty
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\aartemisSoftware
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\eSafeSecControl
Schlüssel Gelöscht : HKLM\Software\SupDp
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\SupTab\SEARCH~1.DLL
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
*************************
AdwCleaner[R0].txt - [10029 octets] - [09/07/2014 13:29:01]
AdwCleaner[S0].txt - [9828 octets] - [09/07/2014 13:30:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9888 octets] ##########
--- --- ---
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:09-07-2014
Ran by Ramona (administrator) on RAMONA-HP on 09-07-2014 14:09:18
Running from C:\Users\Ramona\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QEX79I6E
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(SurfRight B.V.) C:\Program Files\HitmanPro.Alert\hmpalert.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\BCMWLTRY.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AEstSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
(McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Ramona\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [McAfee Managed Services Tray] => C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.Exe [476480 2010-02-17] (McAfee, Inc.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-05] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [NortonOnlineBackupReminder] => C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2013-03-27] (IDT, Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-26] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [6510592 2013-07-09] (Broadcom Corporation)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-14] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [FreePDF Assistant] => C:\Program Files\FreePDF_XP\fpassist.exe [374784 2014-01-09] (shbox.de)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [191016 2014-05-14] (Geek Software GmbH)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-06-24] (Hewlett-Packard)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\windows\System32\SPReview\SPReview.exe [280576 2013-03-21] (Microsoft Corporation)
HKU\S-1-5-21-4256409248-1071207549-3705033787-1001\...\Run: [HPAdvisorDock] => C:\Program Files\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
HKU\S-1-5-21-4256409248-1071207549-3705033787-1001\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Ramona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Ramona\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {93CBC2B5-1E09-4092-B1AD-55B4D89D4C20} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {531795A6-54C6-47E1-8ED6-34F290D57429} URL =
SearchScopes: HKCU - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL =
SearchScopes: HKCU - {93CBC2B5-1E09-4092-B1AD-55B4D89D4C20} URL = https://www.google.com/search?q={searchTerms}
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100909125144.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
Handler: myrm - {4D034FC3-013F-4b95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\myRmProt5.1.0.325.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{B7082FAA-CB62-4872-9106-E42DD88EDE45}] - C:\Program Files\McAfee\SiteAdvisor Enterprise
FF Extension: McAfee SiteAdvisor Enterprise - C:\Program Files\McAfee\SiteAdvisor Enterprise [2010-09-09]
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-06-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-26] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1028688 2014-06-26] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-14] (Avira Operations GmbH & Co. KG)
R2 hmpalertsvc; C:\Program Files\HitmanPro.Alert\hmpalert.exe [1876816 2014-04-09] (SurfRight B.V.)
R2 HP Support Assistant Service; C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard)
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Enterprise Service; C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe [222528 2009-08-07] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [170144 2010-02-04] (McAfee, Inc.)
R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [141792 2010-02-08] (McAfee, Inc.)
R2 myAgtSvc; C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe [282824 2010-02-17] (McAfee, Inc.)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [254034 2013-03-27] (IDT, Inc.)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [5217280 2013-07-09] (Broadcom Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [97648 2014-06-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R3 BCM42RLY; C:\windows\System32\drivers\BCM42RLY.sys [18536 2013-07-09] (Broadcom Corporation)
R3 btwampfl; C:\windows\System32\drivers\btwampfl.sys [297000 2010-07-14] (Broadcom Corporation.)
R2 hmpalert; C:\windows\System32\drivers\hmpalert.sys [75640 2014-04-09] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R3 mfeapfk; C:\windows\System32\drivers\mfeapfk.sys [95728 2010-02-08] (McAfee, Inc.)
R3 mfeavfk; C:\windows\System32\drivers\mfeavfk.sys [152736 2010-02-08] (McAfee, Inc.)
R3 mfebopk; C:\windows\System32\drivers\mfebopk.sys [51720 2010-02-08] (McAfee, Inc.)
R0 mfehidk; C:\windows\System32\drivers\mfehidk.sys [385184 2010-02-08] (McAfee, Inc.)
S3 mferkdet; C:\windows\System32\drivers\mferkdet.sys [83912 2010-02-08] (McAfee, Inc.)
R0 mfewfpk; C:\windows\System32\drivers\mfewfpk.sys [160912 2010-02-08] (McAfee, Inc.)
R3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-04-27] ()
R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2013-06-12] (Avira GmbH)
U3 mfeavfk01; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-09 14:07 - 2014-07-09 14:07 - 01074688 _____ (Farbar) C:\Users\Ramona\Downloads\FRST (1).exe
2014-07-09 14:01 - 2014-07-09 14:01 - 00001145 _____ () C:\Users\Ramona\Desktop\JRT.txt
2014-07-09 13:40 - 2014-07-09 13:40 - 01016261 _____ (Thisisu) C:\Users\Ramona\Downloads\JRT.exe
2014-07-09 13:40 - 2014-07-09 13:40 - 00000000 ____D () C:\windows\ERUNT
2014-07-09 13:28 - 2014-07-09 13:30 - 00000000 ____D () C:\AdwCleaner
2014-07-09 13:28 - 2014-07-09 13:28 - 01348263 _____ () C:\Users\Ramona\Downloads\adwcleaner_3.215.exe
2014-07-09 13:19 - 2014-07-09 13:19 - 00004785 _____ () C:\Users\Ramona\Desktop\mbam.txt
2014-07-09 12:47 - 2014-07-09 13:46 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-09 12:47 - 2014-07-09 12:47 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-09 12:46 - 2014-07-09 12:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-09 12:46 - 2014-07-09 12:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-09 12:46 - 2014-07-09 12:46 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-09 12:46 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-07-09 12:46 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-07-09 12:46 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-07-09 12:40 - 2014-07-09 12:45 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ramona\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-09 12:13 - 2014-07-09 12:13 - 00001226 _____ () C:\Users\Ramona\Desktop\Revo Uninstaller.lnk
2014-07-09 12:13 - 2014-07-09 12:13 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-09 12:12 - 2014-07-09 12:12 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Ramona\Downloads\revosetup95.exe
2014-07-08 14:35 - 2014-07-08 14:36 - 00025826 _____ () C:\Users\Ramona\Downloads\Addition.txt
2014-07-08 14:33 - 2014-07-09 14:09 - 00000000 ____D () C:\FRST
2014-07-08 14:33 - 2014-07-08 14:36 - 00031199 _____ () C:\Users\Ramona\Downloads\FRST.txt
2014-07-08 14:33 - 2014-07-08 14:33 - 01074688 _____ (Farbar) C:\Users\Ramona\Downloads\FRST.exe
2014-07-06 22:54 - 2014-07-06 22:54 - 00000146 _____ () C:\windows\system32\Avira.OE.ServiceHost.log
2014-06-28 19:23 - 2014-06-28 19:23 - 00000000 ____D () C:\Users\Ramona\AppData\Local\com
2014-06-26 14:27 - 2014-06-26 14:29 - 177255064 _____ () C:\Users\Ramona\Downloads\22.02. Sandras 13. Geburtstag.zip
2014-06-11 09:25 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-11 09:25 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-11 09:25 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-11 09:25 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-11 09:25 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-11 09:25 - 2014-05-30 10:28 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-11 09:25 - 2014-05-30 10:21 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-11 09:25 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-11 09:25 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 09:25 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-11 09:25 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-11 09:25 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-11 09:25 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-11 09:25 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-11 09:25 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-11 09:24 - 2014-06-08 10:48 - 00391680 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-11 09:24 - 2014-06-08 10:43 - 00302592 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-11 09:24 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-11 09:24 - 2014-05-30 11:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-11 09:24 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-11 09:24 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-11 09:24 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-11 09:24 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-11 09:24 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-11 09:24 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-11 09:24 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-11 09:24 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-11 09:24 - 2014-05-30 09:57 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-11 09:24 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-11 09:24 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-11 09:24 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-11 09:24 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-11 09:24 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-11 09:24 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-11 09:24 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-11 09:24 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 09:23 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
==================== One Month Modified Files and Folders =======
2014-07-09 14:09 - 2014-07-08 14:33 - 00000000 ____D () C:\FRST
2014-07-09 14:07 - 2014-07-09 14:07 - 01074688 _____ (Farbar) C:\Users\Ramona\Downloads\FRST (1).exe
2014-07-09 14:01 - 2014-07-09 14:01 - 00001145 _____ () C:\Users\Ramona\Desktop\JRT.txt
2014-07-09 13:55 - 2009-07-14 06:34 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-09 13:55 - 2009-07-14 06:34 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-09 13:53 - 2010-09-09 20:53 - 01620796 _____ () C:\windows\system32\PerfStringBackup.INI
2014-07-09 13:48 - 2014-05-07 08:21 - 00000000 ____D () C:\Users\Ramona\AppData\Roaming\DropboxMaster
2014-07-09 13:48 - 2013-05-21 20:12 - 00000000 ___RD () C:\Users\Ramona\Dropbox
2014-07-09 13:48 - 2013-05-21 20:06 - 00000000 ____D () C:\Users\Ramona\AppData\Roaming\Dropbox
2014-07-09 13:47 - 2014-04-09 10:48 - 00000000 ____D () C:\windows\CryptoGuard
2014-07-09 13:46 - 2014-07-09 12:47 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-09 13:43 - 2013-04-22 19:42 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-07-09 13:43 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-07-09 13:43 - 2009-07-14 06:39 - 00168623 _____ () C:\windows\setupact.log
2014-07-09 13:42 - 2013-02-20 17:38 - 01892655 _____ () C:\windows\WindowsUpdate.log
2014-07-09 13:40 - 2014-07-09 13:40 - 01016261 _____ (Thisisu) C:\Users\Ramona\Downloads\JRT.exe
2014-07-09 13:40 - 2014-07-09 13:40 - 00000000 ____D () C:\windows\ERUNT
2014-07-09 13:40 - 2013-04-22 19:42 - 00699056 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-07-09 13:40 - 2013-04-22 19:42 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 13:31 - 2010-09-09 21:57 - 00273718 _____ () C:\windows\PFRO.log
2014-07-09 13:30 - 2014-07-09 13:28 - 00000000 ____D () C:\AdwCleaner
2014-07-09 13:28 - 2014-07-09 13:28 - 01348263 _____ () C:\Users\Ramona\Downloads\adwcleaner_3.215.exe
2014-07-09 13:21 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\PLA
2014-07-09 13:19 - 2014-07-09 13:19 - 00004785 _____ () C:\Users\Ramona\Desktop\mbam.txt
2014-07-09 12:47 - 2014-07-09 12:47 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-09 12:47 - 2014-07-09 12:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-09 12:46 - 2014-07-09 12:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-09 12:46 - 2014-07-09 12:46 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-09 12:45 - 2014-07-09 12:40 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ramona\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-09 12:45 - 2014-05-26 19:18 - 00000000 ____D () C:\Program Files\gs
2014-07-09 12:13 - 2014-07-09 12:13 - 00001226 _____ () C:\Users\Ramona\Desktop\Revo Uninstaller.lnk
2014-07-09 12:13 - 2014-07-09 12:13 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-09 12:12 - 2014-07-09 12:12 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Ramona\Downloads\revosetup95.exe
2014-07-08 14:54 - 2013-03-03 00:59 - 00000000 ____D () C:\Users\Ramona\AppData\Roaming\SoftGrid Client
2014-07-08 14:36 - 2014-07-08 14:35 - 00025826 _____ () C:\Users\Ramona\Downloads\Addition.txt
2014-07-08 14:36 - 2014-07-08 14:33 - 00031199 _____ () C:\Users\Ramona\Downloads\FRST.txt
2014-07-08 14:33 - 2014-07-08 14:33 - 01074688 _____ (Farbar) C:\Users\Ramona\Downloads\FRST.exe
2014-07-08 10:34 - 2014-05-27 11:10 - 00465920 ___SH () C:\Users\Ramona\Desktop\Thumbs.db
2014-07-07 10:05 - 2010-09-09 21:09 - 00000000 ____D () C:\ProgramData\PDFC
2014-07-06 22:54 - 2014-07-06 22:54 - 00000146 _____ () C:\windows\system32\Avira.OE.ServiceHost.log
2014-07-06 20:24 - 2013-02-20 17:48 - 00000000 ____D () C:\ProgramData\WinZip
2014-07-06 20:14 - 2014-05-26 19:09 - 00000000 ____D () C:\ProgramData\FreePDF
2014-07-05 17:14 - 2013-03-19 18:32 - 00000324 _____ () C:\windows\Tasks\HPCeeScheduleForRamona.job
2014-07-02 14:07 - 2009-07-14 06:53 - 00032640 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-07-01 17:13 - 2013-03-26 17:56 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-07-01 17:13 - 2013-02-26 19:07 - 00000052 _____ () C:\windows\system32\DOErrors.log
2014-06-28 19:45 - 2013-02-20 18:03 - 00001413 _____ () C:\Users\Ramona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-28 19:23 - 2014-06-28 19:23 - 00000000 ____D () C:\Users\Ramona\AppData\Local\com
2014-06-26 14:29 - 2014-06-26 14:27 - 177255064 _____ () C:\Users\Ramona\Downloads\22.02. Sandras 13. Geburtstag.zip
2014-06-26 11:49 - 2013-06-12 11:59 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2014-06-12 15:21 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache
2014-06-11 17:38 - 2014-05-06 18:50 - 00000000 ___SD () C:\windows\system32\CompatTel
Some content of TEMP:
====================
C:\Users\Ramona\AppData\Local\Temp\air1038.exe
C:\Users\Ramona\AppData\Local\Temp\avgnt.exe
C:\Users\Ramona\AppData\Local\Temp\BackupSetup.exe
C:\Users\Ramona\AppData\Local\Temp\CpqMC.dll
C:\Users\Ramona\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxciiqt.dll
C:\Users\Ramona\AppData\Local\Temp\Extract.exe
C:\Users\Ramona\AppData\Local\Temp\HPHelpUpdater.exe
C:\Users\Ramona\AppData\Local\Temp\HPQSi.exe
C:\Users\Ramona\AppData\Local\Temp\Quarantine.exe
C:\Users\Ramona\AppData\Local\Temp\Resource.exe
C:\Users\Ramona\AppData\Local\Temp\SP49415.exe
C:\Users\Ramona\AppData\Local\Temp\SP50291.exe
C:\Users\Ramona\AppData\Local\Temp\SP51129.exe
C:\Users\Ramona\AppData\Local\Temp\SP51765.exe
C:\Users\Ramona\AppData\Local\Temp\SP52407.exe
C:\Users\Ramona\AppData\Local\Temp\SP57760.exe
C:\Users\Ramona\AppData\Local\Temp\sp58915.exe
C:\Users\Ramona\AppData\Local\Temp\SP60504.exe
C:\Users\Ramona\AppData\Local\Temp\sp64126.exe
C:\Users\Ramona\AppData\Local\Temp\uninst1.exe
C:\Users\Ramona\AppData\Local\Temp\UninstallHPSA.exe
C:\Users\Ramona\AppData\Local\Temp\UninstallHPTCA.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-08 18:31
==================== End Of Log ============================
--- --- ---