Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.09.2014
Suchlauf-Zeit: 08:23:51
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.15.03
Rootkit Datenbank: v2014.09.13.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Jonas
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 379927
Verstrichene Zeit: 19 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe, 1476, Löschen bei Neustart, [ea0512db0a7169cdea6c485169984fb1]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 23
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsProtectManger, In Quarantäne, [ea0512db0a7169cdea6c485169984fb1],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\Plus-HD-5.0, In Quarantäne, [717e18d50972ae88623037fdb1522dd3],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsProtectManger, In Quarantäne, [23ccb637d7a40f27e38f898439ca05fb],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [9d526d80fe7d290d2a80203cb2522cd4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, In Quarantäne, [43ac5796601b88aed7ee47baa36056aa],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [14dbd914d7a4350103f5da27887bbf41],
PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantäne, [836c32bb5922af874f0ece61cf3428d8],
PUP.Optional.GreenerWeb.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Greener Web, In Quarantäne, [38b7ba332259e94d35a8a86a798a4fb1],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-5.0, Löschen bei Neustart, [47a8af3e34473204f139c362e91acb35],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Löschen bei Neustart, [22cd905da6d563d337377fdd49bb04fc],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-5.0, Löschen bei Neustart, [618efdf0b6c58bab79b150d5847f56aa],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [6887e7068fec8fa71fafa78a798ab050],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [af407a733d3eed49f0398fb92fd5ba46],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD, Löschen bei Neustart, [22cd3ab33843a98d5cc627db58abb050],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110411771118}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411771118}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440444774418}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550455775518}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660466776618}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550455775518}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660466776618}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440444774418}, In Quarantäne, [6e8127c67b00ab8b6291649f7c896799],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110411771118}, Löschen bei Neustart, [6e8127c67b00ab8b6291649f7c896799],
Registrierungswerte: 5
PUP.Optional.NextLive.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NextLive, C:\WINDOWS\SysWOW64\rundll32.exe "C:\Users\Jonas\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l, Löschen bei Neustart, [707f509deb90f83e9ec690d4d62b14ec]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, In Quarantäne, [43ac5796601b88aed7ee47baa36056aa]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [14dbd914d7a4350103f5da27887bbf41]
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSPROTECTMANGER|ImagePath, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe -service, In Quarantäne, [e30cb23b38432e0864538888996a30d0]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-60212469-607860961-1350188199-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0E2Z1U1R1I1R2W0Q, Löschen bei Neustart, [af407a733d3eed49f0398fb92fd5ba46]
Registrierungsdaten: 4
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}),Ersetzt,[e40b09e4fd7e9b9be95744ba8d77de22]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}),Ersetzt,[4ba40fdeb8c3ef47e040b73c12f27090]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}),Ersetzt,[628d925bf58667cf96aa6a9417edf50b]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403020304&from=cor&uid=TOSHIBAXMQ01ABD100_33AMT08XTXX33AMT08XT&q={searchTerms}),Ersetzt,[7c73a34a1d5e52e44dd314df01038f71]
Ordner: 10
PUP.Optional.NextLive.A, C:\Users\Jonas\AppData\Roaming\newnext.me, In Quarantäne, [826dab42f784ca6cd3cf09c9ac56bf41],
PUP.Optional.NextLive.A, C:\Users\Jonas\AppData\Roaming\newnext.me\cache, In Quarantäne, [826dab42f784ca6cd3cf09c9ac56bf41],
PUP.Optional.PlusHD.A, C:\Users\Jonas\AppData\LocalLow\Plus-HD-5.0, In Quarantäne, [38b72ac3cdae2d09e2d890471de5be42],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [876814d9a7d488aebbf9ebfb04fe4bb5],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [876814d9a7d488aebbf9ebfb04fe4bb5],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, Löschen bei Neustart, [f0ff24c93b402610302b10d7c939619f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log, In Quarantäne, [f0ff24c93b402610302b10d7c939619f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update, In Quarantäne, [f0ff24c93b402610302b10d7c939619f],
PUP.Optional.Updater.A, C:\Users\Jonas\AppData\Roaming\DigitalSites\UpdateProc, In Quarantäne, [41aed01d0d6e13233d7f43ab857dfb05],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [23cc915c7a01033385bdee01b15157a9],
Dateien: 28
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe, Löschen bei Neustart, [ea0512db0a7169cdea6c485169984fb1],
PUP.Optional.NextLive.A, C:\Users\Jonas\AppData\Roaming\newnext.me\nengine.dll, In Quarantäne, [707f509deb90f83e9ec690d4d62b14ec],
PUP.Optional.NextLive.A, C:\Program Files (x86)\Mobogenie\nengine.dll, In Quarantäne, [7e71c9241f5c84b21a4a2044758c7c84],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, In Quarantäne, [19d68667047787af1298c4d1cd34b947],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [b83701ec42390a2c4b360134748c1ee2],
PUP.Optional.NextLive.A, C:\Users\Jonas\AppData\Local\Temp\is1590112554\281522604_stp\Mobogenie_Setup_UN.exe, In Quarantäne, [fbf49d5088f34ee80d57e87c89784bb5],
PUP.Optional.ScramblePacker.A, C:\Users\Jonas\AppData\Local\Temp\is1590112554\287225010_stp\plus-hd-5-0.exe, In Quarantäne, [48a7b33a7506f343e3173952010011ef],
PUP.Optional.InstallCore, C:\Users\Jonas\Downloads\UltimateCodec.exe, In Quarantäne, [0de2f0fdc7b40234e3b8ed7cea17e41c],
PUP.Optional.JumpyApps, C:\Users\Jonas\Downloads\DownloadManagerSetup.exe, In Quarantäne, [ab440edf106bc76f753aa5ae6a97d12f],
PUP.Optional.NextLive.A, C:\Users\Jonas\AppData\Local\genienext\nengine.dll, In Quarantäne, [1ad5f1fca3d8a096521222421ee3cb35],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-5.0-chromeinstaller.job, In Quarantäne, [b13e9756423975c10e52d733aa5939c7],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-5.0-codedownloader.job, In Quarantäne, [4da2f7f67308f44291cf17f3a45fed13],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-5.0-enabler.job, In Quarantäne, [3fb0e10ca1da9d9907593ccec43f738d],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-5.0-firefoxinstaller.job, In Quarantäne, [cc234da0c9b2bb7b481845c56b9837c9],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-5.0-updater.job, In Quarantäne, [15da717c3c3f7fb72a36c5459d663bc5],
PUP.Optional.PlusHD.A, C:\Windows\System32\Tasks\Plus-HD-5.0-chromeinstaller, In Quarantäne, [707fcc21fa813df92041ff0b7a89b749],
PUP.Optional.PlusHD.A, C:\Windows\System32\Tasks\Plus-HD-5.0-codedownloader, In Quarantäne, [45aaab42611a9c9a7be6bb4f0bf80ff1],
PUP.Optional.PlusHD.A, C:\Windows\System32\Tasks\Plus-HD-5.0-enabler, In Quarantäne, [c728f7f63b4085b1570aca4010f3c33d],
PUP.Optional.PlusHD.A, C:\Windows\System32\Tasks\Plus-HD-5.0-firefoxinstaller, In Quarantäne, [87689c51ff7c45f192cfbf4b56ad1ee2],
PUP.Optional.PlusHD.A, C:\Windows\System32\Tasks\Plus-HD-5.0-updater, In Quarantäne, [d21dc32a92e90c2a21400ffbdc2741bf],
PUP.Optional.DoSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\dosearches.xml, In Quarantäne, [cd2238b56d0e0d29c032c487eb19857b],
PUP.Optional.NextLive.A, C:\Users\Jonas\AppData\Roaming\newnext.me\nengine.cookie, In Quarantäne, [826dab42f784ca6cd3cf09c9ac56bf41],
PUP.Optional.NextLive.A, C:\Users\Jonas\AppData\Roaming\newnext.me\cache\spark.bin, In Quarantäne, [826dab42f784ca6cd3cf09c9ac56bf41],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log\wprotectmanager_2014-06-17[17-52-22-053].log, In Quarantäne, [f0ff24c93b402610302b10d7c939619f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update\conf, In Quarantäne, [f0ff24c93b402610302b10d7c939619f],
PUP.Optional.Updater.A, C:\Users\Jonas\AppData\Roaming\DigitalSites\UpdateProc\config.dat, In Quarantäne, [41aed01d0d6e13233d7f43ab857dfb05],
PUP.Optional.Updater.A, C:\Users\Jonas\AppData\Roaming\DigitalSites\UpdateProc\prod.dat, In Quarantäne, [41aed01d0d6e13233d7f43ab857dfb05],
PUP.Optional.CrossRider.A, C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\2yv9wnyj.default-1383766581564\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "146c4a51853b6e67cd99132d78c0fbca");), Ersetzt,[19d64da05f1c4ee8e3c24de36a9bbd43]
Physische Sektoren: 0
(No malicious items detected)
(end) Erstmal das MBAM Dokument Code:
# AdwCleaner v3.310 - Bericht erstellt am 15/09/2014 um 08:54:56
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Jonas - DER_GAMER
# Gestartet von : C:\Users\Jonas\Downloads\AdwCleaner_3.310.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\NCH Software
Ordner Gelöscht : C:\Program Files (x86)\GreenTree Applications
Ordner Gelöscht : C:\Program Files (x86)\JustCloud
Ordner Gelöscht : C:\Program Files (x86)\Mobogenie
Ordner Gelöscht : C:\Program Files (x86)\NCH Software
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Users\Jonas\AppData\Local\genienext
Ordner Gelöscht : C:\Users\Jonas\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Jonas\AppData\Local\Temp\Greener Web
Ordner Gelöscht : C:\Users\Jonas\AppData\Roaming\DigitalSites
Ordner Gelöscht : C:\Users\Jonas\AppData\Roaming\NCH Software
Ordner Gelöscht : C:\Users\Jonas\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Jonas\AppData\Local\Software
Datei Gelöscht : C:\Users\Jonas\daemonprocess.txt
Datei Gelöscht : C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\m2t56xl3.default-1383682422130\user.js
***** [ Tasks ] *****
Task Gelöscht : Digital Sites
Task Gelöscht : FoxTab
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422772218}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422772218}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Vittalia
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\SoftwareUpdater
Schlüssel Gelöscht : HKLM\SOFTWARE\Vittalia
Schlüssel Gelöscht : HKLM\SOFTWARE\Wpm
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17278
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\2yv9wnyj.default-1383766581564\prefs.js ]
Zeile gelöscht : user_pref("extensions.a8c6c8c1521d74f628a57202aee8f7fb36567ba21e4354eb0838d8395b2265c30com47718.47718.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Zeile gelöscht : user_pref("extensions.aJLPQ94732309TRY102138975com62056.62056.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "146c4a51853b6e67cd99132d78c0fbca");
[ Datei : C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\m2t56xl3.default-1383682422130\prefs.js ]
*************************
AdwCleaner[R0].txt - [2839 octets] - [06/11/2013 20:48:11]
AdwCleaner[R1].txt - [4683 octets] - [15/09/2014 08:53:34]
AdwCleaner[S0].txt - [1943 octets] - [06/11/2013 20:48:47]
AdwCleaner[S1].txt - [4294 octets] - [15/09/2014 08:54:56]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4354 octets] ########## Dann Das Dokument vom AdwCleaner Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Jonas on 15.09.2014 at 9:03:11,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted the following from C:\Users\Jonas\AppData\Roaming\mozilla\firefox\profiles\2yv9wnyj.default-1383766581564\prefs.js
user_pref("extensions.aJLPQ94732309TRY102138975com62056.62056.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%
Emptied folder: C:\Users\Jonas\AppData\Roaming\mozilla\firefox\profiles\2yv9wnyj.default-1383766581564\minidumps [16 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.09.2014 at 9:06:31,82
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Das JRT Dokument
[CODE]
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Jonas (administrator) on DER_GAMER on 15-09-2014 12:14:13
Running from C:\Users\Jonas\Downloads
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Thisisu) C:\Users\Jonas\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Farbar) C:\Users\Jonas\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2876304 2013-01-18] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-07-30] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [131712 2013-01-25] ( (Atheros Communications))
HKU\S-1-5-21-60212469-607860961-1350188199-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1939136 2014-08-28] (Valve Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logo Calibration Loader.lnk
ShortcutTarget: Logo Calibration Loader.lnk -> C:\Program Files (x86)\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe (LOGO Kommunikations- und Drucktechnik GmbH & Co. KG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ProfileReminder.lnk
ShortcutTarget: ProfileReminder.lnk -> C:\Program Files (x86)\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe (LOGO Kommunikations- und Drucktechnik GmbH & Co. KG)
Startup: C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Jonas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKCU - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0E4C1769-3A1F-4285-95C1-4CD737D999C6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM-x32 - {0E4C1769-3A1F-4285-95C1-4CD737D999C6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - {0E4C1769-3A1F-4285-95C1-4CD737D999C6} URL =
BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-00A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO-x32: No Name -> {41564952-412D-5637-00A7-7A786E7484D7} -> No File
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Tcpip\Parameters: [DhcpNameServer] 192.168.20.1
FireFox:
========
FF ProfilePath: C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\2yv9wnyj.default-1383766581564
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Plus-HD-5.0c - C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\2yv9wnyj.default-1383766581564\Extensions\JLPQ94732309@TRY102138975.com [2014-07-27]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-09-11]
CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-09-11]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1021520 2014-07-30] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-08-22] (APN LLC.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-25] (Qualcomm Atheros Commnucations)
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-14] (Avira Operations GmbH & Co. KG)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-19] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-01-30] (Intel Corporation)
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-03-15] (Acer Incorporate)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-08] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [42040 2014-07-26] (Avira Operations GmbH & Co. KG)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-24] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-15] (Malwarebytes Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-15 09:06 - 2014-09-15 09:06 - 00001351 _____ () C:\Users\Jonas\Desktop\JRT.txt
2014-09-15 09:02 - 2014-09-15 09:02 - 01016261 _____ (Thisisu) C:\Users\Jonas\Downloads\JRT.exe
2014-09-15 08:54 - 2014-09-15 08:55 - 00004446 _____ () C:\Users\Jonas\Desktop\AdwCleaner[S1].txt
2014-09-15 08:52 - 2014-09-15 08:53 - 01373475 _____ () C:\Users\Jonas\Downloads\AdwCleaner_3.310.exe
2014-09-15 08:51 - 2014-09-15 08:51 - 00012670 _____ () C:\Users\Jonas\Desktop\mbam.txt
2014-09-15 08:22 - 2014-09-15 08:49 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-15 08:22 - 2014-09-15 08:22 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-15 08:22 - 2014-09-15 08:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-15 08:22 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-09-15 08:22 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-09-15 08:22 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-09-15 08:19 - 2014-08-15 02:36 - 00146752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2014-09-15 08:16 - 2014-09-15 08:20 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Jonas\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 08:14 - 2014-09-13 08:14 - 00047837 _____ () C:\FRST.txt
2014-09-13 08:11 - 2014-09-13 08:11 - 02105856 _____ (Farbar) C:\Users\Jonas\Downloads\FRST64(1).exe
2014-09-13 05:01 - 2014-09-13 05:01 - 00000244 _____ () C:\Users\Jonas\Downloads\defogger_enable.log
2014-09-13 05:00 - 2014-09-13 05:01 - 00000472 _____ () C:\Users\Jonas\Downloads\defogger_disable.log
2014-09-13 05:00 - 2014-09-13 05:00 - 00050477 _____ () C:\Users\Jonas\Downloads\Defogger.exe
2014-09-13 04:35 - 2014-09-14 23:22 - 00040695 _____ () C:\Users\Jonas\Downloads\Addition.txt
2014-09-13 04:34 - 2014-09-15 12:14 - 00016284 _____ () C:\Users\Jonas\Downloads\FRST.txt
2014-09-13 04:34 - 2014-09-15 12:14 - 00000000 ____D () C:\FRST
2014-09-13 04:33 - 2014-09-13 04:33 - 02105856 _____ (Farbar) C:\Users\Jonas\Downloads\FRST64.exe
2014-09-12 08:14 - 2014-08-16 04:40 - 23591424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-09-12 08:14 - 2014-08-16 04:04 - 17455104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-09-12 08:14 - 2014-08-16 04:00 - 05833728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-09-12 08:14 - 2014-08-16 04:00 - 02793984 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-09-12 08:14 - 2014-08-16 03:56 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-09-12 08:14 - 2014-08-16 03:54 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-09-12 08:14 - 2014-08-16 03:45 - 04232704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-09-12 08:14 - 2014-08-16 03:43 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-09-12 08:14 - 2014-08-16 03:32 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-09-12 08:14 - 2014-08-16 03:25 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-12 08:14 - 2014-08-16 03:22 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-09-12 08:14 - 2014-08-16 03:20 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-09-12 08:14 - 2014-08-16 03:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-09-12 08:14 - 2014-08-16 03:18 - 02185728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-09-12 08:14 - 2014-08-16 03:18 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-09-12 08:14 - 2014-08-16 03:11 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-09-12 08:14 - 2014-08-16 03:06 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-09-12 08:14 - 2014-08-16 03:05 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-09-12 08:14 - 2014-08-16 03:05 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-09-12 08:14 - 2014-08-16 03:03 - 02104832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-09-12 08:14 - 2014-08-16 03:03 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-09-12 08:14 - 2014-08-16 02:58 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-12 08:14 - 2014-08-16 02:56 - 02310656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-09-12 08:14 - 2014-08-16 02:53 - 13588480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-09-12 08:14 - 2014-08-16 02:53 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-09-12 08:14 - 2014-08-16 02:53 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-09-12 08:14 - 2014-08-16 02:51 - 11769856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-09-12 08:14 - 2014-08-16 02:45 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-09-12 08:14 - 2014-08-16 02:44 - 02014208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-09-12 08:14 - 2014-08-16 02:44 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-09-12 08:14 - 2014-08-16 02:34 - 01447424 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-09-12 08:14 - 2014-08-16 02:20 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-09-12 08:14 - 2014-08-16 02:18 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-09-12 08:14 - 2014-08-16 02:14 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-09-12 08:14 - 2014-08-16 02:12 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-09-11 07:13 - 2014-08-02 02:18 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2014-09-11 07:08 - 2014-07-24 05:20 - 00875688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2014-09-11 07:08 - 2014-07-24 05:20 - 00869544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-07 04:56 - 2014-09-07 04:56 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-09-07 04:56 - 2014-09-07 04:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-09-07 04:55 - 2014-09-07 04:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-07 04:55 - 2014-09-07 04:56 - 00000000 ____D () C:\Program Files\iTunes
2014-09-07 04:55 - 2014-09-07 04:56 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-09-07 04:55 - 2014-09-07 04:55 - 00000000 ____D () C:\Program Files\iPod
2014-08-30 08:07 - 2014-08-23 02:42 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-30 08:07 - 2014-08-07 04:12 - 01336624 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-08-30 08:07 - 2014-08-02 05:56 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-08-21 03:34 - 2014-09-10 02:45 - 00000000 ____D () C:\Users\Jonas\AppData\Local\Spotify
2014-08-21 03:34 - 2014-08-21 03:34 - 00001856 _____ () C:\Users\Jonas\Desktop\Spotify.lnk
2014-08-21 03:34 - 2014-08-21 03:34 - 00001842 _____ () C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-08-21 03:33 - 2014-09-14 10:16 - 00000000 ____D () C:\Users\Jonas\AppData\Roaming\Spotify
2014-08-21 03:31 - 2014-08-21 03:31 - 00127136 _____ (Spotify Ltd) C:\Users\Jonas\Downloads\SpotifySetup.exe
2014-08-20 04:09 - 2014-09-02 22:06 - 00706016 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-08-20 04:09 - 2014-09-02 22:06 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-19 06:49 - 2014-08-19 06:49 - 00675988 _____ () C:\Users\Jonas\Downloads\Minecraft(2).exe
2014-08-17 05:35 - 2014-05-13 09:01 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\BulkOperationHost.exe
2014-08-17 05:35 - 2014-05-13 07:07 - 02844160 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-08-17 05:35 - 2014-05-13 06:41 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-08-17 05:35 - 2014-05-13 06:26 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-08-17 05:35 - 2014-05-13 05:59 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-08-17 05:35 - 2014-05-13 05:31 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-08-17 05:35 - 2014-05-03 13:29 - 01726224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-08-17 05:35 - 2014-05-03 11:20 - 01473080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-08-17 05:35 - 2014-05-03 07:36 - 00997888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2014-08-17 05:35 - 2014-05-03 07:19 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncobjapi.dll
2014-08-17 05:35 - 2014-05-03 07:08 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedynos.dll
2014-08-17 05:35 - 2014-05-03 07:07 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedyn.dll
2014-08-17 05:35 - 2014-05-03 06:46 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncobjapi.dll
2014-08-17 05:35 - 2014-05-03 06:37 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedynos.dll
2014-08-17 05:35 - 2014-05-03 06:37 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedyn.dll
2014-08-17 05:35 - 2014-05-03 01:26 - 00050745 _____ () C:\WINDOWS\system32\srms.dat
2014-08-17 05:35 - 2014-05-01 07:44 - 01025536 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-08-17 05:35 - 2014-04-30 08:43 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2014-08-17 05:35 - 2014-04-30 08:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-08-17 05:35 - 2014-04-30 08:41 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2014-08-17 05:35 - 2014-04-30 08:41 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2014-08-17 05:35 - 2014-04-30 07:45 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2014-08-17 05:35 - 2014-04-30 06:48 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2014-08-17 05:35 - 2014-04-30 06:24 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2014-08-17 05:35 - 2014-04-30 06:23 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2014-08-17 05:35 - 2014-04-30 06:23 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2014-08-17 05:35 - 2014-04-30 06:23 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2014-08-17 05:35 - 2014-04-30 06:14 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2014-08-17 05:35 - 2014-04-30 05:59 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2014-08-17 05:35 - 2014-04-30 05:46 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2014-08-17 05:35 - 2014-04-30 05:46 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2014-08-17 05:35 - 2014-04-30 05:46 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2014-08-17 05:35 - 2014-04-30 05:45 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2014-08-17 05:35 - 2014-04-30 05:42 - 00403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2014-08-17 05:35 - 2014-04-29 00:40 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2014-08-17 05:35 - 2014-04-27 00:03 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-08-17 05:35 - 2014-04-26 22:14 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-08-17 05:35 - 2014-04-26 18:39 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2014-08-17 05:35 - 2014-04-14 11:37 - 02125344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-08-17 05:35 - 2014-04-14 10:08 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2014-08-17 05:35 - 2014-04-14 07:18 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2014-08-17 05:35 - 2014-04-09 08:11 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2014-08-17 05:35 - 2014-04-09 07:20 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2014-08-17 05:34 - 2014-06-20 03:48 - 01273184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2014-08-17 05:34 - 2014-06-20 01:52 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2014-08-17 05:34 - 2014-06-13 03:15 - 00517528 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-08-17 05:34 - 2014-06-13 03:14 - 01557848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-08-17 05:34 - 2014-06-13 02:10 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2014-08-17 05:34 - 2014-06-06 13:34 - 02133504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-08-17 05:31 - 2014-07-15 20:16 - 03048880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-08-17 05:31 - 2014-07-15 10:29 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-08-17 05:31 - 2014-07-15 10:22 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-08-17 05:31 - 2014-07-15 10:03 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2014-08-17 05:31 - 2014-07-10 06:16 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-08-17 05:31 - 2014-07-10 06:03 - 04756992 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-08-17 05:31 - 2014-07-10 05:33 - 01120256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-08-17 05:31 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2014-08-17 05:31 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2014-08-17 05:31 - 2014-05-31 08:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-08-17 05:26 - 2014-08-02 05:11 - 00918528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-08-17 05:26 - 2014-07-12 06:17 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-08-17 05:26 - 2014-06-05 16:13 - 00216368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2014-08-17 05:26 - 2014-06-05 15:14 - 00189016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2014-08-17 05:26 - 2014-06-04 11:27 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-08-17 05:26 - 2014-06-04 07:31 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-08-17 05:26 - 2014-06-04 07:22 - 02790912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-08-17 05:26 - 2014-06-04 06:43 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-08-17 05:26 - 2014-06-04 06:38 - 03304448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-08-17 05:26 - 2014-06-04 04:15 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-08-17 05:26 - 2014-06-04 04:14 - 02318336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-08-17 05:26 - 2014-06-02 04:10 - 00423768 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2014-08-17 05:26 - 2014-05-31 12:07 - 00467800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2014-08-17 05:26 - 2014-05-31 12:07 - 00440664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys
2014-08-17 05:26 - 2014-05-31 12:07 - 00419672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2014-08-17 05:26 - 2014-05-31 12:07 - 00089944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbehci.sys
2014-08-17 05:26 - 2014-05-31 12:07 - 00027480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys
2014-08-17 05:26 - 2014-05-31 08:30 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbuhci.sys
2014-08-17 05:26 - 2014-05-31 08:27 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFPf.sys
2014-08-17 05:26 - 2014-05-31 08:26 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFRd.sys
2014-08-17 05:26 - 2014-05-31 06:01 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFHost.exe
2014-08-17 05:26 - 2014-05-31 06:01 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2014-08-17 05:26 - 2014-05-31 06:01 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFSvc.dll
2014-08-17 05:26 - 2014-05-27 17:53 - 02518360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-08-17 05:26 - 2014-05-27 11:56 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\DaOtpCredentialProvider.dll
2014-08-17 05:26 - 2014-05-27 11:53 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll
2014-08-17 05:26 - 2014-05-17 06:59 - 16871936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-08-17 05:26 - 2014-05-17 06:13 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-15 12:14 - 2014-09-13 04:34 - 00016284 _____ () C:\Users\Jonas\Downloads\FRST.txt
2014-09-15 12:14 - 2014-09-13 04:34 - 00000000 ____D () C:\FRST
2014-09-15 12:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-09-15 11:53 - 2013-06-28 17:57 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-09-15 11:31 - 2013-07-05 23:57 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-15 10:17 - 2013-10-30 20:30 - 01524533 _____ () C:\WINDOWS\WindowsUpdate.log
2014-09-15 09:45 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-09-15 09:26 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-09-15 09:20 - 2013-06-28 17:45 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-60212469-607860961-1350188199-1002
2014-09-15 09:06 - 2014-09-15 09:06 - 00001351 _____ () C:\Users\Jonas\Desktop\JRT.txt
2014-09-15 09:02 - 2014-09-15 09:02 - 01016261 _____ (Thisisu) C:\Users\Jonas\Downloads\JRT.exe
2014-09-15 08:59 - 2014-01-01 14:47 - 00000000 ___DO () C:\Users\Jonas\SkyDrive
2014-09-15 08:59 - 2013-11-06 20:48 - 00000000 ____D () C:\AdwCleaner
2014-09-15 08:56 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-09-15 08:56 - 2013-07-05 23:57 - 00001124 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-15 08:55 - 2014-09-15 08:54 - 00004446 _____ () C:\Users\Jonas\Desktop\AdwCleaner[S1].txt
2014-09-15 08:55 - 2013-09-29 21:04 - 00027978 _____ () C:\WINDOWS\PFRO.log
2014-09-15 08:55 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-09-15 08:54 - 2013-10-30 20:36 - 00000000 ____D () C:\Users\Jonas
2014-09-15 08:53 - 2014-09-15 08:52 - 01373475 _____ () C:\Users\Jonas\Downloads\AdwCleaner_3.310.exe
2014-09-15 08:51 - 2014-09-15 08:51 - 00012670 _____ () C:\Users\Jonas\Desktop\mbam.txt
2014-09-15 08:49 - 2014-09-15 08:22 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-15 08:46 - 2013-08-22 17:36 - 00000000 __RSD () C:\WINDOWS\Media
2014-09-15 08:22 - 2014-09-15 08:22 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-15 08:22 - 2014-09-15 08:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-15 08:22 - 2013-11-06 19:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-15 08:20 - 2014-09-15 08:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Jonas\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-15 08:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-09-15 08:14 - 2013-11-09 01:03 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8A0D6FBE-57FC-4C97-A8F8-CE4532E7DC4F}
2014-09-14 23:22 - 2014-09-13 04:35 - 00040695 _____ () C:\Users\Jonas\Downloads\Addition.txt
2014-09-14 11:30 - 2013-07-02 21:25 - 00000000 ____D () C:\Users\Jonas\AppData\Roaming\Skype
2014-09-14 10:16 - 2014-08-21 03:33 - 00000000 ____D () C:\Users\Jonas\AppData\Roaming\Spotify
2014-09-14 01:45 - 2013-11-03 17:17 - 00083456 ___SH () C:\Users\Jonas\Downloads\Thumbs.db
2014-09-13 08:14 - 2014-09-13 08:14 - 00047837 _____ () C:\FRST.txt
2014-09-13 08:11 - 2014-09-13 08:11 - 02105856 _____ (Farbar) C:\Users\Jonas\Downloads\FRST64(1).exe
2014-09-13 05:01 - 2014-09-13 05:01 - 00000244 _____ () C:\Users\Jonas\Downloads\defogger_enable.log
2014-09-13 05:01 - 2014-09-13 05:00 - 00000472 _____ () C:\Users\Jonas\Downloads\defogger_disable.log
2014-09-13 05:00 - 2014-09-13 05:00 - 00050477 _____ () C:\Users\Jonas\Downloads\Defogger.exe
2014-09-13 04:33 - 2014-09-13 04:33 - 02105856 _____ (Farbar) C:\Users\Jonas\Downloads\FRST64.exe
2014-09-13 04:24 - 2013-12-24 21:48 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-09-13 03:18 - 2013-08-03 16:45 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-09-13 03:15 - 2013-06-28 15:49 - 101694776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-09-10 02:53 - 2013-06-28 17:57 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-09-10 02:45 - 2014-08-21 03:34 - 00000000 ____D () C:\Users\Jonas\AppData\Local\Spotify
2014-09-07 05:06 - 2014-08-03 04:12 - 00000765 _____ () C:\Users\Jonas\Desktop\World of Tanks 0.9.2 ProMod.lnk
2014-09-07 04:56 - 2014-09-07 04:56 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-09-07 04:56 - 2014-09-07 04:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-09-07 04:56 - 2014-09-07 04:55 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-07 04:56 - 2014-09-07 04:55 - 00000000 ____D () C:\Program Files\iTunes
2014-09-07 04:56 - 2014-09-07 04:55 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-09-07 04:56 - 2013-07-01 15:57 - 00155136 _____ () C:\WINDOWS\SysWOW64\unrar.dll
2014-09-07 04:56 - 2013-07-01 15:57 - 00034308 _____ () C:\WINDOWS\SysWOW64\bassmod.dll
2014-09-07 04:55 - 2014-09-07 04:55 - 00000000 ____D () C:\Program Files\iPod
2014-09-03 08:43 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-09-03 08:14 - 2013-09-30 06:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-03 08:14 - 2013-09-30 05:56 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat
2014-09-03 08:14 - 2013-09-30 05:56 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat
2014-09-02 22:06 - 2014-08-20 04:09 - 00706016 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-09-02 22:06 - 2014-08-20 04:09 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-31 08:57 - 2013-07-02 21:25 - 00000000 ____D () C:\ProgramData\Skype
2014-08-31 01:52 - 2013-08-22 16:44 - 00449704 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-08-30 08:30 - 2013-06-30 20:50 - 00000000 ____D () C:\Users\Jonas\AppData\Roaming\TS3Client
2014-08-23 02:42 - 2014-08-30 08:07 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-21 03:34 - 2014-08-21 03:34 - 00001856 _____ () C:\Users\Jonas\Desktop\Spotify.lnk
2014-08-21 03:34 - 2014-08-21 03:34 - 00001842 _____ () C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-08-21 03:31 - 2014-08-21 03:31 - 00127136 _____ (Spotify Ltd) C:\Users\Jonas\Downloads\SpotifySetup.exe
2014-08-20 04:08 - 2013-06-28 17:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-19 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-08-19 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-08-19 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-08-19 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-08-19 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-08-19 06:49 - 2014-08-19 06:49 - 00675988 _____ () C:\Users\Jonas\Downloads\Minecraft(2).exe
2014-08-19 06:49 - 2013-10-30 22:01 - 00000000 ____D () C:\Users\Jonas\AppData\Roaming\.minecraft
2014-08-17 05:12 - 2013-06-30 20:21 - 00000000 ____D () C:\Users\Jonas\AppData\Local\TeamSpeak 3 Client
2014-08-16 04:40 - 2014-09-12 08:14 - 23591424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-08-16 04:04 - 2014-09-12 08:14 - 17455104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-08-16 04:00 - 2014-09-12 08:14 - 05833728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-08-16 04:00 - 2014-09-12 08:14 - 02793984 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-08-16 03:56 - 2014-09-12 08:14 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-08-16 03:54 - 2014-09-12 08:14 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-08-16 03:45 - 2014-09-12 08:14 - 04232704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-08-16 03:43 - 2014-09-12 08:14 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-08-16 03:32 - 2014-09-12 08:14 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-08-16 03:25 - 2014-09-12 08:14 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-08-16 03:22 - 2014-09-12 08:14 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-08-16 03:20 - 2014-09-12 08:14 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-08-16 03:19 - 2014-09-12 08:14 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-08-16 03:18 - 2014-09-12 08:14 - 02185728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-08-16 03:18 - 2014-09-12 08:14 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-08-16 03:11 - 2014-09-12 08:14 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-08-16 03:06 - 2014-09-12 08:14 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-08-16 03:05 - 2014-09-12 08:14 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-08-16 03:05 - 2014-09-12 08:14 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-08-16 03:03 - 2014-09-12 08:14 - 02104832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-08-16 03:03 - 2014-09-12 08:14 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-08-16 02:58 - 2014-09-12 08:14 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-16 02:56 - 2014-09-12 08:14 - 02310656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-08-16 02:53 - 2014-09-12 08:14 - 13588480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-08-16 02:53 - 2014-09-12 08:14 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-08-16 02:53 - 2014-09-12 08:14 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-08-16 02:51 - 2014-09-12 08:14 - 11769856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-08-16 02:45 - 2014-09-12 08:14 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-08-16 02:44 - 2014-09-12 08:14 - 02014208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-08-16 02:44 - 2014-09-12 08:14 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-08-16 02:34 - 2014-09-12 08:14 - 01447424 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-08-16 02:20 - 2014-09-12 08:14 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-08-16 02:18 - 2014-09-12 08:14 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-08-16 02:14 - 2014-09-12 08:14 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-08-16 02:12 - 2014-09-12 08:14 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
Some content of TEMP:
====================
C:\Users\Jonas\AppData\Local\Temp\13287uninstall.exe
C:\Users\Jonas\AppData\Local\Temp\228412-673527-minecraft.exe
C:\Users\Jonas\AppData\Local\Temp\27886uninstall.exe
C:\Users\Jonas\AppData\Local\Temp\avgnt.exe
C:\Users\Jonas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_kloqi.dll
C:\Users\Jonas\AppData\Local\Temp\FreemakeAudioConverter_1.1.0.54.exe
C:\Users\Jonas\AppData\Local\Temp\ICReinstall_installer_minecraft_Deutsch.exe
C:\Users\Jonas\AppData\Local\Temp\instloffer.exe
C:\Users\Jonas\AppData\Local\Temp\Quarantine.exe
C:\Users\Jonas\AppData\Local\Temp\Sqlite3.dll
C:\Users\Jonas\AppData\Local\Temp\ubi5B13.tmp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-15 09:20
==================== End Of Log ============================ --- --- ---
Und das frische FRST.txt. wenn ich mal länger brauch zum antworten liegt es daran, dass ich in Neuseeland bin. :) |