CODE]ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internet# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=c2210ea21e59d341b5912d5b1fe0bed5
# engine=21335
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-11-30 08:25:39
# local_time=2014-11-30 09:25:39 (+0100, Mitteleuropäische Zeit)
# country="Switzerland"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 6838024 58692455 0 0
# scanned=4178
# found=2
# cleaned=0
# scan_time=989
sh=7A5B168BB2B8C06B2A9134B656BBF195830D21C2 ft=1 fh=55d4f387d8566cf4 vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\juerg\AppData\LocalLow\softonic-de3\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.1.1\bin\PriceGongIE.dll.vir"
sh=B5C93DA0C608B26C9487ABC49CCB643C9A15ED33 ft=1 fh=75f1c65aa8a331ed vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\jwenger\AppData\LocalLow\softonic-de3\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=c2210ea21e59d341b5912d5b1fe0bed5
# engine=21335
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-12-01 07:29:39
# local_time=2014-12-01 08:29:39 (+0100, Mitteleuropäische Zeit)
# country="Switzerland"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 6877864 58732295 0 0
# scanned=407952
# found=59
# cleaned=0
# scan_time=39704
sh=7A5B168BB2B8C06B2A9134B656BBF195830D21C2 ft=1 fh=55d4f387d8566cf4 vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\juerg\AppData\LocalLow\softonic-de3\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.1.1\bin\PriceGongIE.dll.vir"
sh=B5C93DA0C608B26C9487ABC49CCB643C9A15ED33 ft=1 fh=75f1c65aa8a331ed vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\jwenger\AppData\LocalLow\softonic-de3\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll.vir"
sh=171AD50832FDF830DA0C93E98852370A973E7650 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Anwendungsdaten\Mozilla\Firefox\Profiles\dhds84dh.default\prefs-1.js"
sh=171AD50832FDF830DA0C93E98852370A973E7650 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\AppData\Roaming\Mozilla\Firefox\Profiles\dhds84dh.default\prefs-1.js"
sh=68F2E75BA584D23C7D4F3526B6804061C5D01F7A ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten\user.js"
sh=E1C3203F383A77FA951DCB165FFC69C7093DA4F1 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-1\prefs-1.js"
sh=6B7990BAFB2B2623904F71186EEC4B9A9631DEF2 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-1\prefs-2.js"
sh=5BC55F51C80E772E5965C97D10115A27EAF4AF6A ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-1\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-1\user.js"
sh=CD3F843A41130E8E6BDE0C9DFEA9CE872EE2C092 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-2\prefs-1.js"
sh=FDF8EB93E5E52317C066848A3A1E2F85E7A1204A ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-2\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-2\user.js"
sh=46E77F527658853B02B6863D0672EC3F50F92372 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-3\prefs-1.js"
sh=00F09B564BA8AD89D21E7030CC07B0697F617E62 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-3\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Desktop\Alte Firefox-Daten-3\user.js"
sh=60C66FB36C25DC4BB4B5A1CFE6E429FFD7A198B5 ft=1 fh=973819cf50a84f28 vn="Variante von Win32/OpenInstall evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\AVGSecureSearchInstaller.exe"
sh=8E05264386E7A5BB39DF521952AABC76624D493A ft=1 fh=3a6facd612fa631a vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\PDFCreator-1_2_2_setup.exe"
sh=0C7E1F8EB63F9F1C75EB08A156E54A7349853EFF ft=1 fh=d24020069345d3b6 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\PDFCreator-1_6_0_setup.exe"
sh=64131EBCE68286BAAEFAC74F12628EBFC159B7CB ft=1 fh=252d3f247af8095f vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\PDFCreator-1_6_1_setup(1).exe"
sh=64131EBCE68286BAAEFAC74F12628EBFC159B7CB ft=1 fh=252d3f247af8095f vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\PDFCreator-1_6_1_setup.exe"
sh=BCF43267B4416C6DDEFAAD5AE0A63E3F682C5BB0 ft=1 fh=905be375e5c80006 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\PDFCreator-1_6_2_setup.exe"
sh=01CACEFA17BD98011A6885F29442A6EF5048F0CF ft=1 fh=3033c6800f5f569d vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\SoftonicDownloader_fuer_freepdf(2).exe"
sh=01CACEFA17BD98011A6885F29442A6EF5048F0CF ft=1 fh=3033c6800f5f569d vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\juerg\Downloads\SoftonicDownloader_fuer_freepdf.exe"
sh=CFAE6AEEA2738A3C57CD8D40B923103511537362 ft=0 fh=0000000000000000 vn="Win32/PriceGong.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\jwenger\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4L74TRNC\html_comp[1].htm"
sh=2C64472CE377FB6C7E015F0844853BD896EAC2BA ft=1 fh=57a2d92182ab7f7c vn="Variante von Win32/FileTypeAssistant.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\jwenger\Downloads\FreeFileViewerSetup.exe"
sh=AF9481F029C578D17D09078914103DCB4B79E628 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\Users\juerg\AppData\Roaming\Mozilla\Firefox\Profiles\dhds84dh.default\extensions\staged\mR9@Qw.org\content\bg.js.vir"
sh=C836F9B0F6C88A6B1DFC824433238770227D07F9 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\Users\juerg\AppData\Roaming\Mozilla\Firefox\Profiles\dhds84dh.default\extensions\staged\nGYlRBWM8B@0.com\content\bg.js.vir "
sh=AF9481F029C578D17D09078914103DCB4B79E628 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\Users\jwenger\AppData\Roaming\Mozilla\Firefox\Profiles\mv7lbc2s.default\extensions\mR9@Qw.org\content\bg.js.vir"
sh=C836F9B0F6C88A6B1DFC824433238770227D07F9 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\Users\jwenger\AppData\Roaming\Mozilla\Firefox\Profiles\mv7lbc2s.default\extensions\nGYlRBWM8B@0.com\content\bg.js.vir"
sh=AF9481F029C578D17D09078914103DCB4B79E628 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\Users\jwpc21\AppData\Roaming\Mozilla\Firefox\Profiles\apu1ytwx.default\extensions\staged\mR9@Qw.org\content\bg.js.vir"
sh=C836F9B0F6C88A6B1DFC824433238770227D07F9 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\Users\jwpc21\AppData\Roaming\Mozilla\Firefox\Profiles\apu1ytwx.default\extensions\staged\nGYlRBWM8B@0.com\content\bg.js.vir "
sh=171AD50832FDF830DA0C93E98852370A973E7650 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Anwendungsdaten\Mozilla\Firefox\Profiles\dhds84dh.default\prefs-1.js"
sh=171AD50832FDF830DA0C93E98852370A973E7650 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\AppData\Roaming\Mozilla\Firefox\Profiles\dhds84dh.default\prefs-1.js"
sh=68F2E75BA584D23C7D4F3526B6804061C5D01F7A ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten\user.js"
sh=E1C3203F383A77FA951DCB165FFC69C7093DA4F1 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-1\prefs-1.js"
sh=6B7990BAFB2B2623904F71186EEC4B9A9631DEF2 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-1\prefs-2.js"
sh=5BC55F51C80E772E5965C97D10115A27EAF4AF6A ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-1\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-1\user.js"
sh=CD3F843A41130E8E6BDE0C9DFEA9CE872EE2C092 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-2\prefs-1.js"
sh=FDF8EB93E5E52317C066848A3A1E2F85E7A1204A ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-2\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-2\user.js"
sh=46E77F527658853B02B6863D0672EC3F50F92372 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-3\prefs-1.js"
sh=00F09B564BA8AD89D21E7030CC07B0697F617E62 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-3\prefs.js"
sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Desktop\Alte Firefox-Daten-3\user.js"
sh=60C66FB36C25DC4BB4B5A1CFE6E429FFD7A198B5 ft=1 fh=973819cf50a84f28 vn="Variante von Win32/OpenInstall evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\AVGSecureSearchInstaller.exe"
sh=8E05264386E7A5BB39DF521952AABC76624D493A ft=1 fh=3a6facd612fa631a vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\PDFCreator-1_2_2_setup.exe"
sh=0C7E1F8EB63F9F1C75EB08A156E54A7349853EFF ft=1 fh=d24020069345d3b6 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\PDFCreator-1_6_0_setup.exe"
sh=64131EBCE68286BAAEFAC74F12628EBFC159B7CB ft=1 fh=252d3f247af8095f vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\PDFCreator-1_6_1_setup(1).exe"
sh=64131EBCE68286BAAEFAC74F12628EBFC159B7CB ft=1 fh=252d3f247af8095f vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\PDFCreator-1_6_1_setup.exe"
sh=BCF43267B4416C6DDEFAAD5AE0A63E3F682C5BB0 ft=1 fh=905be375e5c80006 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\PDFCreator-1_6_2_setup.exe"
sh=01CACEFA17BD98011A6885F29442A6EF5048F0CF ft=1 fh=3033c6800f5f569d vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\SoftonicDownloader_fuer_freepdf(2).exe"
sh=01CACEFA17BD98011A6885F29442A6EF5048F0CF ft=1 fh=3033c6800f5f569d vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\juerg\Downloads\SoftonicDownloader_fuer_freepdf.exe"
sh=CFAE6AEEA2738A3C57CD8D40B923103511537362 ft=0 fh=0000000000000000 vn="Win32/PriceGong.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jwenger\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4L74TRNC\html_comp[1].htm"
sh=2C64472CE377FB6C7E015F0844853BD896EAC2BA ft=1 fh=57a2d92182ab7f7c vn="Variante von Win32/FileTypeAssistant.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jwenger\Downloads\FreeFileViewerSetup.exe"
sh=256BCF5C1F87BC7B51007A66CCFC1C9B98B146E5 ft=1 fh=d869476f779c0e5f vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIA948.tmp-\Smartbar.Resources.LanguageSettings.resources.dll"
sh=06AB8E0F5FA19E49564CF583E1A1B886A7E92090 ft=1 fh=b20b00d0cb737d90 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIA948.tmp-\Smartbar.Resources.ProductUninstaller.dll"
sh=F910917A651D25EF5D068A92C6D6B8472F2ABC52 ft=1 fh=5f31b122156eac2b vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIA948.tmp-\Smartbar.Resource
[/CODE]
Code:
Results of screen317's Security Check version 0.99.91
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 2.0.3.1025
Java 8 Update 25
Java version 32-bit out of Date!
Adobe Flash Player 15.0.0.239
Adobe Reader XI
Mozilla Firefox (33.1.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2014
Ran by jwenger (administrator) on JW-PC-21 on 01-12-2014 15:09:57
Running from C:\Users\jwenger\Desktop\Viren-Entferner
Loaded Profile: jwenger (Available profiles: jwpc21 & juerg & jwenger)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Livescribe) C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Windows\PLFSetI.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.EXE
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
() C:\Windows\Samsung\PanelMgr\caller64.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\Unlimited Connection Manager\Unlimited Connection Manager.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\outlook.exe
(Acer Incoporated) C:\Program Files (x86)\Acer\Acer VCM\VC.exe
() C:\Users\jwenger\Desktop\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [503864 2009-07-20] (Conexant Systems, Inc.)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [206072 2009-12-14] ()
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [825864 2009-09-24] (Dritek System Inc.)
HKLM-x32\...\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\SSMMgr.exe [606208 2009-12-09] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-78893223-4109146470-2151321330-1009\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-78893223-4109146470-2151321330-1009\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-78893223-4109146470-2151321330-1009\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com/?ocid=U218DHP&pc=U218
HKU\S-1-5-21-78893223-4109146470-2151321330-1009\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8FA42CC14C53CE01
HKU\S-1-5-21-78893223-4109146470-2151321330-1009\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-CH
HKU\S-1-5-21-78893223-4109146470-2151321330-1009\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1me10IE11DEDE/WOL_WCP
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKU\S-1-5-21-78893223-4109146470-2151321330-1009 -> {3938F9E9-348A-F180-C78C-7DFF875EDD8C} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=071713&q={searchTerms}&src=IE-SearchBox
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-78893223-4109146470-2151321330-1009 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\..\Interfaces\{295648C0-9D12-4565-A8B6-16611EC3D9ED}: [NameServer] 195.186.152.33 195.186.216.33
Tcpip\..\Interfaces\{BA9548F9-8922-4868-AEB0-7E26ECAC2199}: [NameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\jwenger\AppData\Roaming\Mozilla\Firefox\Profiles\mv7lbc2s.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.4.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-78893223-4109146470-2151321330-1009: @citrixonline.com/appdetectorplugin -> C:\Users\jwenger\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF SearchPlugin: C:\Users\jwenger\AppData\Roaming\Mozilla\Firefox\Profiles\mv7lbc2s.default\searchplugins\ecosia.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml
FF Extension: Avira Browser Safety - C:\Users\jwenger\AppData\Roaming\Mozilla\Firefox\Profiles\mv7lbc2s.default\Extensions\abs@avira.com [2014-11-20]
FF Extension: Adblock Plus - C:\Users\jwenger\AppData\Roaming\Mozilla\Firefox\Profiles\mv7lbc2s.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-01]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-11]
FF HKU\S-1-5-21-78893223-4109146470-2151321330-1009\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2013-08-22]
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\jwenger\AppData\Local\Google\Chrome\User Data\Default
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2443960 2014-10-30] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 PenCommService; C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe [470528 2011-10-27] (Livescribe) [File not signed]
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-12] (AVG Technologies)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-06-09] (Samsung Electronics Co., Ltd.)
S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-01] (HTC, Corporation) [File not signed]
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 PulseUsb; C:\Windows\System32\DRIVERS\PulseUsb.sys [26112 2011-10-27] (Windows (R) Win 7 DDK provider)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 Andbus; system32\DRIVERS\lgandbus64.sys [X]
S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X]
S3 AndGps; system32\DRIVERS\lgandgps64.sys [X]
S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 LgBttPort; system32\DRIVERS\lgbtpt64.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbs64.sys [X]
S3 LGVMODEM; system32\DRIVERS\lgvmdm64.sys [X]
S1 MpKslb4b96a00; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A89CEB89-0B96-475A-9B86-0C671688CF03}\MpKslb4b96a00.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-01 08:55 - 2014-12-01 08:55 - 00852490 _____ () C:\Users\jwenger\Desktop\SecurityCheck.exe
2014-11-30 21:04 - 2014-11-30 21:04 - 02347384 _____ (ESET) C:\Users\jwenger\Downloads\esetsmartinstaller_deu.exe
2014-11-30 17:12 - 2014-12-01 15:09 - 00000000 ____D () C:\Users\jwenger\Desktop\Viren-Entferner
2014-11-30 11:11 - 2014-11-30 11:11 - 00000000 ____D () C:\Windows\ERUNT
2014-11-30 11:09 - 2014-11-30 11:09 - 01707646 _____ (Thisisu) C:\Users\jwenger\Downloads\JRT.exe
2014-11-30 11:00 - 2014-11-30 11:04 - 00000000 ____D () C:\AdwCleaner
2014-11-30 10:58 - 2014-11-30 10:58 - 02148864 _____ () C:\Users\jwenger\Downloads\AdwCleaner_4.102.exe
2014-11-30 10:08 - 2014-11-30 10:08 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\jwenger\Downloads\mbam-setup-2.0.3.1025(2).exe
2014-11-30 09:36 - 2014-11-30 09:36 - 00022872 _____ () C:\ComboFix.txt
2014-11-30 09:09 - 2014-11-30 09:36 - 00000000 ____D () C:\Qoobox
2014-11-30 09:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-11-30 09:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-11-30 09:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-11-30 09:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-11-30 09:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-11-30 09:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-11-30 09:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-11-30 09:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-11-30 09:08 - 2014-11-30 09:34 - 00000000 ____D () C:\Windows\erdnt
2014-11-30 09:02 - 2014-11-30 09:02 - 05599228 ____R (Swearware) C:\Users\jwenger\Downloads\ComboFix.exe
2014-11-30 08:43 - 2014-11-30 08:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-11-30 08:41 - 2014-11-30 08:41 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\jwenger\Downloads\revosetup95.exe
2014-11-28 17:53 - 2014-11-28 17:54 - 00000248 _____ () C:\Users\jwenger\Downloads\defogger_enable.log
2014-11-28 17:23 - 2014-11-28 17:23 - 00380416 _____ () C:\Users\jwenger\Downloads\ps9eg9lw.exe
2014-11-28 17:21 - 2014-11-28 17:21 - 00000476 _____ () C:\Users\jwenger\Downloads\defogger_disable.log
2014-11-28 17:20 - 2014-11-28 17:20 - 00050477 _____ () C:\Users\jwenger\Downloads\Defogger.exe
2014-11-28 16:29 - 2014-11-28 16:28 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-11-28 16:00 - 2014-11-28 16:00 - 00638888 _____ (Oracle Corporation) C:\Users\jwenger\Downloads\jxpiinstall.exe
2014-11-25 11:41 - 2014-12-01 15:10 - 00000000 ____D () C:\FRST
2014-11-24 11:48 - 2014-11-24 11:48 - 00001211 _____ () C:\Users\Public\Desktop\Unlimited Connection Manager.lnk
2014-11-24 11:48 - 2014-11-24 11:48 - 00001211 _____ () C:\ProgramData\Desktop\Unlimited Connection Manager.lnk
2014-11-24 11:48 - 2014-11-24 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unlimited Connection Manager
2014-11-24 11:47 - 2008-03-17 11:58 - 00117120 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbfake.sys
2014-11-24 11:47 - 2008-03-17 11:06 - 00115328 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys
2014-11-24 11:47 - 2008-03-16 14:47 - 01003008 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys
2014-11-24 11:47 - 2008-01-22 15:11 - 00119296 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbnet.sys
2014-11-24 11:47 - 2007-08-09 04:10 - 00029696 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys
2014-11-23 09:02 - 2014-11-23 09:02 - 14107296 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\mseinstall.exe
2014-11-22 22:47 - 2014-11-30 10:11 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-22 22:47 - 2014-11-30 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-22 22:46 - 2014-11-30 10:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-22 22:46 - 2014-11-22 22:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-22 22:46 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-22 22:46 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-22 22:46 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-22 22:45 - 2014-11-22 22:45 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\jwenger\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-22 22:45 - 2014-11-22 22:45 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\jwenger\Downloads\mbam-setup-2.0.3.1025(1).exe
2014-11-21 19:09 - 2014-11-21 19:09 - 00003158 _____ () C:\Windows\System32\Tasks\{1E5022FD-3D45-4EF5-BE1B-F201B0BA1DF1}
2014-11-20 19:59 - 2014-11-20 19:59 - 65446536 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\EIE11_DE-DE_WOL_WIN764(1).EXE
2014-11-20 19:41 - 2014-11-20 19:41 - 63320784 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\IE11-Windows6.1-x64-de-de(3).exe
2014-11-20 19:07 - 2014-11-20 19:07 - 00003454 _____ () C:\Windows\System32\Tasks\{EB8D5177-1EFD-49E5-B86F-5330FB58AE20}
2014-11-20 19:02 - 2014-11-20 19:03 - 63320784 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\IE11-Windows6.1-x64-de-de(2).exe
2014-11-20 18:44 - 2014-11-20 18:44 - 02077392 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\IE11-Windows6.1(2).exe
2014-11-20 18:42 - 2014-11-20 18:42 - 02077392 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\IE11-Windows6.1(1).exe
2014-11-20 18:40 - 2014-11-20 18:42 - 65446536 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\EIE11_DE-DE_WOL_WIN764.EXE
2014-11-20 18:39 - 2014-11-20 18:40 - 37059280 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\IE11-Windows6.1-x86-de-de.exe
2014-11-20 18:38 - 2014-11-20 18:39 - 63320784 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\IE11-Windows6.1-x64-de-de(1).exe
2014-11-19 11:04 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 11:04 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 11:04 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 11:04 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-19 11:04 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-19 11:04 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-19 11:04 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-19 11:04 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-18 04:55 - 2014-11-18 04:55 - 04583464 _____ (Avira Operations GmbH & Co. KG) C:\Users\jwenger\Downloads\avira_de_av_5649732519__ws.exe
2014-11-16 15:12 - 2014-11-16 15:12 - 00001123 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-16 15:12 - 2014-11-16 15:12 - 00001111 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-16 15:12 - 2014-11-16 15:12 - 00001111 _____ () C:\ProgramData\Desktop\Mozilla Firefox.lnk
2014-11-16 15:12 - 2014-11-16 15:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-16 15:10 - 2014-11-16 15:10 - 00244392 _____ () C:\Users\jwenger\Downloads\Firefox Setup Stub 33.1.1.exe
2014-11-16 15:02 - 2014-11-16 15:04 - 63320784 _____ (Microsoft Corporation) C:\Users\jwenger\Downloads\IE11-Windows6.1-x64-de-de.exe
2014-11-12 14:07 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-12 14:07 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 14:07 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-12 14:07 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-12 14:07 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 14:07 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-12 14:07 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-12 14:07 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-12 14:07 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-12 14:07 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-12 14:07 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-12 14:07 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-12 14:07 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-12 14:07 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-12 14:07 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-12 14:07 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-12 14:07 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-12 14:07 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-12 14:07 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 14:07 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-12 14:07 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-12 14:07 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-12 14:07 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-12 14:07 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-12 14:07 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-12 14:07 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 14:07 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-12 14:07 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 14:07 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-12 14:07 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-12 14:07 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-12 14:07 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-12 14:07 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-12 14:07 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-12 14:07 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-12 14:07 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 14:07 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-12 14:07 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-12 14:07 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-12 14:07 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-12 14:07 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-12 14:07 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-12 14:07 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 14:07 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 14:07 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-12 14:07 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 14:07 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-12 14:07 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-12 14:07 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-12 14:07 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-12 14:07 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-12 14:07 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-12 14:07 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-12 14:07 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-12 14:07 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-12 14:07 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-12 14:07 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-12 14:07 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-12 14:07 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-12 14:07 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-12 14:07 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-12 14:05 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-12 14:05 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-12 14:05 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-12 14:05 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-12 14:05 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-12 14:05 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 14:05 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 14:05 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 14:05 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-12 14:05 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-12 14:05 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-12 14:05 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-12 14:05 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-12 14:05 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-12 14:05 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 14:05 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-12 14:05 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 14:05 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-12 14:05 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 14:05 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-12 14:05 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-12 14:05 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-12 14:05 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-12 14:05 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 14:05 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-12 14:05 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 14:04 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-12 14:04 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-12 14:04 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-12 14:04 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 14:04 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-12 14:04 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-12 14:04 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-11 18:03 - 2014-11-16 15:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-01 15:09 - 2013-05-16 13:30 - 00000000 ____D () C:\Users\jwenger\AppData\Roaming\Skype
2014-12-01 15:08 - 2010-10-22 10:38 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-01 14:51 - 2014-09-30 15:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-01 14:37 - 2014-03-27 16:02 - 00000574 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-78893223-4109146470-2151321330-1009.job
2014-12-01 14:23 - 2009-07-19 22:08 - 00703192 _____ () C:\Windows\system32\perfh007.dat
2014-12-01 14:23 - 2009-07-19 22:08 - 00150800 _____ () C:\Windows\system32\perfc007.dat
2014-12-01 14:23 - 2009-07-14 06:13 - 01629348 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-01 14:20 - 2009-07-19 21:29 - 01825201 _____ () C:\Windows\WindowsUpdate.log
2014-12-01 14:12 - 2009-07-14 05:51 - 00616504 _____ () C:\Windows\setupact.log
2014-12-01 08:06 - 2010-12-09 20:11 - 00000099 _____ () C:\Users\Public\LMDebug.log
2014-11-30 16:59 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-30 16:59 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-30 16:52 - 2010-10-22 10:38 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-30 16:51 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-30 11:06 - 2009-10-20 01:04 - 01305134 _____ () C:\Windows\PFRO.log
2014-11-30 09:32 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-11-30 09:29 - 2010-11-03 14:37 - 00000000 ____D () C:\Users\juerg
2014-11-30 08:59 - 2013-06-25 18:00 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-11-28 17:53 - 2013-05-10 16:28 - 00000000 ____D () C:\Users\jwenger
2014-11-28 16:29 - 2014-06-06 13:40 - 00000000 ____D () C:\ProgramData\Oracle
2014-11-28 16:28 - 2014-10-23 09:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-11-28 16:28 - 2011-05-05 20:13 - 00000000 ____D () C:\Program Files (x86)\Java
2014-11-28 16:03 - 2014-10-23 09:10 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-11-28 16:03 - 2014-10-23 09:09 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-11-28 16:03 - 2014-10-23 09:09 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-11-27 09:17 - 2013-05-15 16:42 - 00000000 ____D () C:\Users\jwenger\AppData\Local\CUSTPDF Writer
2014-11-26 11:51 - 2014-09-30 15:32 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-26 11:51 - 2014-09-30 15:32 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-26 11:51 - 2014-09-30 15:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-24 12:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-11-24 11:48 - 2011-04-05 21:38 - 00000000 ____D () C:\Program Files (x86)\Unlimited Connection Manager
2014-11-23 14:08 - 2014-03-27 16:02 - 00003604 _____ () C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-78893223-4109146470-2151321330-1009
2014-11-23 09:25 - 2009-07-14 05:45 - 00442632 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-23 09:13 - 2009-10-20 00:39 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-23 09:06 - 2013-11-29 05:45 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-23 09:05 - 2013-05-10 10:45 - 00002127 _____ () C:\Windows\epplauncher.mif
2014-11-23 08:57 - 2010-10-22 11:43 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-20 20:00 - 2014-01-22 20:31 - 00044419 _____ () C:\Windows\IE11_main.log
2014-11-20 19:28 - 2009-07-19 21:46 - 00110246 _____ () C:\Windows\DPINST.LOG
2014-11-19 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-19 09:17 - 2010-10-22 10:02 - 00000000 ____D () C:\Users\jwpc21
2014-11-18 06:34 - 2013-12-19 09:56 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-11-18 04:58 - 2010-11-03 15:35 - 00112312 _____ () C:\Users\juerg\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-17 20:34 - 2013-05-08 10:35 - 00000000 ____D () C:\Users\juerg\AppData\Roaming\Izexlo
2014-11-13 16:03 - 2010-10-22 10:38 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-13 16:03 - 2010-10-22 10:38 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
Some content of TEMP:
====================
C:\Users\jwenger\AppData\Local\Temp\DataCard_Setup64.exe
C:\Users\jwenger\AppData\Local\Temp\Quarantine.exe
C:\Users\jwenger\AppData\Local\Temp\ResetDevice.exe
C:\Users\jwenger\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-25 12:02
==================== End Of Log ============================
--- --- ---
Auch gespannt, ob damit alle Probleme - jedenfalls auf der Ebene von viren in meinem Laptop :-) - gelöst sind. IHnen, Schraiber, jedenfalls vielen Dank bisher schon.
Und liebe Grüsse aus dem Bernerland
Jürg Wenger