nadimauz2611 | 21.07.2015 13:16 | Hallo Schrauber,
danke für deine Hilfe. Hat leider ein wenig länger gedauert! Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 21.07.2015
Suchlauf-Zeit: 09:44:26
Logdatei: mbamlog.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.07.21.01
Rootkit Datenbank: v2015.07.17.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Sarah
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 346411
Verstrichene Zeit: 3 Std, 18 Min, 29 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 1
PUP.Optional.Multiplug, C:\Program Files (x86)\SectionLogistics\SectionLogistics.dll, Löschen bei Neustart, [99ccfee61a700f27d09b13679968936d],
Registrierungsschlüssel: 22
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{8BB736A5-5657-4B96-9CFF-4F19318E6F05}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{14F4C881-7034-4A04-8520-4BBAF990322F}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3A53A14A-3507-44C0-A43A-BE1A740E459E}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A37ED31E-EF56-45C0-BD97-E163EAD0B29F}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B883605B-FD97-412E-BDDB-697FE7B1F656}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{14F4C881-7034-4A04-8520-4BBAF990322F}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3A53A14A-3507-44C0-A43A-BE1A740E459E}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A37ED31E-EF56-45C0-BD97-E163EAD0B29F}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B883605B-FD97-412E-BDDB-697FE7B1F656}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{14F4C881-7034-4A04-8520-4BBAF990322F}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3A53A14A-3507-44C0-A43A-BE1A740E459E}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{A37ED31E-EF56-45C0-BD97-E163EAD0B29F}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B883605B-FD97-412E-BDDB-697FE7B1F656}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{8BB736A5-5657-4B96-9CFF-4F19318E6F05}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{8BB736A5-5657-4B96-9CFF-4F19318E6F05}, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [5213865e454567cf1132bbdac440ce32],
PUP.Optional.FFPluginHp.A, HKLM\SOFTWARE\WOW6432NODE\FFPluginHp, In Quarantäne, [481d38ac5733181ee6526b9edf2446ba],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, In Quarantäne, [6afb26beec9ede586a555ac6fe059a66],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{4072cbd7}, In Quarantäne, [c89dcf15f793fa3ce7b2593a887cc33d],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [f4714f953e4c0036251ec3d2b94b6f91],
PUP.Optional.SectionLogistics.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\4072cbd7, In Quarantäne, [b0b55d87d3b7fc3a6da57912c83c5ea2],
PUP.Optional.FastSearch.A, HKU\S-1-5-21-1104028462-2252768145-1088222659-1001\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [bea7b1336327c5710daf6d9b13f0d42c],
Registrierungswerte: 5
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [5213865e454567cf1132bbdac440ce32]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|searchffv2@gmail.com, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\searchffv2@gmail.com, In Quarantäne, [82e3994b276382b4d00b880a699bb947]
PUP.Optional.SweetSearch.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|sweetsearch@gmail.com, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\sweetsearch@gmail.com, In Quarantäne, [3b2ac61e3258e5519b8c29e1ed1627d9]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [f4714f953e4c0036251ec3d2b94b6f91]
PUP.Optional.FastSearch.A, HKU\S-1-5-21-1104028462-2252768145-1088222659-1001\SOFTWARE\MOZILLA\EXTENDS|appid, searchffv2@gmail.com, In Quarantäne, [bea7b1336327c5710daf6d9b13f0d42c]
Registrierungsdaten: 11
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK),Ersetzt,[20458163a7e355e1c95231fa73926e92]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}),Ersetzt,[baabecf892f8c472f8a31317c93c23dd]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK),Ersetzt,[98cda341bbcf0c2aeeadf337838204fc]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}),Ersetzt,[adb8459fcbbf2b0b1a815cce996c04fc]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[7fe633b14f3b5dd95fbf74c2669fe719]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK),Ersetzt,[11541fc5d0ba87aff72479b2ac598080]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}),Ersetzt,[a3c25193b9d1e94d6d2ea2886b9a54ac]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK),Ersetzt,[68fdaa3a1e6c06302972d3575fa6cb35]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q={searchTerms}),Ersetzt,[056023c1fb8f1a1c702b1a10ae5737c9]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[6df86e761575ee481608ad8937ce5fa1]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1104028462-2252768145-1088222659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK),Ersetzt,[3f2624c01c6e191d7b21da5060a557a9]
Ordner: 6
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpmobilbpcccgegofocnlfmallakegc\141, In Quarantäne, [4421766e9af042f454711a72ad577789],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpmobilbpcccgegofocnlfmallakegc, In Quarantäne, [4421766e9af042f454711a72ad577789],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\qGW@I.org\content, In Quarantäne, [85e00fd5543664d225ae177547bd15eb],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\qGW@I.org, In Quarantäne, [85e00fd5543664d225ae177547bd15eb],
PUP.Optional.DownSave.A, C:\Program Files (x86)\DowNSavee, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.EnjoyCoupon.A, C:\Program Files (x86)\EennjoyaCaooUpoen, In Quarantäne, [273eab390b7f112561f3d8b517ed3fc1],
Dateien: 42
PUP.Optional.Multiplug, C:\Program Files (x86)\SectionLogistics\SectionLogistics.dll, Löschen bei Neustart, [99ccfee61a700f27d09b13679968936d],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\Authy Chrome Extension\Authy Chrome Extension.exe, In Quarantäne, [5a0b43a1a0ea10261afd46355ca50af6],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\Awesome Widget ANTP\Awesome Widget ANTP.exe, In Quarantäne, [0f56756f89013600c84f285322dfbe42],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\DowNSavee\UNYiYpwTkG4hNM.exe, In Quarantäne, [e184e4001971082efa1d87f46b961be5],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\EennjoyaCaooUpoen\hPdhLFfsu8CFEs.exe, In Quarantäne, [2f3621c34545a3937b9c79029e636a96],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\EnJOyCoouponn\EnJOyCoouponn.exe, In Quarantäne, [60057f65f79371c534e35d1efe03a25e],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\Mozilla Firefox\dbghelp.dll, In Quarantäne, [ce97b232e3a72610ab6c0ea641c0738d],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$R6UADVT\50CCouuponss.exe, In Quarantäne, [b9aceff54a4064d24fc8295290714bb5],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$R92SQ8I\xHyUFaOCtbe2sZ.exe, In Quarantäne, [bda85490a2e853e3b3645427ae53a759],
PUP.Optional.MultiPlug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$R92SQ8I\xHyUFaOCtbe2sZ.x64.dll, In Quarantäne, [bea77c6890fa90a64776e0dda55cfe02],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$R9TQ35X\IwillriL Unnoficial Pocket Client.exe, In Quarantäne, [7ce98a5af09abf779c7ba0dbd32ea759],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$RD8O3AX\i2Symbol Emoticons Smileys Symbols.exe, In Quarantäne, [e48153912268191daaed0395a75a44bc],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$RF3XQRJ\GreeiatSaveo44U.exe, In Quarantäne, [c2a337ad6327ac8a8e893546f50c6e92],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$ROCKKN4\Twitcher Twitter Account Switcher.exe, In Quarantäne, [570e42a2ec9eac8a46d1cead52af32ce],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$RQDK2I8\z11y5Dd3D4zJ4W.exe, In Quarantäne, [00658e56e1a92313fb1c3249936e09f7],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$RR8SA79\PriCeMeinuus.exe, In Quarantäne, [372e707435558bab880fd1c7c63b817f],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$RSINS2Y\Tab for a Cause.exe, In Quarantäne, [9ec7558f3159ff37c55292e941c09967],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$RVNRZ8G\fy8LvyXmPCuyny.exe, In Quarantäne, [a1c46c78474386b060376c2c11f0e21e],
PUP.Optional.Multiplug.A, C:\$Recycle.Bin\S-1-5-21-1104028462-2252768145-1088222659-1001\$RGJZPBQ\DoWnSaaVe.exe, In Quarantäne, [6203bc288bff56e0b067c3b8629ff50b],
PUP.Optional.Multiplug.A, C:\Users\Sarah\AppData\Local\Temp\QSALFR.tmp\z11y5Dd3D4zJ4W.exe, In Quarantäne, [f96c1fc53c4ebd79b5624437679a41bf],
PUP.Optional.LightningDownloader.A, C:\Users\Sarah\AppData\Local\Temp\DC20\temp\lightningdownloader.exe, In Quarantäne, [aabb5f855e2ccc6a86ac5ef788787b85],
PUP.Optional.MyStartSearch.A, C:\Users\Sarah\AppData\Local\Temp\DC20\temp\wpc_mystartsearch.exe, In Quarantäne, [7ee75d87256562d4df4980e86f96fa06],
PUP.Optional.PricePeep.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage, In Quarantäne, [ec7922c2d5b5f83e95a5e920c73c51af],
PUP.Optional.PricePeep.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, In Quarantäne, [7fe6d3117a10171ff74345c4e023e818],
PUP.Optional.MyStartSearch.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\searchplugins\mystartsearch.xml, In Quarantäne, [70f5df057218fa3c3e8056ca9c6760a0],
PUP.Optional.ShoppingGate.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_inst.shoppingate.info_0.localstorage, In Quarantäne, [eb7a4b9967230a2c96c1330b0af94fb1],
PUP.Optional.ShoppingGate.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_inst.shoppingate.info_0.localstorage-journal, In Quarantäne, [79ecbb297713ba7c87d083bb0201aa56],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpmobilbpcccgegofocnlfmallakegc\141\lsdb.js, In Quarantäne, [4421766e9af042f454711a72ad577789],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpmobilbpcccgegofocnlfmallakegc\141\background.html, In Quarantäne, [4421766e9af042f454711a72ad577789],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpmobilbpcccgegofocnlfmallakegc\141\content.js, In Quarantäne, [4421766e9af042f454711a72ad577789],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpmobilbpcccgegofocnlfmallakegc\141\iArpsazt.js, In Quarantäne, [4421766e9af042f454711a72ad577789],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpmobilbpcccgegofocnlfmallakegc\141\manifest.json, In Quarantäne, [4421766e9af042f454711a72ad577789],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\qGW@I.org\content\bg.js, In Quarantäne, [85e00fd5543664d225ae177547bd15eb],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\qGW@I.org\bootstrap.js, In Quarantäne, [85e00fd5543664d225ae177547bd15eb],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\qGW@I.org\chrome.manifest, In Quarantäne, [85e00fd5543664d225ae177547bd15eb],
PUP.Optional.MultiPlug.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\qGW@I.org\install.rdf, In Quarantäne, [85e00fd5543664d225ae177547bd15eb],
PUP.Optional.DownSave.A, C:\Program Files (x86)\DowNSavee\UNYiYpwTkG4hNM.tlb, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.DownSave.A, C:\Program Files (x86)\DowNSavee\UNYiYpwTkG4hNM.dat, In Quarantäne, [dc8910d4becc26108ec5ccc1699b07f9],
PUP.Optional.EnjoyCoupon.A, C:\Program Files (x86)\EennjoyaCaooUpoen\hPdhLFfsu8CFEs.tlb, In Quarantäne, [273eab390b7f112561f3d8b517ed3fc1],
PUP.Optional.EnjoyCoupon.A, C:\Program Files (x86)\EennjoyaCaooUpoen\hPdhLFfsu8CFEs.dat, In Quarantäne, [273eab390b7f112561f3d8b517ed3fc1],
PUP.Optional.QuickStart.A, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Ersetzt,[90d53aaa76141323e047e78738cd8f71]
PUP.Optional.MyStartSearch, C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.selectedEngine", "mystartsearch");), Ersetzt,[b2b3bf25ee9cd264ade7c9a7d134d32d]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.208 - Bericht erstellt 21/07/2015 um 13:32:39
# Aktualisiert 09/07/2015 von Xplode
# Datenbank : 2015-07-15.1 [Server]
# Betriebssystem : Windows 8 Pro (x64)
# Benutzername : Sarah - SARAH-PC
# Gestarted von : C:\Users\Sarah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LY2R0EN4\AdwCleaner_4.208.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\507114f000000d5c
Ordner Gelöscht : C:\ProgramData\7207110823293547146
Ordner Gelöscht : C:\ProgramData\cfa6a2ca000017dc
Ordner Gelöscht : C:\ProgramData\{8dc2438e-f28c-7ded-8dc2-2438ef280e3b}
Ordner Gelöscht : C:\Program Files (x86)\EnJOyCoouponn
Ordner Gelöscht : C:\Users\Sarah\AppData\Roaming\LightningDownloader
Datei Gelöscht : C:\Program Files (x86)\prefs.js
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Sarah\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\0cc95f73-29ee-fdcb-9935-203172566a87
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{588BD59D-3E28-483B-8484-164D57F40D62}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9A44AB5B-B488-42A3-8D2B-7A0DA772F3A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{06B99631-BFA2-3B7A-F58B-D067C2BA59B7}
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v10.0.9200.17377
-\\ Mozilla Firefox v38.0.5 (x86 de)
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.alias", "mystartsearch");
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.iconURL", "hxxp://www.mystartsearch.com/favicon.ico");
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.name", "mystartsearch");
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.url", "hxxp://www.mystartsearch.com/web/?type=ds&ts=1433360258&z=2ec1dafe4262a358582527bg3z6cccecdq7e1ofw9w&from=wpc&uid=ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK&q[...]
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.1GmPWiF5IzYx5Fdc.scode", "(function(){try{if(window.location.href.indexOf(\"rjr8qTs4rTYGpjw4rTYGqHC7qdU\")>-1){return;}}catch(e){}try{var d=[[\"www.ewoss.com\",\"livewebcams.xyz\[...]
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.2JywK3ut6XxQ8ELM.scode", "(function(){try{if(window.location.href.indexOf(\"rjr8qTs4rTYGpjw4rTYGqHC7qdU\")>-1){return;}}catch(e){}try{var d=[[\"search.asistents.com\",\"cryptogma[...]
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.7XpNy5DEcuTwcghF.scode", "(function(){try{if(window.location.href.indexOf(\"rjr8qTs4rTYGpjw4rTYGqHC7qdU\")>-1){return;}}catch(e){}try{var d=[[\"cryptogmail.com\",\"bancdebinary.c[...]
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.FjfGnjNQ8PNf5dRo.scode", "(function(){try{if(window.location.href.indexOf(\"rjr8qTs4rTYGpjw4rTYGqHC7qdU\")>-1){return;}}catch(e){}try{var d=[[\"www.ewoss.com\",\"livewebcams.xyz\[...]
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.Un4kzeatNsx0tBHY.scode", "(function(){try{if(window.location.href.indexOf(\"rjr8qTs4rTYGpjw4rTYGqHC7qdU\")>-1){return;}}catch(e){}try{var d=[[\"www.ewoss.com\",\"livewebcams.xyz\[...]
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.Y9CPLWW7Aty6R8eb.scode", "(function(){try{if(window.location.href.indexOf(\"rjr8qTs4rTYGpjw4rTYGqHC7qdU\")>-1){return;}}catch(e){}try{var d=[[\"cryptogmail.com\",\"bancdebinary.c[...]
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.enable_search1", false);
[xh3mnej0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
-\\ Google Chrome v43.0.2357.134
*************************
AdwCleaner[R0].txt - [4819 Bytes] - [21/07/2015 13:27:29]
AdwCleaner[S0].txt - [4853 Bytes] - [21/07/2015 13:32:39]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4912 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.1 (07.16.2015:1)
OS: Windows 8 Pro x64
Ran by Sarah on 21.07.2015 at 13:44:04,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Users\Sarah\AppData\Roaming\appdataFr25.bin
Successfully deleted: [File] C:\Users\Sarah\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_ogminpmldncgcmokldnmmapddoccmhfl_0.localstorage
Successfully deleted: [File] C:\Users\Sarah\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_ogminpmldncgcmokldnmmapddoccmhfl_0.localstorage-journal
~~~ Folders
Successfully deleted: [Folder] C:\ProgramData\google
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Sarah\AppData\Roaming\mozilla\firefox\profiles\xh3mnej0.default\extensions\staged
Successfully deleted the following from C:\Users\Sarah\AppData\Roaming\mozilla\firefox\profiles\xh3mnej0.default\prefs.js
user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
user_pref(browser.search.searchengine.ptid, wpc);
user_pref(browser.search.searchengine.uid, ST500LT012-1DG142_S3P7QMWKXXXXS3P7QMWK);
user_pref(extensions.unitedinternet.email.runonceNewUsersShown, true);
Emptied folder: C:\Users\Sarah\AppData\Roaming\mozilla\firefox\profiles\xh3mnej0.default\minidumps [2 files]
~~~ Chrome
[C:\Users\Sarah\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Sarah\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Sarah\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Sarah\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.07.2015 at 14:07:46,38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-07-2015
Ran by Sarah (administrator) on SARAH-PC on 21-07-2015 14:11:20
Running from C:\Users\Sarah\Desktop
Loaded Profiles: Sarah (Available Profiles: Sarah)
Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-06-29] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191528 2014-07-04] (Geek Software GmbH)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] (Atheros Communications)
HKU\S-1-5-21-1104028462-2252768145-1088222659-1001\...\Run: [AdobeBridge] => [X]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-1104028462-2252768145-1088222659-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKU\S-1-5-21-1104028462-2252768145-1088222659-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1104028462-2252768145-1088222659-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{8359DAD9-E1CC-4321-8ED0-D2A7BE0D0EFE}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{9A39B855-A6CE-4479-9C4E-E6D63ABFFC4A}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{A66A9838-764E-4561-8285-7913128B9293}: [DhcpNameServer] 192.168.178.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-18] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-18] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-01-21] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-01-21] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\xh3mnej0.default\extensions\mtry_qxbyjnj_wyp@oaenfxhaibldvvy.org [not found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-16]
CHR Extension: (Google Drive) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-16]
CHR Extension: (YouTube) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-16]
CHR Extension: (Google Search) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-16]
CHR Extension: (Google Wallet) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-16]
CHR Extension: (Gmail) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-16]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Windows (R) Win 7 DDK provider) [File not signed]
S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-18] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 Rotten Stay; C:\Program Files (x86)\Rotten Stay\Rotten Stay.exe [8016609 2015-07-18] () [File not signed] <==== ATTENTION
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16024 2015-01-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-25] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-07-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-21 14:11 - 2015-07-21 14:11 - 00000000 ____D C:\Users\Sarah\Desktop\FRST-OlderVersion
2015-07-21 14:07 - 2015-07-21 14:07 - 00002205 _____ C:\Users\Sarah\Desktop\JRT.txt
2015-07-21 13:26 - 2015-07-21 13:32 - 00000000 ____D C:\AdwCleaner
2015-07-21 09:40 - 2015-07-21 13:39 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-21 09:39 - 2015-07-21 09:39 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-21 09:39 - 2015-07-21 09:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-21 09:38 - 2015-07-21 09:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-21 09:38 - 2015-07-21 09:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-21 09:38 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-07-21 09:38 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-07-21 09:38 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-07-21 09:23 - 2015-07-21 12:43 - 00000000 ____D C:\Program Files (x86)\Awesome Widget ANTP
2015-07-20 18:23 - 2015-07-13 23:22 - 00792032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-20 18:23 - 2015-07-13 23:22 - 00177632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-18 21:18 - 2015-07-18 21:18 - 00000000 ____D C:\Program Files (x86)\Rotten Stay
2015-07-16 16:26 - 2015-06-15 17:22 - 13771264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 02056704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 01763328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00737280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00690176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-07-16 16:26 - 2015-06-15 17:22 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 15415296 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 02656768 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 02237440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 01409024 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 00949760 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 00601600 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-07-16 16:26 - 2015-06-15 17:20 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-07-16 16:26 - 2015-06-15 17:19 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-07-16 16:26 - 2015-06-15 17:19 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-07-16 16:25 - 2015-06-27 18:36 - 00171352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-07-16 16:25 - 2015-06-27 15:56 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2015-07-16 16:25 - 2015-06-27 15:55 - 02865152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-07-16 16:25 - 2015-06-27 15:55 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-07-16 16:25 - 2015-06-27 15:55 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-07-16 16:25 - 2015-06-27 15:46 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-07-16 16:25 - 2015-06-27 15:46 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-16 16:25 - 2015-06-27 15:46 - 00829952 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-16 16:25 - 2015-06-27 15:46 - 00588800 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2015-07-16 16:25 - 2015-06-27 15:46 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-16 16:25 - 2015-06-27 15:23 - 00694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-07-16 16:25 - 2015-06-25 20:29 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-16 16:25 - 2015-06-25 20:27 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-16 16:25 - 2015-06-11 22:29 - 01302528 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-16 16:25 - 2015-06-11 18:27 - 01024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-07-16 16:23 - 2015-06-17 16:13 - 01150264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-07-16 16:23 - 2015-06-17 15:44 - 01567560 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-16 16:23 - 2015-06-09 15:57 - 03248640 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-07-16 16:22 - 2015-06-15 17:22 - 08858112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2015-07-16 16:22 - 2015-06-15 17:22 - 02416640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-07-16 16:22 - 2015-06-15 17:22 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-07-16 16:22 - 2015-06-15 17:22 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-07-16 16:22 - 2015-06-15 17:21 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-16 16:22 - 2015-06-15 17:20 - 10116608 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2015-07-16 16:22 - 2015-06-15 17:20 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-16 16:22 - 2015-06-15 17:19 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-07-16 16:20 - 2015-07-03 15:33 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-16 16:20 - 2015-07-03 15:32 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-16 16:20 - 2015-07-03 15:17 - 00366592 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-16 16:20 - 2015-07-03 15:16 - 00304128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-16 16:20 - 2015-07-02 22:31 - 19291136 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-07-16 16:20 - 2015-07-02 21:15 - 14384640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-07-16 16:20 - 2015-01-07 06:25 - 00403456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-16 16:17 - 2015-06-25 03:54 - 04064768 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-10 09:06 - 2015-07-21 13:18 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-10 09:06 - 2015-07-10 09:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-10 09:04 - 2015-07-21 13:19 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-10 09:04 - 2015-07-21 13:10 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-10 09:04 - 2015-07-10 09:04 - 00000000 ____D C:\Program Files\Google
2015-07-10 09:03 - 2015-07-21 13:39 - 00001132 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-10 09:03 - 2015-07-21 13:10 - 00003872 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-10 09:03 - 2015-07-16 16:18 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-07-10 09:03 - 2015-07-16 16:17 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-07-10 09:03 - 2015-07-16 15:46 - 00000000 ____D C:\Users\Sarah\AppData\Local\Google
2015-07-10 09:03 - 2015-07-10 09:06 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-10 09:03 - 2015-07-10 09:03 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-07-09 17:54 - 2015-07-09 17:57 - 00000000 ____D C:\Users\Sarah\Desktop\VA-TOP100_Single_Charts_vom_13-07-2015-CannaPower
2015-07-09 17:50 - 2015-07-09 18:18 - 00000000 ____D C:\Users\Sarah\Desktop\Empire_Cast-Original_Soundtrack_from_Season_1_of_Empire-(Deluxe_Edition)-WEB-2015-TSX
2015-07-09 17:50 - 2015-07-09 17:53 - 00000000 ____D C:\Users\Sarah\Downloads\_Empire_Cast-Original_Soundtrack_from_Season_1_of_Empire-(Deluxe_Edition)-WEB-2015-TSX
2015-07-09 17:47 - 2015-07-09 17:49 - 150069901 _____ C:\Users\Sarah\Downloads\_Empire_Cast-Original_Soundtrack_from_Season_1_of_Empire-(Deluxe_Edition)-WEB-2015-TSX.rar
2015-07-09 17:44 - 2015-07-09 17:44 - 19433552 _____ C:\Users\Sarah\Downloads\VA-TOP100_Single_Charts_vom_13-07-2015_05-CannaPower.zip
2015-07-09 17:43 - 2015-07-09 17:47 - 200182159 _____ C:\Users\Sarah\Downloads\_VA-TOP100_Single_Charts_vom_13-07-2015_04-CannaPower.zip
2015-07-09 17:40 - 2015-07-09 17:43 - 203606123 _____ C:\Users\Sarah\Downloads\_VA-TOP100_Single_Charts_vom_13-07-2015_03-CannaPower.zip
2015-07-09 17:40 - 2015-07-09 17:41 - 202492847 _____ C:\Users\Sarah\Downloads\VA-TOP100_Single_Charts_vom_13-07-2015_02-CannaPower.zip
2015-07-09 17:35 - 2015-07-09 17:37 - 202475885 _____ C:\Users\Sarah\Downloads\VA-TOP100_Single_Charts_vom_13-07-2015_01-CannaPower.zip
2015-07-09 17:17 - 2015-07-09 17:17 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_netaapl64_01009.Wdf
2015-07-09 16:33 - 2015-07-09 16:33 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-07-09 16:33 - 2015-07-09 16:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-07-09 16:30 - 2015-07-09 16:33 - 00000000 ____D C:\Program Files\iTunes
2015-07-09 16:30 - 2015-07-09 16:30 - 00000000 ____D C:\Program Files\iPod
2015-07-09 16:30 - 2015-07-09 16:30 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-07-07 09:41 - 2015-07-21 13:19 - 00000000 ____D C:\Program Files (x86)\SectionLogistics
2015-07-07 09:39 - 2015-07-21 12:43 - 00000000 ____D C:\Program Files (x86)\Authy Chrome Extension
2015-07-07 09:18 - 2015-07-07 09:18 - 00001268 _____ C:\Users\Sarah\Desktop\Revo Uninstaller.lnk
2015-07-07 09:18 - 2015-07-07 09:18 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-06 15:58 - 2015-07-06 16:00 - 00023533 _____ C:\Users\Sarah\Desktop\Addition.txt
2015-07-06 15:55 - 2015-07-21 14:11 - 00010633 _____ C:\Users\Sarah\Desktop\FRST.txt
2015-07-06 12:14 - 2015-07-21 14:11 - 02135552 _____ (Farbar) C:\Users\Sarah\Desktop\FRST64.exe
2015-07-06 11:57 - 2015-07-06 11:57 - 00007870 _____ C:\Users\Sarah\Desktop\Gmer.txt
2015-07-02 18:06 - 2015-07-21 14:11 - 00000000 ____D C:\FRST
2015-07-02 18:05 - 2015-07-02 18:05 - 00000472 _____ C:\Users\Sarah\Desktop\defogger_disable.log
2015-07-02 18:05 - 2015-07-02 18:05 - 00000000 _____ C:\Users\Sarah\defogger_reenable
2015-07-02 18:04 - 2015-07-02 18:04 - 00050477 _____ C:\Users\Sarah\Downloads\Defogger.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-10-21 15:36 - 2014-06-28 23:45 - 00000852 _____ C:\Windows\system32\Drivers\RTKHDRC.DAT
2021-10-04 09:34 - 2014-06-28 23:45 - 00000712 _____ C:\Windows\system32\Drivers\RTMICEQ0.DAT
2015-07-21 14:02 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2015-07-21 13:45 - 2012-07-26 12:27 - 00715482 _____ C:\Windows\system32\perfh007.dat
2015-07-21 13:45 - 2012-07-26 12:27 - 00148046 _____ C:\Windows\system32\perfc007.dat
2015-07-21 13:45 - 2012-07-26 09:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-21 13:39 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-21 13:38 - 2014-06-29 14:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-21 13:38 - 2014-06-28 19:31 - 01849235 _____ C:\Windows\WindowsUpdate.log
2015-07-21 13:38 - 2014-06-28 19:27 - 00036016 _____ C:\Windows\PFRO.log
2015-07-21 13:37 - 2012-07-26 09:59 - 00000000 ____D C:\Windows\CbsTemp
2015-07-21 13:32 - 2014-06-28 19:32 - 00000995 _____ C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-21 13:30 - 2014-12-08 12:30 - 00000937 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {DE4FEC30-9B34-4EA2-953F-BE7755838752}.job
2015-07-21 13:30 - 2014-12-08 12:30 - 00000751 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {DE4FEC30-9B34-4EA2-953F-BE7755838752}.job
2015-07-21 13:30 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-07-21 13:19 - 2012-07-26 12:29 - 00000000 ____D C:\Windows\SKB
2015-07-21 13:18 - 2014-06-28 22:14 - 00000000 ____D C:\Windows\system32\MRT
2015-07-21 13:18 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-07-21 13:09 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2015-07-21 12:45 - 2015-06-03 20:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-20 18:21 - 2015-04-16 18:29 - 05047664 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-20 18:17 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2015-07-18 20:39 - 2014-06-29 14:42 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-16 15:47 - 2014-06-30 15:25 - 00000000 ____D C:\Users\Sarah\AppData\Local\Adobe
2015-07-10 09:07 - 2014-06-30 15:26 - 00000000 ____D C:\ProgramData\Adobe
2015-07-10 09:05 - 2014-06-28 19:32 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Adobe
2015-07-10 09:02 - 2014-07-01 20:38 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-07-09 17:29 - 2014-06-28 19:44 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1104028462-2252768145-1088222659-1001
2015-07-09 17:17 - 2012-07-26 09:21 - 00025232 _____ C:\Windows\setupact.log
2015-07-09 17:10 - 2014-07-17 15:31 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Apple Computer
2015-07-09 16:30 - 2014-07-17 15:35 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2015-07-09 16:30 - 2014-07-17 15:29 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-07-06 12:23 - 2014-07-17 15:15 - 00000000 ____D C:\Users\Sarah\AppData\Local\CrashDumps
2015-07-06 11:23 - 2014-10-13 18:18 - 00000000 ____D C:\Users\Sarah\Documents\Bluetooth Folder
2015-07-05 12:08 - 2014-06-28 22:34 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 08:43 - 2014-06-28 22:14 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-07-02 18:05 - 2014-06-28 19:31 - 00000000 ____D C:\Users\Sarah
2015-07-02 17:20 - 2014-06-28 19:34 - 00000000 ____D C:\Windows\KJ
2015-06-24 19:13 - 2014-06-29 09:55 - 00000000 ____D C:\Users\Sarah\Documents\Bewerbungen
2015-06-23 11:46 - 2014-06-28 23:47 - 00000000 ____D C:\Users\Sarah\AppData\Local\Microsoft Help
==================== Files in the root of some directories =======
2015-06-04 12:25 - 2015-06-20 13:22 - 0001456 _____ () C:\Users\Sarah\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2015-06-03 22:33 - 2015-06-03 22:33 - 0000000 _____ () C:\Users\Sarah\AppData\Local\Temp.dat
2014-06-28 23:45 - 2014-06-28 23:45 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Sarah\AppData\Local\Temp\ose00000.exe
C:\Users\Sarah\AppData\Local\Temp\Quarantine.exe
C:\Users\Sarah\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-16 16:34
==================== End of log ============================ |