JoyDivision | 12.09.2013 10:37 | Alles gemacht :)
Anbei die Logs
Malwarebytes Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.12.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
Tim :: TIM-PC [Administrator]
Schutz: Aktiviert
12.09.2013 10:51:17
mbam-log-2013-09-12 (10-51-17).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 224257
Laufzeit: 7 Minute(n), 57 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 3
C:\Users\Tim\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Tim\AppData\Roaming\OpenCandy\5337FEFFE081463E9965DB21C833CBAE (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Tim\AppData\Roaming\OpenCandy\OpenCandy_5337FEFFE081463E9965DB21C833CBAE (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 4
C:\Users\Tim\AppData\Roaming\OpenCandy\5337FEFFE081463E9965DB21C833CBAE\frostwire-5.3.6.windows.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Tim\Downloads\DTLite4453-0297.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Tim\Downloads\FlashPlayer_V.97586600c.exe (Adware.DomaIQ) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Tim\Downloads\IlemiTVApp_Setup_18_22.exe (PUP.BundleInstaller.DW) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.0 (09.12.2013:1)
OS: Windows 7 Home Premium x64
Ran by Tim on 12.09.2013 at 11:17:13,72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\a28b4d68debaa244eb686953b7074fef
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\a28b4d68debaa244eb686953b7074fef
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskToolbarNRO_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskToolbarNRO_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskToolbarNRO_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskToolbarNRO_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4BB70AB0-C466-4415-86A4-5CDE2B02D5A2}
Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho1B18.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho26EA.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho30CC.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3328.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho53A4.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho5E77.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho5F8D.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho61E6.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho641.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho782C.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho7DE6.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho7DF.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8347.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8EA1.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9A42.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9F8C.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA3E6.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA884.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA97E.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB3AC.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB82F.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB86B.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoCBF2.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoCDEF.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoCF1B.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoD458.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoDBA.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE394.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoEF7C.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF3F1.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoFCE4.tmp
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{000D30A3-4F59-45AF-BEF0-236D04440D4D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{02A94AD1-8354-4AF5-ACDD-CA9F067DB78A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{04D7309F-D5B9-41DB-9375-BE49AAA65BAF}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{05AEB6E4-77B5-492E-AF61-B0F2426D5061}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{05EC3BFB-54A0-4A57-BF3A-D9BEF03FB015}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{06BEBCC6-BB44-4CF9-A7EE-716ED48454F7}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{077A097F-ABD3-4569-A4D1-7D316801E6AF}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{07D3881C-B32F-46AF-B3F5-B18D522F0E6D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{081844FF-346E-48AF-A772-FA0CE1957409}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{0955DA87-6146-4A83-BD6B-E48EED6191C5}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{0AEC0E5C-C115-4B58-AFB5-492F8A37DA79}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{0B611CD8-C45F-41D0-AFF2-4AED54EF2686}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{0B721824-1A01-4D31-BBC2-0344679F1DDA}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{0B78798E-5C4A-4D49-BA53-9D44F2A49D3D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{0C8AC2A5-DF28-4624-AB23-4C3D5543677E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{0D267387-95DC-4D6D-8371-D3C12AED0350}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{1208A24A-FB5F-45AB-A106-DCA8E67B533A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{120CA8B8-2D42-447F-8323-2470D966D185}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{1213EA75-FDCE-44C1-B2F7-1937A1D7D1E4}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{12D06A07-E103-45E0-A135-E1FFED6CBEF3}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{132A3D01-78AB-43BB-AEE2-C679353CED53}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{147EEF62-E482-4A65-A381-DE332873B537}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{152844A5-262E-4B6B-BCFE-756A54A0BBFD}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{16469650-6A9A-4B23-8416-E0A07142BFE4}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{16CE7695-8B63-4E45-877C-A33B7A970138}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{16D2F278-DE55-4A37-A92C-48D69C0AB92E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{178B569F-4F4C-4930-B8EB-9489CA7E1C7E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{190EB854-A13A-46F8-9F74-BDA513967EE7}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{1BD09D49-B0BB-4A65-82CE-B446DBD4F8EB}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{1BE947C5-12D9-4F39-8054-A0FB454A0C9D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{1E046E2A-97DA-48B3-A62E-23CF5C57A1FF}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{1F572402-9E00-4FA6-B06C-86AE66547308}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{20BBE9A1-9391-47D7-8E81-901884DEC4A8}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{20D7D52D-9303-424C-80FE-8B36D58B9338}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{21E44BB9-6BB5-4FB2-9FCA-3A08CCE537F1}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{22BA84DA-9DEE-424C-B3B1-0D3C7CA97785}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{23386211-F7DD-43BD-B641-CC5A00C4A663}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{24C2DA2F-7BAC-4FFF-966D-047FB0514711}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{25166FC8-9841-42DF-82B6-DCCBBD7D35FE}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{255B7AB8-7599-41A5-9D35-54E4E1C9A0B6}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{25951F83-0B18-4D6B-8E46-864B3EF5CA19}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{29AF60E8-E434-414F-AC98-15A865D27F19}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{29C0406F-7801-4231-AFDD-EC7016588778}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{29ECEA3A-71E3-456F-98CB-5D776ED3DC8F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{2A0FB382-BFDF-4BFD-93D6-55E24EED25B7}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{2D537635-FE60-49E7-9F8F-DE9662446942}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{2DEBE254-C1FE-4BEC-B9C9-64B4F82ECB25}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{2E1A7919-780D-4BE1-90FD-7F7AF7C291DC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{2E4AC56C-A6CC-4C06-8C85-C12BBFC77099}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{2E4B22FC-D0B3-4178-B7C2-1F4A99DE484A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{2FA53917-9ADB-4564-85F2-01D7072F7965}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{30C55527-F058-4E8A-86DA-C23184EA82A5}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{30F19F3C-8CA4-4AB4-99B2-2F682A6FEA4D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{32C360B1-CBA9-46DD-9D03-F68677E25023}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{334B8B85-2A09-4B85-8E56-E2FF7D70A494}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{33F06579-B91E-4A8E-AC4C-906EA6DF50AD}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{34A5A46A-2734-46BF-96CA-532201F76199}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{35098390-D3D7-48BD-92E1-E52FD453AD86}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{35432C65-FDDA-418B-A104-4E2F27FFF37B}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{355694A4-BF48-4B77-88D9-E1A551D72513}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{35ABB204-A1AC-4D05-B05F-3141D258F682}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3784283C-6690-4513-9E6E-B4F4329BE570}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{37D96AC2-C869-4CC7-B4DD-F954DEF1A8F2}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{39FAC4E8-C05B-457F-A743-8DD6C1125191}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3A546509-BD81-43AD-88E1-0BEEC0AD45C5}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3A5A5173-9076-4559-800C-D5542A601B96}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3C0F6E2B-BB4A-4EF2-8B73-4883A728E051}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3E27F120-74A8-4CFD-AE3C-47A2EDF85EE0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3F10B8DE-E68D-432C-90F6-F10DFC10B4FB}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3F1EB905-834B-4A9B-B584-8E7A018603BF}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{3FD41215-B473-4B63-8792-2166C9217418}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{4021E0D3-C758-4C15-8828-975208CC27FE}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{403C4C4A-CE98-4796-A106-E8F3C96FCE66}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{414136D4-CEF7-4AD0-B27B-264F637B22D1}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{4214AC71-9605-403F-9E60-B8B3C004212E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{4240750E-509A-4B92-8D5B-19E5786F0DB2}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{45A204D9-DCBB-4D60-B219-06F5E1BF161C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{48292D73-1D64-409B-9F21-EE7100B06B92}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{494ECF0F-091A-4DE5-8BDC-35175E751333}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{4AE1660F-9971-46B5-B74C-265B108A69A7}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{4C15C6D7-4DDE-46AA-917C-665659FC0AC3}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{504B34ED-9CFF-4CB3-BFE2-6F680D34C117}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5119C6EB-9461-4320-BBAB-EE6C888DABD9}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{54A08D0C-5894-4FDA-9A0E-6B92B5C0D2B5}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{55853648-4212-4A9C-8231-8AABA46DEF7F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{569F3C17-65F0-480A-B376-AF55E4637BBC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{576473F1-6DE9-4152-8951-6B9DD81B2483}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{58D82097-A7EB-4711-B6E2-00E7DE4D5FA9}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5986893F-D10B-40F4-9984-EB032CADD2D8}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{59FF8B83-3D7C-4664-BB92-D09DF1A26B10}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5AB86F79-9C69-4A8A-B765-8382E4A89137}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5BA8958B-23AC-4FEC-8FF1-C812EB5EE152}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5C4F2403-AD7C-48E4-980D-A5705F651FCC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5D2AFB3C-9EA7-4C81-99CF-D6353F62CC21}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5DF147F9-F325-478F-BA55-4FF9BBD63F5B}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{5E4D8C11-8DC8-4261-AA82-14951DBC236D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{61B46BA9-E5E3-4D4E-9300-019BF8C3577C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6236D630-DE96-4A47-B4C8-BFD462C3C765}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{62869877-C466-4FC7-A8D1-6F19888300D6}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{643C076A-A9DE-4A1F-9EE9-AA16EC25B6D2}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6571F241-D124-4A23-A0D9-36B476F32D6A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{68031E0F-FC66-4DD7-93AA-AA645D809654}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6A357A38-FD47-4D23-A9C7-81BB12010C1B}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6A4F073E-851E-4798-950D-1112F12560F1}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6C05C3F1-2F6F-4F36-AE75-CB7E2FD74DDF}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6C101E5C-8EA3-4C6E-A17E-5CBF5D2730C0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6CD65DC6-D2B4-43E8-80FC-860F8D2904D5}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{6D68EBA0-3F09-4C0A-88E2-F15BF5AE66D9}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{71E053FC-47CB-4A99-A700-001CFBE2E1C4}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{734D4756-4EA7-4C26-91FF-631B4AA7BD40}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{74590766-451D-4B85-93B5-B2D19F2AF300}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{752ECCB5-61CA-4E99-A349-0589377A55ED}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{753B8651-3A34-4098-A627-CAE40EB8243D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{7563FC86-7697-4A24-88C6-1395B2A6D3CC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{758E0D61-B7F7-4540-8EAE-92C19CBF12B6}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{75C974F5-9AAE-498D-8333-6ABB36CB2878}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{76550401-0A12-4C8D-A39C-6B7EACD39065}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{769E00C5-BBCD-47F7-8A2A-9E839DC2E3F0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{77039DBE-1A06-446F-B47A-EEBEF36B5EAC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{78BDA9E1-2FD1-44C9-8700-8E33F8B1CE70}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{7B972162-ABD8-4951-B5CD-ED90B2378E4F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{7DAB8E9A-189A-45CD-A8BE-6E1B945A67B0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{7EAFB18B-1039-4484-BA25-EEFDFA9DAA35}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{7FB205CC-314F-4E4D-8ABD-2548D7EE74F0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{7FDCE6A9-B284-48B7-9723-42F682FD94A0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{806F3638-6DEB-48A7-8FEE-95820AD203BC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{82204A3E-9A1D-4194-888D-79BD499CE899}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{83606D10-3674-48D3-B2BF-C9C2C6CCB8EC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{83F7BF6E-4E07-4627-8AD6-0D68BE13FEF5}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{86483831-4CF7-460A-A623-E1824E7B5768}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{882043C2-1DE0-414D-878D-AC739BCC40C3}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{8850AA17-7D03-4EC6-A255-0F3E548CE3FC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{88AAC97E-EE36-4F5B-A483-5CE33CDEE505}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{8A49CF87-8D79-46D4-9E90-387814EB52DE}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{8AE2AA04-7280-4D1F-8CAE-115F5063274C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{8AF16D2D-BFC4-4B4A-88E1-DFAA9C74F969}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{8B5E64D8-61F7-464A-8F71-8A4BEEC88003}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{8CDD6E36-58B3-4008-97D6-81028175DD15}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{8F939EA2-068D-4EFB-B63A-C3F2A488939F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{91E0F76E-FBAF-45A2-A154-53C32767300E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9270D998-8160-47AA-9172-2203AA52E5A3}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9276F351-77EC-40F1-9A29-EE278673482F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{93CFDFD8-10D2-489C-86A1-BB549680F7F4}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{941FB3B0-21A7-49C5-9C23-7902F11647B4}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9751B06F-695C-4994-8A9E-40D80886EAE1}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{98CAAB4C-6010-44CF-AF38-BADC0C1E59DE}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9927B7F8-F5F2-444F-8658-D6FCD400EAD2}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{997E799C-335E-4D37-AA01-4D4E6F0240FE}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9BE5B324-3BA8-4A55-B8FC-CA534A494672}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9E4C78A3-2F0C-42E1-89D8-B6B00C2BFE66}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9EECFFEC-56B7-434C-AA91-328CF5B395CB}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9EEE2C2F-0F5F-4C96-93E7-A356564AC346}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{9FC9F4FE-AE2A-486C-8D3A-3597B23FDB0C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A0E49F9C-CE4F-4C0F-A067-6BD9E4FADAF0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A2585C10-BD26-4832-88E3-AB0709271A6A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A2DC47D4-D1B4-465D-8F2F-19965A8ABDB3}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A31A4A2A-892B-4FDD-8611-2FB9CAD86216}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A5781BC2-0450-4DA8-B8BA-6EAB78918EB6}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A60456F3-1991-4BDF-A425-C6A59D8FB867}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A75022BC-536B-490D-A369-29904B4650AD}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A78160E1-4EAB-40F9-972B-19EF1BF36708}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A7A9C69D-9EE9-4E89-85B4-0025FA43DD65}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A87D47B1-9FD4-46B3-9F10-9F54A64D2A9C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{A9255859-FD85-48F9-82F7-E8C998297C65}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{AA722B1F-2830-4ADD-A5A2-EBB5F7CBF4F4}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{AE96D258-19DB-4A75-AA16-A0EC65DE122B}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{AEA01854-139F-4585-B349-FD4F3895CA69}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{AEE07B08-A1C1-411C-A715-41A652957171}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B155E83B-81DA-4ED5-9A05-4B2D67349D70}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B2A025AA-822C-41FA-9C8F-0821FE8A3A04}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B2A08889-0C1E-48D1-B2F4-D9770205D6C7}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B2EFFDBF-F72E-4D9A-B0A1-E6613E5FE745}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B331C310-F523-4306-99E3-FBF21CCFB68D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B33EC854-FD13-4685-8FC4-B74FD806D544}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B4AA3043-B667-4CC7-BBC6-76A57D156E2A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B4DF4241-92E6-4944-9742-F4B4274FA883}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B6444E96-27A2-4F6C-9B66-9E91B82DD6BB}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{B7017B47-D43E-485E-9488-EA419594FC5A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BAC4AEB7-5799-48A9-98E7-E0806B7B27CD}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BB008CFE-99A0-4591-B664-A127637FC000}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BB483AA2-03D6-4F0C-8D3C-157F016E558C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BC63EFBE-EB32-44A9-A56A-CCC09228D986}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BD0E74BE-43E4-4AB6-90EC-028F981BAA44}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BD409CAC-7A4E-4383-9D8C-B653BC0F0A54}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BD573BC5-2EA7-4988-9B8D-BC2877331574}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BDDDF1CB-0B97-4048-86CF-E9FE042877BA}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BE600FDA-FFF6-4DB4-90DF-824E826EC62D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BF4DCE9B-E97F-4FBE-BA84-39503713500F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BFBFEB8A-F0AD-4C6A-A3D9-19545AF55914}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{BFECAC58-17E5-4B93-AA73-A44B1AAEEB13}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C24A1173-A2FE-418F-8FB7-5B7531B9AEB8}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C33D6434-A7BC-48D9-9BE6-BC85B26489CC}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C4FFC8BA-1534-4484-B59B-F119DE6CFE7E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C67D489E-0884-4D9A-B95A-CE569EAB375E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C699A1DB-7952-424A-BA4F-DFD372E07466}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C6BABD7B-72DC-4CDF-BA54-FA8B6349B001}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C817653C-506A-4C24-A9B2-3F43602251BB}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{C897E243-204F-414A-8BC1-5C95ECB4002A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{CB577DFE-599F-4F7B-9561-43E42836531E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{CB64FB3F-EA48-46AA-8378-476CF6DB9B52}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{CC344A75-D9EB-49B0-B677-6D1AD2C38456}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{CC755D0E-B104-4935-8B27-2F79CC452F4A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{CFA326DF-B6F0-4508-9D84-41DE75E83E39}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D26A1D1D-F638-4C77-9983-7808518C6ADB}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D39E1961-1218-4109-BEC9-67E7D144E09A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D5742ED3-EC97-4121-A018-CEB318D05D7C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D5A80243-2DD2-4904-B8DC-6D21C78F68DB}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D5E6F25A-1220-4920-BDF9-A10C1F13E938}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D6294130-3D62-4D64-A4DF-8910AFD4E981}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D6B259E3-B30E-4218-A162-4D9B5CDB42AA}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D7807C9D-7166-438A-AA83-35F389539778}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D7D18AC6-B088-40B7-9190-1E9900721631}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D82F48C4-31A7-4333-9829-04FA1C086785}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{D9FF0A24-4703-4931-B12D-D81F8CBF1D41}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{DA5C98B7-7291-4166-93C8-E570C151DB60}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{DB08A50C-0D97-4C07-8134-D19D33476F6F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{DB62C2DA-44EE-4C12-B084-9FFAD62D138D}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{DB769858-3BE5-4EEB-B974-E69788E42FA7}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{DBC78715-4C17-47E8-9B9A-E8E250064F6F}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{DD7E46AA-694A-4307-A96F-EC81361FCDBA}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{DE166178-2918-4F75-A084-4369A82C13B9}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E0351B38-0F9D-4337-8BC2-2EB1103FF5CE}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E0C2C02A-5A76-4009-9E88-97D2053638EE}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E3EDB5E5-AFCC-4EBA-BA33-679E9568D00E}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E4DC0132-9633-4852-B52E-AC82550A2881}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E66EC23D-F4AF-4181-B899-C30CBC34FB1A}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E6E7ECEC-9D34-4F4C-99A5-2F1C0CD34885}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E8D0E9CD-971B-4F47-9DAD-AACA98426626}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{E94D7099-9532-4143-8FFA-A1F7ABA94CE0}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{EDFB5C9D-8604-41B3-AFFD-CF77DD6DCB52}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{EF3601B9-2A8A-4005-B46B-F5B04F340B96}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{F08689D7-6A2C-418E-87CF-6B9B9103ACF2}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{F0D41B40-FC52-4A70-88D0-342811611DF9}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{F1DD5DE1-00FE-4DC3-8A28-FF16C04FDE84}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{F45F3799-A1EC-4A45-B1AE-E66D2EED3916}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{F5CBD3BB-FC24-4319-BAD5-308E67D6798C}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{F5D46353-793F-4FFF-816A-FFF0FEEAADA9}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{FB72007E-B548-4EB4-BA3A-645ED3402492}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{FBA81466-40AF-4B37-BAFE-B11501B68605}
Successfully deleted: [Empty Folder] C:\Users\Tim\appdata\local\{FFBD9172-6036-4A0E-A1DD-BA4DCCE23C54}
Successfully deleted: [Folder] "C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.09.2013 at 11:24:55,49
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ AdwCleaner Code:
# AdwCleaner v3.003 - Bericht erstellt am 12/09/2013 um 11:09:54
# Updated 07/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Tim - TIM-PC
# Gestartet von : C:\Users\Tim\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : ICQ Service
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\Program Files (x86)\Ask.com
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\ConduitEngine
Ordner Gelöscht : C:\Program Files (x86)\DVDVideoSoftTB
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Plasmoo
Ordner Gelöscht : C:\Users\Tim\AppData\Local\apn
Ordner Gelöscht : C:\Users\Tim\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Tim\AppData\Local\Temp\AskSearch
Ordner Gelöscht : C:\Users\Tim\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Tim\AppData\Local\Temp\CT2269050
Ordner Gelöscht : C:\Users\Tim\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Tim\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Tim\AppData\LocalLow\ConduitEngine
Ordner Gelöscht : C:\Users\Tim\AppData\LocalLow\DVDVideoSoftTB
Ordner Gelöscht : C:\Users\Tim\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\Smartbar
Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\Extensions\toolbar@ask.com
Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Ordner Gelöscht : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\Askcom.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-1.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-10.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-2.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-3.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-4.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-5.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-6.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-7.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-8.xml
Datei Gelöscht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\icqplugin-9.xml
Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_nero-burning-rom_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_nero-burning-rom_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3ECD1E31-F6D8-49E3-BDFB-AD61A9C5AAEB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{0C58B7D1-D415-492B-A149-E976156BD3B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3ECD1E31-F6D8-49E3-BDFB-AD61A9C5AAEB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CEA54AC0-0E0F-4673-B696-DA89AEDEBD10}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6DD7901F-DDF9-4FA4-A2E9-A217D45B98EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2BE26CB-D9D8-490A-B987-5F2361549FAC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Schlüssel Gelöscht : HKCU\Software\APN
Schlüssel Gelöscht : HKCU\Software\Ask.com
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\conduitEngine
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKLM\Software\APN
Schlüssel Gelöscht : HKLM\Software\AskToolbar
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\conduitEngine
Schlüssel Gelöscht : HKLM\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICQToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16686
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v8.0.1 (de)
[ Datei : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\prefs.js ]
Zeile gelöscht : user_pref("CT2269050.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2269050.FirstTime", "true");
Zeile gelöscht : user_pref("CT2269050.FirstTimeFF3", "true");
Zeile gelöscht : user_pref("CT2269050.UserID", "UN77273010461910406");
Zeile gelöscht : user_pref("CT2269050.autoDisableScopes", -1);
Zeile gelöscht : user_pref("CT2269050.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2269050.isPerformedSmartBarTransition", "true");
Zeile gelöscht : user_pref("CT2269050.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fbvb.de%2F\",\"EB_MAIN_FRAME_TITLE\":\"Seiten-Ladefehler\"}");
Zeile gelöscht : user_pref("CT2269050.openThankYouPage", "FALSE");
Zeile gelöscht : user_pref("CT2269050.openUninstallPage", "FALSE");
Zeile gelöscht : user_pref("CT2269050.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2269050.serviceLayer_services_serviceMap_lastUpdate", "1371812484039");
Zeile gelöscht : user_pref("CT2269050.settingsINI", true);
Zeile gelöscht : user_pref("CT2269050.shouldFirstTimeDialog", "FALSE");
Zeile gelöscht : user_pref("CT2269050.smartbar.CTID", "CT2269050");
Zeile gelöscht : user_pref("CT2269050.smartbar.Uninstall", "0");
Zeile gelöscht : user_pref("CT2269050.smartbar.toolbarName", "DVDVideoSoftTB ");
Zeile gelöscht : user_pref("CT2269050.toolbarBornServerTime", "7-08-2012");
Zeile gelöscht : user_pref("CT2269050.toolbarCurrentServerTime", "7-08-2012");
Zeile gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Zeile gelöscht : user_pref("browser.search.order.1", "Ask.com");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Ask.com");
Zeile gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}&qsrc={qsrc}");
Zeile gelöscht : user_pref("extensions.asktb.keyword-toggled-in-session", false);
Zeile gelöscht : user_pref("extensions.asktb.new-tab-opt-out", true);
Zeile gelöscht : user_pref("extensions.asktb.oldVersion", "5.15.23.36191");
Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Zeile gelöscht : user_pref("extensions.enabledAddons", "ich@maltegoetz.de:1.3.4,{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.1,{ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10,{872b5b88-9db5-4310-bdd0-ac189557e5f5}:10.10.2[...]
Zeile gelöscht : user_pref("icqtoolbar.allowSendURL", false);
Zeile gelöscht : user_pref("icqtoolbar.defSearchChange", true);
Zeile gelöscht : user_pref("icqtoolbar.engineVerified", true);
Zeile gelöscht : user_pref("icqtoolbar.geolastmodified", 1322225334);
Zeile gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options");
Zeile gelöscht : user_pref("icqtoolbar.hpChange", true);
Zeile gelöscht : user_pref("icqtoolbar.icqgeo", 49);
Zeile gelöscht : user_pref("icqtoolbar.installTime", "1320753288");
Zeile gelöscht : user_pref("icqtoolbar.installsource", "1");
Zeile gelöscht : user_pref("icqtoolbar.newtab_state", "1");
Zeile gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
Zeile gelöscht : user_pref("icqtoolbar.previousFFVersion", "7.0.1");
Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
Zeile gelöscht : user_pref("icqtoolbar.suggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "130462095313046209531304624639820");
Zeile gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1322495014);
Zeile gelöscht : user_pref("icqtoolbar.userEngineApproved", true);
Zeile gelöscht : user_pref("icqtoolbar.userHpApproved", true);
Zeile gelöscht : user_pref("icqtoolbar.version", "1.3.6");
Zeile gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherWasShown", 1);
Zeile gelöscht : user_pref("icqtoolbar.xmlEnableHomePageDsGuard", false);
Zeile gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");
-\\ Google Chrome v29.0.1547.66
[ Datei : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [19173 octets] - [12/09/2013 11:08:49]
AdwCleaner[S0].txt - [16628 octets] - [12/09/2013 11:09:54]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16689 octets] ########## FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-09-2013 02
Ran by Tim (administrator) on TIM-PC on 12-09-2013 11:28:10
Running from C:\Users\Tim\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\ICQ.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
(Spotify Ltd) C:\Users\Tim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
(Wistron) C:\Program Files (x86)\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files (x86)\Launch Manager\OSD.exe
(Wistron Corp.) C:\Program Files (x86)\Launch Manager\WButton.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\watchmi\TvdService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(X10) C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Wistron Corp.) C:\Program Files (x86)\Launch Manager\WisLMSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11780712 2011-03-09] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-09] (Realtek Semiconductor)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2294568 2010-09-03] (Synaptics Incorporated)
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-05-05] (Google Inc.)
HKCU\...\Run: [ICQ] - C:\Program Files (x86)\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3481408 2012-02-13] (DT Soft Ltd)
HKCU\...\Run: [msnmsgr] - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4283256 2011-05-13] (Microsoft Corporation)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Tim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-05] (Spotify Ltd)
HKCU\...\Run: [Spotify] - C:\Users\Tim\AppData\Roaming\Spotify\spotify.exe [4640768 2013-07-05] (Spotify Ltd)
MountPoints2: G - G:\Launcher.exe -a
MountPoints2: {171c6b7f-7ca5-11e1-b834-00262dc5da2f} - F:\Autorun.exe
HKLM-x32\...\Run: [HotkeyApp] - C:\Program Files (x86)\Launch Manager\HotkeyApp.exe [207400 2010-12-16] (Wistron)
HKLM-x32\...\Run: [LMgrVolOSD] - C:\Program Files (x86)\Launch Manager\OSD.exe [348960 2009-12-12] (Wistron Corp.)
HKLM-x32\...\Run: [LMgrOSD] - "C:\Program Files (x86)\Launch Manager\OSDCtrl.exe" [x]
HKLM-x32\...\Run: [Wbutton] - C:\Program Files (x86)\Launch Manager\Wbutton.exe [436264 2010-06-21] (Wistron Corp.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [296096 2012-08-19] (RealNetworks, Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aldi.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files (x86)\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 195.50.140.118 195.50.140.248
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default
FF Homepage: bvb.de
FF NetworkProxy: "http", "98.103.7.148"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=15.0.6.14 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.6.14 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.6.14 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=15.0.6.14 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: ich - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\Extensions\ich@maltegoetz.de.xpi
FF Extension: No Name - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\j2yq6cue.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Anti-Banner - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{0153E448-190B-4987-BDE1-F256CADA672F}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
Chrome:
=======
CHR HomePage: hxxp://www.bvb.de/
CHR RestoreOnStartup: "hxxp://www.bvb.de/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0
CHR Extension: (ProxTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdbaehcjcomcnnjhlmnfddpgoafpcko\1.0.6_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx
==================== Services (Whitelisted) =================
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-02-05] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-12-14] ()
R2 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [62464 2010-12-06] ()
R3 WisLMSvc; C:\Program Files (x86)\Launch Manager\WisLMSvc.exe [118560 2009-10-23] (Wistron Corp.)
R2 x10nets; C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe [20480 2009-11-07] (X10)
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-04-02] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 mod7700; C:\Windows\System32\DRIVERS\mod7700.sys [1077840 2010-11-19] (DiBcom SA)
S3 mod7764; C:\Windows\System32\DRIVERS\mod77-64.sys [1077416 2010-09-16] (DiBcom SA)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [32792 2009-05-13] (X10 Wireless Technology, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-12 11:24 - 2013-09-12 11:24 - 00029015 _____ C:\Users\Tim\Desktop\JRT.txt
2013-09-12 11:17 - 2013-09-12 11:17 - 00000000 ____D C:\Windows\ERUNT
2013-09-12 11:15 - 2013-09-12 11:15 - 01029509 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2013-09-12 11:12 - 2013-09-12 11:12 - 00016774 _____ C:\Users\Tim\Desktop\AdwCleaner[S0].txt
2013-09-12 11:08 - 2013-09-12 11:10 - 00000000 ____D C:\AdwCleaner
2013-09-12 11:08 - 2013-09-12 11:08 - 01037278 _____ C:\Users\Tim\Desktop\adwcleaner.exe
2013-09-12 10:48 - 2013-09-12 10:48 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-12 10:48 - 2013-09-12 10:48 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Malwarebytes
2013-09-12 10:48 - 2013-09-12 10:48 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-12 10:48 - 2013-09-12 10:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-12 10:48 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-12 10:46 - 2013-09-12 10:47 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tim\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-12 03:56 - 2013-09-12 03:56 - 00000000 ____D C:\FRST
2013-09-11 03:06 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 03:06 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 03:06 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 03:06 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 03:06 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 03:06 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 03:06 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 03:06 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-11 03:06 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 03:06 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-11 03:06 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 03:06 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-11 03:06 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-11 03:06 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-10 21:02 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-10 21:02 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-10 21:02 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-10 21:02 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-10 21:02 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-10 21:02 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-10 21:02 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-10 21:02 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-10 21:02 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-10 21:02 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-10 21:02 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-10 21:02 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-10 21:02 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-10 21:02 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-10 21:02 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-10 21:02 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-10 21:02 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-10 21:02 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-10 21:02 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-10 21:02 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-10 21:02 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-10 21:02 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-10 21:02 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-10 21:02 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-10 21:02 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-10 21:02 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-10 21:02 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-10 00:56 - 2013-09-10 00:56 - 00000000 ____D C:\Users\Tim\Desktop\Online Bewerbungen
2013-09-09 17:48 - 2013-09-10 14:10 - 00014999 _____ C:\Users\Tim\Desktop\Lebenslauf.odt
2013-09-09 17:46 - 2013-09-09 17:46 - 00014772 _____ C:\Users\Tim\Downloads\lebenslauf.odt
2013-09-06 10:31 - 2013-09-06 10:31 - 00000098 ____H C:\Users\Tim\Documents\.~lock.Unbenannt 1.odt#
2013-09-05 12:19 - 2013-09-10 14:09 - 00000000 ____D C:\Users\Tim\Desktop\Bewerbungen
2013-08-15 11:27 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 11:27 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-15 11:27 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 11:27 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-15 11:27 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 11:27 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 11:27 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 11:27 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 11:27 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-15 11:27 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-15 11:27 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-15 11:27 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-15 11:26 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 11:26 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-15 11:26 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 11:26 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-09-12 11:26 - 2013-09-12 11:26 - 01949642 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2013-09-12 11:26 - 2009-07-14 06:51 - 00104531 _____ C:\Windows\setupact.log
2013-09-12 11:24 - 2013-09-12 11:24 - 00029015 _____ C:\Users\Tim\Desktop\JRT.txt
2013-09-12 11:21 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-12 11:21 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-12 11:17 - 2013-09-12 11:17 - 00000000 ____D C:\Windows\ERUNT
2013-09-12 11:17 - 2011-05-05 20:07 - 01892918 _____ C:\Windows\WindowsUpdate.log
2013-09-12 11:15 - 2013-09-12 11:15 - 01029509 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2013-09-12 11:12 - 2013-09-12 11:12 - 00016774 _____ C:\Users\Tim\Desktop\AdwCleaner[S0].txt
2013-09-12 11:12 - 2012-08-25 13:48 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Spotify
2013-09-12 11:12 - 2012-06-18 22:15 - 00000000 ____D C:\Users\Tim\Tracing
2013-09-12 11:11 - 2011-05-05 20:09 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-12 11:11 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-12 11:10 - 2013-09-12 11:08 - 00000000 ____D C:\AdwCleaner
2013-09-12 11:09 - 2011-05-05 21:43 - 00000000 ____D C:\ProgramData\ICQ
2013-09-12 11:08 - 2013-09-12 11:08 - 01037278 _____ C:\Users\Tim\Desktop\adwcleaner.exe
2013-09-12 11:02 - 2010-11-21 05:47 - 00035032 _____ C:\Windows\PFRO.log
2013-09-12 11:00 - 2013-02-28 12:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-12 10:48 - 2013-09-12 10:48 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-12 10:48 - 2013-09-12 10:48 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Malwarebytes
2013-09-12 10:48 - 2013-09-12 10:48 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-12 10:48 - 2013-09-12 10:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-12 10:47 - 2013-09-12 10:46 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tim\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-12 10:47 - 2011-03-12 20:22 - 00654852 _____ C:\Windows\system32\perfh007.dat
2013-09-12 10:47 - 2011-03-12 20:22 - 00130434 _____ C:\Windows\system32\perfc007.dat
2013-09-12 10:47 - 2009-07-14 07:13 - 01500294 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-12 10:43 - 2011-05-05 20:09 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-12 03:56 - 2013-09-12 03:56 - 00000000 ____D C:\FRST
2013-09-11 11:35 - 2012-08-25 13:49 - 00000000 ____D C:\Users\Tim\AppData\Local\Spotify
2013-09-11 11:34 - 2011-05-05 20:16 - 00000000 ___RD C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-11 11:34 - 2011-05-05 20:16 - 00000000 ___RD C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-11 04:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-11 03:29 - 2009-07-14 06:45 - 00393624 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-11 03:05 - 2011-10-14 21:27 - 01527912 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-11 03:05 - 2011-10-14 21:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2013-09-11 00:31 - 2012-08-21 13:21 - 00000444 ____H C:\Windows\Tasks\Norton Security Scan for Tim.job
2013-09-10 21:00 - 2013-02-28 12:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-10 21:00 - 2013-02-28 12:06 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-10 21:00 - 2011-08-10 13:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-10 14:10 - 2013-09-09 17:48 - 00014999 _____ C:\Users\Tim\Desktop\Lebenslauf.odt
2013-09-10 14:09 - 2013-09-05 12:19 - 00000000 ____D C:\Users\Tim\Desktop\Bewerbungen
2013-09-10 00:56 - 2013-09-10 00:56 - 00000000 ____D C:\Users\Tim\Desktop\Online Bewerbungen
2013-09-09 17:46 - 2013-09-09 17:46 - 00014772 _____ C:\Users\Tim\Downloads\lebenslauf.odt
2013-09-06 16:44 - 2011-05-06 17:05 - 00000000 ____D C:\Users\Tim\AppData\Local\Last.fm
2013-09-06 10:31 - 2013-09-06 10:31 - 00000098 ____H C:\Users\Tim\Documents\.~lock.Unbenannt 1.odt#
2013-09-06 10:31 - 2013-08-12 15:01 - 00016658 _____ C:\Users\Tim\Documents\Unbenannt 1.odt
2013-09-04 10:32 - 2011-05-05 20:09 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
Files to move or delete:
====================
C:\Users\Tim\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-11 03:57
==================== End Of Log ============================ --- --- ---
Und die Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-09-2013 02
Ran by Tim at 2013-09-12 11:29:01
Running from C:\Users\Tim\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (x32 Version: 15.4.5722.2)
Adobe AIR (x32 Version: 3.1.0.4880)
Adobe Download Assistant (x32 Version: 1.0.6)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.168)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader X MUI (x32 Version: 10.0.0)
AMI VR-pulse OS Switcher (Version: 1.1)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Ashampoo Burning Studio (x32 Version: 9.23.0)
Ashampoo Photo Commander (x32 Version: 8.3.2)
Ashampoo Photo Optimizer (x32 Version: 3.12.0)
Ashampoo Snap (x32 Version: 3.4.1)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.0.39)
Audacity 2.0.3 (x32 Version: 2.0.3)
Bing Bar (x32 Version: 7.0.619.0)
Bonjour (Version: 3.0.0.10)
Complément Messenger (x32 Version: 15.4.3502.0922)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Corel Graphics - Windows Shell Extension (x32 Version: 15.1.0.588)
Corel Graphics - Windows Shell Extension (x32 Version: 15.1.588)
CorelDRAW Essentials X5 - Common (x32 Version: 15.0)
CorelDRAW Essentials X5 - Connect (x32 Version: 15.0)
CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.0)
CorelDRAW Essentials X5 - DE (x32 Version: 15.0)
CorelDRAW Essentials X5 - Draw (x32 Version: 15.0)
CorelDRAW Essentials X5 - EN (x32 Version: 15.0)
CorelDRAW Essentials X5 - ES (x32 Version: 15.0)
CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0)
CorelDRAW Essentials X5 - Extra Content (x32)
CorelDRAW Essentials X5 - Filters (x32 Version: 15.0)
CorelDRAW Essentials X5 - FR (x32 Version: 15.0)
CorelDRAW Essentials X5 - IPM (x32 Version: 15.0)
CorelDRAW Essentials X5 - IT (x32 Version: 15.0)
CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.0)
CorelDRAW Essentials X5 - Redist (x32 Version: 15.0)
CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.0)
CorelDRAW Essentials X5 - WT (x32 Version: 15.0)
CorelDRAW Essentials X5 (x32 Version: 15.0)
CorelDRAW Essentials X5 (x32 Version: 15.1.0.588)
CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (Version: 15.1.588)
CyberLink LabelPrint (x32 Version: 2.5.3624)
CyberLink MediaEspresso (x32 Version: 6.5.1508_36229)
CyberLink MediaShow (x32 Version: 5.1.2414)
CyberLink PhotoNow (x32 Version: 1.1.0.6904)
CyberLink Power2Go (x32 Version: 6.1.4813)
CyberLink PowerDirector (x32 Version: 8.0.3224a)
CyberLink PowerDVD 10 (x32 Version: 10.0.2225.02)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306)
CyberLink PowerProducer (x32 Version: 5.0.2.3503)
CyberLink YouCam (x32 Version: 3.1.3428)
D3DX10 (x32 Version: 15.4.2368.0902)
DAEMON Tools Lite (x32 Version: 4.45.3.0297)
EA Installer (x32 Version: 2.3.0.74)
Equalify v2.2.1 (Stable) (x32 Version: 2.2.1.0)
FlashFXP v3 (x32 Version: 3.4.0.1145)
Fragen-Lern-CD 4.1 (x32 Version: 4.1.0)
Free Audio CD Burner version 1.4.8 (x32)
Free YouTube to MP3 Converter version 3.11.22.508 (x32 Version: 3.11.22.508)
FrostWire 5.3.6 (x32 Version: 5.3.6.0)
FUSSBALL MANAGER 11 (x32)
FUSSBALL MANAGER 12 (x32 Version: 1.0.0.3)
FUSSBALL MANAGER 12 Demo (x32 Version: 1.0.0.0)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Google Chrome (x32 Version: 29.0.1547.66)
Google Earth (x32 Version: 7.1.1.1888)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4413.1752)
Google Update Helper (x32 Version: 1.3.21.153)
ICQ7.5 (x32 Version: 7.5)
Intel PROSet Wireless
Intel(R) Processor Graphics (x32 Version: 8.15.10.2291)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version: 1.0.0.0135)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.2.0518)
Intel(R) PROSet/Wireless WiFi Software (Version: 14.0.3000)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008)
Intel(R) Wireless Display
Intel(R) Wireless Display (x32 Version: 2.0.30.0)
Internet-TV für Windows Media Center (x32 Version: 4.2.2.0)
iTunes (Version: 11.0.4.4)
Java 7 Update 21 (x32 Version: 7.0.210)
Java Auto Updater (x32 Version: 2.1.9.5)
Java(TM) 6 Update 24 (64-bit) (Version: 6.0.240)
Java(TM) 6 Update 24 (x32 Version: 6.0.240)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Last.fm Scrobbler 2.1.32 (x32)
Launch Manager (x32 Version: 1.5.1.3)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
McAfee Security Scan Plus (x32 Version: 3.0.318.3)
Medion Home Cinema (x32 Version: 8.0.2608)
Mesh Runtime (x32 Version: 15.4.5722.2)
Messenger Companion (x32 Version: 15.4.3502.0922)
Messenger-kumppani (x32 Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 8.0.1 (x86 de) (x32 Version: 8.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Nero Backup Drivers (Version: 1.0.11100.8.0)
Nero Burning ROM 11 (x32 Version: 11.0.10400)
Nero Burning ROM 11 (x32 Version: 11.0.12200.23.100)
Nero Burning ROM 11 Help (CHM) (x32 Version: 11.0.10300)
Nero BurnLite 10 (x32 Version: 10.0.10500.5.100)
Nero BurnLite 10 (x32 Version: 10.0.10600)
Nero Control Center 10 (x32 Version: 10.0.13100.3.1)
Nero ControlCenter 10 Help (CHM) (x32 Version: 1.0.10700)
Nero ControlCenter 11 (x32 Version: 11.0.12300.0.23)
Nero ControlCenter 11 Help (CHM) (x32 Version: 11.0.10300)
Nero Core Components 10 (x32 Version: 2.0.15100.0.1)
Nero Core Components 11 (x32 Version: 11.0.14700.1.9)
Nero RescueAgent 11 (x32 Version: 4.0.10600.10.100)
Nero RescueAgent 11 Help (CHM) (x32 Version: 11.0.10400)
Nero Update (x32 Version: 11.0.10623.22.0)
nero.prerequisites.msi (x32 Version: 11.0.20007)
OpenOffice 4.0.0 (x32 Version: 4.00.9702)
PlayReady PC Runtime amd64 (Version: 1.3.0)
QuickTime (x32 Version: 7.74.80.86)
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0)
RealPlayer (x32 Version: 15.0.6)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6321)
Realtek USB 2.0 Reader Driver (x32 Version: 6.1.7600.10003)
RealUpgrade 1.1 (x32 Version: 1.1.0)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0)
Spotify (HKCU Version: 0.9.1.57.ge7405149)
Synaptics Pointing Device Driver (Version: 15.1.12.0)
TmNationsForever (x32)
Uninstall 1.0.0.1 (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Versandhelfer (x32 Version: 0.9.511)
VR-pulse Installer (Version: 1.2.0)
watchmi (x32 Version: 2.5.0)
WAV To MP3 V2 (x32)
Windows Live (x32 Version: 15.4.3502.0922)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3538.0513)
Windows Live Family Safety (Version: 15.4.3538.0513)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Meshin etäyhteyksien ActiveX-komponentti (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922)
Windows Liven sähköposti (x32 Version: 15.4.3502.0922)
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922)
Windows Media Encoder 9 Series (x32 Version: 9.00.2980)
Windows Media Encoder 9 Series (x32)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)
WinRAR 4.00 (64-Bit) (Version: 4.00.0)
X10 Hardware(TM) (x32)
==================== Restore Points =========================
16-08-2013 01:00:43 Windows Update
25-08-2013 12:14:14 Geplanter Prüfpunkt
01-09-2013 12:17:24 Geplanter Prüfpunkt
11-09-2013 01:01:17 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {16C75393-128F-441D-9D86-B9C4C69FE154} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-05-05] (Google Inc.)
Task: {4963CEA6-7041-4A0A-9B94-BA98E16D46A0} - \Scheduled Update for Ask Toolbar No Task File
Task: {52D9FB02-F4DE-4BC4-89AA-47DECAEBFEE0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-10] (Adobe Systems Incorporated)
Task: {6AA71B89-3A55-4DEA-B801-E7CF5C84C975} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation)
Task: {6CFA2764-4B2B-4592-83E9-5FDDE5F74BA7} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3798724326-2438103813-2358414704-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-07-27] (RealNetworks, Inc.)
Task: {7E0E7552-7528-4B01-A473-4324446F4190} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {92B9CB09-F08D-4CE1-8B6D-0343357EFC93} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-21] (Microsoft Corporation)
Task: {93BE4DA1-79FF-4C83-ADB7-EE875A4EE2E5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A7C55CCA-E061-49FD-AFF6-9DCADD8BA9AA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-05-05] (Google Inc.)
Task: {B19888A0-1A6A-4EF0-8D16-D753CF3A6463} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3798724326-2438103813-2358414704-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-07-27] (RealNetworks, Inc.)
Task: {C7EAC3B4-0CCD-42F6-9970-9760FFCA3F36} - System32\Tasks\Norton Security Scan for Tim => C:\PROGRA~2\NORTON~2\Engine\372~1.5\Nss.exe
Task: {EB6BFF91-BE94-4F56-B23A-30C806F47CBE} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Tim.job => C:\PROGRA~2\NORTON~2\Engine\372~1.5\Nss.exe
==================== Loaded Modules (whitelisted) =============
2011-03-14 04:48 - 2011-03-09 16:16 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2011-03-14 04:48 - 2011-03-09 16:16 - 02839656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2011-02-04 13:38 - 2011-01-27 09:25 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrDEU.lrc
2011-02-04 13:38 - 2011-01-27 09:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-02-04 13:40 - 2010-09-03 14:43 - 00400168 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll
2011-02-04 13:40 - 2010-09-03 14:44 - 00221480 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll
2012-02-13 10:05 - 2012-02-13 10:05 - 00367424 _____ (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTGadget64.dll
2011-05-06 18:10 - 2011-03-02 12:40 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00607232 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MUtils.dll
2011-05-05 21:43 - 2011-05-05 21:43 - 00221696 _____ (AOL Inc.) C:\Program Files (x86)\ICQ7.5\xprt6.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00247296 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MKernel.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00763392 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MDb.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00104448 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MCoreLib.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 02392576 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MUIUtils.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00785920 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MUICoreLib.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00199168 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MBContainer.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 01432576 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MCore.dll
2011-05-05 21:43 - 2011-05-05 21:43 - 00747008 _____ (AOL Inc.) C:\Program Files (x86)\ICQ7.5\coolcore59.dll
2011-05-05 21:43 - 2011-05-05 21:43 - 00761344 _____ (AOL Inc.) C:\Program Files (x86)\ICQ7.5\acccore.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00859648 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MISB.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 02581504 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MUICore.dll
2011-05-05 21:43 - 2011-08-01 10:28 - 00091136 _____ (ICQ, LLC.) C:\Program Files (x86)\ICQ7.5\MReport.dll
2011-03-14 04:59 - 2009-10-23 01:58 - 00211232 _____ (Wistron Corp.) C:\Program Files (x86)\Launch Manager\KBHOOK.dll
2010-11-17 10:52 - 2010-11-17 10:52 - 00096904 _____ (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.dll
2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2011-03-21 17:30 - 2011-03-21 17:30 - 00053024 _____ (Open Source Software community project) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\pthreadVC2.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-08-30 23:05 - 2011-08-30 23:05 - 00085864 _____ (Apple Inc.) C:\Windows\system32\dnssd.dll
2012-02-13 10:06 - 2012-02-13 10:06 - 03995456 _____ (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTCommonRes.dll
2012-02-13 10:06 - 2012-02-13 10:06 - 03759936 _____ (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\Engine.dll
2012-01-30 13:07 - 2012-01-30 13:07 - 00382784 _____ (DT Soft Ltd.) C:\Program Files (x86)\DAEMON Tools Lite\ImgEngine.dll
2012-08-19 14:59 - 2012-08-19 14:59 - 00426736 _____ (RealPlayer) C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2013-09-10 20:00 - 2013-09-10 20:00 - 16242568 ____R (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_8_800_168.ocx
2012-08-06 08:17 - 2012-08-06 08:17 - 00073672 _____ (Equalify / Kenneth Leonardsen) C:\Windows\SysWOW64\Macromed\Flash\DSOUND.dll
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 40%
Total physical RAM: 4003.07 MB
Available physical RAM: 2373.21 MB
Total Pagefile: 8004.32 MB
Available Pagefile: 6281.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:657.54 GB) (Free:406.54 GB) NTFS
Drive d: (Recover) (Fixed) (Total:38 GB) (Free:16.16 GB) NTFS
Drive g: (USB DISK) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 699 GB) (Disk ID: D3AF660C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=658 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=40 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=2 GB) - (Type=0C)
==================== End Of Log ============================ MfG |