Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-01-2014 02
Ran by flo at 2014-01-26 20:14:48 Run:1
Running from C:\Users\flo\Downloads\1.schritt FRST
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
C:\Program Files (x86)\Mobogenie
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
ProxyServer: http=127.0.0.1:49180;https=127.0.0.1:49180
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully.
C:\Program Files (x86)\Mobogenie => Moved successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe => Key deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully.
==== End of Fixlog ====
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-01-2014 02
Ran by flo (administrator) on FLOPC on 26-01-2014 20:17:20
Running from C:\Users\flo\Downloads\1.schritt FRST
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Akamai Technologies, Inc.) C:\Users\flo\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Users\flo\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
(Akamai Technologies, Inc.) C:\Users\flo\AppData\Local\Akamai\netsession_win.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dropbox, Inc.) C:\Users\flo\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1822504 2009-08-24] (Synaptics Incorporated)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\flo\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\flo\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000
MountPoints2: {9009fa87-cea9-11e2-af51-002219efd4d6} - F:\SETUP.EXE
Startup: C:\Users\flo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\flo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\flo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0ByEzy0C0F0B0CyBzzyE0EtN0D0Tzu0SyByDtDtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1768954480&ir=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0101&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0ByEzy0C0F0B0CyBzzyE0EtN0D0Tzu0SyByDtDtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1768954480&ir=
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=1487&systemid=1&v=n11099-232&apn_uid=2204336073854104&apn_dtid=IME001&o=APN10653&apn_ptnrs=AGE&q={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
FireFox:
========
FF ProfilePath: C:\Users\flo\AppData\Roaming\Mozilla\Firefox\Profiles\7u1kceh7.default
FF Homepage: https://mail.google.com/mail/u/0/?shva=1#inbox
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\flo\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Noia 4 Theme Manager - C:\Users\flo\AppData\Roaming\Mozilla\Firefox\Profiles\7u1kceh7.default\Extensions\Noia4Options@ArisT2.xpi [2014-01-19]
FF Extension: Noia 4 - C:\Users\flo\AppData\Roaming\Mozilla\Firefox\Profiles\7u1kceh7.default\Extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi [2014-01-19]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-26 19:53 - 2014-01-26 19:53 - 00000000 ____D C:\ProgramData\Oracle
2014-01-26 19:53 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-26 19:53 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-26 19:53 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-26 19:53 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-26 19:52 - 2014-01-26 19:53 - 00006631 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-25 18:16 - 2014-01-25 18:17 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-25 18:16 - 2014-01-25 18:17 - 00000000 ____D C:\Program Files\iTunes
2014-01-25 18:16 - 2014-01-25 18:17 - 00000000 ____D C:\Program Files (x86)\iTunes
2014-01-25 18:16 - 2014-01-25 18:16 - 00000000 ____D C:\Program Files\iPod
2014-01-21 19:26 - 2014-01-21 19:26 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 19:13 - 2014-01-21 19:14 - 00001786 _____ C:\sc-cleaner.txt
2014-01-21 18:50 - 2014-01-21 18:50 - 00000000 ____D C:\Users\flo\AppData\Roaming\Malwarebytes
2014-01-21 18:50 - 2014-01-21 18:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 18:50 - 2014-01-21 18:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-21 18:50 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-19 14:50 - 2014-01-26 20:17 - 00000000 ____D C:\Users\flo\Downloads\1.schritt FRST
2014-01-19 14:46 - 2014-01-26 20:14 - 00000000 ____D C:\FRST
2014-01-19 14:42 - 2014-01-19 14:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-19 14:35 - 2014-01-19 14:35 - 00000000 ____D C:\Users\flo\Documents\My Received Files
2014-01-19 14:35 - 2014-01-19 14:35 - 00000000 ____D C:\Users\flo\AppData\Roaming\MusicNet
2014-01-19 14:04 - 2014-01-19 14:42 - 00000000 ____D C:\Users\flo\AppData\Local\Mozilla
2014-01-19 14:04 - 2014-01-19 14:04 - 00000000 ____D C:\Users\flo\AppData\Roaming\Mozilla
2014-01-19 14:02 - 2014-01-19 14:10 - 00000000 ____D C:\Users\flo\AppData\Local\Mobogenie
2014-01-19 14:02 - 2014-01-19 14:02 - 00000000 ____D C:\Users\flo\AppData\Local\genienext
2014-01-19 14:01 - 2013-12-27 18:10 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2014-01-19 14:00 - 2014-01-19 14:00 - 22240760 _____ (Mozilla) C:\Users\flo\Downloads\Firefox [1].exe
2014-01-19 12:55 - 2014-01-19 13:12 - 23867560 _____ (Mozilla) C:\Users\flo\Downloads\Firefox_Setup_26.0.exe
2014-01-19 11:39 - 2014-01-19 13:45 - 00000000 ____D C:\AdwCleaner
2014-01-19 11:39 - 2014-01-19 11:39 - 01236282 _____ C:\Users\flo\Downloads\adwcleaner_3.017.exe
2014-01-18 12:03 - 2014-01-18 12:03 - 00003848 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2014-01-18 12:02 - 2014-01-19 14:02 - 00000000 ____D C:\Users\flo\AppData\Local\cache
2014-01-18 12:02 - 2014-01-18 12:02 - 00000000 ____D C:\Users\flo\.android
2014-01-18 12:02 - 2014-01-18 12:02 - 00000000 _____ C:\Users\flo\daemonprocess.txt
2014-01-18 12:00 - 2014-01-18 12:00 - 00000000 ____D C:\ProgramData\Updater
2014-01-18 11:59 - 2014-01-18 12:08 - 00000000 ____D C:\ProgramData\IePluginService
2014-01-17 12:35 - 2014-01-19 16:53 - 00000000 ____D C:\ProgramData\firebird
2014-01-17 12:35 - 2014-01-17 12:35 - 00000000 ____D C:\Users\flo\Documents\Eendsoft
2014-01-17 12:35 - 2014-01-17 12:35 - 00000000 ____D C:\Users\flo\AppData\Roaming\Eendsoft
2014-01-17 12:31 - 2014-01-17 12:35 - 00000000 ____D C:\Program Files (x86)\Picto Selector
2014-01-15 16:04 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 16:04 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 16:04 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 16:04 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 16:04 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 16:04 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 16:04 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 16:04 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 16:04 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== One Month Modified Files and Folders =======
2014-01-26 20:17 - 2014-01-19 14:50 - 00000000 ____D C:\Users\flo\Downloads\1.schritt FRST
2014-01-26 20:14 - 2014-01-19 14:46 - 00000000 ____D C:\FRST
2014-01-26 19:54 - 2013-09-25 19:34 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-26 19:53 - 2014-01-26 19:53 - 00000000 ____D C:\ProgramData\Oracle
2014-01-26 19:53 - 2014-01-26 19:52 - 00006631 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-26 19:53 - 2013-06-06 13:51 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-26 19:41 - 2013-06-06 14:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-26 19:20 - 2013-06-06 13:25 - 01393260 _____ C:\Windows\WindowsUpdate.log
2014-01-26 19:13 - 2009-07-14 05:45 - 00014752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-26 19:13 - 2009-07-14 05:45 - 00014752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-26 19:06 - 2013-06-06 17:21 - 00000000 ___RD C:\Users\flo\Dropbox
2014-01-26 19:06 - 2013-06-06 17:17 - 00000000 ____D C:\Users\flo\AppData\Roaming\Dropbox
2014-01-26 19:05 - 2013-09-25 19:33 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-26 19:05 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-26 19:04 - 2009-07-14 05:51 - 00038309 _____ C:\Windows\setupact.log
2014-01-26 00:59 - 2013-06-06 14:47 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-26 00:59 - 2013-06-06 14:47 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-26 00:59 - 2013-06-06 14:47 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-26 00:57 - 2013-06-06 13:37 - 00000000 ____D C:\Users\flo\AppData\Local\Adobe
2014-01-25 18:28 - 2013-06-06 16:59 - 00000000 ___RD C:\Users\flo\Desktop\mp3
2014-01-25 18:17 - 2014-01-25 18:16 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-25 18:17 - 2014-01-25 18:16 - 00000000 ____D C:\Program Files\iTunes
2014-01-25 18:17 - 2014-01-25 18:16 - 00000000 ____D C:\Program Files (x86)\iTunes
2014-01-25 18:16 - 2014-01-25 18:16 - 00000000 ____D C:\Program Files\iPod
2014-01-25 18:13 - 2013-06-06 13:54 - 00000000 ____D C:\ProgramData\Apple
2014-01-24 09:01 - 2013-06-06 14:27 - 00032232 _____ C:\Windows\PFRO.log
2014-01-23 20:08 - 2013-06-06 16:55 - 00000000 ___RD C:\Users\flo\Desktop\wd
2014-01-23 19:36 - 2013-06-06 16:55 - 00000000 ___RD C:\Users\flo\Desktop\shit
2014-01-23 16:14 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat
2014-01-23 16:14 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat
2014-01-23 16:14 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-22 16:47 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-21 19:26 - 2014-01-21 19:26 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 19:14 - 2014-01-21 19:13 - 00001786 _____ C:\sc-cleaner.txt
2014-01-21 18:50 - 2014-01-21 18:50 - 00000000 ____D C:\Users\flo\AppData\Roaming\Malwarebytes
2014-01-21 18:50 - 2014-01-21 18:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 18:50 - 2014-01-21 18:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-19 16:53 - 2014-01-17 12:35 - 00000000 ____D C:\ProgramData\firebird
2014-01-19 14:42 - 2014-01-19 14:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-19 14:42 - 2014-01-19 14:04 - 00000000 ____D C:\Users\flo\AppData\Local\Mozilla
2014-01-19 14:42 - 2013-12-20 12:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-19 14:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2014-01-19 14:35 - 2014-01-19 14:35 - 00000000 ____D C:\Users\flo\Documents\My Received Files
2014-01-19 14:35 - 2014-01-19 14:35 - 00000000 ____D C:\Users\flo\AppData\Roaming\MusicNet
2014-01-19 14:10 - 2014-01-19 14:02 - 00000000 ____D C:\Users\flo\AppData\Local\Mobogenie
2014-01-19 14:08 - 2013-06-06 13:30 - 00000000 ___RD C:\Users\flo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-19 14:04 - 2014-01-19 14:04 - 00000000 ____D C:\Users\flo\AppData\Roaming\Mozilla
2014-01-19 14:02 - 2014-01-19 14:02 - 00000000 ____D C:\Users\flo\AppData\Local\genienext
2014-01-19 14:02 - 2014-01-18 12:02 - 00000000 ____D C:\Users\flo\AppData\Local\cache
2014-01-19 14:01 - 2013-09-25 19:33 - 00000000 ____D C:\Users\flo\AppData\Local\Google
2014-01-19 14:00 - 2014-01-19 14:00 - 22240760 _____ (Mozilla) C:\Users\flo\Downloads\Firefox [1].exe
2014-01-19 13:45 - 2014-01-19 11:39 - 00000000 ____D C:\AdwCleaner
2014-01-19 13:12 - 2014-01-19 12:55 - 23867560 _____ (Mozilla) C:\Users\flo\Downloads\Firefox_Setup_26.0.exe
2014-01-19 11:42 - 2013-06-06 13:31 - 00000991 _____ C:\Users\flo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-19 11:39 - 2014-01-19 11:39 - 01236282 _____ C:\Users\flo\Downloads\adwcleaner_3.017.exe
2014-01-19 08:33 - 2013-06-06 13:47 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-18 12:08 - 2014-01-18 11:59 - 00000000 ____D C:\ProgramData\IePluginService
2014-01-18 12:03 - 2014-01-18 12:03 - 00003848 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2014-01-18 12:02 - 2014-01-18 12:02 - 00000000 ____D C:\Users\flo\.android
2014-01-18 12:02 - 2014-01-18 12:02 - 00000000 _____ C:\Users\flo\daemonprocess.txt
2014-01-18 12:02 - 2013-06-06 13:30 - 00000000 ____D C:\Users\flo
2014-01-18 12:00 - 2014-01-18 12:00 - 00000000 ____D C:\ProgramData\Updater
2014-01-18 11:59 - 2011-06-11 00:58 - 00773680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2014-01-18 11:59 - 2011-06-11 00:58 - 00420912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2014-01-17 12:35 - 2014-01-17 12:35 - 00000000 ____D C:\Users\flo\Documents\Eendsoft
2014-01-17 12:35 - 2014-01-17 12:35 - 00000000 ____D C:\Users\flo\AppData\Roaming\Eendsoft
2014-01-17 12:35 - 2014-01-17 12:31 - 00000000 ____D C:\Program Files (x86)\Picto Selector
2014-01-16 18:36 - 2009-07-14 05:45 - 00367672 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 17:40 - 2013-08-07 09:53 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 17:37 - 2013-06-06 16:08 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-16 17:34 - 2013-06-06 17:19 - 00000000 ____D C:\Users\flo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-08 14:43 - 2013-06-06 14:02 - 00000000 ____D C:\Users\flo\AppData\Roaming\vlc
2014-01-05 16:35 - 2013-07-07 17:55 - 00000184 _____ C:\Windows\AutoKMS.ini
2014-01-05 16:35 - 2013-07-07 17:54 - 00000000 ____D C:\Users\flo\Documents\Backups
2013-12-27 18:10 - 2014-01-19 14:01 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
Some content of TEMP:
====================
C:\Users\flo\AppData\Local\Temp\38771uninstall.exe
C:\Users\flo\AppData\Local\Temp\BackupSetup.exe
C:\Users\flo\AppData\Local\Temp\DLG_shopping-toolbar_softonic_de-DE.exe
C:\Users\flo\AppData\Local\Temp\ose00000.exe
C:\Users\flo\AppData\Local\Temp\Quarantine.exe
C:\Users\flo\AppData\Local\Temp\Sqlite3.dll
C:\Users\flo\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\flo\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-21 20:08
==================== End Of Log ============================
--- --- ---
--- --- ---