Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Suchlauf Datum: 04.04.2014
Suchlauf-Zeit: 02:36:54
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.03.11
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Franca
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 257020
Verstrichene Zeit: 32 Min, 55 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.SweetPacks.A, C:\Program Files\Web Assistant\ExtensionUpdaterService.exe, 2292, Löschen bei Neustart, [2bd502feb34d9967e01f56a8c13fe51b]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 20
PUP.Optional.SweetPacks.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Web Assistant, In Quarantäne, [2bd502feb34d9967e01f56a8c13fe51b],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\CLASSES\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\CLASSES\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}\INPROCSERVER32, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\CLASSES\Extension.ExtensionHelperObject.1, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\CLASSES\Extension.ExtensionHelperObject, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Extension.ExtensionHelperObject, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{336D0C35-8A85-403A-B9D2-65C292C39087}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{336D0C35-8A85-403A-B9D2-65C292C39087}, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Extension.ExtensionHelperObject.1, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-2890242748-1743184828-694113758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{336D0C35-8A85-403A-B9D2-65C292C39087}, Löschen bei Neustart, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-2890242748-1743184828-694113758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{336D0C35-8A85-403A-B9D2-65C292C39087}, Löschen bei Neustart, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.Incredibar, HKU\S-1-5-21-2890242748-1743184828-694113758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}, Löschen bei Neustart, [0af6718fd42c1de3091efb48758d758b],
PUP.Optional.Incredibar, HKU\S-1-5-21-2890242748-1743184828-694113758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}, Löschen bei Neustart, [0af6718fd42c1de3091efb48758d758b],
PUP.Optional.Incredibar, HKU\S-1-5-21-2890242748-1743184828-694113758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{F9639E4A-801B-4843-AEE3-03D9DA199E77}, Löschen bei Neustart, [d82847b99070d22e4adeb68d2dd53bc5],
PUP.Optional.Incredibar, HKU\S-1-5-21-2890242748-1743184828-694113758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{F9639E4A-801B-4843-AEE3-03D9DA199E77}, Löschen bei Neustart, [d82847b99070d22e4adeb68d2dd53bc5],
Registrierungswerte: 4
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3]
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3]
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [f40cff0146baa45c5c5b1feb7a8835cb],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [9868e51bac5455ab1a9d3eccca389868],
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 2
PUP.Optional.Incredibar, C:\Program Files (x86)\Incredibar.com, In Quarantäne, [a35d8d735ba516eac5316be912f05aa6],
PUP.Optional.Incredibar, C:\Program Files (x86)\Incredibar.com\incredibar, In Quarantäne, [a35d8d735ba516eac5316be912f05aa6],
Dateien: 3
PUP.Optional.SweetPacks.A, C:\Program Files\Web Assistant\ExtensionUpdaterService.exe, Löschen bei Neustart, [2bd502feb34d9967e01f56a8c13fe51b],
PUP.Optional.HomePageProtector.A, C:\Program Files\Web Assistant\Extension64.dll, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
PUP.Optional.HomePageProtector.A, C:\Program Files\Web Assistant\Extension32.dll, In Quarantäne, [6898eb150bf535cbc5f20efce81a0df3],
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.023 - Bericht erstellt am 04/04/2014 um 02:52:25
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Franca - FRANCA-PC
# Gestartet von : C:\Users\Franca\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\Premium
Ordner Gelöscht : C:\Program Files (x86)\Ask.com
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
Ordner Gelöscht : C:\Program Files\Web Assistant
Ordner Gelöscht : C:\Users\Franca\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Franca\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Franca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKCU\Software\Ask.com
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gelöscht : HKLM\Software\Web Assistant
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Web Assistant
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\Franca\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [5589 octets] - [04/04/2014 02:51:15]
AdwCleaner[S0].txt - [5227 octets] - [04/04/2014 02:52:25]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5287 octets] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by Franca on 04.04.2014 at 2:59:49,90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2890242748-1743184828-694113758-1000\Software\web assistant
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2B09C5BA-D53D-4C54-B0FF-A15368D4EE59}
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho3F30.tmp
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{007F5CD8-B0EB-480F-9CEC-19B393DD7B14}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{062E5B87-8DB5-48F4-926A-456AF10BF57D}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{09B8CE6D-9CA4-492C-817C-23A4CBAD1A5C}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{0A71F735-5E42-4B82-88A6-E1615346E24D}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{27D2F48D-D70A-400D-8031-85082DC105D0}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{2E161397-DE5C-420F-BB93-0EC5FA36CA5E}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{2E268981-087B-47CD-92F8-4BCC6E6D6EC2}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{2FA1FC7A-6EB3-4799-B019-BA4360B81DA6}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{337B59C9-4F22-4AB8-BF82-A8B690F68A6B}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{3F6B46C1-9E93-4B97-8E34-3077670B57AB}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{454CC3BB-FDB5-4698-9055-BA71ED342AE0}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{50F6BC7B-7718-4E49-8438-9D21422BD01C}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{6350A121-7750-4C19-B622-95C7E7FE3861}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{6847CB4A-2704-4062-8004-8A45250591E3}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{6E18D0D0-33C1-4684-B517-1E49B5FC4D25}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{75F8AA68-241F-49C4-A65E-FF636814C3BE}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{7E325AC6-18D6-4A12-B71E-AEDCC5C1A87D}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{8520E05B-BCE1-4F6B-9295-FB08F03A0DCC}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{8D5FBA18-549B-4E6E-874D-5CA33FA28883}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{94D4DE8E-AB3F-4C9E-85B6-1D6D07498306}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{9A51A204-5914-40F8-A98A-FE2B6DD281C6}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{A526C1CA-6CB7-4C68-8135-315562FDA9BC}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{A7F87453-0F02-4D2F-A2E7-D53F2FA88486}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{B167A168-FC40-44FC-A350-3DFA08A24A0B}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{B3C9A06A-8BC0-4686-BA03-8F62DD4AD04F}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{B9658555-E966-46A8-A08A-75D492238B21}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{BD9304FC-AF27-44C2-8474-BC3D9CA8F3BF}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{C17C1833-3B9F-4B40-88BB-7BB6455A5EFF}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{C5234D80-E01B-409D-AD15-66324800166E}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{CC01450B-58A2-4168-ADEC-2FFBD7FB31D8}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{CE8CE75F-A270-49B2-B6CF-E7AC09EF826A}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{E0A0C9C0-3D21-4946-9A61-7B1F9DAE8765}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{E366C126-C594-472D-BB5E-2025B7DE68D1}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{EA7DF461-95EB-4735-AC3D-5179DF78E29B}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{F0796194-C804-4CCE-AA48-438BDB4113C0}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{F11C812C-CEDA-445B-99B9-847BB86C2D3C}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{FAE0B704-89D3-485D-81E7-4AD7260EAE3C}
Successfully deleted: [Empty Folder] C:\Users\Franca\appdata\local\{FD66C49B-E45D-4381-BB98-892EA650922B}
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Franca\appdata\local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.04.2014 at 3:10:00,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Franca (administrator) on FRANCA-PC on 04-04-2014 03:18:19
Running from C:\Users\Franca\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(ASUS) C:\Windows\AsScrPro.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Dropbox, Inc.) C:\Users\Franca\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Thisisu) C:\Users\Franca\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [983200 2011-11-30] (Atheros Communications)
HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800416 2011-11-30] (Atheros Commnucations)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Nuance PDF Reader-reminder] - C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2011-10-19] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [SonicMasterTray] - C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-08] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2319536 2011-10-19] (ASUS)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [] - [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2890242748-1743184828-694113758-1000\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation)
HKU\S-1-5-21-2890242748-1743184828-694113758-1000\...\Run: [AdobeBridge] - [X]
Startup: C:\Users\Franca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Franca\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Franca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Franca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.440_0\npbrowserext.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Java Deployment Toolkit 6.0.370.6) - C:\Windows\SysWOW64\npdeployJava1.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Extension: (Adblock Plus) - C:\Users\Franca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-08]
CHR Extension: (Google Wallet) - C:\Users\Franca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Google Mail) - C:\Users\Franca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-11]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [92800 2011-12-01] (ASUS)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-11-30] (Atheros)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-04] (Malwarebytes Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-04 03:10 - 2014-04-04 03:10 - 00005256 _____ () C:\Users\Franca\Desktop\JRT.txt
2014-04-04 02:59 - 2014-04-04 02:59 - 00000000 ____D () C:\Windows\ERUNT
2014-04-04 02:57 - 2014-04-04 02:57 - 01038974 _____ (Thisisu) C:\Users\Franca\Downloads\JRT.exe
2014-04-04 02:57 - 2014-04-04 02:57 - 01038974 _____ (Thisisu) C:\Users\Franca\Downloads\JRT (1).exe
2014-04-04 02:54 - 2014-04-04 02:54 - 00000000 ___RD () C:\Users\Franca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-04-04 02:51 - 2014-04-04 02:52 - 00000000 ____D () C:\AdwCleaner
2014-04-04 02:49 - 2014-04-04 02:49 - 01426178 _____ () C:\Users\Franca\Downloads\adwcleaner.exe
2014-04-04 02:48 - 2014-04-04 02:48 - 00006518 _____ () C:\Users\Franca\Desktop\mbam.txt
2014-04-04 02:09 - 2014-04-04 02:10 - 00000000 ____D () C:\Users\Franca\AppData\Local\Microsoft Games
2014-04-04 02:07 - 2014-04-04 02:07 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\Go-Go Gourmet Chef of the Year
2014-04-04 02:00 - 2014-04-04 02:46 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-04 02:00 - 2014-04-04 02:00 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-04 02:00 - 2014-04-04 02:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-04 02:00 - 2014-04-04 02:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-04 02:00 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-04 02:00 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-04 02:00 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-04 01:57 - 2014-04-04 01:58 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Franca\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-04 01:32 - 2014-04-04 01:32 - 00001266 _____ () C:\Users\Franca\Desktop\Revo Uninstaller.lnk
2014-04-04 01:32 - 2014-04-04 01:32 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-04 01:31 - 2014-04-04 01:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Franca\Downloads\revosetup95.exe
2014-04-03 16:11 - 2014-04-03 16:12 - 00000000 ____D () C:\91e3d83d38e66f8a3c6c
2014-04-03 03:00 - 2014-04-03 03:01 - 00000000 ____D () C:\cd00002f4cb58184cdf938a73d26
2014-04-02 05:01 - 2014-04-02 05:01 - 00000000 ____D () C:\7641723a64526887d7b29b32eb6163
2014-04-02 03:00 - 2014-04-02 03:01 - 00000000 ____D () C:\0f4a6b61b724447c58fd4dc392945f4e
2014-04-01 20:14 - 2014-04-01 21:33 - 00036210 _____ () C:\Users\Franca\Downloads\Addition.txt
2014-04-01 20:12 - 2014-04-04 03:18 - 00016352 _____ () C:\Users\Franca\Downloads\FRST.txt
2014-04-01 20:11 - 2014-04-04 03:18 - 00000000 ____D () C:\FRST
2014-04-01 20:10 - 2014-04-01 20:10 - 02157056 _____ (Farbar) C:\Users\Franca\Downloads\FRST64.exe
2014-04-01 19:19 - 2014-04-01 21:32 - 00014337 _____ () C:\Users\Franca\Documents\Statement.odt
2014-04-01 03:01 - 2014-04-01 03:02 - 00000000 ____D () C:\b11e1ed5072f071fc1a4
2014-03-31 14:55 - 2014-03-31 14:55 - 00000000 ____D () C:\41046b8d8980248372ea
2014-03-31 03:00 - 2014-03-31 03:01 - 00000000 ____D () C:\1422204a4d0c5214678e7e513f
2014-03-30 05:56 - 2014-03-30 05:57 - 00000000 ____D () C:\93be8ac8c76718ece248f37b
2014-03-29 04:00 - 2014-03-29 04:01 - 00000000 ____D () C:\8ec08d4ae2da85e078d1587ac9592d
2014-03-28 04:00 - 2014-03-28 04:01 - 00000000 ____D () C:\3c68f122100d650fb03016c965
2014-03-26 17:25 - 2014-03-26 17:26 - 00000000 ____D () C:\05ba261ba95feeaa2f2a4eae0444
2014-03-26 04:00 - 2014-03-26 04:01 - 00000000 ____D () C:\e928d92cbc5b4cc45c05
2014-03-25 04:00 - 2014-03-25 04:01 - 00000000 ____D () C:\0afea791792ec427a5f735
2014-03-24 04:00 - 2014-03-24 04:01 - 00000000 ____D () C:\b1e55c82e8f36c4e71ca
2014-03-24 03:09 - 2014-03-24 03:10 - 00000000 ____D () C:\81ca3b3b9c646c8dc377
2014-03-23 15:55 - 2014-03-23 15:56 - 00000000 ____D () C:\a3fb930042e9d1c52e73739d
2014-03-23 08:08 - 2014-03-23 08:08 - 00000000 ____D () C:\724d8c3eb4b4c4edd9b033
2014-03-23 04:01 - 2014-03-23 04:03 - 00000000 ____D () C:\20a663dac598c3eb7c
2014-03-22 14:31 - 2014-03-22 14:32 - 00000000 ____D () C:\6f056854c068b9ddcf504d7300219beb
2014-03-21 21:25 - 2014-03-21 21:26 - 00000000 ____D () C:\d122489aee4965454a04
2014-03-21 07:10 - 2014-03-21 07:11 - 00000000 ____D () C:\427631fe5925411c48b280
2014-03-21 03:45 - 2013-12-18 08:13 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-21 03:30 - 2014-03-21 14:20 - 00003256 _____ () C:\Windows\system32\TmInstall.log
2014-03-21 03:30 - 2014-03-21 03:30 - 00004280 _____ () C:\Windows\SysWOW64\TmInstall.log
2014-03-19 11:08 - 2014-03-19 11:08 - 00000000 ____D () C:\5f8726a59ef879f13d037c9a3efd6822
2014-03-19 01:05 - 2014-03-23 06:02 - 00000000 ____D () C:\Users\Franca\Cover
2014-03-19 00:45 - 2014-03-19 01:34 - 00573440 _____ () C:\Users\Franca\Documents\Unbenannt-1.indd
2014-03-18 17:20 - 2014-04-01 21:29 - 27996160 _____ () C:\Users\Franca\Documents\Portfolio2014.indd
2014-03-18 13:12 - 2014-03-18 13:13 - 00000000 ____D () C:\c4c17989c2d1af59cf9a60519a
2014-03-18 01:48 - 2014-03-18 01:48 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-03-14 21:24 - 2014-03-14 21:24 - 00042585 _____ () C:\Users\Franca\Downloads\Google-Ergebnis für http criminologia.de blog wp-content uploads 2012 09 tumblr_m8no7o21X91r65rllo1_500-199x300.jpg.htm
2014-03-14 21:24 - 2014-03-14 21:24 - 00000000 ____D () C:\Users\Franca\Downloads\Google-Ergebnis für http criminologia.de blog wp-content uploads 2012 09 tumblr_m8no7o21X91r65rllo1_500-199x300.jpg_files
2014-03-12 14:13 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 14:13 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 14:13 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 14:13 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 14:13 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 14:13 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 14:13 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 14:13 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 14:13 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 14:13 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 14:13 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 14:13 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 14:13 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-12 14:13 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 14:13 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 14:13 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-12 14:13 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 14:13 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 14:13 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-12 14:13 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-12 14:13 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-12 14:13 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-12 14:13 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-12 14:13 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 14:13 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-12 14:13 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-12 14:13 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-12 14:13 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 14:13 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 14:13 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-12 14:13 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-12 14:13 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 14:13 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-12 14:13 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-12 14:13 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-12 14:13 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 14:13 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-12 14:13 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-12 14:13 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 14:13 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-12 14:13 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 14:13 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 14:13 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-12 14:13 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-12 14:11 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 14:11 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 14:11 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-12 14:11 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-11 16:23 - 2014-03-11 16:23 - 00000000 ____D () C:\212b49d22a1ffdf144c5
2014-03-11 04:27 - 2014-03-11 04:29 - 00000000 ____D () C:\38dedcf8b8cd76f373
2014-03-10 17:53 - 2014-03-10 17:55 - 00000000 ____D () C:\588c8bc9f8add3c4ef
2014-03-05 13:09 - 2014-03-05 13:09 - 00000000 ____D () C:\06f564d11fcf5d636818743e037ca5
2014-03-05 05:48 - 2014-03-05 05:49 - 00000000 ____D () C:\23c9a39f75d5cee8f07aa348
==================== One Month Modified Files and Folders =======
2014-04-04 03:19 - 2014-04-01 20:12 - 00016352 _____ () C:\Users\Franca\Downloads\FRST.txt
2014-04-04 03:18 - 2014-04-01 20:11 - 00000000 ____D () C:\FRST
2014-04-04 03:10 - 2014-04-04 03:10 - 00005256 _____ () C:\Users\Franca\Desktop\JRT.txt
2014-04-04 03:02 - 2012-01-30 17:33 - 01056017 _____ () C:\Windows\WindowsUpdate.log
2014-04-04 03:02 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-04 03:02 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-04 03:00 - 2012-05-24 10:39 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-04 03:00 - 2012-02-26 21:20 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-04 02:59 - 2014-04-04 02:59 - 00000000 ____D () C:\Windows\ERUNT
2014-04-04 02:59 - 2011-02-19 06:24 - 00708734 _____ () C:\Windows\system32\perfh007.dat
2014-04-04 02:59 - 2011-02-19 06:24 - 00152080 _____ () C:\Windows\system32\perfc007.dat
2014-04-04 02:59 - 2009-07-14 07:13 - 01644796 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-04 02:57 - 2014-04-04 02:57 - 01038974 _____ (Thisisu) C:\Users\Franca\Downloads\JRT.exe
2014-04-04 02:57 - 2014-04-04 02:57 - 01038974 _____ (Thisisu) C:\Users\Franca\Downloads\JRT (1).exe
2014-04-04 02:56 - 2013-05-23 00:33 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\Dropbox
2014-04-04 02:55 - 2013-07-26 16:20 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-04-04 02:55 - 2013-05-23 00:36 - 00000000 ___RD () C:\Users\Franca\Dropbox
2014-04-04 02:54 - 2014-04-04 02:54 - 00000000 ___RD () C:\Users\Franca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-04-04 02:54 - 2012-02-26 21:20 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-04 02:54 - 2012-02-24 19:55 - 00000000 ___HD () C:\ASUS.DAT
2014-04-04 02:53 - 2012-02-24 19:55 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-04-04 02:53 - 2011-10-19 05:20 - 00480440 _____ () C:\Windows\PFRO.log
2014-04-04 02:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-04 02:53 - 2009-07-14 06:51 - 00150694 _____ () C:\Windows\setupact.log
2014-04-04 02:52 - 2014-04-04 02:51 - 00000000 ____D () C:\AdwCleaner
2014-04-04 02:52 - 2012-05-19 22:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-04 02:49 - 2014-04-04 02:49 - 01426178 _____ () C:\Users\Franca\Downloads\adwcleaner.exe
2014-04-04 02:48 - 2014-04-04 02:48 - 00006518 _____ () C:\Users\Franca\Desktop\mbam.txt
2014-04-04 02:46 - 2014-04-04 02:00 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-04 02:37 - 2009-07-14 06:45 - 00000000 ____D () C:\Windows\Setup
2014-04-04 02:10 - 2014-04-04 02:09 - 00000000 ____D () C:\Users\Franca\AppData\Local\Microsoft Games
2014-04-04 02:07 - 2014-04-04 02:07 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\Go-Go Gourmet Chef of the Year
2014-04-04 02:00 - 2014-04-04 02:00 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-04 02:00 - 2014-04-04 02:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-04 02:00 - 2014-04-04 02:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-04 02:00 - 2012-02-26 21:23 - 00000000 ____D () C:\Users\Franca\AppData\Local\Adobe
2014-04-04 01:58 - 2014-04-04 01:57 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Franca\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-04 01:32 - 2014-04-04 01:32 - 00001266 _____ () C:\Users\Franca\Desktop\Revo Uninstaller.lnk
2014-04-04 01:32 - 2014-04-04 01:32 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-04 01:32 - 2014-04-04 01:31 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Franca\Downloads\revosetup95.exe
2014-04-03 16:12 - 2014-04-03 16:11 - 00000000 ____D () C:\91e3d83d38e66f8a3c6c
2014-04-03 16:11 - 2012-02-24 23:12 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\SoftGrid Client
2014-04-03 03:01 - 2014-04-03 03:00 - 00000000 ____D () C:\cd00002f4cb58184cdf938a73d26
2014-04-03 01:03 - 2014-02-28 00:10 - 00183080 _____ () C:\Users\Franca\Documents\2.5.1_007 Verfuegbarkeitsformular Nebenbeschaeftigte 2014.ods
2014-04-02 05:01 - 2014-04-02 05:01 - 00000000 ____D () C:\7641723a64526887d7b29b32eb6163
2014-04-02 03:01 - 2014-04-02 03:00 - 00000000 ____D () C:\0f4a6b61b724447c58fd4dc392945f4e
2014-04-01 21:33 - 2014-04-01 20:14 - 00036210 _____ () C:\Users\Franca\Downloads\Addition.txt
2014-04-01 21:32 - 2014-04-01 19:19 - 00014337 _____ () C:\Users\Franca\Documents\Statement.odt
2014-04-01 21:29 - 2014-03-18 17:20 - 27996160 _____ () C:\Users\Franca\Documents\Portfolio2014.indd
2014-04-01 20:10 - 2014-04-01 20:10 - 02157056 _____ (Farbar) C:\Users\Franca\Downloads\FRST64.exe
2014-04-01 03:02 - 2014-04-01 03:01 - 00000000 ____D () C:\b11e1ed5072f071fc1a4
2014-03-31 14:55 - 2014-03-31 14:55 - 00000000 ____D () C:\41046b8d8980248372ea
2014-03-31 03:01 - 2014-03-31 03:00 - 00000000 ____D () C:\1422204a4d0c5214678e7e513f
2014-03-30 05:57 - 2014-03-30 05:56 - 00000000 ____D () C:\93be8ac8c76718ece248f37b
2014-03-29 12:55 - 2012-02-26 21:20 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-29 12:55 - 2012-02-26 21:20 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-29 04:01 - 2014-03-29 04:00 - 00000000 ____D () C:\8ec08d4ae2da85e078d1587ac9592d
2014-03-28 04:01 - 2014-03-28 04:00 - 00000000 ____D () C:\3c68f122100d650fb03016c965
2014-03-26 17:26 - 2014-03-26 17:25 - 00000000 ____D () C:\05ba261ba95feeaa2f2a4eae0444
2014-03-26 04:01 - 2014-03-26 04:00 - 00000000 ____D () C:\e928d92cbc5b4cc45c05
2014-03-25 04:01 - 2014-03-25 04:00 - 00000000 ____D () C:\0afea791792ec427a5f735
2014-03-24 04:01 - 2014-03-24 04:00 - 00000000 ____D () C:\b1e55c82e8f36c4e71ca
2014-03-24 03:10 - 2014-03-24 03:09 - 00000000 ____D () C:\81ca3b3b9c646c8dc377
2014-03-24 00:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-23 15:56 - 2014-03-23 15:55 - 00000000 ____D () C:\a3fb930042e9d1c52e73739d
2014-03-23 08:08 - 2014-03-23 08:08 - 00000000 ____D () C:\724d8c3eb4b4c4edd9b033
2014-03-23 06:02 - 2014-03-19 01:05 - 00000000 ____D () C:\Users\Franca\Cover
2014-03-23 04:03 - 2014-03-23 04:01 - 00000000 ____D () C:\20a663dac598c3eb7c
2014-03-22 14:32 - 2014-03-22 14:31 - 00000000 ____D () C:\6f056854c068b9ddcf504d7300219beb
2014-03-21 21:26 - 2014-03-21 21:25 - 00000000 ____D () C:\d122489aee4965454a04
2014-03-21 14:20 - 2014-03-21 03:30 - 00003256 _____ () C:\Windows\system32\TmInstall.log
2014-03-21 07:11 - 2014-03-21 07:10 - 00000000 ____D () C:\427631fe5925411c48b280
2014-03-21 03:51 - 2013-08-11 14:48 - 00000000 ____D () C:\Users\Franca\ARCHIV
2014-03-21 03:30 - 2014-03-21 03:30 - 00004280 _____ () C:\Windows\SysWOW64\TmInstall.log
2014-03-21 03:30 - 2011-10-19 06:36 - 00000000 ____D () C:\ProgramData\Trend Micro
2014-03-20 16:59 - 2012-05-24 11:25 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\vlc
2014-03-20 00:35 - 2012-07-09 21:11 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\dvdcss
2014-03-19 11:08 - 2014-03-19 11:08 - 00000000 ____D () C:\5f8726a59ef879f13d037c9a3efd6822
2014-03-19 01:34 - 2014-03-19 00:45 - 00573440 _____ () C:\Users\Franca\Documents\Unbenannt-1.indd
2014-03-19 01:05 - 2012-02-24 19:54 - 00000000 ____D () C:\Users\Franca
2014-03-18 13:13 - 2014-03-18 13:12 - 00000000 ____D () C:\c4c17989c2d1af59cf9a60519a
2014-03-18 13:12 - 2013-08-15 02:28 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 13:09 - 2012-02-28 20:15 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-18 01:48 - 2014-03-18 01:48 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-03-18 01:48 - 2012-02-26 21:17 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-18 01:48 - 2012-02-24 19:57 - 00000000 ____D () C:\Users\Franca\AppData\Roaming\Adobe
2014-03-15 23:14 - 2012-11-11 04:21 - 00002177 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-14 21:24 - 2014-03-14 21:24 - 00042585 _____ () C:\Users\Franca\Downloads\Google-Ergebnis für http criminologia.de blog wp-content uploads 2012 09 tumblr_m8no7o21X91r65rllo1_500-199x300.jpg.htm
2014-03-14 21:24 - 2014-03-14 21:24 - 00000000 ____D () C:\Users\Franca\Downloads\Google-Ergebnis für http criminologia.de blog wp-content uploads 2012 09 tumblr_m8no7o21X91r65rllo1_500-199x300.jpg_files
2014-03-12 22:46 - 2009-07-14 06:45 - 04918208 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-12 22:44 - 2012-05-14 11:08 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-12 22:44 - 2012-05-14 11:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-12 00:00 - 2012-05-24 10:39 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 00:00 - 2012-05-24 10:39 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 00:00 - 2012-02-28 03:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-11 16:23 - 2014-03-11 16:23 - 00000000 ____D () C:\212b49d22a1ffdf144c5
2014-03-11 04:29 - 2014-03-11 04:27 - 00000000 ____D () C:\38dedcf8b8cd76f373
2014-03-10 17:55 - 2014-03-10 17:53 - 00000000 ____D () C:\588c8bc9f8add3c4ef
2014-03-05 13:09 - 2014-03-05 13:09 - 00000000 ____D () C:\06f564d11fcf5d636818743e037ca5
2014-03-05 09:26 - 2014-04-04 02:00 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-04 02:00 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-04-04 02:00 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-05 05:49 - 2014-03-05 05:48 - 00000000 ____D () C:\23c9a39f75d5cee8f07aa348
Some content of TEMP:
====================
C:\Users\Franca\AppData\Local\Temp\avgnt.exe
C:\Users\Franca\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-24 04:25
==================== End Of Log ============================
--- --- ---
--- --- ---