fixlog ( richtig so ?? )
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-04-2014
Ran by oliver at 2014-04-15 12:12:20 Run:1
Running from C:\Users\oliver\Downloads\FRST-OlderVersion
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
*****************
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
HKCU\SOFTWARE\Policies\Google => Key deleted successfully.
==== End of Fixlog ====
Mbam Log :
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.04.2014
Suchlauf-Zeit: 12:38:04
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.15.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: oliver
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 262391
Verstrichene Zeit: 19 Min, 12 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 2
Refog.Keylogger, HKLM\SOFTWARE\Refog Software, In Quarantäne, [14ecdc24d927748cf426937909fa09f7],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1972273453-3807663751-171534141-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Löschen bei Neustart, [c33d04fcb9474ab66ab236326b9719e7],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Conduit.A, HKU\S-1-5-21-1972273453-3807663751-171534141-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?gd=&ctid=CT3324790&octid=EB_ORIGINAL_CTID&ISID=M72FE993A-0214-405F-BB2C-175D7D49BF8A&SearchSource=55&CUI=&UM=5&UP=SP19964EC2-F0C6-4A71-A77E-C7DB3995671E&SSPV=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.conduit.com/?gd=&ctid=CT3324790&octid=EB_ORIGINAL_CTID&ISID=M72FE993A-0214-405F-BB2C-175D7D49BF8A&SearchSource=55&CUI=&UM=5&UP=SP19964EC2-F0C6-4A71-A77E-C7DB3995671E&SSPV=),Löschen bei Neustart,[1be5ae52b94712ee2a6363b612f2b14f]
Ordner: 3
PUP.Optional.Babylon.A, C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\ffxtlbr@babylon.com, In Quarantäne, [0df3ba461fe13cc4b60acc9580826898],
PUP.Optional.Babylon.A, C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\ffxtlbr@babylon.com\defaults, In Quarantäne, [0df3ba461fe13cc4b60acc9580826898],
PUP.Optional.Babylon.A, C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\ffxtlbr@babylon.com\defaults\preferences, In Quarantäne, [0df3ba461fe13cc4b60acc9580826898],
Dateien: 19
PUP.Optional.Bandoo, C:\Users\oliver\Downloads\iLividSetupV1 (1).exe, In Quarantäne, [6b9538c8b0507b85cb3c5ca89e639b65],
PUP.Optional.Bandoo, C:\Users\oliver\Downloads\iLividSetupV1.exe, In Quarantäne, [0af637c9788835cbc740b252d928da26],
PUP.Optional.Domalq, C:\Users\oliver\Downloads\Player_Setup.exe, In Quarantäne, [da262bd5ae521ce4724b8070ee158c74],
PUP.Optional.SafeInstall.A, C:\Users\oliver\Downloads\vioplayerv.exe, In Quarantäne, [3ec26c94c43cd9279852d96d28d9768a],
PUP.Optional.OpenCandy, C:\Users\oliver\Downloads\winamp563_full_emusic-7plus_de-de.exe, In Quarantäne, [cc3416ea847c33cdfe779da9da2a21df],
PUP.Optional.OpenCandy, C:\Users\oliver\Downloads\winamp564_full_emusic-7plus_de-de.exe, In Quarantäne, [0cf4ad53847cac5420555cea5da7fd03],
PUP.Optional.Smart, C:\Users\oliver\Downloads\FlvPlayer (1).exe, In Quarantäne, [0df3c83817e913eda22bff039869e51b],
PUP.Optional.Smart, C:\Users\oliver\Downloads\FlvPlayer.exe, In Quarantäne, [d52bd52be71930d05479c240649dc040],
PUP.Optional.OpenCandy, C:\Users\oliver\Downloads\veetle-0.9.18.exe, In Quarantäne, [847c2cd432ce57a96e0790b620e429d7],
PUP.Optional.BundleInstaller.A, C:\Users\oliver\Downloads\Setup (1).exe, In Quarantäne, [43bd20e004fc8e72b64ac75d17e9df21],
PUP.Optional.BundleInstaller.A, C:\Users\oliver\Downloads\Setup (2).exe, In Quarantäne, [97698e729967758bd52b9c88d52ba35d],
PUP.Optional.BundleInstaller.A, C:\Users\oliver\Downloads\Setup (3).exe, In Quarantäne, [8977cd33847c3ac6fb05d3519e626d93],
PUP.Optional.Tuguu, C:\Users\oliver\Downloads\Setup (4).exe, In Quarantäne, [27d97c84cb358b7547c334e6b64b9769],
PUP.Optional.Tuguu, C:\Users\oliver\Downloads\Setup (5).exe, In Quarantäne, [d030ca36fa06be4212f8958531d058a8],
PUP.Optional.Domalq, C:\Users\oliver\Downloads\Setup (6).exe, In Quarantäne, [7090df2117e947b91f4f10e69a694ab6],
PUP.Optional.BundleInstaller.A, C:\Users\oliver\Downloads\Setup (8).exe, In Quarantäne, [ab5546ba3ec23ec28a5581bc827f8e72],
PUP.Optional.Bundlore, C:\Users\oliver\Downloads\setup (9).exe, In Quarantäne, [60a0f40ce41cbc440b6c8677788bf30d],
PUP.Optional.BundleInstaller.A, C:\Users\oliver\Downloads\Setup.exe, In Quarantäne, [01ffad53f0108779718f9a8a56aa21df],
PUP.Optional.Babylon.A, C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\ffxtlbr@babylon.com\defaults\preferences\dflt.js, In Quarantäne, [0df3ba461fe13cc4b60acc9580826898],
Physische Sektoren: 0
(No malicious items detected)
(end)
rest folgt gleich
adw cleanerAdwCleaner Logfile:
Code:
# AdwCleaner v3.023 - Bericht erstellt am 15/04/2014 um 12:51:41
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : oliver - OLIVER-PC
# Gestartet von : C:\Users\oliver\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Users\oliver\AppData\Local\cool_mirage
Ordner Gelöscht : C:\Users\oliver\AppData\Local\Temp\OCS
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Datei Gelöscht : C:\windows\System32\Tasks\Funmoods
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FTDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FTDownloader_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FTDownloader_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{08337871-0E50-4031-9110-3BD21CA3C065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{08337871-0E50-4031-9110-3BD21CA3C065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{08337871-0E50-4031-9110-3BD21CA3C065}
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Vsharecomplete
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (de)
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [4446 octets] - [15/04/2014 12:49:30]
AdwCleaner[S0].txt - [4152 octets] - [15/04/2014 12:51:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4212 octets] ##########
--- --- ---
jrt log
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by oliver on 15.04.2014 at 12:55:27,85
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1972273453-3807663751-171534141-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6BE547F0-A203-4ECC-B476-C43C3A11B084}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{80272FE5-DE96-4AB0-B0C0-A4D7F04CA654}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{80272FE5-DE96-4AB0-B0C0-A4D7F04CA654}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\oliver\AppData\Roaming\getrighttogo"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.04.2014 at 13:06:39,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~
und frst ..
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014
Ran by oliver (administrator) on OLIVER-PC on 15-04-2014 13:18:38
Running from C:\Users\oliver\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 3\CheckUpdate.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 3\Integrator.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Rainlendar2\Rainlendar2.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\windows\System32\alg.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2735400 2011-03-31] (Synaptics Incorporated)
HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [161304 2010-12-28] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\windows\system32\hkcmd.exe [386584 2010-12-28] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\windows\system32\igfxpers.exe [415256 2010-12-28] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12558440 2011-07-07] (Realtek Semiconductor)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl8] => C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-07-21] (CyberLink Corp.)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [80480 2013-06-19] (Nullsoft, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1972273453-3807663751-171534141-1000\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe [4359680 2012-12-29] ()
HKU\S-1-5-21-1972273453-3807663751-171534141-1000\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung)
HKU\S-1-5-21-1972273453-3807663751-171534141-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
HKU\S-1-5-21-1972273453-3807663751-171534141-1000\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\C:\Users\oliver\AppData\Roaming\Mozilla\Profiles\o76bw92q.Standard-Benutzer
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2013-04-08]
FF Extension: FTdownloader 2 - C:\Users\oliver\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftdownloader2@ftdownloader.com.xpi [2013-02-11]
Chrome:
=======
CHR HomePage: hxxp://www.t-online.de/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.313\npMcAfeeMss.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Google Docs) - C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-01]
CHR Extension: (Google Drive) - C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-01]
CHR Extension: (YouTube) - C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-01]
CHR Extension: (Google-Suche) - C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-01]
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-08-01]
CHR Extension: (Google Wallet) - C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Google Mail) - C:\Users\oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-01]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\oliver\AppData\Roaming\DVDVideoSoft\DVDVideoSoftBrowserExtension.crx [2012-11-20]
CHR HKLM-x32\...\Chrome\Extension: [mbcjjdjanpccmehilicphhmeobiljcpk] - C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx [2012-11-20]
CHR HKLM-x32\...\Chrome\Extension: [pilobbegphefikcgjpajnneiiahhejam] - C:\Users\oliver\Econa\Gutscheinsammler\Chrome\chrome.crx [2012-02-14]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2211000 2014-03-30] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] ()
S2 ScrybeUpdater; C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe [1300264 2011-05-27] (Synaptics, Inc.)
S2 vToolbarUpdater15.4.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [45856 2013-07-29] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-27] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-04-15] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
S3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader)
S0 PxHlpa64; C:\Windows\SysWOW64\Drivers\PxHlpa64.sys [26720 2004-09-23] (Sonic Solutions)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2011-02-15] (Windows (R) 2003 DDK 3790 provider)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-15 13:06 - 2014-04-15 13:06 - 00001385 _____ () C:\Users\oliver\Desktop\JRT.txt
2014-04-15 12:54 - 2014-04-15 12:55 - 01016261 _____ (Thisisu) C:\Users\oliver\Downloads\JRT.exe
2014-04-15 12:49 - 2014-04-15 12:51 - 00000000 ____D () C:\AdwCleaner
2014-04-15 12:48 - 2014-04-15 12:49 - 01426178 _____ () C:\Users\oliver\Downloads\adwcleaner.exe
2014-04-15 12:46 - 2014-04-15 12:46 - 00004953 _____ () C:\Users\oliver\Desktop\mbam.txt
2014-04-15 12:40 - 2014-04-15 12:40 - 00005626 _____ () C:\windows\PFRO.log
2014-04-15 12:38 - 2014-04-15 12:38 - 00004953 _____ () C:\mbma.txt
2014-04-15 12:17 - 2014-04-15 12:57 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-15 12:17 - 2014-04-15 12:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-15 12:17 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-15 12:17 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-15 12:13 - 2014-04-15 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\oliver\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-15 12:11 - 2014-04-15 12:12 - 00000000 ____D () C:\Users\oliver\Downloads\FRST-OlderVersion
2014-04-15 11:32 - 2014-04-15 12:52 - 00000168 _____ () C:\windows\setupact.log
2014-04-15 11:32 - 2014-04-15 11:32 - 00000000 _____ () C:\windows\setuperr.log
2014-04-14 07:42 - 2014-04-14 07:42 - 00032734 _____ () C:\Users\oliver\Downloads\Addition.txt
2014-04-14 07:40 - 2014-04-15 13:18 - 00019101 _____ () C:\Users\oliver\Downloads\FRST.txt
2014-04-14 07:40 - 2014-04-15 13:18 - 00000000 ____D () C:\FRST
2014-04-14 07:40 - 2014-04-15 12:11 - 02054144 _____ (Farbar) C:\Users\oliver\Downloads\FRST64.exe
2014-04-11 12:31 - 2014-04-11 12:35 - 00000000 __SHD () C:\windows\syspkgwk
2014-04-11 12:31 - 2014-04-11 12:31 - 00000878 ___SH () C:\windows\SysWOW64\sysskl.dat
2014-04-11 12:29 - 2014-04-11 12:30 - 22179248 _____ (SoftActivity ) C:\Users\oliver\Downloads\activmon.exe
2014-04-11 09:18 - 2014-04-11 09:18 - 00000000 ____D () C:\Program Files (x86)\RobotSoft
2014-04-10 09:16 - 2004-03-09 00:00 - 00212240 _____ (Microsoft Corporation) C:\windows\SysWOW64\RICHTX32.OCX
2014-04-10 09:16 - 2004-02-23 00:00 - 00119808 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSSTDFMT.DLL
2014-04-10 09:16 - 2003-07-06 14:07 - 00372736 _____ (Intel Corporation) C:\windows\SysWOW64\IJL_11.DLL
2014-04-09 19:33 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-09 19:33 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-09 19:33 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-09 19:33 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-09 19:33 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-09 19:33 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2014-04-09 19:33 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-04-09 19:33 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-04-09 19:33 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-04-09 19:33 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-04-09 19:33 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-04-09 19:33 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-04-09 19:33 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-04-09 19:33 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-04-09 19:33 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-04-09 19:33 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-09 19:33 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-09 19:33 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-09 19:33 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-09 19:33 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2014-04-09 19:33 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-03 20:54 - 2014-04-03 20:58 - 00000000 ____D () C:\Users\oliver\AppData\Local\Sony
2014-04-03 20:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_43.dll
2014-04-03 20:49 - 2014-04-03 20:55 - 00000000 ____D () C:\Users\oliver\AppData\Roaming\Sony
2014-04-03 20:49 - 2014-04-03 20:53 - 00000000 ____D () C:\Program Files (x86)\Sony Media Go Install
2014-04-03 20:43 - 2014-04-03 20:54 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-04-03 20:43 - 2014-04-03 20:43 - 00002098 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-03-27 00:07 - 2014-04-06 13:48 - 00000000 ____D () C:\Users\oliver\Downloads\Corinna
==================== One Month Modified Files and Folders =======
2014-04-15 13:18 - 2014-04-14 07:40 - 00019101 _____ () C:\Users\oliver\Downloads\FRST.txt
2014-04-15 13:18 - 2014-04-14 07:40 - 00000000 ____D () C:\FRST
2014-04-15 13:14 - 2011-08-04 21:57 - 00001110 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-15 13:11 - 2012-03-29 23:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-15 13:06 - 2014-04-15 13:06 - 00001385 _____ () C:\Users\oliver\Desktop\JRT.txt
2014-04-15 13:02 - 2009-07-14 06:45 - 00013936 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-15 13:02 - 2009-07-14 06:45 - 00013936 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-15 12:59 - 2010-11-06 04:52 - 00700134 _____ () C:\windows\system32\perfh007.dat
2014-04-15 12:59 - 2010-11-06 04:52 - 00149984 _____ () C:\windows\system32\perfc007.dat
2014-04-15 12:59 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-15 12:57 - 2014-04-15 12:17 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-15 12:56 - 2011-07-23 19:33 - 00000374 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-04-15 12:55 - 2014-04-15 12:54 - 01016261 _____ (Thisisu) C:\Users\oliver\Downloads\JRT.exe
2014-04-15 12:55 - 2013-08-01 13:11 - 00000000 ____D () C:\windows\ERUNT
2014-04-15 12:53 - 2013-07-30 10:59 - 00000334 _____ () C:\windows\Tasks\GlaryInitialize 3.job
2014-04-15 12:53 - 2013-07-30 10:59 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 3
2014-04-15 12:53 - 2013-02-06 19:44 - 00000000 ____D () C:\Users\oliver\.rainlendar2
2014-04-15 12:53 - 2011-07-09 19:35 - 00000000 ____D () C:\Users\oliver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-04-15 12:52 - 2014-04-15 11:32 - 00000168 _____ () C:\windows\setupact.log
2014-04-15 12:52 - 2011-08-04 21:57 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-15 12:52 - 2010-11-08 01:10 - 01989402 _____ () C:\windows\WindowsUpdate.log
2014-04-15 12:52 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-15 12:51 - 2014-04-15 12:49 - 00000000 ____D () C:\AdwCleaner
2014-04-15 12:49 - 2014-04-15 12:48 - 01426178 _____ () C:\Users\oliver\Downloads\adwcleaner.exe
2014-04-15 12:46 - 2014-04-15 12:46 - 00004953 _____ () C:\Users\oliver\Desktop\mbam.txt
2014-04-15 12:40 - 2014-04-15 12:40 - 00005626 _____ () C:\windows\PFRO.log
2014-04-15 12:40 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\security
2014-04-15 12:38 - 2014-04-15 12:38 - 00004953 _____ () C:\mbma.txt
2014-04-15 12:17 - 2014-04-15 12:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-15 12:17 - 2012-07-19 18:20 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-15 12:17 - 2012-06-19 19:43 - 00000000 ____D () C:\Users\oliver\AppData\Roaming\Malwarebytes
2014-04-15 12:14 - 2014-04-15 12:13 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\oliver\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-15 12:12 - 2014-04-15 12:11 - 00000000 ____D () C:\Users\oliver\Downloads\FRST-OlderVersion
2014-04-15 12:11 - 2014-04-14 07:40 - 02054144 _____ (Farbar) C:\Users\oliver\Downloads\FRST64.exe
2014-04-15 11:32 - 2014-04-15 11:32 - 00000000 _____ () C:\windows\setuperr.log
2014-04-14 18:21 - 2012-02-12 00:31 - 00003938 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{999711EC-264D-4CF4-933C-4C0B21BB1F68}
2014-04-14 17:16 - 2012-10-23 22:21 - 00000000 ____D () C:\Users\oliver\Desktop\Comanndos
2014-04-14 07:42 - 2014-04-14 07:42 - 00032734 _____ () C:\Users\oliver\Downloads\Addition.txt
2014-04-12 10:24 - 2013-09-25 11:37 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-04-11 12:35 - 2014-04-11 12:31 - 00000000 __SHD () C:\windows\syspkgwk
2014-04-11 12:31 - 2014-04-11 12:31 - 00000878 ___SH () C:\windows\SysWOW64\sysskl.dat
2014-04-11 12:30 - 2014-04-11 12:29 - 22179248 _____ (SoftActivity ) C:\Users\oliver\Downloads\activmon.exe
2014-04-11 09:18 - 2014-04-11 09:18 - 00000000 ____D () C:\Program Files (x86)\RobotSoft
2014-04-10 11:38 - 2011-07-09 13:58 - 00000000 ____D () C:\Users\oliver\Desktop\Nicht verwendete Desktop Dateien
2014-04-10 11:08 - 2011-07-09 19:40 - 00000000 ___RD () C:\Users\oliver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-10 08:33 - 2011-07-09 19:35 - 00000000 ____D () C:\Users\oliver
2014-04-09 21:57 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache
2014-04-09 21:03 - 2013-08-01 23:35 - 00000000 ____D () C:\windows\system32\MRT
2014-04-09 21:01 - 2011-07-10 20:07 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-06 13:48 - 2014-03-27 00:07 - 00000000 ____D () C:\Users\oliver\Downloads\Corinna
2014-04-04 18:54 - 2011-07-09 13:52 - 00000000 ____D () C:\Users\oliver\AppData\Roaming\Winamp
2014-04-03 20:58 - 2014-04-03 20:54 - 00000000 ____D () C:\Users\oliver\AppData\Local\Sony
2014-04-03 20:55 - 2014-04-03 20:49 - 00000000 ____D () C:\Users\oliver\AppData\Roaming\Sony
2014-04-03 20:54 - 2014-04-03 20:43 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-04-03 20:53 - 2014-04-03 20:49 - 00000000 ____D () C:\Program Files (x86)\Sony Media Go Install
2014-04-03 20:43 - 2014-04-03 20:43 - 00002098 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-04-03 20:43 - 2010-11-08 01:07 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-03 09:51 - 2014-04-15 12:17 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-15 12:17 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2012-06-19 19:54 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-03-31 03:16 - 2014-04-09 19:33 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 19:33 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 19:33 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 19:33 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-28 22:09 - 2011-08-04 21:57 - 00004106 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-28 22:09 - 2011-08-04 21:57 - 00003854 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-19 19:15 - 2011-07-09 14:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
Some content of TEMP:
====================
C:\Users\oliver\AppData\Local\Temp\avgnt.exe
C:\Users\oliver\AppData\Local\Temp\gusetup3.exe
C:\Users\oliver\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 12:18
==================== End Of Log ============================
--- --- ---
--- --- ---