Folglich schicke ich dir die Textdateien in Reihenfolge:
Schritt 1 Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.04.2014
Suchlauf-Zeit: 17:24:18
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.23.06
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Jaqueline
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 269907
Verstrichene Zeit: 38 Min, 50 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 14
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [9f61af5169978d733426ff4f52b01ee2],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [42bef0107e82669aeb7071dde41e8a76],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, In Quarantäne, [2ad67c843ac6ea16de11a5a8877b10f0],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, In Quarantäne, [26dac33dd030976944016b1870922ad6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [a7596b9540c0ac5451f43c47847e1ce4],
PUP.Optional.OnlineVid.A, HKLM\SOFTWARE\WOW6432NODE\OnlineHD V6.0, In Quarantäne, [e51bb8487a8637c98029a2e052b0ca36],
PUP.Optional.OnlineHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\OnlineHD V6.0, In Quarantäne, [13edf010a35dbf417028fe7f8979c937],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-3545342124-3751203487-2797069715-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, In Quarantäne, [4ab614ec57a93fc16175d9c0f013b64a],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3545342124-3751203487-2797069715-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, In Quarantäne, [ef11808012ee867a67df1e65be440cf4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3545342124-3751203487-2797069715-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [ac54b54bbd43ca3657ba2e7f4fb4e719],
PUP.Optional.OnlineHD.A, HKU\S-1-5-21-3545342124-3751203487-2797069715-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\OnlineHD V6.0, In Quarantäne, [b54bae528b75c7394a4e7d008e74b848],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3545342124-3751203487-2797069715-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [b848f60aa65a5ca42255f37d936f7a86],
PUP.Optional.OnlineVid.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\OnlineHD V6.0, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\1ClickDownload, In Quarantäne, [e11f6a96db25837d89611b47f40e6c94],
Registrierungswerte: 2
PUP.Optional.Iminent.A, HKU\S-1-5-21-3545342124-3751203487-2797069715-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, In Quarantäne, [2ad67c843ac6ea16de11a5a8877b10f0],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3545342124-3751203487-2797069715-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, In Quarantäne, [0ff12fd1659bd12f549b4a039969af51],
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 7
PUP.Optional.Iminent.A, C:\Program Files (x86)\IminentToolbar, In Quarantäne, [b050dd237f81cb3543af77e9ae54d030],
PUP.Optional.OpenCandy, C:\Users\Jaqueline\AppData\Roaming\OpenCandy, In Quarantäne, [669a659b0ef2a15f44b7431d0ef45ea2],
PUP.Optional.OpenCandy, C:\Users\Jaqueline\AppData\Roaming\OpenCandy\071150BCD2F948B681B17418AC4E6D58, In Quarantäne, [669a659b0ef2a15f44b7431d0ef45ea2],
PUP.Optional.OpenCandy, C:\Users\Jaqueline\AppData\Roaming\OpenCandy\27F17CA4345D4D038494E4CF8F10F8F3, In Quarantäne, [669a659b0ef2a15f44b7431d0ef45ea2],
PUP.Optional.Iminent.A, C:\Users\Jaqueline\AppData\Roaming\IminentToolbar, In Quarantäne, [0ef257a9be42907021a97be745bdd42c],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD.TV, In Quarantäne, [e11f6a96db25837d89611b47f40e6c94],
Dateien: 38
PUP.Optional.OpenCandy.A, C:\Users\Jaqueline\AppData\Roaming\OpenCandy\27F17CA4345D4D038494E4CF8F10F8F3\Setupsft_chr_p1v7.exe, In Quarantäne, [fc047f8151af6b951fa1001fbe469c64],
PUP.Optional.ToolBarInstaller.A, C:\Users\Jaqueline\AppData\Local\Temp\BuenoSearchTB.exe, In Quarantäne, [b54b8d73f60aa65a74f27b89b74dfa06],
PUP.Optional.Iminent.A, C:\Users\Jaqueline\AppData\Local\Temp\IminentSetup-1-.exe, In Quarantäne, [c53b22de0af6956b50b62cfd5ca51de3],
PUP.Optional.Iminent, C:\Users\Jaqueline\AppData\Local\Temp\Umbrella.exe4fc6d, In Quarantäne, [59a73dc318e83fc123080ef55fa27c84],
PUP.Optional.Bandoo, C:\Users\Jaqueline\Downloads\iLividSetup-r400-n-bc (1).exe, In Quarantäne, [897715ebac54f60ac8505ca940c18a76],
PUP.Optional.OutBrowse, C:\Users\Jaqueline\Downloads\setup.exe, In Quarantäne, [8a76e21ef10f05fb455601bfc43f43bd],
PUP.Optional.Softonic.A, C:\Users\Jaqueline\Downloads\SoftonicDownloader_fuer_pdfbinder.exe, In Quarantäne, [d62adc24679932cea0d7ab709a670af6],
PUP.Optional.InstallCore.A, C:\Users\Jaqueline\Downloads\uplayermediaplayer-setup (1).exe, In Quarantäne, [48b82dd302fe1de31b7fe72c996b847c],
PUP.Optional.InstallCore.A, C:\Users\Jaqueline\Downloads\uplayermediaplayer-setup.exe, In Quarantäne, [9868f40c54acd9272e6cc350af559d63],
PUP.Optional.Bandoo, C:\Users\Jaqueline\Downloads\iLividSetup-r400-n-bc (2).exe, In Quarantäne, [fe0244bcce329b650d0b40c51be649b7],
PUP.Optional.OpenCandy, C:\Users\Jaqueline\Downloads\DTLite4481-0347.exe, In Quarantäne, [ea16d92730d035cb72e53d138084916f],
PUP.Optional.Bandoo, C:\Users\Jaqueline\Downloads\iLividSetup-r400-n-bc (3).exe, In Quarantäne, [4cb454aceb15db2529ef35d02ed3e020],
PUP.Optional.Bandoo, C:\Users\Jaqueline\Downloads\iLividSetup-r400-n-bc.exe, In Quarantäne, [bc4414eca35deb156fa9887dbe437f81],
PUP.Optional.OptimumInstaller.A, C:\Users\Jaqueline\Downloads\Player-Chrome.exe, In Quarantäne, [a55b35cbbe42857b1d03a3a60bf60000],
PUP.Optional.BundleInstaller.A, C:\Users\Jaqueline\Downloads\Player_Setup (1).exe, In Quarantäne, [4bb512eeb44cc9370a7cdf278b7942be],
PUP.Optional.BundleInstaller.A, C:\Users\Jaqueline\Downloads\Player_Setup (2).exe, In Quarantäne, [7d8301ff22de9e627a60380ad8299d63],
PUP.Optional.DomalQ, C:\Users\Jaqueline\Downloads\player_setup.exe, In Quarantäne, [8e7218e86c948e728b31719606fe8a76],
PUP.Optional.Iminent.A, C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage, In Quarantäne, [7c84718f24dc32ceb02c1c551be727d9],
PUP.Optional.OnlineVid.A, C:\Windows\Tasks\OnlineHD V6.0-chromeinstaller.job, In Quarantäne, [c739b34d53adf40c347486fca16115eb],
PUP.Optional.OnlineVid.A, C:\Windows\Tasks\OnlineHD V6.0-codedownloader.job, In Quarantäne, [4db3a957b24e9769a008e49e8a78bf41],
PUP.Optional.OnlineVid.A, C:\Windows\Tasks\OnlineHD V6.0-firefoxinstaller.job, In Quarantäne, [35cb1de3926efd03a4045f2344bea759],
PUP.Optional.OpenCandy, C:\Users\Jaqueline\AppData\Roaming\OpenCandy\071150BCD2F948B681B17418AC4E6D58\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [669a659b0ef2a15f44b7431d0ef45ea2],
PUP.Optional.Iminent.A, C:\Users\Jaqueline\AppData\Roaming\IminentToolbar\sqlite3.dll, In Quarantäne, [0ef257a9be42907021a97be745bdd42c],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\48260.crx, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\48260.xpi, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-buttonutil.dll, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-buttonutil.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-buttonutil64.dll, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-buttonutil64.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-chromeinstaller.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-codedownloader.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-firefoxinstaller.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0-helper.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\OnlineHD V6.0.ico, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\Uninstall.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD V6.0\utils.exe, In Quarantäne, [837d4db30df355ab3cad1a48966c9e62],
PUP.Optional.OnlineVid.A, C:\Program Files (x86)\OnlineHD.TV\uninst.exe, In Quarantäne, [e11f6a96db25837d89611b47f40e6c94],
PUP.Optional.BuenoSearch.A, C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=40491EAF78D8BE01&affID=128491&tsp=5175" ],), Ersetzt,[26da000039c76c940ac3d08859ab5ea2]
Physische Sektoren: 0
(No malicious items detected)
(end) Schritt 2
AdwCleaner Logfile: Code:
# AdwCleaner v3.201 - Bericht erstellt am 23/04/2014 um 17:36:05
# Aktualisiert 22/04/2014 von Xplode
# Betriebssystem : Windows 8.1 Pro (64 bits)
# Benutzername : Jaqueline - JAQUS
# Gestartet von : C:\Users\Jaqueline\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\SecretSauce
Ordner Gelöscht : C:\Users\Jaqueline\AppData\LocalLow\Softonic
Datei Gelöscht : C:\END
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Startup_urls] :
Gelöscht [Extension] : pkhojieggfgllhllcegoffdcnmdeojgb
*************************
AdwCleaner[R0].txt - [2770 octets] - [23/04/2014 17:34:44]
AdwCleaner[S0].txt - [2374 octets] - [23/04/2014 17:36:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2434 octets] ########## --- --- ---
Schritt 3: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 Pro x64
Ran by Jaqueline on 23.04.2014 at 17:41:31,54
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{57F16186-ED46-4B6D-BF4E-21CBD41BDEED}
~~~ Files
Successfully deleted: [File] C:\WINDOWS\syswow64\sho4485.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Jaqueline\appdata\locallow\boost_interprocess"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.04.2014 at 17:45:40,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Schritt 4:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by Jaqueline (administrator) on JAQUS on 23-04-2014 17:52:36
Running from C:\Users\Jaqueline\Desktop
Windows 8.1 Pro (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Atheros Commnucations) C:\WINDOWS\system32\AdminService.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Bitdefender) C:\Program Files\Bitdefender\60-Second Virus Scanner\pdscan.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Spotify Ltd) C:\Users\Jaqueline\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Bitdefender) C:\Program Files\Bitdefender\60-Second Virus Scanner\pdiface.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\Installer.exe"
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-12-23] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-11-15] ()
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2013-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\.DEFAULT\...\Run: [Bitdefender Wallet Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe"
HKU\.DEFAULT\...\Run: [Bitdefender Wallet] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard
HKU\.DEFAULT\...\Run: [Bitdefender Wallet Application Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe"
HKU\S-1-5-21-3545342124-3751203487-2797069715-1001\...\Run: [Spotify Web Helper] => C:\Users\Jaqueline\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-17] (Spotify Ltd)
HKU\S-1-5-21-3545342124-3751203487-2797069715-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
HKU\S-1-5-21-3545342124-3751203487-2797069715-1001\...\Run: [pdiface] => C:\Program Files\Bitdefender\60-Second Virus Scanner\pdiface.exe [283608 2013-10-30] (Bitdefender)
HKU\S-1-5-21-3545342124-3751203487-2797069715-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3545342124-3751203487-2797069715-1001\...\MountPoints2: {a3a07df4-84c4-11e3-be6e-ccaf78d8be02} - "E:\Startme.exe"
HKU\S-1-5-21-3545342124-3751203487-2797069715-1001\...\MountPoints2: {ab475adb-6c17-11e3-be66-78843cefab0d} - "E:\start.exe"
HKU\S-1-5-21-3545342124-3751203487-2797069715-1001\...\MountPoints2: {c1b48961-97d5-11e3-be73-ccaf78d8be02} - "F:\HTC_Sync_Manager_PC.exe"
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
Chrome:
=======
CHR HomePage:
CHR RestoreOnStartup: "spellcheck": {
"confirm_dialog_shown": true,
"use_spelling_service"
CHR DefaultSearchKeyword: gmx.de
CHR DefaultSearchProvider: GMX Suche
CHR DefaultSearchURL: hxxp://suche.gmx.net/search/web/?su={searchTerms}&mc=searchplugin@suche@ffox.suche@web&origin=searchplugin
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll No File
CHR Extension: (SmallringFX MetalSliver Theme) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\amoaokkohdcekgomnddkdfocbifmiafo [2014-01-05]
CHR Extension: (Google Docs) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-24]
CHR Extension: (Google Drive) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-24]
CHR Extension: (YouTube) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-24]
CHR Extension: (Google-Suche) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-24]
CHR Extension: (OnlineHD V6.0) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\jooebibmaabdachfgeeopohjbkhlkkop [2013-12-24]
CHR Extension: (Google Wallet) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-24]
CHR Extension: (Google Mail) - C:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-24]
==================== Services (Whitelisted) =================
R2 AtherosSvc; C:\Windows\system32\AdminService.exe [208384 2012-08-29] (Atheros Commnucations)
R3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [321024 2013-08-22] (Microsoft Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 pdserv; C:\Program Files\Bitdefender\60-Second Virus Scanner\pdscan.exe [1445424 2013-11-11] (Bitdefender)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-12-09] (WiseCleaner.com)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [131584 2013-08-22] (Microsoft Corporation)
R3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [32640 2013-08-22] (Microsoft Corporation)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-01-21] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-11-14] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-01-21] (Microsoft Corporation)
R3 Sftfs; C:\Windows\system32\DRIVERS\Sftfswin7.sys [768680 2013-06-26] (Microsoft Corporation)
R3 Sftplay; C:\Windows\system32\DRIVERS\Sftplaywin7.sys [273576 2013-06-26] (Microsoft Corporation)
R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29352 2013-06-26] (Microsoft Corporation)
R3 Sftvol; C:\Windows\system32\DRIVERS\Sftvolwin7.sys [23208 2013-06-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
S3 WUDFWpdComp; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-23 17:47 - 2014-04-23 17:52 - 00013067 _____ () C:\Users\Jaqueline\Desktop\FRST.txt
2014-04-23 17:47 - 2014-04-23 17:47 - 00991504 _____ () C:\Users\Jaqueline\Downloads\setup (2).exe
2014-04-23 17:45 - 2014-04-23 17:45 - 00001058 _____ () C:\Users\Jaqueline\Desktop\JRT.txt
2014-04-23 17:41 - 2014-04-23 17:41 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-23 17:40 - 2014-04-23 17:41 - 01016261 _____ (Thisisu) C:\Users\Jaqueline\Downloads\JRT.exe
2014-04-23 17:40 - 2014-04-23 17:40 - 00991504 _____ () C:\Users\Jaqueline\Downloads\setup (1).exe
2014-04-23 17:40 - 2014-04-23 17:40 - 00002526 _____ () C:\Users\Jaqueline\Desktop\AdwCleaner[S0].txt
2014-04-23 17:33 - 2014-04-23 17:40 - 00000000 ____D () C:\AdwCleaner
2014-04-23 17:32 - 2014-04-23 17:32 - 01345299 _____ () C:\Users\Jaqueline\Desktop\adwcleaner.exe
2014-04-23 17:32 - 2014-04-23 17:32 - 00010434 _____ () C:\Users\Jaqueline\Desktop\mbam.txt
2014-04-23 17:30 - 2014-04-23 17:30 - 00991504 _____ () C:\Users\Jaqueline\Downloads\setup.exe
2014-04-23 16:44 - 2014-04-23 17:37 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 16:43 - 2014-04-23 16:43 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-23 16:43 - 2014-04-23 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-23 16:43 - 2014-04-23 16:43 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 16:43 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-23 16:43 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-04-23 16:43 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-23 16:42 - 2014-04-23 16:42 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Jaqueline\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-23 16:21 - 2014-04-23 16:30 - 00027868 _____ () C:\Users\Jaqueline\Downloads\Addition.txt
2014-04-23 16:20 - 2014-04-23 17:52 - 00000000 ____D () C:\FRST
2014-04-23 16:20 - 2014-04-23 16:30 - 00040586 _____ () C:\Users\Jaqueline\Downloads\FRST.txt
2014-04-23 16:19 - 2014-04-23 16:19 - 02061312 _____ (Farbar) C:\Users\Jaqueline\Downloads\FRST64 (1).exe
2014-04-23 16:18 - 2014-04-23 16:18 - 02061312 _____ (Farbar) C:\Users\Jaqueline\Desktop\FRST64.exe
2014-04-17 10:20 - 2014-04-17 10:20 - 00281027 _____ () C:\ProgramData\1397722679.bdinstall.bin
2014-04-17 10:20 - 2014-04-17 10:20 - 00049288 _____ () C:\ProgramData\1397722782.bdinstall.bin
2014-04-16 22:42 - 2014-04-16 22:42 - 00000000 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-16 22:37 - 2014-04-16 22:37 - 00000000 ____D () C:\Users\Jaqueline\Documents\Electronic Arts
2014-04-16 22:33 - 2014-04-16 22:33 - 00002088 _____ () C:\Users\Public\Desktop\Die*Sims™*3.lnk
2014-04-15 21:41 - 2014-04-15 21:41 - 00000000 ____D () C:\Program Files\Common Files\Atheros
2014-04-13 16:25 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-13 16:25 - 2014-03-10 12:35 - 02008408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-04-13 16:25 - 2014-03-10 12:35 - 00377176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2014-04-13 16:25 - 2014-03-06 11:19 - 01287576 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-04-13 16:25 - 2014-03-06 11:02 - 01109424 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-04-13 16:25 - 2014-03-06 08:17 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-04-13 16:25 - 2014-03-06 08:10 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2014-04-13 16:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-04-13 16:21 - 2014-04-13 16:21 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-04-13 16:20 - 2014-04-13 16:20 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-04-02 11:46 - 2014-04-02 11:46 - 00001868 _____ () C:\Users\Jaqueline\Desktop\TS3W.exe - Verknüpfung.lnk
2014-04-02 11:44 - 2014-04-02 11:44 - 00001853 _____ () C:\Users\Jaqueline\Desktop\TS3.exe - Verknüpfung.lnk
2014-03-31 18:02 - 2014-03-27 18:08 - 01844884 _____ () C:\Users\Jaqueline\Documents\Open%20englisch).odp_1odp
2014-03-31 18:02 - 2014-03-27 17:15 - 00064644 _____ () C:\Users\Jaqueline\Documents\Englisch%20Präsentation.docx_0odt
2014-03-31 18:02 - 2014-03-27 17:15 - 00052085 _____ () C:\Users\Jaqueline\Documents\Handout.docx_0odt
2014-03-28 07:34 - 2014-03-28 07:34 - 00000000 __RHD () C:\MSOCache
2014-03-27 12:16 - 2014-03-27 12:16 - 00000385 _____ () C:\Users\Jaqueline\AppData\Roaminguser_gensett.xml
2014-03-27 12:15 - 2014-03-27 12:15 - 00000385 _____ () C:\WINDOWS\system32\user_gensett.xml
2014-03-26 19:11 - 2014-04-23 17:37 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf491663174c7d.job
2014-03-26 19:11 - 2014-04-23 17:16 - 00001130 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf491666463019.job
2014-03-26 19:11 - 2014-03-26 19:11 - 00004102 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1cf491666463019
2014-03-26 19:11 - 2014-03-26 19:11 - 00003866 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1cf491663174c7d
2014-03-26 19:00 - 2014-03-26 19:00 - 00000097 ____H () C:\Users\Jaqueline\Desktop\.~lock.OpenDocument Präsentation (neu).odp#
2014-03-26 18:45 - 2014-03-30 17:35 - 00000407 _____ () C:\WINDOWS\system32\checkdnsid.xml
==================== One Month Modified Files and Folders =======
2014-04-23 17:52 - 2014-04-23 17:47 - 00013067 _____ () C:\Users\Jaqueline\Desktop\FRST.txt
2014-04-23 17:52 - 2014-04-23 16:20 - 00000000 ____D () C:\FRST
2014-04-23 17:48 - 2013-12-23 23:31 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3545342124-3751203487-2797069715-1001
2014-04-23 17:47 - 2014-04-23 17:47 - 00991504 _____ () C:\Users\Jaqueline\Downloads\setup (2).exe
2014-04-23 17:46 - 2014-01-09 14:06 - 00595968 ___SH () C:\Users\Jaqueline\Downloads\Thumbs.db
2014-04-23 17:45 - 2014-04-23 17:45 - 00001058 _____ () C:\Users\Jaqueline\Desktop\JRT.txt
2014-04-23 17:41 - 2014-04-23 17:41 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-23 17:41 - 2014-04-23 17:40 - 01016261 _____ (Thisisu) C:\Users\Jaqueline\Downloads\JRT.exe
2014-04-23 17:40 - 2014-04-23 17:40 - 00991504 _____ () C:\Users\Jaqueline\Downloads\setup (1).exe
2014-04-23 17:40 - 2014-04-23 17:40 - 00002526 _____ () C:\Users\Jaqueline\Desktop\AdwCleaner[S0].txt
2014-04-23 17:40 - 2014-04-23 17:33 - 00000000 ____D () C:\AdwCleaner
2014-04-23 17:39 - 2013-12-24 00:00 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-23 17:38 - 2014-01-21 20:12 - 00000000 __RDO () C:\Users\Jaqueline\SkyDrive
2014-04-23 17:38 - 2013-12-29 19:22 - 00312832 ___SH () C:\Users\Jaqueline\Desktop\Thumbs.db
2014-04-23 17:38 - 2013-12-24 00:17 - 00000000 ____D () C:\Users\Jaqueline\AppData\Roaming\Wise Care 365
2014-04-23 17:38 - 2013-12-23 23:59 - 00001124 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-23 17:37 - 2014-04-23 16:44 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 17:37 - 2014-03-26 19:11 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf491663174c7d.job
2014-04-23 17:37 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-23 17:36 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-04-23 17:33 - 2013-11-14 09:26 - 01778494 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-23 17:33 - 2013-11-14 09:11 - 00766026 _____ () C:\WINDOWS\system32\perfh007.dat
2014-04-23 17:33 - 2013-11-14 09:11 - 00159552 _____ () C:\WINDOWS\system32\perfc007.dat
2014-04-23 17:32 - 2014-04-23 17:32 - 01345299 _____ () C:\Users\Jaqueline\Desktop\adwcleaner.exe
2014-04-23 17:32 - 2014-04-23 17:32 - 00010434 _____ () C:\Users\Jaqueline\Desktop\mbam.txt
2014-04-23 17:30 - 2014-04-23 17:30 - 00991504 _____ () C:\Users\Jaqueline\Downloads\setup.exe
2014-04-23 17:27 - 2013-11-14 00:18 - 00358012 _____ () C:\WINDOWS\PFRO.log
2014-04-23 17:27 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-04-23 17:26 - 2014-01-21 20:04 - 01921974 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-23 17:16 - 2014-03-26 19:11 - 00001130 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf491666463019.job
2014-04-23 17:15 - 2013-12-23 23:59 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-23 17:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-04-23 16:57 - 2013-12-24 00:18 - 00000000 ____D () C:\Users\Jaqueline\AppData\Roaming\Spotify
2014-04-23 16:43 - 2014-04-23 16:43 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-23 16:43 - 2014-04-23 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-23 16:43 - 2014-04-23 16:43 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 16:42 - 2014-04-23 16:42 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Jaqueline\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-23 16:30 - 2014-04-23 16:21 - 00027868 _____ () C:\Users\Jaqueline\Downloads\Addition.txt
2014-04-23 16:30 - 2014-04-23 16:20 - 00040586 _____ () C:\Users\Jaqueline\Downloads\FRST.txt
2014-04-23 16:19 - 2014-04-23 16:19 - 02061312 _____ (Farbar) C:\Users\Jaqueline\Downloads\FRST64 (1).exe
2014-04-23 16:18 - 2014-04-23 16:18 - 02061312 _____ (Farbar) C:\Users\Jaqueline\Desktop\FRST64.exe
2014-04-23 15:34 - 2014-02-05 16:00 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8B9ABAB9-9036-4E14-9127-D4EDE22FB5F6}
2014-04-23 15:25 - 2013-12-24 00:19 - 00000000 ____D () C:\Users\Jaqueline\AppData\Local\Spotify
2014-04-20 11:07 - 2013-12-23 23:56 - 00000000 ____D () C:\Users\Jaqueline\AppData\Local\Adobe
2014-04-17 10:24 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-04-17 10:20 - 2014-04-17 10:20 - 00281027 _____ () C:\ProgramData\1397722679.bdinstall.bin
2014-04-17 10:20 - 2014-04-17 10:20 - 00049288 _____ () C:\ProgramData\1397722782.bdinstall.bin
2014-04-17 10:20 - 2014-03-22 12:21 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-04-17 10:19 - 2014-03-22 12:21 - 00000000 ____D () C:\Program Files\Bitdefender
2014-04-17 10:19 - 2014-03-22 12:20 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-04-16 23:14 - 2013-12-24 15:50 - 00000000 ____D () C:\ProgramData\Origin
2014-04-16 22:48 - 2014-01-24 14:33 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-16 22:42 - 2014-04-16 22:42 - 00000000 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-16 22:42 - 2014-01-24 14:33 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-16 22:37 - 2014-04-16 22:37 - 00000000 ____D () C:\Users\Jaqueline\Documents\Electronic Arts
2014-04-16 22:34 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-04-16 22:33 - 2014-04-16 22:33 - 00002088 _____ () C:\Users\Public\Desktop\Die*Sims™*3.lnk
2014-04-16 22:32 - 2014-01-08 00:08 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-16 14:44 - 2014-02-05 15:37 - 00447752 _____ (On2.com) C:\WINDOWS\SysWOW64\vp6vfw.dll
2014-04-16 14:31 - 2014-01-06 17:40 - 00001106 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-04-16 14:25 - 2013-12-24 15:53 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-04-16 13:56 - 2013-12-24 15:49 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-04-16 13:40 - 2013-12-25 00:37 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-16 13:39 - 2013-12-25 00:37 - 90655440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-15 21:41 - 2014-04-15 21:41 - 00000000 ____D () C:\Program Files\Common Files\Atheros
2014-04-15 21:41 - 2013-08-22 16:46 - 00309517 _____ () C:\WINDOWS\setupact.log
2014-04-15 21:41 - 2013-08-22 16:46 - 00000262 _____ () C:\WINDOWS\setuperr.log
2014-04-13 16:21 - 2014-04-13 16:21 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-04-13 16:20 - 2014-04-13 16:20 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-04-03 09:51 - 2014-04-23 16:43 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-23 16:43 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-23 16:43 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-02 11:46 - 2014-04-02 11:46 - 00001868 _____ () C:\Users\Jaqueline\Desktop\TS3W.exe - Verknüpfung.lnk
2014-04-02 11:44 - 2014-04-02 11:44 - 00001853 _____ () C:\Users\Jaqueline\Desktop\TS3.exe - Verknüpfung.lnk
2014-04-02 09:30 - 2014-02-17 17:57 - 00000000 ____D () C:\Users\Jaqueline\Desktop\matrei referat
2014-04-01 20:58 - 2014-03-22 10:35 - 00000000 ____D () C:\Users\Jaqueline\AppData\Roaming\SoftGrid Client
2014-03-31 23:23 - 2014-03-05 17:39 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-03-31 23:23 - 2014-03-05 17:39 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-31 03:16 - 2014-04-13 16:25 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-03-31 01:57 - 2014-04-13 16:24 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-03-30 17:35 - 2014-03-26 18:45 - 00000407 _____ () C:\WINDOWS\system32\checkdnsid.xml
2014-03-28 07:34 - 2014-03-28 07:34 - 00000000 __RHD () C:\MSOCache
2014-03-28 07:29 - 2014-03-22 10:35 - 00000000 ____D () C:\Users\Jaqueline\AppData\Local\SoftGrid Client
2014-03-28 07:29 - 2014-01-20 20:23 - 00041472 ___SH () C:\Users\Jaqueline\Documents\Thumbs.db
2014-03-27 18:09 - 2013-12-23 20:42 - 00000000 ____D () C:\Users\Jaqueline\Documents\Bea Stick daten
2014-03-27 18:08 - 2014-03-31 18:02 - 01844884 _____ () C:\Users\Jaqueline\Documents\Open%20englisch).odp_1odp
2014-03-27 17:15 - 2014-03-31 18:02 - 00064644 _____ () C:\Users\Jaqueline\Documents\Englisch%20Präsentation.docx_0odt
2014-03-27 17:15 - 2014-03-31 18:02 - 00052085 _____ () C:\Users\Jaqueline\Documents\Handout.docx_0odt
2014-03-27 12:16 - 2014-03-27 12:16 - 00000385 _____ () C:\Users\Jaqueline\AppData\Roaminguser_gensett.xml
2014-03-27 12:15 - 2014-03-27 12:15 - 00000385 _____ () C:\WINDOWS\system32\user_gensett.xml
2014-03-27 12:13 - 2014-01-23 20:02 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-03-27 12:13 - 2013-12-23 23:59 - 00000000 ____D () C:\Program Files\Google
2014-03-27 12:13 - 2013-12-23 23:59 - 00000000 ____D () C:\Program Files (x86)\Google
2014-03-27 12:13 - 2013-08-22 16:44 - 05184768 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-26 19:11 - 2014-03-26 19:11 - 00004102 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1cf491666463019
2014-03-26 19:11 - 2014-03-26 19:11 - 00003866 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1cf491663174c7d
2014-03-26 19:00 - 2014-03-26 19:00 - 00000097 ____H () C:\Users\Jaqueline\Desktop\.~lock.OpenDocument Präsentation (neu).odp#
2014-03-26 11:51 - 2014-01-08 00:08 - 00227188 _____ () C:\WINDOWS\DPINST.LOG
2014-03-26 11:50 - 2014-01-08 00:08 - 00002042 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
Some content of TEMP:
====================
C:\Users\Jaqueline\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Jaqueline\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Jaqueline\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-16 14:47
==================== End Of Log ============================ --- --- ---
Dieses mal zeigt er mir keine Addition.txt, woran liegt das?:killpc: |