mbam.txt
Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Suchlauf Datum: 04.05.2014
Suchlauf-Zeit: 16:43:51
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.04.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Anna
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 270194
Verstrichene Zeit: 22 Min, 7 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 12
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\ICReinstall_nslD6B1.tmp, In Quarantäne, [d52bf50b68983dc3e1bdc2ac1fe233cd],
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\ICReinstall_nsqD9DC.tmp, In Quarantäne, [f40c000088789f61eeb0e5893dc40000],
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\ICReinstall_nswD56A.tmp, In Quarantäne, [3ac62ad6bf41be42811d5915877aa65a],
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\ICReinstall_nswDC6C.tmp, In Quarantäne, [39c7827e4fb1fb051f7fd29cdb26a957],
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\nslD6B1.tmp, In Quarantäne, [c838946c68981ce49fff234b956c7a86],
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\nsqD9DC.tmp, In Quarantäne, [8c74c937b9472bd58816d29c8180669a],
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\nswD56A.tmp, In Quarantäne, [c73941bfe61a2fd1ecb2f07e53ae758b],
PUP.Optional.InstallCore.A, C:\Users\Anna\AppData\Local\Temp\nswDC6C.tmp, In Quarantäne, [a65aec14e61a5fa16836a3cb44bd936d],
PUP.FunMoods, C:\Users\Anna\Desktop\Oni\Sonstiges\agsetup183se.exe, In Quarantäne, [5ea2aa5610f07b85669ab25ea25f5fa1],
PUP.Optional.Softonic.A, C:\Users\Anna\Desktop\Oni\Sonstiges\SoftonicDownloader_fuer_audacity.exe, In Quarantäne, [ac54de2267990ef2d380bd60728f8d73],
PUP.Optional.Softonic.A, C:\Users\Anna\Desktop\Oni\Sonstiges\SoftonicDownloader_fuer_free-rar-extract-frog.exe, In Quarantäne, [6c949f61fa063dc378db081503fee020],
PUP.Optional.SoftonicTB.A, C:\Users\Anna\Desktop\Oni\Sonstiges\Softonic_ggl_1.5.21.0.exe, In Quarantäne, [659b33cdaf51867abdc85024ac557090],
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.206 - Bericht erstellt am 04/05/2014 um 16:56:46
# Aktualisiert 04/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Anna - ANNA-PC
# Gestartet von : C:\Users\Anna\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Anna\.android
Ordner Gelöscht : C:\Users\Anna\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Anna\AppData\Roaming\Systweak
Ordner Gelöscht : D:\EigeneDateien\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\ICQToolbarData
Datei Gelöscht : C:\Users\Anna\daemonprocess.txt
Datei Gelöscht : C:\Users\Anna\Desktop\Continue VuuPC Installation.lnk
Datei Gelöscht : C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\searchplugins\bingp.xml
Datei Gelöscht : C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\Advanced System Protector_startup
Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FreeRIP3_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FreeRIP3_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchProtectINT_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchProtectINT_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_audacity_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_audacity_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-rar-extract-frog_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-rar-extract-frog_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_picasa_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_picasa_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\MGShareware
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\Software\MGShareware
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Mozilla Firefox v17.0 (de)
[ Datei : C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\prefs.js ]
Zeile gelöscht : user_pref("icqtoolbar.allowSendURL", false);
Zeile gelöscht : user_pref("icqtoolbar.defSearchChange", true);
Zeile gelöscht : user_pref("icqtoolbar.engineVerified", true);
Zeile gelöscht : user_pref("icqtoolbar.geolastmodified", 1347972452);
Zeile gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options");
Zeile gelöscht : user_pref("icqtoolbar.history", "prophezeihen||%D0%BA%D0%B0%D1%80%D1%82%D0%B0%20%D1%83%D0%BA%D1%80%D0%B0%D0%B8%D0%BD%D1%8B||indoorpark||cache%3AlqWFmHI6QwEJ%3Awww.potrebitel.net.ua%2Fnode%2F1255%20%D0[...]
Zeile gelöscht : user_pref("icqtoolbar.hpChange", true);
Zeile gelöscht : user_pref("icqtoolbar.icqgeo", 49);
Zeile gelöscht : user_pref("icqtoolbar.installTime", "1313778350");
Zeile gelöscht : user_pref("icqtoolbar.newtab_state", "1");
Zeile gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
Zeile gelöscht : user_pref("icqtoolbar.previousFFVersion", "6.0.1");
Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
Zeile gelöscht : user_pref("icqtoolbar.suggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "130510310813051031081305109060535");
Zeile gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1348427033);
Zeile gelöscht : user_pref("icqtoolbar.userEngineApproved", true);
Zeile gelöscht : user_pref("icqtoolbar.userHpApproved", true);
Zeile gelöscht : user_pref("icqtoolbar.version", "1.3.1");
Zeile gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherWasShown", 0);
Zeile gelöscht : user_pref("icqtoolbar.xmlEnableHomePageDsGuard", false);
Zeile gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");
*************************
AdwCleaner[R0].txt - [7272 octets] - [04/05/2014 16:51:15]
AdwCleaner[R1].txt - [7332 octets] - [04/05/2014 16:54:28]
AdwCleaner[S0].txt - [7083 octets] - [04/05/2014 16:56:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7143 octets] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Anna on 04.05.2014 at 17:01:39,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\apnstub_RASDLG
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{16E9CF08-52AE-422B-90B4-FA4C7303C0C5}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4EFD4B31-56CE-4028-9FC4-48069D294C08}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A897A806-DB8B-47C5-BB31-E674E7484DE6}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Anna\AppData\Roaming\mozilla\firefox\profiles\bu3hi8sj.default\minidumps [558 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.05.2014 at 17:06:09,75
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-05-2014
Ran by Anna (administrator) on ANNA-PC on 04-05-2014 17:07:51
Running from C:\Users\Anna\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
() C:\OEM\USBDECTION\USBS3S4Detection.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
() C:\Program Files (x86)\Common Files\logishrd\LQCVFX\COCIManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Hotkey Utility] => C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe [611872 2010-08-04] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-13] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [190808 2011-03-01] (Logitech Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2691480 2014-03-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-3536708093-2688288980-3666440286-1000\...\Run: [Global Registration] => "C:\Program Files (x86)\Packard Bell\Registration\GREG.exe" /boot
HKU\S-1-5-21-3536708093-2688288980-3666440286-1000\...\Run: [Logitech Vid] => C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [6129496 2011-01-13] (Logitech Inc.)
HKU\S-1-5-21-3536708093-2688288980-3666440286-1000\...\MountPoints2: {c24d3bbe-cb5b-11e2-9a08-d027881769da} - J:\Startme.exe
HKU\S-1-5-21-3536708093-2688288980-3666440286-1000\...\MountPoints2: {dee0fcbf-b42f-11e3-a7e8-d027881769da} - J:\Startme.exe
AppInit_DLLs-x32: C:\PROGRA~2\Citrix\ICACLI~1\RSHook.dll => C:\Program Files (x86)\Citrix\ICA Client\RSHook.dll [257208 2012-07-27] (Citrix Systems, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0A1ED960-4D49-45C7-9477-2D710592B658} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=386496&p={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689 URL = hxxp://search.chatzum.com/?q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll No File
Tcpip\..\Interfaces\{8F1F1139-F24B-4778-821F-71319443B5F6}: [NameServer]62.220.18.8 89.246.64.8
FireFox:
========
FF ProfilePath: C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default
FF DefaultSearchEngine: Bing
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Citrix.com/npican - C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.10.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=1.1.9 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Anna\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\searchplugins\icq-search.xml
FF SearchPlugin: C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\searchplugins\search-results.xml
FF SearchPlugin: C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Feedback - C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\Extensions\testpilot@labs.mozilla.com.xpi [2012-10-29]
FF Extension: Adblock Plus - C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\bu3hi8sj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-20]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-07] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-07] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-16] (Avira Operations GmbH & Co. KG)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R1 {59981518-8b2b-431e-90db-17dacc8cfa86}w64; C:\Windows\System32\drivers\{59981518-8b2b-431e-90db-17dacc8cfa86}w64.sys [61112 2014-04-24] (StdLib)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-04 17:06 - 2014-05-04 17:06 - 00001438 _____ () C:\Users\Anna\Desktop\JRT.txt
2014-05-04 17:01 - 2014-05-04 17:01 - 01016261 _____ (Thisisu) C:\Users\Anna\Desktop\JRT.exe
2014-05-04 17:01 - 2014-05-04 17:01 - 00000000 ____D () C:\Windows\ERUNT
2014-05-04 16:51 - 2014-05-04 16:56 - 00000000 ____D () C:\AdwCleaner
2014-05-04 16:50 - 2014-05-04 16:50 - 01313617 _____ () C:\Users\Anna\Desktop\adwcleaner.exe
2014-05-04 16:48 - 2014-05-04 16:48 - 00002760 _____ () C:\Users\Anna\Desktop\mbam.txt
2014-05-04 16:19 - 2014-05-04 16:19 - 00001078 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-04 16:19 - 2014-05-04 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-04 16:19 - 2014-05-04 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-04 16:19 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-04 16:19 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-04 16:19 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-04 16:18 - 2014-05-04 16:19 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Anna\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-04 16:10 - 2014-05-04 16:10 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Anna\Desktop\revosetup95.exe
2014-05-04 16:10 - 2014-05-04 16:10 - 00001240 _____ () C:\Users\Anna\Desktop\Revo Uninstaller.lnk
2014-05-04 16:10 - 2014-05-04 16:10 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-03 17:13 - 2014-05-03 17:15 - 00043868 _____ () C:\Users\Anna\Desktop\Addition.txt
2014-05-03 17:12 - 2014-05-04 17:07 - 00015858 _____ () C:\Users\Anna\Desktop\FRST.txt
2014-05-03 17:12 - 2014-05-04 17:07 - 00000000 ____D () C:\FRST
2014-05-03 17:12 - 2014-05-03 17:12 - 02062336 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2014-05-02 12:11 - 2014-05-02 19:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-05-01 21:22 - 2014-05-04 16:59 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-01 01:08 - 2014-05-01 01:08 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-30 08:24 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-30 08:24 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-26 17:40 - 2014-04-26 17:40 - 00003152 _____ () C:\Windows\System32\Tasks\{48537833-5B03-4D3A-A1B7-A9B1072DC491}
2014-04-26 17:37 - 2014-04-26 17:37 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-25 17:11 - 2014-04-25 17:11 - 00001200 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Dreamweaver CC.lnk
2014-04-25 16:59 - 2014-04-25 16:59 - 00001285 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-04-25 16:58 - 2014-04-25 16:59 - 00000000 ____D () C:\ProgramData\Package Cache
2014-04-25 16:45 - 2014-04-24 12:23 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{59981518-8b2b-431e-90db-17dacc8cfa86}w64.sys
2014-04-09 14:43 - 2014-04-09 14:43 - 00001021 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-04-09 14:43 - 2014-04-09 14:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-04-09 14:42 - 2014-04-09 14:42 - 00000000 ____D () C:\Program Files (x86)\WinZip
2014-04-09 10:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 10:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 10:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 10:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 10:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 10:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 10:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 10:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 10:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 10:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 10:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 10:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 10:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 10:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 10:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 10:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 10:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-06 12:00 - 2014-04-06 12:00 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-04-06 10:34 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-04-06 10:34 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-04-06 10:30 - 2014-04-06 10:30 - 00000000 ____D () C:\Users\Anna\AppData\Local\Spoon
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files\MSBuild
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-04-06 10:28 - 2012-07-25 12:03 - 00016896 _____ () C:\Windows\system32\sasnative64.exe
2014-04-06 10:27 - 2014-04-26 17:51 - 00000000 ____D () C:\Program Files (x86)\Jotzey
2014-04-06 10:27 - 2014-04-17 11:11 - 00000000 ____D () C:\Users\Anna\AppData\Local\cache
2014-04-06 10:27 - 2014-04-06 10:27 - 00000000 ____D () C:\Users\Anna\AppData\Roaming\Free Picture Solutions
2014-04-06 10:26 - 2014-04-06 10:28 - 00131072 _____ () C:\Windows\ocsetup_install_NetFx3.etl
2014-04-06 10:26 - 2014-04-06 10:28 - 00057157 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.txt
2014-04-06 10:24 - 2014-04-06 10:24 - 00930952 _____ (CNET Download.com) C:\Users\Anna\cbsidlm-cbsi183-Free_XPS_Viewer-ORG-75999367.exe
==================== One Month Modified Files and Folders =======
2014-05-04 17:08 - 2014-05-03 17:12 - 00015858 _____ () C:\Users\Anna\Desktop\FRST.txt
2014-05-04 17:07 - 2014-05-03 17:12 - 00000000 ____D () C:\FRST
2014-05-04 17:06 - 2014-05-04 17:06 - 00001438 _____ () C:\Users\Anna\Desktop\JRT.txt
2014-05-04 17:05 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-04 17:05 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-04 17:02 - 2010-10-11 04:00 - 00699670 _____ () C:\Windows\system32\perfh007.dat
2014-05-04 17:02 - 2010-10-11 04:00 - 00149810 _____ () C:\Windows\system32\perfc007.dat
2014-05-04 17:02 - 2009-07-14 07:13 - 01621684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-04 17:01 - 2014-05-04 17:01 - 01016261 _____ (Thisisu) C:\Users\Anna\Desktop\JRT.exe
2014-05-04 17:01 - 2014-05-04 17:01 - 00000000 ____D () C:\Windows\ERUNT
2014-05-04 16:59 - 2014-05-01 21:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-04 16:58 - 2011-05-11 10:17 - 00000000 ____D () C:\Users\Anna\AppData\Local\Adobe
2014-05-04 16:57 - 2013-01-20 12:00 - 00116363 _____ () C:\Windows\setupact.log
2014-05-04 16:57 - 2013-01-20 11:59 - 00295748 _____ () C:\Windows\PFRO.log
2014-05-04 16:57 - 2010-10-15 16:52 - 01317897 _____ () C:\Windows\WindowsUpdate.log
2014-05-04 16:57 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-04 16:56 - 2014-05-04 16:51 - 00000000 ____D () C:\AdwCleaner
2014-05-04 16:56 - 2011-05-11 10:03 - 00000000 ____D () C:\Users\Anna
2014-05-04 16:50 - 2014-05-04 16:50 - 01313617 _____ () C:\Users\Anna\Desktop\adwcleaner.exe
2014-05-04 16:48 - 2014-05-04 16:48 - 00002760 _____ () C:\Users\Anna\Desktop\mbam.txt
2014-05-04 16:19 - 2014-05-04 16:19 - 00001078 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-04 16:19 - 2014-05-04 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-04 16:19 - 2014-05-04 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-04 16:19 - 2014-05-04 16:18 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Anna\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-04 16:10 - 2014-05-04 16:10 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Anna\Desktop\revosetup95.exe
2014-05-04 16:10 - 2014-05-04 16:10 - 00001240 _____ () C:\Users\Anna\Desktop\Revo Uninstaller.lnk
2014-05-04 16:10 - 2014-05-04 16:10 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-04 16:09 - 2012-11-04 20:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-04 15:09 - 2014-02-20 12:12 - 00000000 ____D () C:\Users\Anna\Desktop\MASTERARBEIT
2014-05-03 17:15 - 2014-05-03 17:13 - 00043868 _____ () C:\Users\Anna\Desktop\Addition.txt
2014-05-03 17:12 - 2014-05-03 17:12 - 02062336 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2014-05-03 17:09 - 2012-10-27 14:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-03 01:42 - 2011-05-11 12:05 - 00000000 ____D () C:\Users\Anna\AppData\Roaming\Skype
2014-05-02 19:00 - 2014-05-02 12:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-05-01 21:21 - 2012-12-25 18:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-01 01:08 - 2014-05-01 01:08 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-29 19:59 - 2011-07-02 10:06 - 00000000 ____D () C:\Users\Anna\AppData\Local\FreePDF_XP
2014-04-29 13:14 - 2012-11-04 20:18 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-29 13:13 - 2012-11-04 20:18 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-29 13:13 - 2011-12-05 21:12 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-26 17:53 - 2011-05-11 10:03 - 00087448 _____ () C:\Users\Anna\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-26 17:52 - 2009-07-14 06:45 - 00350672 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-26 17:51 - 2014-04-06 10:27 - 00000000 ____D () C:\Program Files (x86)\Jotzey
2014-04-26 17:43 - 2012-10-07 21:41 - 00000000 ____D () C:\Users\Anna\AppData\Local\Google
2014-04-26 17:43 - 2012-10-07 21:41 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-26 17:42 - 2013-01-04 19:04 - 00000000 ____D () C:\ProgramData\B+P Heyer
2014-04-26 17:41 - 2011-05-11 10:04 - 00000000 ___RD () C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-26 17:40 - 2014-04-26 17:40 - 00003152 _____ () C:\Windows\System32\Tasks\{48537833-5B03-4D3A-A1B7-A9B1072DC491}
2014-04-26 17:37 - 2014-04-26 17:37 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-26 17:37 - 2013-01-19 20:21 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-26 17:37 - 2011-05-11 10:17 - 00000000 ____D () C:\Users\Anna\AppData\Roaming\Adobe
2014-04-26 17:30 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2014-04-25 17:16 - 2010-08-25 13:58 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-04-25 17:12 - 2010-08-25 13:58 - 00000000 ____D () C:\ProgramData\Adobe
2014-04-25 17:11 - 2014-04-25 17:11 - 00001200 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Dreamweaver CC.lnk
2014-04-25 16:59 - 2014-04-25 16:59 - 00001285 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-04-25 16:59 - 2014-04-25 16:58 - 00000000 ____D () C:\ProgramData\Package Cache
2014-04-25 16:45 - 2014-04-01 16:38 - 00000000 ____D () C:\ik
2014-04-24 15:36 - 2011-05-11 12:12 - 00000000 ____D () C:\Users\Anna\Desktop\Fotos
2014-04-24 15:35 - 2014-02-25 19:37 - 00000000 ____D () C:\Users\Anna\Desktop\BESTELLUNG
2014-04-24 12:23 - 2014-04-25 16:45 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{59981518-8b2b-431e-90db-17dacc8cfa86}w64.sys
2014-04-22 01:05 - 2014-03-06 22:09 - 00000000 ____D () C:\Users\Anna\Desktop\Барахло 2
2014-04-17 11:11 - 2014-04-06 10:27 - 00000000 ____D () C:\Users\Anna\AppData\Local\cache
2014-04-14 04:24 - 2014-04-30 08:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-30 08:24 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-09 22:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-09 15:24 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-09 14:43 - 2014-04-09 14:43 - 00001021 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-04-09 14:43 - 2014-04-09 14:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-04-09 14:42 - 2014-04-09 14:42 - 00000000 ____D () C:\Program Files (x86)\WinZip
2014-04-09 10:28 - 2013-07-14 22:48 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 10:28 - 2011-05-11 10:29 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 10:27 - 2013-01-02 15:27 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-07 20:47 - 2012-10-29 20:06 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-04-06 12:00 - 2014-04-06 12:00 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-04-06 11:47 - 2011-05-11 12:15 - 00000000 ____D () C:\Users\Anna\Desktop\Oni
2014-04-06 10:30 - 2014-04-06 10:30 - 00000000 ____D () C:\Users\Anna\AppData\Local\Spoon
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files\MSBuild
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-04-06 10:28 - 2014-04-06 10:28 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-04-06 10:28 - 2014-04-06 10:26 - 00131072 _____ () C:\Windows\ocsetup_install_NetFx3.etl
2014-04-06 10:28 - 2014-04-06 10:26 - 00057157 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.txt
2014-04-06 10:27 - 2014-04-06 10:27 - 00000000 ____D () C:\Users\Anna\AppData\Roaming\Free Picture Solutions
2014-04-06 10:24 - 2014-04-06 10:24 - 00930952 _____ (CNET Download.com) C:\Users\Anna\cbsidlm-cbsi183-Free_XPS_Viewer-ORG-75999367.exe
2014-04-04 09:35 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Files to move or delete:
====================
C:\Users\Anna\ALDI NORD Bestellsoftware Setup.exe
C:\Users\Anna\AmazonMP3DownloaderInstall.exe
C:\Users\Anna\cbsidlm-cbsi183-Free_XPS_Viewer-ORG-75999367.exe
C:\Users\Anna\CitrixReceiverWeb.exe
Some content of TEMP:
====================
C:\Users\Anna\AppData\Local\Temp\avgnt.exe
C:\Users\Anna\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-29 19:37
==================== End Of Log ============================
--- --- ---
--- --- ---