Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 06.05.2014 19:20:24, SYSTEM, JUSTUS-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 06.05.2014 19:20:26, SYSTEM, JUSTUS-PC, Manual, Malware Database, 2014.3.4.9, 2014.5.6.8,
(end) Code:
# AdwCleaner v3.207 - Bericht erstellt am 06/05/2014 um 20:58:03
# Aktualisiert 05/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Justus - JUSTUS-PC
# Gestartet von : C:\Users\Justus\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : BackupStack
Dienst Gelöscht : RrFilterService64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\Windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}
Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin
Ordner Gelöscht : C:\Program Files\002
Ordner Gelöscht : C:\Program Files\RrFilter
Ordner Gelöscht : C:\Program Files\RrSavings
Ordner Gelöscht : C:\Users\Justus\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\Justus\AppData\Local\LPT
Ordner Gelöscht : C:\Users\Justus\AppData\Local\Smartbar
Ordner Gelöscht : C:\Users\Justus\AppData\Local\Temp\BabylonToolbar
Ordner Gelöscht : C:\Users\Justus\AppData\Local\Temp\Smartbar
Ordner Gelöscht : C:\Users\Justus\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\Justus\AppData\LocalLow\Smartbar
Ordner Gelöscht : C:\Users\Justus\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Justus\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Ordner Gelöscht : C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kofjjfgnmnjmoihhmjpafcllkhinmboe
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Justus\AppData\Local\Temp\Searchqu.ini
Datei Gelöscht : C:\Users\Justus\AppData\Local\Temp\searchqutoolbar-manifest.xml
Datei Gelöscht : C:\Users\Justus\AppData\Local\Temp\SetupDataMngr_Searchqu.exe
Datei Gelöscht : C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Justus\AppData\Roaming\Mozilla\Firefox\Profiles\y9t5g8z3.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Windows\System32\Tasks\Advanced System Protector
Datei Gelöscht : C:\Windows\System32\Tasks\Advanced System Protector_startup
Datei Gelöscht : C:\Windows\System32\Tasks\RegClean Pro
Datei Gelöscht : C:\Windows\Tasks\RegClean Pro_DEFAULT.job
Datei Gelöscht : C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
Datei Gelöscht : C:\Windows\Tasks\RegClean Pro_UPDATES.job
Datei Gelöscht : C:\Windows\System32\Tasks\RegClean Pro_UPDATES
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_gamespy-arcade_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_gamespy-arcade_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10AD2C61-0898-4348-8600-14A342F22AC3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10AD2C61-0898-4348-8600-14A342F22AC3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\RrSavings
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\smartbarbackup
Schlüssel Gelöscht : HKCU\Software\smartbarlog
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Rr Savings
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\RrSavings
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3566FB70-E722-4182-8266-815EAE862998}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DataMngr
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Rr Savings
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\RrSavings
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{813BA625-B0FA-48D8-9B75-59759C88C219}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RrSavings
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\07BF6653227E2814286618E5EA689289
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\07BF6653227E2814286618E5EA689289
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Justus\AppData\Roaming\Mozilla\Firefox\Profiles\y9t5g8z3.default\prefs.js ]
Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwugvkecS8vMTddoFZ1JOSS-uAGUcMxkW0jIL_KJC7xZuVYxQVPGHQMG43X_7_DiA82iBr8Ozu9CsspYWCLcB511qc5B1ZU_z[...]
Zeile gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Zeile gelöscht : user_pref("browser.search.order.1", "Search Results");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?AF=17350&babsrc=NT_ss&mntrId=305e35620000000000000008549fe9f1");
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", false);
Zeile gelöscht : user_pref("extensions.helperbar.backPageCapacity", 3);
Zeile gelöscht : user_pref("extensions.helperbar.backPageCounter", 0);
Zeile gelöscht : user_pref("extensions.helperbar.backPageDay", 4);
Zeile gelöscht : user_pref("extensions.helperbar.backPageLastEvent", "1399064239242");
Zeile gelöscht : user_pref("extensions.helperbar.backPageMinInterval", 15);
Zeile gelöscht : user_pref("extensions.helperbar.barcodeid", "127714");
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "ry_1955_ch");
Zeile gelöscht : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\",\\\"www.only-apartments.es\\\",\\\"www.only-apartments.de\\\",\\\"www.only-apar[...]
Zeile gelöscht : user_pref("extensions.helperbar.fromautoupdate", "false");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "9e66b98d-b353-e16a-84c9-87bff1d9c2ca");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "04/05/2014");
Zeile gelöscht : user_pref("extensions.helperbar.keepAliveLastevent", "1399237039");
Zeile gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1399237041384");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "shoppinghelper");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwugvkecS8vMTddoFZ1JOSS-uAGUcMxkW0jIL_KJC7xZuVYxQVPGHQMG43X_7_DiA82iBr8Ozu9CsspYWCLcB511qc5B3zopX_KSIEKl[...]
-\\ Google Chrome v Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Justus on 06.05.2014 at 21:12:16,46
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Emptied folder: C:\Users\Justus\AppData\Roaming\mozilla\firefox\profiles\y9t5g8z3.default\minidumps [28 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.05.2014 at 21:19:10,05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2014
Ran by Justus (administrator) on JUSTUS-PC on 06-05-2014 21:51:08
Running from C:\Users\Justus\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Spotify Ltd) C:\Users\Justus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Akamai Technologies, Inc.) C:\Users\Justus\AppData\Local\Akamai\netsession_win.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Akamai Technologies, Inc.) C:\Users\Justus\AppData\Local\Akamai\netsession_win.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
() C:\Program Files\ShrewSoft\VPN Client\iked.exe
() C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Thisisu) C:\Users\Justus\Desktop\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6297088 2008-05-28] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-04-15] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\Run: [Google Update] => C:\Users\Justus\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-03-24] (Google Inc.)
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\Run: [Spotify] => C:\Users\Justus\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-08] (Spotify Ltd)
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\Run: [Spotify Web Helper] => C:\Users\Justus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-08] (Spotify Ltd)
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Justus\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\Run: [GoogleChromeAutoLaunch_4B58CE89BFB61E88DC2FAC95911F6EFA] => C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe [841032 2014-04-02] (Google Inc.)
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\MountPoints2: {233aaba2-b816-11e2-9849-0008549fe9f1} - E:\Windows\CHECK\DriveNavigator.exe
HKU\S-1-5-21-2227984459-1923807984-2254057487-1000\...\MountPoints2: {7f9a167f-0fc1-11e3-9ef2-003067abfac7} - E:\autorun.exe
Startup: C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEC025D046775CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
BHO-x32: ConstaSurf - {96cf2cbe-b6d5-454a-a62a-84bcda86ef1d} - C:\Program Files (x86)\ConstaSurf\ConstaSurfbho.dll ()
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{C8DC7B6B-C500-463E-ADEE-1A9B04422CE7}: [NameServer]132.252.3.10,132.252.1.7
FireFox:
========
FF ProfilePath: C:\Users\Justus\AppData\Roaming\Mozilla\Firefox\Profiles\y9t5g8z3.default
FF Homepage: https://www.google.de/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nexon.net/NxGame - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @coreonline.com/run3d,version=1.0 - C:\Users\Justus\AppData\LocalLow\Square Enix\nprun3d.dll (Square Enix)
FF Plugin HKCU: @eximion.com/KalydoPlayer - C:\Users\Justus\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll (Eximion B.V.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Justus\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Justus\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Justus\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Zotero - C:\Users\Justus\AppData\Roaming\Mozilla\Firefox\Profiles\y9t5g8z3.default\Extensions\zotero@chnm.gmu.edu [2012-08-07]
FF Extension: NoScript - C:\Users\Justus\AppData\Roaming\Mozilla\Firefox\Profiles\y9t5g8z3.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-09-29]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-11]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2014-01-12]
Chrome:
=======
CHR HomePage: hxxp://www.google.de/
CHR StartupUrls: "hxxp://www.spiegel.de/"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Justus\AppData\Local\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Justus\AppData\Local\Google\Chrome\Application\34.0.1847.116\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Justus\AppData\Local\Google\Chrome\Application\34.0.1847.116\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll No File
CHR Extension: (YouTube) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-03-24]
CHR Extension: (Adblock Plus) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-01]
CHR Extension: (Google-Suche) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-03-24]
CHR Extension: (HTTPS Everywhere) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2012-03-24]
CHR Extension: (AdBlock) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-03-20]
CHR Extension: (Zotero Connector) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\jciblakmllnhbhjjgkbkeihelcndmgnh [2012-04-10]
CHR Extension: (Skype Click to Call) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2012-03-24]
CHR Extension: (Google Wallet) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Citavi Picker) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio [2014-01-12]
CHR Extension: (Google Mail) - C:\Users\Justus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-03-24]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
CHR HKLM-x32\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx [2014-01-12]
CHR StartMenuInternet: Google Chrome - C:\Users\Justus\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2014-04-18] (Perfect World Entertainment Inc)
R2 iked; C:\Program Files\ShrewSoft\VPN Client\iked.exe [1127736 2013-07-01] ()
R2 ipsecd; C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe [810808 2013-07-01] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-04-08] (LogMeIn, Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-08-28] ()
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH)
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe [X]
S2 yewimmxqbs64; C:\Program Files\002\yewimmxqbs64.exe run options=01100010020000000000000000000000 sourceguid=3A5B3E40-3C96-4F4E-A48D-C161A8B0E1A6 [X]
==================== Drivers (Whitelisted) ====================
R1 BIOS; C:\Windows\system32\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
R1 BIOS; C:\Windows\SysWOW64\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation)
S3 hxctlflt; C:\Windows\System32\Drivers\hxctlflt.sys [111104 2009-02-08] (Guillemot Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-06] (Malwarebytes Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [61736 2014-02-28] (NetFilterSDK.com)
R3 rtl819xpn64; C:\Windows\System32\DRIVERS\rtl819xp.sys [570880 2009-05-18] (Realtek Semiconductor Corporation )
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3552384 2009-04-22] ()
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Classic\safedrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-06 21:51 - 2014-05-06 21:51 - 00000000 ____D () C:\Users\Justus\Downloads\FRST-OlderVersion
2014-05-06 21:19 - 2014-05-06 21:19 - 00000866 _____ () C:\Users\Justus\Desktop\JRT.txt
2014-05-06 21:12 - 2014-05-06 21:12 - 00000000 ____D () C:\Windows\ERUNT
2014-05-06 21:11 - 2014-05-06 21:10 - 01016261 _____ (Thisisu) C:\Users\Justus\Desktop\JRT.exe
2014-05-06 21:10 - 2014-05-06 21:10 - 01016261 _____ (Thisisu) C:\Users\Justus\Downloads\JRT.exe
2014-05-06 21:06 - 2014-05-06 21:06 - 00015925 _____ () C:\Users\Justus\Desktop\AdwCleaner[S0].txt
2014-05-06 20:53 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-06 20:52 - 2014-05-06 21:02 - 00000000 ____D () C:\AdwCleaner
2014-05-06 20:50 - 2014-05-06 20:51 - 01316991 _____ () C:\Users\Justus\Desktop\adwcleaner.exe
2014-05-06 20:50 - 2014-05-06 20:50 - 00000262 _____ () C:\Users\Justus\Desktop\mbam.txt
2014-05-06 20:42 - 2014-05-06 20:48 - 00002279 _____ () C:\Users\Justus\Desktop\Neues Textdokument.txt
2014-05-06 19:20 - 2014-05-06 20:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-06 19:20 - 2014-05-06 19:20 - 00001112 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-06 19:20 - 2014-05-06 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-06 19:19 - 2014-05-06 19:20 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-06 19:19 - 2014-05-06 19:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-06 19:19 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-06 19:19 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-06 19:19 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-06 19:18 - 2014-05-06 19:18 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Justus\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-06 18:53 - 2014-05-06 18:53 - 00000050 _____ () C:\Users\Justus\AppData\Local\Citavi Picker Internet Explorer Protocol.txt
2014-05-06 18:43 - 2014-05-06 18:43 - 00001274 _____ () C:\Users\Justus\Desktop\Revo Uninstaller.lnk
2014-05-06 18:43 - 2014-05-06 18:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-06 18:42 - 2014-05-06 18:42 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Justus\Downloads\revosetup95.exe
2014-05-04 23:38 - 2014-05-05 10:38 - 00047919 _____ () C:\Users\Justus\Downloads\Addition.txt
2014-05-04 23:37 - 2014-05-06 21:51 - 00018571 _____ () C:\Users\Justus\Downloads\FRST.txt
2014-05-04 23:37 - 2014-05-06 21:51 - 00000000 ____D () C:\FRST
2014-05-04 23:36 - 2014-05-06 21:51 - 02063872 _____ (Farbar) C:\Users\Justus\Downloads\FRST64.exe
2014-05-04 23:00 - 2014-05-04 23:00 - 00000000 ____D () C:\Program Files (x86)\Rr Savings
2014-05-04 22:58 - 2014-05-04 22:58 - 00000000 ____D () C:\Program Files (x86)\ConstaSurf
2014-05-04 22:58 - 2012-07-25 12:03 - 00016896 _____ () C:\Windows\system32\sasnative64.exe
2014-05-04 22:57 - 2014-05-06 21:06 - 00001445 _____ () C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-05-03 15:22 - 2014-04-29 18:00 - 23133184 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-03 15:22 - 2014-04-29 17:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-03 15:22 - 2014-04-29 16:47 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-03 15:22 - 2014-04-29 16:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 23:42 - 2014-05-01 23:48 - 00000000 ____D () C:\Users\Justus\Desktop\UF-Text
2014-04-28 23:12 - 2014-04-28 23:12 - 00000000 ____D () C:\Users\Justus\AppData\Local\Blizzard
2014-04-28 23:06 - 2014-04-28 23:12 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-04-28 23:06 - 2014-04-28 23:06 - 00001167 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-04-28 23:06 - 2014-04-28 23:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2014-04-28 22:43 - 2014-05-02 11:31 - 00000000 ____D () C:\Users\Justus\AppData\Local\Battle.net
2014-04-28 22:43 - 2014-05-02 11:30 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-04-28 22:43 - 2014-04-28 23:06 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\Battle.net
2014-04-28 22:43 - 2014-04-28 22:43 - 00001130 _____ () C:\Users\Public\Desktop\Battle.net.lnk
2014-04-28 22:43 - 2014-04-28 22:43 - 00000000 ____D () C:\Users\Justus\AppData\Local\Blizzard Entertainment
2014-04-28 22:43 - 2014-04-28 22:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2014-04-28 22:43 - 2014-04-28 22:43 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-04-28 22:40 - 2014-04-28 22:40 - 07094224 _____ (Blizzard Entertainment) C:\Users\Justus\Downloads\Hearthstone-Setup-deDE.exe
2014-04-28 22:40 - 2014-04-28 22:40 - 00000000 ____D () C:\ProgramData\Battle.net
2014-04-23 15:06 - 2014-04-28 14:01 - 00000000 ____D () C:\Users\Justus\Desktop\Stiendium
2014-04-23 12:30 - 2014-04-23 12:30 - 00316160 _____ (Dropbox, Inc.) C:\Users\Justus\Downloads\DropboxInstaller (1).exe
2014-04-22 23:44 - 2014-04-22 23:44 - 00001499 _____ () C:\Users\Justus\.recently-used.xbel
2014-04-18 17:02 - 2014-04-18 17:04 - 00009843 _____ () C:\Users\Justus\Desktop\Sammlung.txt
2014-04-16 14:57 - 2014-04-16 14:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-04-16 14:57 - 2014-04-16 14:57 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-04-15 00:14 - 2014-04-15 00:14 - 01070496 _____ (Unity Technologies ApS) C:\Users\Justus\Downloads\UnityWebPlayer.exe
2014-04-15 00:14 - 2014-04-15 00:14 - 00000000 ____D () C:\Users\Justus\AppData\Local\Unity
2014-04-14 13:39 - 2014-05-04 20:45 - 00000000 ____D () C:\Users\Justus\Desktop\Keta-Forum
2014-04-11 20:29 - 2014-04-11 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-10 17:32 - 2014-04-10 17:32 - 00000000 ____D () C:\Users\Justus\AppData\Local\IBM
2014-04-10 17:32 - 2014-04-10 17:32 - 00000000 ____D () C:\ProgramData\SafeNet Sentinel
2014-04-10 17:31 - 2014-04-10 17:31 - 00000000 ____D () C:\ProgramData\SPSS
2014-04-10 17:31 - 2014-04-10 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IBM SPSS Statistics
2014-04-10 17:30 - 2014-04-10 17:30 - 00000000 ____D () C:\Program Files\Common Files\IBM
2014-04-10 17:29 - 2014-04-10 17:29 - 00001025 _____ () C:\Windows\SysWOW64\sysprs7.tgz
2014-04-10 17:29 - 2014-04-10 17:29 - 00001025 _____ () C:\Windows\SysWOW64\sysprs7.dll
2014-04-10 17:29 - 2014-04-10 17:29 - 00000219 _____ () C:\Windows\SysWOW64\lsprst7.tgz
2014-04-10 17:29 - 2014-04-10 17:29 - 00000205 _____ () C:\Windows\SysWOW64\lsprst7.dll
2014-04-10 17:29 - 2014-04-10 17:29 - 00000016 ____H () C:\Windows\SysWOW64\servdat.slm
2014-04-10 17:29 - 2014-04-10 17:29 - 00000000 ____D () C:\Program Files\IBM
2014-04-10 17:22 - 2014-04-10 17:22 - 00000000 ___HD () C:\Program Files (x86)\Zero G Registry
2014-04-10 17:21 - 2014-04-10 17:21 - 00000000 ___HD () C:\Users\Justus\InstallAnywhere
2014-04-10 17:20 - 2014-04-10 17:23 - 812131760 _____ (IBM Corp) C:\Users\Justus\Downloads\SPSS_Statistics_22_win64_.exe
2014-04-10 17:17 - 2014-04-10 17:18 - 95156272 _____ (Flexera Software) C:\Users\Justus\Downloads\SPSS_CnDS_50_StatsAdap_22_win64.exe
2014-04-10 13:58 - 2014-04-10 13:58 - 00000845 _____ () C:\Users\Justus\Downloads\vpn-extern.pcf
2014-04-10 13:56 - 2014-04-10 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShrewSoft VPN Client
2014-04-10 13:55 - 2014-04-10 13:55 - 00000000 ____D () C:\Users\Justus\AppData\Local\Shrew Soft VPN
2014-04-10 13:55 - 2014-04-10 13:55 - 00000000 ____D () C:\ProgramData\Shrew Soft VPN
2014-04-10 13:55 - 2014-04-10 13:55 - 00000000 ____D () C:\Program Files\ShrewSoft
2014-04-10 13:54 - 2014-04-10 13:55 - 00009171 _____ () C:\install.log
2014-04-10 13:54 - 2014-04-10 13:54 - 03346256 _____ () C:\Users\Justus\Downloads\vpn-client-2.2.2-release.exe
2014-04-09 11:19 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 11:19 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 11:19 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 11:19 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 11:19 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 11:18 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 11:18 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 11:18 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 11:18 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 11:18 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 11:18 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 11:18 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 11:18 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 11:18 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 11:18 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 11:18 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 11:18 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
==================== One Month Modified Files and Folders =======
2014-05-06 21:51 - 2014-05-06 21:51 - 00000000 ____D () C:\Users\Justus\Downloads\FRST-OlderVersion
2014-05-06 21:51 - 2014-05-04 23:37 - 00018571 _____ () C:\Users\Justus\Downloads\FRST.txt
2014-05-06 21:51 - 2014-05-04 23:37 - 00000000 ____D () C:\FRST
2014-05-06 21:51 - 2014-05-04 23:36 - 02063872 _____ (Farbar) C:\Users\Justus\Downloads\FRST64.exe
2014-05-06 21:46 - 2012-03-24 15:22 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2227984459-1923807984-2254057487-1000UA.job
2014-05-06 21:43 - 2011-09-17 20:37 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-06 21:43 - 2011-09-17 16:05 - 01378311 _____ () C:\Windows\WindowsUpdate.log
2014-05-06 21:19 - 2014-05-06 21:19 - 00000866 _____ () C:\Users\Justus\Desktop\JRT.txt
2014-05-06 21:15 - 2009-07-14 06:45 - 00020304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-06 21:15 - 2009-07-14 06:45 - 00020304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-06 21:14 - 2012-04-02 22:16 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-05-06 21:12 - 2014-05-06 21:12 - 00000000 ____D () C:\Windows\ERUNT
2014-05-06 21:11 - 2011-09-17 20:37 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\Skype
2014-05-06 21:10 - 2014-05-06 21:11 - 01016261 _____ (Thisisu) C:\Users\Justus\Desktop\JRT.exe
2014-05-06 21:10 - 2014-05-06 21:10 - 01016261 _____ (Thisisu) C:\Users\Justus\Downloads\JRT.exe
2014-05-06 21:10 - 2013-09-03 22:28 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\Spotify
2014-05-06 21:06 - 2014-05-06 21:06 - 00015925 _____ () C:\Users\Justus\Desktop\AdwCleaner[S0].txt
2014-05-06 21:06 - 2014-05-04 22:57 - 00001445 _____ () C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-05-06 21:06 - 2013-05-23 19:13 - 00000000 ____D () C:\Users\Justus\AppData\Local\LogMeIn Hamachi
2014-05-06 21:05 - 2011-09-17 20:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-06 21:04 - 2010-11-21 05:47 - 00326232 _____ () C:\Windows\PFRO.log
2014-05-06 21:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-06 21:04 - 2009-07-14 06:51 - 00327470 _____ () C:\Windows\setupact.log
2014-05-06 21:02 - 2014-05-06 20:52 - 00000000 ____D () C:\AdwCleaner
2014-05-06 20:58 - 2011-09-17 16:13 - 00000000 ___RD () C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-06 20:53 - 2012-03-31 10:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-06 20:51 - 2014-05-06 20:50 - 01316991 _____ () C:\Users\Justus\Desktop\adwcleaner.exe
2014-05-06 20:50 - 2014-05-06 20:50 - 00000262 _____ () C:\Users\Justus\Desktop\mbam.txt
2014-05-06 20:48 - 2014-05-06 20:42 - 00002279 _____ () C:\Users\Justus\Desktop\Neues Textdokument.txt
2014-05-06 20:47 - 2014-05-06 19:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-06 20:46 - 2012-03-24 15:22 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2227984459-1923807984-2254057487-1000Core.job
2014-05-06 19:20 - 2014-05-06 19:20 - 00001112 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-06 19:20 - 2014-05-06 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-06 19:20 - 2014-05-06 19:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-06 19:19 - 2014-05-06 19:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-06 19:18 - 2014-05-06 19:18 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Justus\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-06 18:53 - 2014-05-06 18:53 - 00000050 _____ () C:\Users\Justus\AppData\Local\Citavi Picker Internet Explorer Protocol.txt
2014-05-06 18:43 - 2014-05-06 18:43 - 00001274 _____ () C:\Users\Justus\Desktop\Revo Uninstaller.lnk
2014-05-06 18:43 - 2014-05-06 18:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-06 18:42 - 2014-05-06 18:42 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Justus\Downloads\revosetup95.exe
2014-05-06 18:35 - 2014-01-12 13:41 - 00000000 ____D () C:\Users\Justus\Documents\Citavi 4
2014-05-06 09:33 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-05-06 09:33 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-05-06 09:33 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-05 21:32 - 2011-09-17 22:18 - 00000000 ____D () C:\Users\Justus\AppData\Local\PMB Files
2014-05-05 20:15 - 2012-01-26 00:11 - 00000000 ____D () C:\Users\Justus\Desktop\E-Dokumente
2014-05-05 15:26 - 2013-09-03 22:28 - 00000000 ____D () C:\Users\Justus\AppData\Local\Spotify
2014-05-05 10:38 - 2014-05-04 23:38 - 00047919 _____ () C:\Users\Justus\Downloads\Addition.txt
2014-05-04 23:00 - 2014-05-04 23:00 - 00000000 ____D () C:\Program Files (x86)\Rr Savings
2014-05-04 22:58 - 2014-05-04 22:58 - 00000000 ____D () C:\Program Files (x86)\ConstaSurf
2014-05-04 20:45 - 2014-04-14 13:39 - 00000000 ____D () C:\Users\Justus\Desktop\Keta-Forum
2014-05-04 20:41 - 2012-03-24 15:22 - 00004096 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2227984459-1923807984-2254057487-1000UA
2014-05-04 20:41 - 2012-03-24 15:22 - 00003700 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2227984459-1923807984-2254057487-1000Core
2014-05-04 19:44 - 2014-01-16 11:17 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\Dropbox
2014-05-03 14:45 - 2013-09-24 21:51 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\TS3Client
2014-05-02 11:31 - 2014-04-28 22:43 - 00000000 ____D () C:\Users\Justus\AppData\Local\Battle.net
2014-05-02 11:30 - 2014-04-28 22:43 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-05-01 23:48 - 2014-05-01 23:42 - 00000000 ____D () C:\Users\Justus\Desktop\UF-Text
2014-05-01 23:27 - 2012-01-03 22:31 - 00000000 ____D () C:\Users\Justus\Desktop\texte
2014-04-30 13:18 - 2011-11-23 18:41 - 00666112 ___SH () C:\Users\Justus\Downloads\Thumbs.db
2014-04-29 18:00 - 2014-05-03 15:22 - 23133184 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 17:24 - 2014-05-03 15:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 16:47 - 2014-05-03 15:22 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 16:14 - 2014-05-03 15:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-29 08:41 - 2011-09-17 22:18 - 00000000 ____D () C:\ProgramData\PMB Files
2014-04-28 23:12 - 2014-04-28 23:12 - 00000000 ____D () C:\Users\Justus\AppData\Local\Blizzard
2014-04-28 23:12 - 2014-04-28 23:06 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-04-28 23:06 - 2014-04-28 23:06 - 00001167 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-04-28 23:06 - 2014-04-28 23:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2014-04-28 23:06 - 2014-04-28 22:43 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\Battle.net
2014-04-28 22:43 - 2014-04-28 22:43 - 00001130 _____ () C:\Users\Public\Desktop\Battle.net.lnk
2014-04-28 22:43 - 2014-04-28 22:43 - 00000000 ____D () C:\Users\Justus\AppData\Local\Blizzard Entertainment
2014-04-28 22:43 - 2014-04-28 22:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2014-04-28 22:43 - 2014-04-28 22:43 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-04-28 22:40 - 2014-04-28 22:40 - 07094224 _____ (Blizzard Entertainment) C:\Users\Justus\Downloads\Hearthstone-Setup-deDE.exe
2014-04-28 22:40 - 2014-04-28 22:40 - 00000000 ____D () C:\ProgramData\Battle.net
2014-04-28 21:55 - 2012-03-31 10:18 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-28 21:55 - 2012-03-31 10:18 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-28 21:55 - 2011-09-18 04:42 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-28 14:01 - 2014-04-23 15:06 - 00000000 ____D () C:\Users\Justus\Desktop\Stiendium
2014-04-26 19:42 - 2014-03-28 16:16 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\Arc
2014-04-24 15:12 - 2013-12-28 13:50 - 00000000 ____D () C:\Users\Justus\AppData\Local\Akamai
2014-04-23 15:55 - 2014-01-16 11:19 - 00000000 ___RD () C:\Users\Justus\Dropbox
2014-04-23 12:31 - 2014-01-16 11:19 - 00001029 _____ () C:\Users\Justus\Desktop\Dropbox.lnk
2014-04-23 12:31 - 2014-01-16 11:17 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-04-23 12:30 - 2014-04-23 12:30 - 00316160 _____ (Dropbox, Inc.) C:\Users\Justus\Downloads\DropboxInstaller (1).exe
2014-04-22 23:44 - 2014-04-22 23:44 - 00001499 _____ () C:\Users\Justus\.recently-used.xbel
2014-04-22 23:44 - 2011-11-17 23:44 - 00000000 ____D () C:\Users\Justus\AppData\Roaming\gtk-2.0
2014-04-22 23:44 - 2011-11-17 23:35 - 00000000 ____D () C:\Users\Justus\.gimp-2.6
2014-04-22 23:44 - 2011-09-17 16:13 - 00000000 ____D () C:\Users\Justus
2014-04-22 18:13 - 2013-12-20 11:51 - 00000000 ____D () C:\Users\Justus\Desktop\1UNIDUE
2014-04-22 14:54 - 2013-11-03 18:33 - 00000000 ____D () C:\Users\Justus\Desktop\Gutes_Zeug_Listen
2014-04-18 17:04 - 2014-04-18 17:02 - 00009843 _____ () C:\Users\Justus\Desktop\Sammlung.txt
2014-04-16 14:57 - 2014-04-16 14:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-04-16 14:57 - 2014-04-16 14:57 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-04-16 14:57 - 2014-02-27 16:34 - 00000932 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-04-16 09:30 - 2012-03-17 11:39 - 00000000 ____D () C:\Users\Justus\Desktop\Wolfsträume
2014-04-16 09:30 - 2011-10-10 15:47 - 00000000 ____D () C:\Users\Justus\Desktop\rp
2014-04-16 09:29 - 2011-12-04 17:26 - 00000000 ____D () C:\Users\Justus\Desktop\Unterortner
2014-04-16 09:29 - 2011-09-17 20:47 - 00000000 ____D () C:\Users\Justus\Desktop\spiele
2014-04-15 00:14 - 2014-04-15 00:14 - 01070496 _____ (Unity Technologies ApS) C:\Users\Justus\Downloads\UnityWebPlayer.exe
2014-04-15 00:14 - 2014-04-15 00:14 - 00000000 ____D () C:\Users\Justus\AppData\Local\Unity
2014-04-14 15:38 - 2013-03-15 14:09 - 00000000 ____D () C:\Users\Justus\Desktop\Spiel
2014-04-12 10:27 - 2012-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-11 20:30 - 2014-04-11 20:29 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-10 17:32 - 2014-04-10 17:32 - 00000000 ____D () C:\Users\Justus\AppData\Local\IBM
2014-04-10 17:32 - 2014-04-10 17:32 - 00000000 ____D () C:\ProgramData\SafeNet Sentinel
2014-04-10 17:31 - 2014-04-10 17:31 - 00000000 ____D () C:\ProgramData\SPSS
2014-04-10 17:31 - 2014-04-10 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IBM SPSS Statistics
2014-04-10 17:30 - 2014-04-10 17:30 - 00000000 ____D () C:\Program Files\Common Files\IBM
2014-04-10 17:29 - 2014-04-10 17:29 - 00001025 _____ () C:\Windows\SysWOW64\sysprs7.tgz
2014-04-10 17:29 - 2014-04-10 17:29 - 00001025 _____ () C:\Windows\SysWOW64\sysprs7.dll
2014-04-10 17:29 - 2014-04-10 17:29 - 00000219 _____ () C:\Windows\SysWOW64\lsprst7.tgz
2014-04-10 17:29 - 2014-04-10 17:29 - 00000205 _____ () C:\Windows\SysWOW64\lsprst7.dll
2014-04-10 17:29 - 2014-04-10 17:29 - 00000016 ____H () C:\Windows\SysWOW64\servdat.slm
2014-04-10 17:29 - 2014-04-10 17:29 - 00000000 ____D () C:\Program Files\IBM
2014-04-10 17:23 - 2014-04-10 17:20 - 812131760 _____ (IBM Corp) C:\Users\Justus\Downloads\SPSS_Statistics_22_win64_.exe
2014-04-10 17:22 - 2014-04-10 17:22 - 00000000 ___HD () C:\Program Files (x86)\Zero G Registry
2014-04-10 17:21 - 2014-04-10 17:21 - 00000000 ___HD () C:\Users\Justus\InstallAnywhere
2014-04-10 17:18 - 2014-04-10 17:17 - 95156272 _____ (Flexera Software) C:\Users\Justus\Downloads\SPSS_CnDS_50_StatsAdap_22_win64.exe
2014-04-10 14:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-10 13:58 - 2014-04-10 13:58 - 00000845 _____ () C:\Users\Justus\Downloads\vpn-extern.pcf
2014-04-10 13:56 - 2014-04-10 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShrewSoft VPN Client
2014-04-10 13:55 - 2014-04-10 13:55 - 00000000 ____D () C:\Users\Justus\AppData\Local\Shrew Soft VPN
2014-04-10 13:55 - 2014-04-10 13:55 - 00000000 ____D () C:\ProgramData\Shrew Soft VPN
2014-04-10 13:55 - 2014-04-10 13:55 - 00000000 ____D () C:\Program Files\ShrewSoft
2014-04-10 13:55 - 2014-04-10 13:54 - 00009171 _____ () C:\install.log
2014-04-10 13:54 - 2014-04-10 13:54 - 03346256 _____ () C:\Users\Justus\Downloads\vpn-client-2.2.2-release.exe
2014-04-10 11:08 - 2011-11-15 18:35 - 00000000 ____D () C:\Users\Justus\AppData\Local\Mozilla
2014-04-09 14:00 - 2011-10-03 17:07 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 13:59 - 2013-07-15 14:39 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 13:57 - 2011-09-30 08:18 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Justus\AppData\Local\Temp\032939rr.exe
C:\Users\Justus\AppData\Local\Temp\6_Offer_12.exe
C:\Users\Justus\AppData\Local\Temp\ApnStub.exe
C:\Users\Justus\AppData\Local\Temp\AskSLib.dll
C:\Users\Justus\AppData\Local\Temp\BackupSetup.exe
C:\Users\Justus\AppData\Local\Temp\bdfilters.dll
C:\Users\Justus\AppData\Local\Temp\CmdLineExt.dll
C:\Users\Justus\AppData\Local\Temp\CmdLineExt03.dll
C:\Users\Justus\AppData\Local\Temp\comver.dll
C:\Users\Justus\AppData\Local\Temp\contentDATs.exe
C:\Users\Justus\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Justus\AppData\Local\Temp\drm_dyndata_7330017.dll
C:\Users\Justus\AppData\Local\Temp\drm_dyndata_7400009.dll
C:\Users\Justus\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuekmt2.dll
C:\Users\Justus\AppData\Local\Temp\GoogleToolbarInstaller.exe
C:\Users\Justus\AppData\Local\Temp\gtapi.dll
C:\Users\Justus\AppData\Local\Temp\installhelper.dll
C:\Users\Justus\AppData\Local\Temp\instloffer.exe
C:\Users\Justus\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Justus\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Users\Justus\AppData\Local\Temp\jre-7u5-windows-i586-iftw.exe
C:\Users\Justus\AppData\Local\Temp\mgsqlite3.dll
C:\Users\Justus\AppData\Local\Temp\NGMDll.dll
C:\Users\Justus\AppData\Local\Temp\NGMResource.dll
C:\Users\Justus\AppData\Local\Temp\NGMSetup.exe
C:\Users\Justus\AppData\Local\Temp\Quarantine.exe
C:\Users\Justus\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\Justus\AppData\Local\Temp\Shortcut_Shortcut_sweetimsetup.exe
C:\Users\Justus\AppData\Local\Temp\Shortcut_sweetimsetup.exe
C:\Users\Justus\AppData\Local\Temp\SIMEEIInstaller.exe
C:\Users\Justus\AppData\Local\Temp\SIntf16.dll
C:\Users\Justus\AppData\Local\Temp\SIntf32.dll
C:\Users\Justus\AppData\Local\Temp\SIntfNT.dll
C:\Users\Justus\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Justus\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\Justus\AppData\Local\Temp\SRLDetectionLibrary7949106527364205144.dll
C:\Users\Justus\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Justus\AppData\Local\Temp\ubiD60D.tmp.exe
C:\Users\Justus\AppData\Local\Temp\unicows.dll
C:\Users\Justus\AppData\Local\Temp\_is673.exe
C:\Users\Justus\AppData\Local\Temp\_is6F8F.exe
C:\Users\Justus\AppData\Local\Temp\_isB053.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-29 12:38
==================== End Of Log ============================ --- --- ---
--- --- ---
Das sollte alles sein.
Gruß N |