Chris180294 | 12.05.2014 18:53 | Malwarebytes Anti-Malware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 12.05.2014 15:22:00, SYSTEM, CHRIS-HP, Protection, Malware Protection, Starting,
Protection, 12.05.2014 15:22:00, SYSTEM, CHRIS-HP, Protection, Malware Protection, Started,
Protection, 12.05.2014 15:22:00, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Starting,
Update, 12.05.2014 15:22:12, SYSTEM, CHRIS-HP, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Protection, 12.05.2014 15:22:40, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Started,
Update, 12.05.2014 15:25:05, SYSTEM, CHRIS-HP, Manual, Malware Database, 2014.3.4.9, 2014.5.12.2,
Protection, 12.05.2014 15:25:07, SYSTEM, CHRIS-HP, Protection, Refresh, Starting,
Protection, 12.05.2014 15:25:07, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Stopping,
Protection, 12.05.2014 15:25:07, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Stopped,
Protection, 12.05.2014 15:25:10, SYSTEM, CHRIS-HP, Protection, Refresh, Success,
Protection, 12.05.2014 15:25:10, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Starting,
Protection, 12.05.2014 15:25:10, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Started,
Protection, 12.05.2014 15:44:26, SYSTEM, CHRIS-HP, Protection, Malware Protection, Starting,
Protection, 12.05.2014 15:44:26, SYSTEM, CHRIS-HP, Protection, Malware Protection, Started,
Protection, 12.05.2014 15:44:26, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Starting,
Protection, 12.05.2014 15:46:28, SYSTEM, CHRIS-HP, Protection, Malicious Website Protection, Started,
(end)
AdwCleaner: Code:
# AdwCleaner v3.208 - Bericht erstellt am 12/05/2014 um 19:16:33
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Chris - CHRIS-HP
# Gestartet von : C:\Users\Chris\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Users\Chris\AppData\LocalLow\BabylonToolbar
Ordner Gelöscht : C:\Users\Chris\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\Chris\AppData\LocalLow\searchquband
Ordner Gelöscht : C:\Users\Chris\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Chris\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\searchquband
Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\Searchqutoolbar
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Chris\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonToolbarsrv_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonToolbarsrv_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\jZip_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\jZip_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_virtual-dj_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_virtual-dj_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\searchqutoolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\DeviceVM
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DeviceVM
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v
-\\ Google Chrome v34.0.1847.131
[ Datei : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&sr=0&q={searchTerms}
Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3323828&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPF77F99E8-AF03-4553-9896-3D874741D4F1&q={searchTerms}&SSPV=
Gelöscht [Search Provider] : hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
Gelöscht [Search Provider] : hxxp://www.awesomehp.com/web/?type=ds&ts=1393075610&from=adks&uid=HitachiXHTS725050A9A364_101216PCK404GLG5MS5JX&q={searchTerms}
*************************
AdwCleaner[R0].txt - [7565 octets] - [12/05/2014 15:54:14]
AdwCleaner[S0].txt - [6282 octets] - [12/05/2014 19:16:33]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6342 octets] ########## Junkware Removal Tool : Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Chris on 12.05.2014 at 19:21:28,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.05.2014 at 19:29:09,38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01
Ran by Chris (administrator) on CHRIS-HP on 12-05-2014 19:52:05
Running from C:\Users\Chris\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Hewlett-Packard) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(SIEMENS AG) C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Siemens AG) C:\Program Files\Common Files\Siemens\AlmPanelPlugin\ALMPanelPlugin.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Juniper Networks) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Hewlett-Packard Development Company, L.P) C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Korg Inc.) C:\Windows\System32\InitJam.exe
(SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
() C:\Windows\vsnpstd3.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\pniomgr.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(SIEMENS AG) C:\Windows\SysWOW64\pniopcac.exe
(SIEMENS AG) C:\Windows\SysWOW64\pniopcac.exe
(SIEMENS AG) C:\Windows\SysWOW64\pniopcac.exe
(ArcSoft, Inc.) C:\Windows\system\uArcCapture.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
() C:\Windows\tsnpstd3.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [1691192 2010-06-19] (Hewlett-Packard Company)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [JamInit] => C:\windows\system32\InitJam.exe [253008 2009-04-15] (Korg Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [snpstd3] => C:\windows\vsnpstd3.exe [827392 2006-09-19] ()
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11265536 2009-12-12] (Hewlett-Packard)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-05] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [DTRun] => c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [518656 2009-11-19] (ArcSoft Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-10-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.)
HKLM-x32\...\Run: [SiemensAutomationFileStorage] => C:\Program Files (x86)\Siemens\Automation\Portal V11\\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe [856064 2011-11-22] (Siemens AG)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM-x32\...\Run: [tsnpstd3] => C:\windows\tsnpstd3.exe [262144 2006-07-07] ()
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\S-1-5-21-538565719-3422209620-1557115018-1002\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-538565719-3422209620-1557115018-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-538565719-3422209620-1557115018-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-09-14] (Apple Inc.)
HKU\S-1-5-21-538565719-3422209620-1557115018-1002\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-09-15] (Apple Inc.)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO-x32: PodcastBHO Class - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @doubletwist.com/NPPodcast - C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\
FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ []
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Drive) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-28]
CHR Extension: (YouTube) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-28]
CHR Extension: (Google-Suche) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-28]
CHR Extension: (Google Wallet) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-28]
CHR Extension: (Google Mail) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-28]
==================== Services (Whitelisted) =================
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 almservice; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [1543816 2011-12-11] (SIEMENS AG)
R3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2009-12-16] (McAfee, Inc.)
R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462088 2009-11-25] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2009-11-18] (Hewlett-Packard Ltd)
R2 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [36864 2009-11-19] (Hewlett-Packard Development Company, L.P)
R2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2009-12-16] (McAfee, Inc.)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [280120 2010-10-01] (Hewlett-Packard Company)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 s7oiehsx64; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [139864 2012-01-30] (SIEMENS AG)
R2 S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe [470104 2012-01-30] (SIEMENS AG)
R2 uArcCapture; C:\windows\system\uArcCapture.exe [506472 2009-12-04] (ArcSoft, Inc.)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32640 2009-12-04] (ArcSoft, Inc.)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2009-10-21] (Hewlett-Packard Development Company L.P.)
R3 dpmconv; C:\Windows\System32\DRIVERS\dpmconv.sys [259072 2011-04-19] (SIEMENS AG)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.)
S3 JAMVOX_01; C:\Windows\System32\DRIVERS\JamWdm.sys [31824 2009-04-15] ()
S1 JAMVOX_AA; C:\Windows\System32\DRIVERS\JamDRV.sys [62544 2009-04-15] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-12] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2009-12-16] (McAfee, Inc.)
R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2009-12-16] (McAfee, Inc.)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [89216 2009-12-22] (Realtek Semiconductor Corp.)
R3 s7odpx2x64; C:\Windows\System32\DRIVERS\s7odpx2x64.sys [71168 2012-01-17] (SIEMENS AG)
R3 s7oppinx64; C:\Windows\System32\DRIVERS\s7oppinx64.sys [107520 2012-01-17] (SIEMENS AG)
R3 s7oserix64; C:\Windows\System32\Drivers\s7oserix64.sys [121344 2011-05-06] (SIEMENS AG)
R3 s7osmcax64; C:\Windows\System32\DRIVERS\s7osmcax64.sys [195584 2011-09-29] (SIEMENS AG)
R3 s7osobux64; C:\Windows\System32\DRIVERS\s7osobux64.sys [152576 2011-05-06] (SIEMENS AG)
R3 s7otmcd64x; C:\Windows\System32\Drivers\s7otmcd64x.sys [199680 2011-05-06] (SIEMENS AG)
R3 s7otranx64; C:\Windows\System32\DRIVERS\s7otranx64.sys [260096 2012-01-17] (SIEMENS AG)
R3 s7otsadx64; C:\Windows\System32\DRIVERS\s7otsadx64.sys [192000 2011-09-29] (SIEMENS AG)
R2 s7ousbu64x; C:\Windows\System32\DRIVERS\s7ousbu64x.sys [196608 2012-01-17] (SIEMENS AG)
R2 s7sn2srtx; C:\Windows\System32\DRIVERS\s7sn2srtx.sys [83032 2011-06-16] (SIEMENS AG)
R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2009-12-16] ()
R0 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2009-12-16] (McAfee, Inc.)
R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.)
R0 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2009-12-16] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2009-12-16] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2009-12-16] (McAfee, Inc.)
S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10550272 2007-03-27] (Sonix Co. Ltd.)
R2 SNTIE; C:\Windows\System32\DRIVERS\sntie.sys [179288 2011-10-11] (SIEMENS AG)
R3 vsnl2ada; C:\Windows\System32\DRIVERS\vsnl2ada.sys [120832 2011-04-19] (SIEMENS AG)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 nmwcd; system32\drivers\ccdcmbx64.sys [X]
S3 nmwcdc; system32\drivers\ccdcmbox64.sys [X]
S3 STHDA; system32\DRIVERS\stwrt64.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerfltx64.sys [X]
U2 wuaserv;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-12 19:51 - 2014-05-12 19:51 - 00000000 ____D () C:\Users\Chris\Downloads\FRST-OlderVersion
2014-05-12 19:29 - 2014-05-12 19:29 - 00000695 _____ () C:\Users\Chris\Desktop\JRT.txt
2014-05-12 19:21 - 2014-05-12 19:21 - 00000000 ____D () C:\windows\ERUNT
2014-05-12 19:20 - 2014-05-12 19:21 - 01016261 _____ (Thisisu) C:\Users\Chris\Desktop\JRT.exe
2014-05-12 19:19 - 2014-05-12 19:19 - 00006434 _____ () C:\Users\Chris\Desktop\AdwCleaner[S0].txt
2014-05-12 15:54 - 2014-05-12 19:16 - 00000000 ____D () C:\AdwCleaner
2014-05-12 15:54 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-05-12 15:52 - 2014-05-12 15:53 - 01325827 _____ () C:\Users\Chris\Desktop\adwcleaner.exe
2014-05-12 15:49 - 2014-05-12 15:49 - 00001642 _____ () C:\Users\Chris\Desktop\mbam.txt
2014-05-12 15:21 - 2014-05-12 19:20 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 15:21 - 2014-05-12 15:21 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-12 15:21 - 2014-05-12 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-12 15:21 - 2014-05-12 15:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-12 15:21 - 2014-05-12 15:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-12 15:21 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-05-12 15:21 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-05-12 15:21 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-05-12 15:10 - 2014-05-12 15:16 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Chris\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-12 15:04 - 2014-05-12 15:04 - 00003284 _____ () C:\windows\System32\Tasks\{2D6FB43B-3571-411F-AF75-EDDBCB35F900}
2014-05-08 13:38 - 2014-05-08 13:38 - 00026049 _____ () C:\ComboFix.txt
2014-05-08 13:00 - 2014-05-08 13:38 - 00000000 ____D () C:\Qoobox
2014-05-08 13:00 - 2014-05-08 13:34 - 00000000 ____D () C:\windows\erdnt
2014-05-08 13:00 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-05-08 13:00 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-05-08 13:00 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-05-08 13:00 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-05-08 13:00 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-05-08 13:00 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-05-08 13:00 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-05-08 13:00 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-05-08 12:58 - 2014-05-08 13:00 - 05200039 ____R (Swearware) C:\Users\Chris\Desktop\ComboFix.exe
2014-05-08 12:21 - 2014-05-08 12:21 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-05-08 12:21 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-08 12:21 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-08 12:21 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-08 12:21 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-07 08:47 - 2014-05-07 08:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Chris\Downloads\revosetup95 (1).exe
2014-05-07 08:47 - 2014-05-07 08:47 - 00001264 _____ () C:\Users\Chris\Desktop\Revo Uninstaller.lnk
2014-05-07 08:47 - 2014-05-07 08:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-07 08:46 - 2014-05-07 08:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Chris\Downloads\revosetup95.exe
2014-05-07 07:58 - 2014-05-07 08:17 - 00042984 _____ () C:\Users\Chris\Downloads\Addition.txt
2014-05-07 07:57 - 2014-05-12 19:52 - 00021403 _____ () C:\Users\Chris\Downloads\FRST.txt
2014-05-07 07:56 - 2014-05-12 19:52 - 00000000 ____D () C:\FRST
2014-05-07 07:55 - 2014-05-12 19:51 - 02066944 _____ (Farbar) C:\Users\Chris\Downloads\FRST64.exe
2014-05-07 07:47 - 2014-05-07 07:47 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2014-05-07 07:08 - 2014-05-07 07:08 - 00001532 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2014-05-06 12:16 - 2014-05-06 12:38 - 34014392 _____ (DVDVideoSoft Ltd. ) C:\Users\Chris\Downloads\FreeYouTubeToMP3Converter34430.exe
2014-05-06 10:52 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-05-06 10:52 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-05-05 12:23 - 2014-05-05 12:35 - 32346240 _____ (DVDVideoSoft Ltd. ) C:\Users\Chris\Downloads\FreeYouTubeDownload-3.2.33.424.exe
2014-05-05 12:18 - 2014-05-05 12:18 - 00001477 _____ () C:\Users\Public\Desktop\Free MP4 Video Converter.lnk
2014-05-05 11:48 - 2014-05-05 12:01 - 32121120 _____ (DVDVideoSoft Ltd. ) C:\Users\Chris\Downloads\FreeMP4VideoConverter_v5.0.39.430.exe
2014-04-30 14:55 - 2014-04-30 14:55 - 00000000 __SHD () C:\Users\Chris\AppData\Local\EmieUserList
2014-04-30 14:55 - 2014-04-30 14:55 - 00000000 __SHD () C:\Users\Chris\AppData\Local\EmieSiteList
2014-04-29 06:46 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-04-29 06:46 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-04-29 06:46 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-04-29 06:46 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-04-29 06:46 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-04-29 06:46 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-04-29 06:46 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-04-29 06:46 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-04-29 06:46 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-04-29 06:46 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-04-29 06:46 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-04-29 06:46 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-04-29 06:46 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-04-29 06:46 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-04-29 06:46 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-04-29 06:46 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-04-29 06:46 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-04-29 06:46 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-04-29 06:46 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-04-29 06:46 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-04-29 06:46 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-04-29 06:46 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-04-29 06:46 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-04-29 06:46 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-04-29 06:46 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-04-29 06:46 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-04-29 06:46 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-04-29 06:46 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-04-29 06:46 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-04-29 06:46 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-04-29 06:46 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-29 06:46 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-04-29 06:46 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-04-29 06:46 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-04-29 06:46 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-04-29 06:46 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-04-29 06:46 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-04-29 06:46 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-04-29 06:46 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-04-29 06:46 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-04-29 06:46 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-04-29 06:46 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-04-29 06:46 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-04-29 06:46 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-04-28 21:16 - 2014-05-12 19:28 - 00001108 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-28 21:16 - 2014-05-12 19:18 - 00001104 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-28 21:16 - 2014-05-08 12:22 - 00004104 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-28 21:16 - 2014-05-08 12:22 - 00003852 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-28 21:16 - 2014-05-02 12:15 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-28 21:16 - 2014-04-28 21:16 - 00000000 ____D () C:\Users\Chris\AppData\Local\Google
2014-04-28 21:16 - 2014-04-28 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-28 21:16 - 2014-04-28 21:16 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-28 20:55 - 2014-04-28 21:12 - 38317592 _____ (Google Inc.) C:\Users\Chris\Downloads\ChromeStandaloneSetup_34.0.1847.116.exe
2014-04-28 19:11 - 2014-04-28 19:11 - 00000000 ____D () C:\Users\Chris\Desktop\Neuer Ordner
2014-04-28 12:44 - 2014-04-28 19:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-12 22:31 - 2014-04-12 22:31 - 00000000 ____D () C:\Users\Chris\Documents\ArcSoft
==================== One Month Modified Files and Folders =======
2014-05-12 19:52 - 2014-05-07 07:57 - 00021403 _____ () C:\Users\Chris\Downloads\FRST.txt
2014-05-12 19:52 - 2014-05-07 07:56 - 00000000 ____D () C:\FRST
2014-05-12 19:51 - 2014-05-12 19:51 - 00000000 ____D () C:\Users\Chris\Downloads\FRST-OlderVersion
2014-05-12 19:51 - 2014-05-07 07:55 - 02066944 _____ (Farbar) C:\Users\Chris\Downloads\FRST64.exe
2014-05-12 19:29 - 2014-05-12 19:29 - 00000695 _____ () C:\Users\Chris\Desktop\JRT.txt
2014-05-12 19:28 - 2014-04-28 21:16 - 00001108 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-12 19:25 - 2009-07-14 06:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-12 19:25 - 2009-07-14 06:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-12 19:24 - 2010-12-07 14:06 - 00700134 _____ () C:\windows\system32\perfh007.dat
2014-05-12 19:24 - 2010-12-07 14:06 - 00149984 _____ () C:\windows\system32\perfc007.dat
2014-05-12 19:24 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI
2014-05-12 19:21 - 2014-05-12 19:21 - 00000000 ____D () C:\windows\ERUNT
2014-05-12 19:21 - 2014-05-12 19:20 - 01016261 _____ (Thisisu) C:\Users\Chris\Desktop\JRT.exe
2014-05-12 19:20 - 2014-05-12 15:21 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 19:20 - 2010-12-07 14:05 - 00000000 ____D () C:\ProgramData\HPQLOG
2014-05-12 19:19 - 2014-05-12 19:19 - 00006434 _____ () C:\Users\Chris\Desktop\AdwCleaner[S0].txt
2014-05-12 19:18 - 2014-04-28 21:16 - 00001104 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-12 19:18 - 2011-05-19 18:05 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Skype
2014-05-12 19:17 - 2011-01-22 01:27 - 00452180 _____ () C:\windows\PFRO.log
2014-05-12 19:17 - 2011-01-08 11:28 - 01770257 _____ () C:\windows\WindowsUpdate.log
2014-05-12 19:17 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-05-12 19:17 - 2009-07-14 06:51 - 00302985 _____ () C:\windows\setupact.log
2014-05-12 19:16 - 2014-05-12 15:54 - 00000000 ____D () C:\AdwCleaner
2014-05-12 19:16 - 2011-01-21 17:42 - 00000989 _____ () C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-12 15:53 - 2014-05-12 15:52 - 01325827 _____ () C:\Users\Chris\Desktop\adwcleaner.exe
2014-05-12 15:49 - 2014-05-12 15:49 - 00001642 _____ () C:\Users\Chris\Desktop\mbam.txt
2014-05-12 15:43 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\Resources
2014-05-12 15:21 - 2014-05-12 15:21 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-12 15:21 - 2014-05-12 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-12 15:21 - 2014-05-12 15:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-12 15:21 - 2014-05-12 15:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-12 15:16 - 2014-05-12 15:10 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Chris\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-12 15:04 - 2014-05-12 15:04 - 00003284 _____ () C:\windows\System32\Tasks\{2D6FB43B-3571-411F-AF75-EDDBCB35F900}
2014-05-08 20:07 - 2014-03-13 19:55 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForChris
2014-05-08 20:07 - 2014-03-13 19:55 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForChris.job
2014-05-08 13:38 - 2014-05-08 13:38 - 00026049 _____ () C:\ComboFix.txt
2014-05-08 13:38 - 2014-05-08 13:00 - 00000000 ____D () C:\Qoobox
2014-05-08 13:38 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-05-08 13:34 - 2014-05-08 13:00 - 00000000 ____D () C:\windows\erdnt
2014-05-08 13:24 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini
2014-05-08 13:21 - 2014-02-25 18:02 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-08 13:21 - 2009-07-14 04:34 - 23330816 _____ () C:\windows\system32\config\SYSTEM.bak
2014-05-08 13:21 - 2009-07-14 04:34 - 100925440 _____ () C:\windows\system32\config\SOFTWARE.bak
2014-05-08 13:21 - 2009-07-14 04:34 - 01048576 _____ () C:\windows\system32\config\DEFAULT.bak
2014-05-08 13:21 - 2009-07-14 04:34 - 00262144 _____ () C:\windows\system32\config\SECURITY.bak
2014-05-08 13:21 - 2009-07-14 04:34 - 00262144 _____ () C:\windows\system32\config\SAM.bak
2014-05-08 13:00 - 2014-05-08 12:58 - 05200039 ____R (Swearware) C:\Users\Chris\Desktop\ComboFix.exe
2014-05-08 12:22 - 2014-04-28 21:16 - 00004104 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-08 12:22 - 2014-04-28 21:16 - 00003852 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-08 12:21 - 2014-05-08 12:21 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-05-07 11:44 - 2014-02-25 10:16 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-05-07 09:58 - 2011-01-22 01:29 - 00000000 ____D () C:\windows\rescache
2014-05-07 08:48 - 2014-05-07 08:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Chris\Downloads\revosetup95 (1).exe
2014-05-07 08:47 - 2014-05-07 08:47 - 00001264 _____ () C:\Users\Chris\Desktop\Revo Uninstaller.lnk
2014-05-07 08:47 - 2014-05-07 08:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-07 08:47 - 2014-05-07 08:46 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Chris\Downloads\revosetup95.exe
2014-05-07 08:17 - 2014-05-07 07:58 - 00042984 _____ () C:\Users\Chris\Downloads\Addition.txt
2014-05-07 07:47 - 2014-05-07 07:47 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2014-05-07 07:08 - 2014-05-07 07:08 - 00001532 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2014-05-07 07:08 - 2012-11-08 22:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-07 07:08 - 2011-08-05 18:32 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\DVDVideoSoft
2014-05-07 07:08 - 2011-01-24 20:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-06 12:38 - 2014-05-06 12:16 - 34014392 _____ (DVDVideoSoft Ltd. ) C:\Users\Chris\Downloads\FreeYouTubeToMP3Converter34430.exe
2014-05-05 12:35 - 2014-05-05 12:23 - 32346240 _____ (DVDVideoSoft Ltd. ) C:\Users\Chris\Downloads\FreeYouTubeDownload-3.2.33.424.exe
2014-05-05 12:18 - 2014-05-05 12:18 - 00001477 _____ () C:\Users\Public\Desktop\Free MP4 Video Converter.lnk
2014-05-05 12:01 - 2014-05-05 11:48 - 32121120 _____ (DVDVideoSoft Ltd. ) C:\Users\Chris\Downloads\FreeMP4VideoConverter_v5.0.39.430.exe
2014-05-05 11:47 - 2011-01-23 19:32 - 00000052 _____ () C:\windows\SysWOW64\DOErrors.log
2014-05-05 11:46 - 2011-10-30 19:50 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-05-02 12:15 - 2014-04-28 21:16 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-30 15:06 - 2011-01-26 20:37 - 00000000 ____D () C:\Users\Chris\AppData\Local\CrashDumps
2014-04-30 14:55 - 2014-04-30 14:55 - 00000000 __SHD () C:\Users\Chris\AppData\Local\EmieUserList
2014-04-30 14:55 - 2014-04-30 14:55 - 00000000 __SHD () C:\Users\Chris\AppData\Local\EmieSiteList
2014-04-29 16:01 - 2014-05-08 12:21 - 23547904 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-08 12:21 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-08 12:21 - 17384448 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-08 12:21 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-29 07:58 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-04-28 21:16 - 2014-04-28 21:16 - 00000000 ____D () C:\Users\Chris\AppData\Local\Google
2014-04-28 21:16 - 2014-04-28 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-28 21:16 - 2014-04-28 21:16 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-28 21:12 - 2014-04-28 20:55 - 38317592 _____ (Google Inc.) C:\Users\Chris\Downloads\ChromeStandaloneSetup_34.0.1847.116.exe
2014-04-28 20:23 - 2013-03-06 19:03 - 01232896 ___SH () C:\Users\Chris\Desktop\Thumbs.db
2014-04-28 20:07 - 2013-11-27 16:22 - 00017390 _____ () C:\windows\IE11_main.log
2014-04-28 19:11 - 2014-04-28 19:11 - 00000000 ____D () C:\Users\Chris\Desktop\Neuer Ordner
2014-04-28 19:11 - 2014-04-28 12:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-28 19:11 - 2011-01-21 18:20 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Mozilla
2014-04-14 04:24 - 2014-05-06 10:52 - 00465408 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-05-06 10:52 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-04-12 22:31 - 2014-04-12 22:31 - 00000000 ____D () C:\Users\Chris\Documents\ArcSoft
Some content of TEMP:
====================
C:\Users\Chris\AppData\Local\Temp\Quarantine.exe LG |