usernamejuli | 17.06.2014 11:46 | Adw Logatei Code:
# AdwCleaner v3.212 - Bericht erstellt am 17/06/2014 um 08:25:50
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Jana - VAIO
# Gestartet von : C:\Users\Jana\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Browser Manager
Ordner Gelöscht : C:\ProgramData\BrowserDefender
Ordner Gelöscht : C:\ProgramData\wincert
Ordner Gelöscht : C:\Program Files (x86)\DealPly
Ordner Gelöscht : C:\Program Files (x86)\iMesh Applications
Ordner Gelöscht : C:\Program Files (x86)\LyriXeeker
Ordner Gelöscht : C:\Program Files (x86)\Music Toolbar
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Jana\AppData\Local\Temp\mt_ffx
Ordner Gelöscht : C:\Users\Jana\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Jana\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\Jana\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\Jana\AppData\LocalLow\searchresultstb
Ordner Gelöscht : C:\Users\Jana\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Jana\AppData\Roaming\DealPly
Ordner Gelöscht : C:\Users\Jana\AppData\Roaming\DSite
Ordner Gelöscht : C:\Users\Jana\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Jana\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
Ordner Gelöscht : C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Ordner Gelöscht : C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\llbmigfomppbjkjlabpacbhlahacjbkc
Datei Gelöscht : C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\llbmigfomppbjkjlabpacbhlahacjbkc
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\llbmigfomppbjkjlabpacbhlahacjbkc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C4C4F1F4-3074-4CB6-9FB8-0A64273166F0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{474597C5-AB09-49D6-A4D5-2E8D7341384E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7C3B01BC-53A5-48A0-A43B-0C67731134B9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}
Schlüssel Gelöscht : HKCU\Software\APN DTX
Schlüssel Gelöscht : HKCU\Software\Imesh
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Google Chrome v
[ Datei : C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : llbmigfomppbjkjlabpacbhlahacjbkc
Gelöscht [Extension] : nikpibnbobmbdbheedjfogjlikpgpnhp
*************************
AdwCleaner[R0].txt - [7239 octets] - [17/06/2014 08:25:26]
AdwCleaner[S0].txt - [6410 octets] - [17/06/2014 08:25:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6470 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Jana on 17.06.2014 at 11:43:05,27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-429091727-3453439002-3370875811-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.06.2014 at 11:47:46,88
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 17.06.2014
Suchlauf-Zeit: 11:49:40
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.17.03
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Jana
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 291854
Verstrichene Zeit: 18 Min, 34 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 2
PUP.Optional.MusicBoxToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{45177936-603b-4261-8d42-df6f7091d5d0}, In Quarantäne, [2a5dbfba5625f5419eb5344918ec59a7],
PUP.Optional.MusicBoxToolBar.A, HKU\S-1-5-21-429091727-3453439002-3370875811-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{45177936-603B-4261-8D42-DF6F7091D5D0}, In Quarantäne, [2a5dbfba5625f5419eb5344918ec59a7],
Registrierungswerte: 1
PUP.Optional.MusicBoxToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{45177936-603B-4261-8D42-DF6F7091D5D0}, Music Box Toolbar (Dist. by iMesh, Inc.), In Quarantäne, [2a5dbfba5625f5419eb5344918ec59a7]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 1
PUP.Optional.Conduit.A, C:\Users\Jana\AppData\Local\Temp\CT3300847, In Quarantäne, [ea9db6c30d6e2f077a827c0e669ccf31],
Dateien: 11
PUP.Optional.iMeshMusicBoxTB.A, C:\Windows\Temp\7384111\SetupDataMngr_iMesh.exe, In Quarantäne, [384f7504e992ca6c4e9722fc28d9af51],
PUP.Optional.iMeshMusicBoxTB.A, C:\Windows\Temp\f91049c6\SetupDataMngr_iMesh.exe, In Quarantäne, [8700f287b2c9ba7c45a0001ecf328f71],
PUP.Optional.Conduit.A, C:\Users\Jana\Downloads\Zconvert (1).exe, In Quarantäne, [9ceb8feaadce0c2a08e91d303ec3649c],
PUP.Optional.Conduit.A, C:\Users\Jana\Downloads\Zconvert (2).exe, In Quarantäne, [d1b63c3dfe7deb4b0be6b598cc3530d0],
PUP.Optional.Conduit.A, C:\Users\Jana\Downloads\Zconvert.exe, In Quarantäne, [780f55247b00e84ec130143943be48b8],
PUP.Optional.Bandoo.A, C:\Users\Jana\Downloads\iMeshSetup-r1487-w-bc.exe, In Quarantäne, [43440c6d077456e06e93f53cd72a30d0],
PUP.Optional.Conduit.A, C:\Users\Jana\AppData\Local\Temp\CT3300847\CT3300847.txt, In Quarantäne, [ea9db6c30d6e2f077a827c0e669ccf31],
PUP.Optional.Conduit.A, C:\Users\Jana\AppData\Local\Temp\CT3300847\ddt.csf, In Quarantäne, [ea9db6c30d6e2f077a827c0e669ccf31],
PUP.Optional.Conduit.A, C:\Users\Jana\AppData\Local\Temp\CT3300847\initData.json, In Quarantäne, [ea9db6c30d6e2f077a827c0e669ccf31],
PUP.Optional.Conduit.A, C:\Users\Jana\AppData\Local\Temp\CT3300847\manifest.json, In Quarantäne, [ea9db6c30d6e2f077a827c0e669ccf31],
PUP.Optional.ASK.A, C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.search.ask.com/?o=APN10653A&gct=hp&d=1-1487&v=a12627-127&t=4",), Ersetzt,[592eb1c87b0080b679bcd5d321e3c23e]
Physische Sektoren: 0
(No malicious items detected)
(end) FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-06-2014
Ran by Jana (administrator) on VAIO on 17-06-2014 12:41:50
Running from C:\Users\Jana\Desktop
Platform: Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
(Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Users\Jana\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jana\AppData\Local\Google\Chrome\Application\chrome.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Google Inc.) C:\Users\Jana\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Jana\Desktop\FRST64 (1).exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-08-20] (Realtek Semiconductor)
HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64640 2012-08-13] ()
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-21] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [68776 2012-08-18] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [724576 2012-07-27] (Sony Corporation)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [152896 2012-06-25] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKU\S-1-5-21-429091727-3453439002-3370875811-1001\...\Run: [Google Update] => C:\Users\Jana\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-12-24] (Google Inc.)
HKU\S-1-5-21-429091727-3453439002-3370875811-1001\...\Run: [GoogleChromeAutoLaunch_675E120FA2C26CAA07713AAC7BB1A351] => C:\Users\Jana\AppData\Local\Google\Chrome\Application\chrome.exe [860488 2014-06-05] (Google Inc.)
HKU\S-1-5-21-429091727-3453439002-3370875811-1001\...\MountPoints2: {56d9fd2a-34c1-11e2-be69-806e6f6e6963} - "D:\Autorun.exe"
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://vaioportal.sony.eu
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://vaioportal.sony.eu
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {162B520A-5AD7-4B13-85CA-78176DE810E7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASEJS
SearchScopes: HKCU - {162B520A-5AD7-4B13-85CA-78176DE810E7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASEJS
SearchScopes: HKCU - {FAE5EBF0-5F2D-4E92-9751-6B95E696D42C} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q312&_nkw={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.5.0 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.0 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.5.0 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Jana\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Jana\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jana\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR StartupUrls: "https://www.google.de/webhp?sourceid=chrome-instant&rlz=1C1GTPM_deDE516DE516&ion=1&espv=2&ie=UTF-8"
CHR Plugin: (Shockwave Flash) - C:\Users\Jana\AppData\Local\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Jana\AppData\Local\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Jana\AppData\Local\Google\Chrome\Application\35.0.1916.153\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File
CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Unity Player) - C:\Users\Jana\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Google Update) - C:\Users\Jana\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.50.6) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (hxxp://web.de/) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\glbahjlmibhaljaclchckoghdjlmijcn [2013-08-07]
CHR Extension: (Google Wallet) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR HKLM-x32\...\Chrome\Extension: [aaaaihhnfnbnpbhpagnmoplpcjbediml] - C:\Users\Jana\AppData\Local\imeshmusicboxtoolbar\GC\toolbar.crx [2013-08-29]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-13] (Qualcomm Atheros Commnucations)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-08-06] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-08-06] (Intel Corporation)
S3 NetworkSupport; C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe [623784 2012-08-18] (Sony Corporation)
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [474208 2012-07-27] (Sony Corporation)
U2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [156672 2012-08-06] () [File not signed]
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [972000 2012-08-08] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-13] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-08-20] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-13] (Qualcomm Atheros)
R3 BTATH_VDP; C:\Windows\system32\drivers\btath_vdp.sys [427416 2012-08-13] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-21] (Synaptics Incorporated)
R3 SOWS; C:\Windows\System32\drivers\sows.sys [24280 2012-06-11] (Sony Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-17 11:48 - 2014-06-17 11:49 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-17 11:47 - 2014-06-17 11:47 - 00001338 _____ () C:\Users\Jana\Desktop\JRT.txt
2014-06-17 11:46 - 2014-06-17 11:46 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-17 11:46 - 2014-06-17 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-17 11:46 - 2014-06-17 11:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-17 11:46 - 2014-06-17 11:46 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-17 11:46 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-17 11:46 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-17 11:46 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-17 11:43 - 2014-06-17 11:43 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 08:25 - 2014-06-17 08:26 - 00000000 ____D () C:\AdwCleaner
2014-06-17 08:25 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-17 08:19 - 2014-06-17 08:17 - 01333465 _____ () C:\Users\Jana\Desktop\adwcleaner_3.212.exe
2014-06-17 08:18 - 2014-06-17 08:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Jana\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-17 08:18 - 2014-06-17 08:18 - 01016261 _____ (Thisisu) C:\Users\Jana\Desktop\JRT.exe
2014-06-17 08:18 - 2014-06-17 08:18 - 00001264 _____ () C:\Users\Jana\Desktop\Revo Uninstaller.lnk
2014-06-17 08:18 - 2014-06-17 08:18 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-17 08:17 - 2014-06-17 08:17 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Jana\Downloads\revosetup95.exe
2014-06-17 08:17 - 2014-06-17 08:17 - 01333465 _____ () C:\Users\Jana\Downloads\adwcleaner_3.212.exe
2014-06-16 14:35 - 2014-06-16 14:35 - 02081280 _____ (Farbar) C:\Users\Jana\Desktop\FRST64 (1).exe
2014-06-16 13:16 - 2014-06-16 13:17 - 00030849 _____ () C:\Users\Jana\Downloads\Addition.txt
2014-06-16 13:15 - 2014-06-17 12:41 - 00014787 _____ () C:\Users\Jana\Desktop\FRST.txt
2014-06-16 13:14 - 2014-06-17 12:41 - 00000000 ____D () C:\FRST
2014-06-16 13:14 - 2014-06-16 13:14 - 02081280 _____ (Farbar) C:\Users\Jana\Downloads\FRST64.exe
2014-06-15 12:47 - 2014-06-16 07:52 - 00000000 ____D () C:\Windows\system32\MpEngineStore
2014-06-15 12:44 - 2014-06-15 12:44 - 00000000 ____D () C:\6247352875ad5304acbe29
2014-06-14 09:43 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-14 09:43 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-14 09:42 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-14 09:42 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-14 09:42 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-14 09:42 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-14 09:42 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-14 09:42 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-14 09:42 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-14 09:42 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-14 09:42 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-14 09:42 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-14 09:42 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-14 09:42 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-14 09:42 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-14 09:42 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-14 09:42 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-14 09:42 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-14 09:42 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-14 09:42 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-14 09:42 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-14 09:42 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-14 09:42 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-14 09:42 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-14 09:42 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-14 09:42 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-14 09:42 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-14 09:42 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-14 09:41 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-14 09:41 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-14 09:41 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-05-28 16:09 - 2014-05-28 16:41 - 00006468 _____ () C:\Users\Jana\Documents\Klasse 8d.odt
2014-05-25 20:02 - 2014-05-25 20:02 - 02659296 _____ () C:\Users\Jana\Downloads\avira_speedup.exe
==================== One Month Modified Files and Folders =======
2014-06-17 12:42 - 2014-06-16 13:15 - 00014787 _____ () C:\Users\Jana\Desktop\FRST.txt
2014-06-17 12:42 - 2012-12-24 20:22 - 00000000 ____D () C:\Users\Jana\AppData\Local\Temp
2014-06-17 12:41 - 2014-06-16 13:14 - 00000000 ____D () C:\FRST
2014-06-17 12:40 - 2012-12-24 20:24 - 00000000 ___RD () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-17 12:40 - 2012-12-24 20:24 - 00000000 ___RD () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-06-17 12:39 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-17 12:38 - 2012-12-29 10:30 - 00000000 ___RD () C:\Windows\BrowserChoice
2014-06-17 12:38 - 2012-08-03 04:22 - 00119816 _____ () C:\Windows\PFRO.log
2014-06-17 12:36 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-06-17 12:36 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-17 12:36 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-17 12:36 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-06-17 12:35 - 2012-11-22 18:48 - 01118478 _____ () C:\Windows\WindowsUpdate.log
2014-06-17 12:35 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-06-17 12:35 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-06-17 12:35 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-06-17 12:10 - 2012-12-24 20:28 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-429091727-3453439002-3370875811-1001UA.job
2014-06-17 12:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-17 11:49 - 2014-06-17 11:48 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-17 11:47 - 2014-06-17 11:47 - 00001338 _____ () C:\Users\Jana\Desktop\JRT.txt
2014-06-17 11:46 - 2014-06-17 11:46 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-17 11:46 - 2014-06-17 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-17 11:46 - 2014-06-17 11:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-17 11:46 - 2014-06-17 11:46 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-17 11:43 - 2014-06-17 11:43 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 08:45 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-17 08:26 - 2014-06-17 08:25 - 00000000 ____D () C:\AdwCleaner
2014-06-17 08:23 - 2012-11-22 19:10 - 00000000 ____D () C:\ProgramData\Adobe
2014-06-17 08:18 - 2014-06-17 08:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Jana\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-17 08:18 - 2014-06-17 08:18 - 01016261 _____ (Thisisu) C:\Users\Jana\Desktop\JRT.exe
2014-06-17 08:18 - 2014-06-17 08:18 - 00001264 _____ () C:\Users\Jana\Desktop\Revo Uninstaller.lnk
2014-06-17 08:18 - 2014-06-17 08:18 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-17 08:17 - 2014-06-17 08:19 - 01333465 _____ () C:\Users\Jana\Desktop\adwcleaner_3.212.exe
2014-06-17 08:17 - 2014-06-17 08:17 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Jana\Downloads\revosetup95.exe
2014-06-17 08:17 - 2014-06-17 08:17 - 01333465 _____ () C:\Users\Jana\Downloads\adwcleaner_3.212.exe
2014-06-16 14:35 - 2014-06-16 14:35 - 02081280 _____ (Farbar) C:\Users\Jana\Desktop\FRST64 (1).exe
2014-06-16 13:17 - 2014-06-16 13:16 - 00030849 _____ () C:\Users\Jana\Downloads\Addition.txt
2014-06-16 13:14 - 2014-06-16 13:14 - 02081280 _____ (Farbar) C:\Users\Jana\Downloads\FRST64.exe
2014-06-16 07:52 - 2014-06-15 12:47 - 00000000 ____D () C:\Windows\system32\MpEngineStore
2014-06-16 07:52 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-16 07:50 - 2012-12-24 20:28 - 00001074 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-429091727-3453439002-3370875811-1001Core.job
2014-06-15 12:44 - 2014-06-15 12:44 - 00000000 ____D () C:\6247352875ad5304acbe29
2014-06-15 12:44 - 2013-08-16 07:14 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-15 12:44 - 2012-12-26 07:57 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-14 22:25 - 2012-12-24 20:22 - 00000000 ____D () C:\Users\Jana
2014-06-14 14:15 - 2012-12-24 20:30 - 00002313 _____ () C:\Users\Jana\Desktop\Google Chrome.lnk
2014-06-09 09:51 - 2012-12-24 20:29 - 00000000 ____D () C:\Users\Jana\AppData\Local\CrashDumps
2014-06-08 07:42 - 2012-11-22 18:24 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-06-08 07:42 - 2012-11-22 18:24 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-06-08 07:42 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-31 07:16 - 2013-11-18 15:17 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-31 07:16 - 2013-11-18 15:17 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-28 16:41 - 2014-05-28 16:09 - 00006468 _____ () C:\Users\Jana\Documents\Klasse 8d.odt
2014-05-28 13:49 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-25 20:02 - 2014-05-25 20:02 - 02659296 _____ () C:\Users\Jana\Downloads\avira_speedup.exe
2014-05-24 04:48 - 2014-06-14 09:42 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-24 04:47 - 2014-06-14 09:42 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-24 04:47 - 2014-06-14 09:42 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-24 04:47 - 2014-06-14 09:42 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-05-24 04:47 - 2014-06-14 09:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-24 04:46 - 2014-06-14 09:42 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-24 04:45 - 2014-06-14 09:42 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-24 04:45 - 2014-06-14 09:42 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-24 04:45 - 2014-06-14 09:42 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-24 03:26 - 2014-06-14 09:42 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-24 03:26 - 2014-06-14 09:42 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-24 03:26 - 2014-06-14 09:42 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-24 03:26 - 2014-06-14 09:42 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-24 03:26 - 2014-06-14 09:42 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-24 03:26 - 2014-06-14 09:42 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-24 03:26 - 2014-06-14 09:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-24 03:25 - 2014-06-14 09:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-24 03:25 - 2014-06-14 09:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-24 03:09 - 2014-06-14 09:42 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-24 03:03 - 2014-06-14 09:42 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-24 00:37 - 2014-06-14 09:42 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-05-22 13:56 - 2013-04-03 08:28 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-22 13:56 - 2013-04-03 08:28 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Some content of TEMP:
====================
C:\Users\Jana\AppData\Local\Temp\AskSLib.dll
C:\Users\Jana\AppData\Local\Temp\avgnt.exe
C:\Users\Jana\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\Jana\AppData\Local\Temp\EAD1196.exe
C:\Users\Jana\AppData\Local\Temp\EAD1338.exe
C:\Users\Jana\AppData\Local\Temp\EAD175F.exe
C:\Users\Jana\AppData\Local\Temp\EAD19FE.exe
C:\Users\Jana\AppData\Local\Temp\EAD1B58.exe
C:\Users\Jana\AppData\Local\Temp\EAD2258.exe
C:\Users\Jana\AppData\Local\Temp\EAD2502.exe
C:\Users\Jana\AppData\Local\Temp\EAD2680.exe
C:\Users\Jana\AppData\Local\Temp\EAD2A9B.exe
C:\Users\Jana\AppData\Local\Temp\EAD2E20.exe
C:\Users\Jana\AppData\Local\Temp\EAD306C.exe
C:\Users\Jana\AppData\Local\Temp\EAD31EB.exe
C:\Users\Jana\AppData\Local\Temp\EAD32D8.exe
C:\Users\Jana\AppData\Local\Temp\EAD3707.exe
C:\Users\Jana\AppData\Local\Temp\EAD39BE.exe
C:\Users\Jana\AppData\Local\Temp\EAD3CFF.exe
C:\Users\Jana\AppData\Local\Temp\EAD3E2D.exe
C:\Users\Jana\AppData\Local\Temp\EAD409F.exe
C:\Users\Jana\AppData\Local\Temp\EAD437A.exe
C:\Users\Jana\AppData\Local\Temp\EAD442F.exe
C:\Users\Jana\AppData\Local\Temp\EAD460F.exe
C:\Users\Jana\AppData\Local\Temp\EAD46D0.exe
C:\Users\Jana\AppData\Local\Temp\EAD495F.exe
C:\Users\Jana\AppData\Local\Temp\EAD4A04.exe
C:\Users\Jana\AppData\Local\Temp\EAD4CB3.exe
C:\Users\Jana\AppData\Local\Temp\EAD4D06.exe
C:\Users\Jana\AppData\Local\Temp\EAD4E0B.exe
C:\Users\Jana\AppData\Local\Temp\EAD4EA2.exe
C:\Users\Jana\AppData\Local\Temp\EAD54A0.exe
C:\Users\Jana\AppData\Local\Temp\EAD57C0.exe
C:\Users\Jana\AppData\Local\Temp\EAD5C1D.exe
C:\Users\Jana\AppData\Local\Temp\EAD5F80.exe
C:\Users\Jana\AppData\Local\Temp\EAD623B.exe
C:\Users\Jana\AppData\Local\Temp\EAD6681.exe
C:\Users\Jana\AppData\Local\Temp\EAD6FCC.exe
C:\Users\Jana\AppData\Local\Temp\EAD78C6.exe
C:\Users\Jana\AppData\Local\Temp\EAD792D.exe
C:\Users\Jana\AppData\Local\Temp\EAD7FA.exe
C:\Users\Jana\AppData\Local\Temp\EAD81DD.exe
C:\Users\Jana\AppData\Local\Temp\EAD8282.exe
C:\Users\Jana\AppData\Local\Temp\EAD8529.exe
C:\Users\Jana\AppData\Local\Temp\EAD8798.exe
C:\Users\Jana\AppData\Local\Temp\EAD890A.exe
C:\Users\Jana\AppData\Local\Temp\EAD8910.exe
C:\Users\Jana\AppData\Local\Temp\EAD8C18.exe
C:\Users\Jana\AppData\Local\Temp\EAD8DA1.exe
C:\Users\Jana\AppData\Local\Temp\EAD8ECA.exe
C:\Users\Jana\AppData\Local\Temp\EAD9531.exe
C:\Users\Jana\AppData\Local\Temp\EAD972A.exe
C:\Users\Jana\AppData\Local\Temp\EAD984D.exe
C:\Users\Jana\AppData\Local\Temp\EAD9A28.exe
C:\Users\Jana\AppData\Local\Temp\EAD9C13.exe
C:\Users\Jana\AppData\Local\Temp\EAD9CEE.exe
C:\Users\Jana\AppData\Local\Temp\EAD9DEE.exe
C:\Users\Jana\AppData\Local\Temp\EAD9FA6.exe
C:\Users\Jana\AppData\Local\Temp\EADA09B.exe
C:\Users\Jana\AppData\Local\Temp\EADA30A.exe
C:\Users\Jana\AppData\Local\Temp\EADA3C.exe
C:\Users\Jana\AppData\Local\Temp\EADA593.exe
C:\Users\Jana\AppData\Local\Temp\EADAC10.exe
C:\Users\Jana\AppData\Local\Temp\EADAD2.exe
C:\Users\Jana\AppData\Local\Temp\EADADC7.exe
C:\Users\Jana\AppData\Local\Temp\EADAF88.exe
C:\Users\Jana\AppData\Local\Temp\EADB026.exe
C:\Users\Jana\AppData\Local\Temp\EADB1F0.exe
C:\Users\Jana\AppData\Local\Temp\EADB4DF.exe
C:\Users\Jana\AppData\Local\Temp\EADB815.exe
C:\Users\Jana\AppData\Local\Temp\EADB911.exe
C:\Users\Jana\AppData\Local\Temp\EADBA10.exe
C:\Users\Jana\AppData\Local\Temp\EADBCA1.exe
C:\Users\Jana\AppData\Local\Temp\EADC6DB.exe
C:\Users\Jana\AppData\Local\Temp\EADCB3E.exe
C:\Users\Jana\AppData\Local\Temp\EADCBE2.exe
C:\Users\Jana\AppData\Local\Temp\EADCD2E.exe
C:\Users\Jana\AppData\Local\Temp\EADD48F.exe
C:\Users\Jana\AppData\Local\Temp\EADD529.exe
C:\Users\Jana\AppData\Local\Temp\EADDEB5.exe
C:\Users\Jana\AppData\Local\Temp\EADDF7E.exe
C:\Users\Jana\AppData\Local\Temp\EADE058.exe
C:\Users\Jana\AppData\Local\Temp\EADE0B.exe
C:\Users\Jana\AppData\Local\Temp\EADE22B.exe
C:\Users\Jana\AppData\Local\Temp\EADE6A1.exe
C:\Users\Jana\AppData\Local\Temp\EADE783.exe
C:\Users\Jana\AppData\Local\Temp\EADEBCD.exe
C:\Users\Jana\AppData\Local\Temp\EADEC7.exe
C:\Users\Jana\AppData\Local\Temp\EADEEA1.exe
C:\Users\Jana\AppData\Local\Temp\EADF722.exe
C:\Users\Jana\AppData\Local\Temp\EADF90E.exe
C:\Users\Jana\AppData\Local\Temp\EADFA99.exe
C:\Users\Jana\AppData\Local\Temp\EADFD1D.exe
C:\Users\Jana\AppData\Local\Temp\EADFD27.exe
C:\Users\Jana\AppData\Local\Temp\MybabylonTB.exe
C:\Users\Jana\AppData\Local\Temp\ose00000.exe
C:\Users\Jana\AppData\Local\Temp\propsys.dll
C:\Users\Jana\AppData\Local\Temp\Quarantine.exe
C:\Users\Jana\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\Jana\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Jana\AppData\Local\Temp\{B1DC3679-C0DD-4319-A09C-9C9DD9EEF80E}-GoogleUpdateSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-16 13:29
==================== End Of Log ============================ --- --- --- |