jojo1812 | 11.07.2014 17:43 | Mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 11.07.2014
Suchlauf-Zeit: 17:27:46
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.11.06
Rootkit Datenbank: v2014.07.09.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Jo Lehrmann
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 326419
Verstrichene Zeit: 9 Min, 0 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 7
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Wd\wd.exe, 6844, Löschen bei Neustart, [4ef4b1edc7b449ed535d1cbc877bb14f]
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Proxy\pwdg.exe, 7592, Löschen bei Neustart, [0d359608df9cce681227d4f537cbe719]
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe, 7420, Löschen bei Neustart, [7bc7fba3b0cb251140f455bb9d679a66]
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancer.exe, 7748, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa]
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bservice.exe, 4224, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce]
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe, 3708, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce]
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Proxy\proc.exe, 2164, Löschen bei Neustart, [8eb4a1fdff7ca88e16e86446ee147a86]
Module: 13
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\FiddlerCore.dll, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\Newtonsoft.Json.dll, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
Registrierungsschlüssel: 12
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\System Speedup_is1, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\Wajam, In Quarantäne, [21219e00b0cb2e08c079ed2383812cd4],
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\BENCH\BService, In Quarantäne, [73cfc2dc99e244f265a393319c662ed2],
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\BENCH\InstalledExtensions, In Quarantäne, [a69ca3fb86f5f83e6b9ed9eb3dc533cd],
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\BENCH\NmHost, In Quarantäne, [72d06638225940f611f9bf05a55db54b],
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\BENCH\Updater, In Quarantäne, [063cdbc393e8c1755bb04b79b74bde22],
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\com.bench.nmhost, In Quarantäne, [af93b0ee6b10de583bc6ca4455af15eb],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [0240e0be2e4d8da913d4befb7b87b24e],
PUP.Optional.Wajam.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wajam Internet Enhancer Service, In Quarantäne, [7bc7fba3b0cb251140f455bb9d679a66],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-579152262-525530005-515234496-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [271b930b56254de93ea87742d1316898],
PUP.Optional.Wajam.A, HKU\S-1-5-21-579152262-525530005-515234496-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM, In Quarantäne, [54ee9c02710a70c65c943fb901021fe1],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Wajam, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
Registrierungswerte: 7
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Wd, C:\Program Files (x86)\Bench\Wd\wd.exe, In Quarantäne, [4ef4b1edc7b449ed535d1cbc877bb14f]
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Communicator Watcher, C:\Program Files (x86)\Bench\Proxy\pwdg.exe, In Quarantäne, [0d359608df9cce681227d4f537cbe719]
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Settings Cleaner, C:\Program Files (x86)\Bench\Proxy\cl.exe, In Quarantäne, [1230633bc8b3e84e95a557726c96e21e]
PUP.Optional.SmartApps, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|SafetySearch-repairJob, wscript.exe "C:\Users\Johannes\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob", In Quarantäne, [340e4d514635d066e9dad23cda2a758b]
PUP.Optional.Wajam.A, HKU\S-1-5-21-579152262-525530005-515234496-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM|affiliate_id, 1401, In Quarantäne, [54ee9c02710a70c65c943fb901021fe1]
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BService, C:\Program Files (x86)\Bench\BService\1.1\bservice.exe, In Quarantäne, [9ea4edb1cface2541254574a2dd532ce]
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BService64, C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe, In Quarantäne, [9ea4edb1cface2541254574a2dd532ce]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 18
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup, In Quarantäne, [5ae84b538eedba7c3ea661582cd6d62a],
PUP.Optional.BenchUpdater, C:\Program Files (x86)\Bench\NmHost, In Quarantäne, [e75b4559fa812412121b25bb35cdb749],
PUP.Optional.BenchUpdater.A, C:\Users\Johannes\AppData\Local\BenchUpdater, In Quarantäne, [fe445e402a51c472e05c14cd917124dc],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater, In Quarantäne, [350d0e90a3d89d9966190f8f3dc5d729],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\1.7.0.0, In Quarantäne, [350d0e90a3d89d9966190f8f3dc5d729],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Wd, Löschen bei Neustart, [f64ceab42d4e25116403e0c1cb370cf4],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Proxy, Löschen bei Neustart, [8eb4a1fdff7ca88e16e86446ee147a86],
PUP.Optional.SystemSpeedup, C:\Users\Johannes\AppData\Roaming\Systweak\ssd, In Quarantäne, [c181adf15f1c171fdd5acbeb03ffce32],
Dateien: 155
PUP.Optional.AppInstaller, C:\Users\Johannes\AppData\Local\Temp\n2011\FLVMPlayerSetup-c45490cb.exe, In Quarantäne, [ec5647570c6f6ccaed75bccb0001c43c],
PUP.Optional.BundleInstaller.A, C:\Users\Johannes\AppData\Local\Temp\n2011\s2011.exe, In Quarantäne, [78cab3ebbfbc0333fe5b47040df328d8],
PUP.Optional.Wajam.A, C:\Users\Johannes\AppData\Local\Temp\n2011\wajam_2207-6c14163c.exe, In Quarantäne, [d072c4dae99242f4030a66e144bcd030],
PUP.Optional.SystemSpeedup, C:\Windows\Tasks\System Speedup_DEFAULT.job, In Quarantäne, [172bb4ea2853cf6792f7c6f32cd60cf4],
PUP.Optional.SystemSpeedup, C:\Windows\System32\Tasks\System Speedup_DEFAULT, In Quarantäne, [7fc3ebb3d2a991a561297841cc3604fc],
PUP.Optional.SystemSpeedup, C:\Windows\Tasks\System Speedup_UPDATES.job, In Quarantäne, [5fe3dbc34c2f66d0f09bfcbdcd350cf4],
PUP.Optional.SystemSpeedup, C:\Windows\System32\Tasks\System Speedup_UPDATES, In Quarantäne, [083a524ccbb0ae88f39933861ce656aa],
PUP.Optional.SystemSpeedup, C:\Users\Public\Desktop\System Speedup.lnk, In Quarantäne, [cd7599052f4cc37329b92c8dec162bd5],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\SystemSpeedup.exe, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\eng_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\russian_rcp_ru.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\BeforeUninstall.exe, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Chinese_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Chinese_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\CleanSchedule.exe, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Danish_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Danish_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Dutch_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Dutch_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\eng_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Japanese_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Japanese_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\korean_rcp_ko.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\korean_uninst_ko.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Norwegian_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Norwegian_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\polish_rcp_pl.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\polish_uninst_pl.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\portugese_rcp_pt.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\portugese_uninst_pt.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Portuguese_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Portuguese_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\RegCleanPro.dll, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Finnish_rcp_fi.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Finnish_uninst_fi.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\French_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\French_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\German_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\German_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\greek_rcp_el.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\greek_uninst_el.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\install_left_image.bmp, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\isxdl.dll, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Italian_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Italian_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\russian_uninst_ru.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Spanish_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\spanish_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Swedish_rcp.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\swedish_uninst.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\systweakasp.exe, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\TPS.ico, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\TraditionalCn_rcp_zh-tw.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\traditionalcn_uninst_zh-tw.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\turkish_rcp_tr.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\Turkish_uninst_tr.ini, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\unins000.dat, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\unins000.exe, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\unins000.msg, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\Program Files (x86)\System Speedup\xmllite.dll, In Quarantäne, [65ddfea00c6fe650974cf1c8d13146ba],
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup\System Speedup.lnk, In Quarantäne, [5ae84b538eedba7c3ea661582cd6d62a],
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup\Register System Speedup.lnk, In Quarantäne, [5ae84b538eedba7c3ea661582cd6d62a],
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup\System Speedup entfernen.lnk, In Quarantäne, [5ae84b538eedba7c3ea661582cd6d62a],
PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-S-1-5-21-579152262-525530005-515234496-1002, In Quarantäne, [7bc7910ddba0ad896c0b506cb0524cb4],
PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-sys, In Quarantäne, [b58d75292e4d66d02552d0ec48baca36],
PUP.Optional.BenchUpdater, C:\Program Files (x86)\Bench\NmHost\nmhost.exe, In Quarantäne, [e75b4559fa812412121b25bb35cdb749],
PUP.Optional.BenchUpdater, C:\Program Files (x86)\Bench\NmHost\manifest.json, In Quarantäne, [e75b4559fa812412121b25bb35cdb749],
PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-S-1-5-21-579152262-525530005-515234496-1002.job, In Quarantäne, [de649707661574c21229a041ca38847c],
PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-sys.job, In Quarantäne, [57ebe3bbbbc01b1ba893b72a08fa01ff],
PUP.Optional.BenchUpdater.A, C:\Users\Johannes\AppData\Local\BenchUpdater\products.xml, In Quarantäne, [fe445e402a51c472e05c14cd917124dc],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Wd\wd.exe, Löschen bei Neustart, [4ef4b1edc7b449ed535d1cbc877bb14f],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Proxy\pwdg.exe, Löschen bei Neustart, [0d359608df9cce681227d4f537cbe719],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Proxy\cl.exe, In Quarantäne, [1230633bc8b3e84e95a557726c96e21e],
PUP.Optional.SmartApps, C:\Users\Johannes\AppData\Local\SafetySearch\repair.js, In Quarantäne, [340e4d514635d066e9dad23cda2a758b],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe, Löschen bei Neustart, [7bc7fba3b0cb251140f455bb9d679a66],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\uninstall.exe, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\amazon.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\argos.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\ask.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\bestbuy.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\ebay.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\etsy.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\facebook.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\favicon.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\google.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\homedepot.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\ikea.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\imdb.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\lowes.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\mercado.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\mysearchweb.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\myshopping.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\searchresult.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\sears.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\setting.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\settings.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\shopping.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\target.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\tesco.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\tripadvisor.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\twitter.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\wajam.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\walmart.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\wiki.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\yahoo.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\zalando.ico, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\2845734c09907de22309ed6090c7c5b9, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\5e3eed8d71e51fe2acf6b93a5c860ab2, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\8709317cf4c8a5379fcb0faeebabac8c, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\a12534f1688fe7d400f8d5ec8c062411, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\FiddlerCore.dll, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\HtmlAgilityPack.dll, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\makecert.exe, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\Newtonsoft.Json.dll, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamHttpServer.exe, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancer.exe, Löschen bei Neustart, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\wie, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WJManifest, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WJProxyTools.exe, In Quarantäne, [ec56f2acbfbc82b446c7c6d743bf06fa],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\products.xml, In Quarantäne, [350d0e90a3d89d9966190f8f3dc5d729],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\updater.exe, In Quarantäne, [350d0e90a3d89d9966190f8f3dc5d729],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\1.7.0.0\updater.exe, In Quarantäne, [350d0e90a3d89d9966190f8f3dc5d729],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Settings.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Facebook.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Twitter.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Wajam Website.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Ask.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Google.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\IMDb.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Shopping.com.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\TripAdvisor.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Wikipedia.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Yahoo!.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Amazon.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Argos.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ebay.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Etsy.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\HomeDepot.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ikea.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Lowe's.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Mercadolivre.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\MyShopping.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Sears.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Target.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Tesco.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Walmart.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Zalando.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam\uninstall.lnk, In Quarantäne, [be84bbe335462511c8f17d21b44eee12],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bhelper64.dll, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bservice.exe, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe, Löschen bei Neustart, [9ea4edb1cface2541254574a2dd532ce],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Proxy\icon.ico, In Quarantäne, [8eb4a1fdff7ca88e16e86446ee147a86],
PUP.Optional.Bench.A, C:\Program Files (x86)\Bench\Proxy\proc.exe, Löschen bei Neustart, [8eb4a1fdff7ca88e16e86446ee147a86],
PUP.Optional.SystemSpeedup, C:\Users\Johannes\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [c181adf15f1c171fdd5acbeb03ffce32],
Physische Sektoren: 0
(No malicious items detected)
(end) Adw Cleaner Code:
# AdwCleaner v3.215 - Bericht erstellt am 11/07/2014 um 18:15:23
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Jo Lehrmann - JOLEHRMANN
# Gestartet von : C:\Users\Johannes\AppData\Local\Microsoft\Windows\INetCache\IE\Z0P6TESI\adwcleaner_3.215.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Bench
Ordner Gelöscht : C:\Program Files (x86)\FLVM Player
Ordner Gelöscht : C:\Users\Johannes\AppData\Roaming\System Speedup
Ordner Gelöscht : C:\Users\Johannes\AppData\Roaming\Systweak
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS
Schlüssel Gelöscht : HKCU\Software\System Speedup
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\System Speedup
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Google Chrome v
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [12749 octets] - [28/01/2014 23:01:08]
AdwCleaner[R1].txt - [30212 octets] - [03/07/2014 23:47:33]
AdwCleaner[R2].txt - [9782 octets] - [08/07/2014 20:55:04]
AdwCleaner[R3].txt - [5702 octets] - [08/07/2014 21:28:51]
AdwCleaner[R4].txt - [3478 octets] - [11/07/2014 18:13:17]
AdwCleaner[S0].txt - [9266 octets] - [28/01/2014 23:02:41]
AdwCleaner[S1].txt - [14766 octets] - [03/07/2014 23:48:32]
AdwCleaner[S2].txt - [4233 octets] - [08/07/2014 21:37:27]
AdwCleaner[S3].txt - [3291 octets] - [11/07/2014 18:15:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [3351 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Jo Lehrmann on 11.07.2014 at 18:19:41,36
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.07.2014 at 18:23:38,60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014
Ran by Jo Lehrmann (administrator) on JOLEHRMANN on 11-07-2014 18:34:54
Running from C:\Users\Johannes\AppData\Local\Microsoft\Windows\INetCache\IE\Z0P6TESI
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
() C:\Windows\System32\profextd.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-05-22] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [131712 2013-01-25] ( (Atheros Communications))
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-579152262-525530005-515234496-1001\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516608 2013-08-22] (Microsoft Corporation)
HKU\S-1-5-21-579152262-525530005-515234496-1002\...\MountPoints2: {8eac516a-d9f9-11e3-be9e-3c77e65d0496} - "E:\HTC_Sync_Manager_PC.exe"
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {99789B29-C252-4374-B501-76174D17EB5F} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {99789B29-C252-4374-B501-76174D17EB5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - DefaultScope {99789B29-C252-4374-B501-76174D17EB5F} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKCU - {99789B29-C252-4374-B501-76174D17EB5F} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: DownloadProtect Extension - {C654F3FE-8E84-4BB7-87CF-8D9171FC3C73} - C:\Program Files\{BF383C42-B9F2-4E89-87A9-5CCF49AD4CD8}\{5A40C85E-65CD-49BD-8F21-3D2152009E4F}.bin (Download Protect)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-03-09]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-03-09]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-03-09]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-03-09]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-03-09]
FF HKLM-x32\...\Firefox\Extensions: [{E2B2D0E7-6FA3-4056-99B9-B77244F90DFC}] - C:\WINDOWS\Installer\{68C802A5-2967-4E5B-9754-F2B8DBAB1106}\{E2B2D0E7-6FA3-4056-99B9-B77244F90DFC}.xpi
FF Extension: Download Protect - C:\WINDOWS\Installer\{68C802A5-2967-4E5B-9754-F2B8DBAB1106}\{E2B2D0E7-6FA3-4056-99B9-B77244F90DFC}.xpi [2014-05-24]
FF HKLM-x32\...\Firefox\Extensions: [{038F7C2F-4F03-48D5-9366-646F0CF3D5F8}] - C:\WINDOWS\Installer\{7DE888E3-FAC8-44B9-94AB-F17534D57E03}\{038F7C2F-4F03-48D5-9366-646F0CF3D5F8}.xpi
FF Extension: Download Protect - C:\WINDOWS\Installer\{7DE888E3-FAC8-44B9-94AB-F17534D57E03}\{038F7C2F-4F03-48D5-9366-646F0CF3D5F8}.xpi [2014-07-08]
Chrome:
=======
CHR HomePage: hxxp://www.google.de?hl=de&gl=de
CHR Extension: (Google Docs) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-08]
CHR Extension: (Google Drive) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-08]
CHR Extension: (YouTube) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-08]
CHR Extension: (Google-Suche) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-08]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-03-09]
CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-05-30]
CHR Extension: (Download Protect) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihkebkimdfeodjmpogjbjbjdniiglimc [2014-07-08]
CHR Extension: (Virtual Keyboard) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-03-09]
CHR Extension: (Google Wallet) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-08]
CHR Extension: (Google Mail) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-08]
CHR Extension: (Anti-Banner) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-03-09]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-25] (Qualcomm Atheros Commnucations)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated)
R2 cscriptd; C:\Windows\system32\profextd.exe [118784 2014-01-09] () [File not signed]
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [470056 2013-04-30] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-17] (WildTangent)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-01-30] (Intel Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2175264 2014-07-09] (IObit)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-06-17] (Acer Incorporate)
S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4230016 2013-01-28] (Symantec Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-24] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-03-09] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2014-03-09] (Kaspersky Lab)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [115296 2014-03-25] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625760 2014-03-25] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-03-09] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [65120 2014-03-25] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178272 2014-03-09] (Kaspersky Lab ZAO)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-11 18:31 - 2014-07-11 18:31 - 02084864 _____ (Farbar) C:\Users\Johannes\Downloads\FRST64.exe
2014-07-11 18:23 - 2014-07-11 18:23 - 00000620 _____ () C:\Users\Johannes\Desktop\JRT.txt
2014-07-11 18:19 - 2014-07-11 18:19 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-11 18:11 - 2014-07-11 18:11 - 00031146 _____ () C:\Users\Johannes\Desktop\mbam.txt
2014-07-11 17:26 - 2014-07-11 18:10 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-11 17:26 - 2014-07-11 17:26 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-11 17:26 - 2014-07-11 17:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-11 17:26 - 2014-07-11 17:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-11 17:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-07-11 17:26 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-07-11 17:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-07-11 17:09 - 2014-07-11 17:09 - 00001280 _____ () C:\Users\Johannes\Desktop\Revo Uninstaller.lnk
2014-07-11 17:09 - 2014-07-11 17:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-11 17:08 - 2014-07-11 17:09 - 00000003 _____ () C:\Users\Johannes\AppData\Local\proxy.log
2014-07-11 17:08 - 2014-07-11 17:08 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Johannes\Desktop\revosetup.exe
2014-07-11 17:08 - 2014-07-11 17:08 - 00003132 _____ () C:\WINDOWS\System32\Tasks\System Speedup
2014-07-10 18:26 - 2014-07-11 18:34 - 00000000 ____D () C:\FRST
2014-07-10 18:19 - 2014-07-11 18:16 - 00044814 _____ () C:\WINDOWS\PFRO.log
2014-07-09 23:02 - 2014-07-09 23:02 - 00000187 _____ () C:\WINDOWS\setupact.log
2014-07-09 23:02 - 2014-07-09 23:02 - 00000178 _____ () C:\WINDOWS\setuperr.log
2014-07-09 23:00 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2014-07-09 22:59 - 2014-07-09 22:59 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-07-09 21:21 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2014-07-09 21:21 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2014-07-09 21:21 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-07-09 21:21 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-07-09 21:21 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-07-09 21:21 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-07-09 21:21 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-07-09 21:21 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-07-09 21:21 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-07-09 21:21 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-07-09 21:20 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-07-09 21:20 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-07-09 21:20 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-07-09 21:20 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-07-09 21:20 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-07-09 21:20 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-07-09 21:20 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-07-09 21:20 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-07-09 21:20 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-07-09 21:20 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-07-09 21:20 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-07-09 21:20 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-07-09 21:20 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-07-09 21:20 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-07-09 21:20 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-07-09 21:20 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-07-09 21:20 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-07-09 21:20 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-07-09 21:20 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-07-09 21:20 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-07-09 21:20 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-07-09 21:20 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-07-09 21:20 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-07-09 21:20 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-07-09 21:20 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-07-09 21:20 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-07-09 21:20 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-07-09 21:19 - 2014-07-01 00:45 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-07-09 21:19 - 2014-06-28 09:48 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-07-09 21:19 - 2014-06-28 09:07 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2014-07-09 21:19 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-07-09 21:19 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-07-09 21:19 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-07-09 21:19 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-07-09 21:19 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-07-09 21:19 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-07-09 21:19 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 21:19 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-07-09 21:19 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-07-09 21:19 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 21:19 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-07-09 21:19 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-07-09 21:19 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-07-09 21:19 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-07-09 21:19 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-07-09 21:19 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2014-07-09 21:19 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-07-09 21:14 - 2014-07-09 21:14 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-07-09 21:13 - 2014-07-11 18:14 - 00283654 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-09 00:22 - 2014-07-09 00:22 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\ProductData
2014-07-09 00:21 - 2014-07-09 00:22 - 00000000 ____D () C:\ProgramData\ProductData
2014-07-09 00:21 - 2014-07-09 00:22 - 00000000 ____D () C:\ProgramData\IObit
2014-07-09 00:21 - 2014-07-09 00:21 - 12906784 _____ (IObit) C:\Users\Johannes\Downloads\iobituninstaller_3.3.8.exe
2014-07-09 00:21 - 2014-07-09 00:21 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\IObit
2014-07-09 00:21 - 2014-07-09 00:21 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-07-08 21:42 - 2014-07-08 21:42 - 00000000 ____D () C:\Program Files\{BF383C42-B9F2-4E89-87A9-5CCF49AD4CD8}
2014-07-08 21:42 - 2014-07-08 21:42 - 00000000 ____D () C:\Program Files (x86)\{48C67497-55E6-47C2-9669-A39128A58E17}
2014-07-08 21:28 - 2014-07-08 21:28 - 01346519 _____ () C:\Users\Johannes\Downloads\adwcleaner_3.214 (3).exe
2014-07-08 20:54 - 2014-07-08 20:54 - 01346519 _____ () C:\Users\Johannes\Downloads\adwcleaner_3.214 (2).exe
2014-07-08 20:54 - 2014-07-08 20:54 - 01346519 _____ () C:\Users\Johannes\Downloads\adwcleaner_3.214 (1).exe
2014-07-08 20:42 - 2014-07-08 20:42 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Johannes\Downloads\mbam-setup-2.0.2.1012_CB-DL-Manager [1].exe
2014-07-08 20:42 - 2014-07-08 20:42 - 00788832 _____ ( ) C:\Users\Johannes\Downloads\mbam-setup-2.0.2.1012_CB-DL-Manager.exe
2014-07-03 23:48 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-07-03 23:06 - 2014-07-08 20:51 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Network_Me_07032106
2014-07-03 23:06 - 2014-07-03 23:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-03 23:05 - 2014-07-03 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader
2014-06-29 21:04 - 2014-06-29 21:09 - 00000000 ____D () C:\Users\Johannes\Desktop\Urlaub Fritz
2014-06-29 20:18 - 2014-07-11 17:50 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-06-29 20:18 - 2014-07-08 20:50 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-06-29 20:18 - 2014-06-29 20:18 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Macromedia
2014-06-28 15:13 - 2014-06-28 15:13 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Mozilla
2014-06-28 15:13 - 2014-06-28 15:13 - 00000000 ____D () C:\ProgramData\Mozilla
2014-06-19 15:11 - 2014-06-26 22:55 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-06-19 15:11 - 2014-06-26 22:55 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 19:14 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-06-11 19:14 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-06-11 19:14 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-06-11 19:14 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-06-11 19:14 - 2014-02-06 13:30 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-06-11 19:14 - 2014-02-06 13:07 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-06-11 19:14 - 2014-02-06 13:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-06-11 19:14 - 2014-02-06 12:56 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-06-11 19:14 - 2014-02-06 12:49 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-06-11 19:14 - 2014-02-06 12:48 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-06-11 19:14 - 2014-02-06 12:17 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-06-11 19:14 - 2014-02-06 12:00 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-06-11 19:14 - 2014-02-06 11:52 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-06-11 19:14 - 2014-02-06 11:52 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-06-11 19:14 - 2014-02-06 11:47 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-06-11 19:14 - 2014-02-06 11:25 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-06-11 19:13 - 2014-05-10 05:46 - 02151424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-06-11 19:13 - 2014-05-10 05:22 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-06-11 19:13 - 2014-05-09 01:06 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2014-06-11 19:13 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-06-11 19:13 - 2014-04-30 13:16 - 01336648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-06-11 19:13 - 2014-04-30 05:51 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-06-11 19:13 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-06-11 19:13 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-06-11 19:13 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-06-11 19:13 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2014-06-11 19:13 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-06-11 19:13 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-06-11 19:13 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-06-11 19:13 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-06-11 19:13 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-06-11 19:13 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2014-06-11 19:13 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2014-06-11 19:13 - 2014-04-11 08:13 - 01200128 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2014-06-11 19:13 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2014-06-11 19:13 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2014-06-11 19:13 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2014-06-11 19:13 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-06-11 19:13 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2014-06-11 19:13 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
2014-06-11 19:13 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2014-06-11 19:13 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2014-06-11 19:13 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2014-06-11 19:13 - 2014-04-06 18:34 - 00275800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2014-06-11 19:13 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2014-06-11 19:13 - 2014-04-06 18:31 - 21268952 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-06-11 19:13 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2014-06-11 19:13 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2014-06-11 19:13 - 2014-04-06 18:20 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-06-11 19:13 - 2014-04-06 18:20 - 00233912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2014-06-11 19:13 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2014-06-11 19:13 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2014-06-11 19:13 - 2014-04-06 17:22 - 18755672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-06-11 19:13 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2014-06-11 19:13 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2014-06-11 19:13 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll
2014-06-11 19:13 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2014-06-11 19:13 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2014-06-11 19:13 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2014-06-11 19:13 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srclient.dll
2014-06-11 19:13 - 2014-04-06 13:55 - 16872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-06-11 19:13 - 2014-04-06 13:54 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2014-06-11 19:13 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2014-06-11 19:13 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-06-11 19:13 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-06-11 19:13 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-06-11 19:13 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2014-06-11 19:13 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-06-11 19:13 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2014-06-11 19:13 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2014-06-11 19:13 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2014-06-11 19:13 - 2014-04-03 10:12 - 02124840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-06-11 19:13 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2014-06-11 19:13 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2014-06-11 19:13 - 2014-04-03 09:59 - 02518872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-06-11 19:13 - 2014-04-03 09:59 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-06-11 19:13 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2014-06-11 19:13 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll
2014-06-11 19:13 - 2014-04-03 05:53 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2014-06-11 19:13 - 2014-04-03 04:53 - 04269056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-06-11 19:13 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-06-11 19:13 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2014-06-11 19:13 - 2014-04-03 04:23 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-06-11 19:13 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tlscsp.dll
2014-06-11 19:13 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll
2014-06-11 19:13 - 2014-04-01 08:23 - 00384856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-06-11 19:13 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-06-11 19:13 - 2014-03-31 02:41 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2014-06-11 19:13 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2014-06-11 19:13 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2014-06-11 19:13 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2014-06-11 19:13 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-06-11 19:13 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2014-06-11 19:13 - 2014-03-31 00:11 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-06-11 19:13 - 2014-03-30 23:47 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-06-11 19:13 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2014-06-11 19:13 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2014-06-11 19:13 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2014-06-11 19:13 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2014-06-11 19:13 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2014-06-11 19:13 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2014-06-11 19:13 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2014-06-11 19:13 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2014-06-11 19:13 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2014-06-11 19:13 - 2014-03-25 00:58 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-06-11 19:13 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-06-11 19:13 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-06-11 19:13 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-06-11 19:13 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2014-06-11 19:13 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2014-06-11 19:13 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2014-06-11 19:13 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2014-06-11 19:13 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-06-11 19:13 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2014-06-11 19:13 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2014-06-11 19:13 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2014-06-11 19:13 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2014-06-11 19:13 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-06-11 19:13 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2014-06-11 19:13 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2014-06-11 19:13 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-06-11 19:13 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-06-11 19:13 - 2014-03-18 10:19 - 00077312 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2014-06-11 19:13 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2014-06-11 19:13 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2014-06-11 19:13 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-06-11 19:13 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2014-06-11 19:13 - 2014-03-17 05:01 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2014-06-11 19:13 - 2014-03-17 04:47 - 01025024 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-06-11 19:13 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2014-06-11 19:13 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2014-06-11 19:13 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2014-06-11 19:13 - 2014-03-06 14:42 - 00310616 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-06-11 19:12 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvcfg.exe
2014-06-11 19:12 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2014-06-11 19:12 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvinst.exe
2014-06-11 19:12 - 2014-05-01 15:31 - 03048904 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-06-11 19:12 - 2014-05-01 15:31 - 00055328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2014-06-11 19:12 - 2014-05-01 09:14 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-06-11 19:12 - 2014-05-01 09:05 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-06-11 19:12 - 2014-05-01 08:51 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2014-06-11 19:12 - 2014-05-01 07:24 - 02834944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2014-06-11 19:12 - 2014-04-30 06:43 - 01975296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2014-06-11 19:12 - 2014-04-30 06:26 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2014-06-11 19:12 - 2014-04-30 05:47 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2014-06-11 19:11 - 2014-06-11 19:11 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
==================== One Month Modified Files and Folders =======
2014-07-11 18:34 - 2014-07-10 18:26 - 00000000 ____D () C:\FRST
2014-07-11 18:31 - 2014-07-11 18:31 - 02084864 _____ (Farbar) C:\Users\Johannes\Downloads\FRST64.exe
2014-07-11 18:26 - 2014-01-08 14:20 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-579152262-525530005-515234496-1002
2014-07-11 18:23 - 2014-07-11 18:23 - 00000620 _____ () C:\Users\Johannes\Desktop\JRT.txt
2014-07-11 18:19 - 2014-07-11 18:19 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-11 18:18 - 2014-01-16 22:41 - 00000000 __RDO () C:\Users\Johannes\SkyDrive
2014-07-11 18:16 - 2014-07-10 18:19 - 00044814 _____ () C:\WINDOWS\PFRO.log
2014-07-11 18:16 - 2014-03-09 20:26 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-07-11 18:16 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-11 18:16 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-07-11 18:15 - 2014-01-28 23:00 - 00000000 ____D () C:\AdwCleaner
2014-07-11 18:14 - 2014-07-09 21:13 - 00283654 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-11 18:11 - 2014-07-11 18:11 - 00031146 _____ () C:\Users\Johannes\Desktop\mbam.txt
2014-07-11 18:10 - 2014-07-11 17:26 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-11 18:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-07-11 17:58 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-07-11 17:50 - 2014-06-29 20:18 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-11 17:46 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\PLA
2014-07-11 17:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-07-11 17:26 - 2014-07-11 17:26 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-11 17:26 - 2014-07-11 17:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-11 17:26 - 2014-07-11 17:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-11 17:09 - 2014-07-11 17:09 - 00001280 _____ () C:\Users\Johannes\Desktop\Revo Uninstaller.lnk
2014-07-11 17:09 - 2014-07-11 17:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-11 17:09 - 2014-07-11 17:08 - 00000003 _____ () C:\Users\Johannes\AppData\Local\proxy.log
2014-07-11 17:08 - 2014-07-11 17:08 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Johannes\Desktop\revosetup.exe
2014-07-11 17:08 - 2014-07-11 17:08 - 00003132 _____ () C:\WINDOWS\System32\Tasks\System Speedup
2014-07-10 18:19 - 2013-08-22 16:44 - 00360464 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-09 23:15 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-07-09 23:15 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-09 23:15 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-09 23:15 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-07-09 23:08 - 2013-11-14 09:27 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-09 23:08 - 2013-11-14 09:11 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat
2014-07-09 23:08 - 2013-11-14 09:11 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat
2014-07-09 23:02 - 2014-07-09 23:02 - 00000187 _____ () C:\WINDOWS\setupact.log
2014-07-09 23:02 - 2014-07-09 23:02 - 00000178 _____ () C:\WINDOWS\setuperr.log
2014-07-09 23:02 - 2014-01-08 16:30 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-09 23:02 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-07-09 23:01 - 2014-01-08 16:30 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-09 23:01 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-07-09 23:00 - 2013-11-14 09:13 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 22:59 - 2014-07-09 22:59 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-07-09 21:14 - 2014-07-09 21:14 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-07-09 21:14 - 2014-01-08 19:13 - 01048576 ___SH () C:\Users\Johannes\Desktop\Thumbs.db
2014-07-09 00:35 - 2014-01-28 23:00 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Mozilla
2014-07-09 00:34 - 2014-01-08 14:21 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-09 00:22 - 2014-07-09 00:22 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\ProductData
2014-07-09 00:22 - 2014-07-09 00:21 - 00000000 ____D () C:\ProgramData\ProductData
2014-07-09 00:22 - 2014-07-09 00:21 - 00000000 ____D () C:\ProgramData\IObit
2014-07-09 00:21 - 2014-07-09 00:21 - 12906784 _____ (IObit) C:\Users\Johannes\Downloads\iobituninstaller_3.3.8.exe
2014-07-09 00:21 - 2014-07-09 00:21 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\IObit
2014-07-09 00:21 - 2014-07-09 00:21 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-07-08 21:54 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-07-08 21:42 - 2014-07-08 21:42 - 00000000 ____D () C:\Program Files\{BF383C42-B9F2-4E89-87A9-5CCF49AD4CD8}
2014-07-08 21:42 - 2014-07-08 21:42 - 00000000 ____D () C:\Program Files (x86)\{48C67497-55E6-47C2-9669-A39128A58E17}
2014-07-08 21:42 - 2014-03-29 13:18 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-07-08 21:28 - 2014-07-08 21:28 - 01346519 _____ () C:\Users\Johannes\Downloads\adwcleaner_3.214 (3).exe
2014-07-08 20:54 - 2014-07-08 20:54 - 01346519 _____ () C:\Users\Johannes\Downloads\adwcleaner_3.214 (2).exe
2014-07-08 20:54 - 2014-07-08 20:54 - 01346519 _____ () C:\Users\Johannes\Downloads\adwcleaner_3.214 (1).exe
2014-07-08 20:51 - 2014-07-03 23:06 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Network_Me_07032106
2014-07-08 20:50 - 2014-06-29 20:18 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-07-08 20:43 - 2014-01-28 22:55 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-08 20:42 - 2014-07-08 20:42 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Johannes\Downloads\mbam-setup-2.0.2.1012_CB-DL-Manager [1].exe
2014-07-08 20:42 - 2014-07-08 20:42 - 00788832 _____ ( ) C:\Users\Johannes\Downloads\mbam-setup-2.0.2.1012_CB-DL-Manager.exe
2014-07-03 23:06 - 2014-07-03 23:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-03 23:06 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy
2014-07-03 23:05 - 2014-07-03 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader
2014-07-02 23:24 - 2014-01-16 18:52 - 00000519 _____ () C:\Users\Johannes\AppData\Roaming\burnaware.ini
2014-07-01 00:45 - 2014-07-09 21:19 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-06-29 21:09 - 2014-06-29 21:04 - 00000000 ____D () C:\Users\Johannes\Desktop\Urlaub Fritz
2014-06-29 20:18 - 2014-06-29 20:18 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Macromedia
2014-06-28 16:03 - 2014-01-08 18:24 - 00135168 ___SH () C:\Users\Johannes\Downloads\Thumbs.db
2014-06-28 15:13 - 2014-06-28 15:13 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Mozilla
2014-06-28 15:13 - 2014-06-28 15:13 - 00000000 ____D () C:\ProgramData\Mozilla
2014-06-28 09:48 - 2014-07-09 21:19 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-06-28 09:07 - 2014-07-09 21:19 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2014-06-26 22:55 - 2014-06-19 15:11 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-06-26 22:55 - 2014-06-19 15:11 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-19 03:39 - 2014-07-09 21:20 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-06-19 02:48 - 2014-07-09 21:20 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-06-19 02:16 - 2014-07-09 21:20 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-06-19 02:09 - 2014-07-09 21:20 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-06-19 01:51 - 2014-07-09 21:20 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-06-19 01:50 - 2014-07-09 21:20 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-06-19 01:48 - 2014-07-09 21:20 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-06-19 01:46 - 2014-07-09 21:20 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-06-19 01:39 - 2014-07-09 21:20 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-06-19 01:33 - 2014-07-09 21:20 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-06-19 01:32 - 2014-07-09 21:20 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-06-19 01:27 - 2014-07-09 21:20 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-06-19 01:12 - 2014-07-09 21:20 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-06-19 00:59 - 2014-07-09 21:20 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-06-19 00:58 - 2014-07-09 21:20 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-06-19 00:58 - 2014-07-09 21:20 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-06-19 00:57 - 2014-07-09 21:20 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-06-19 00:52 - 2014-07-09 21:20 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-06-19 00:51 - 2014-07-09 21:20 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-06-19 00:49 - 2014-07-09 21:20 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-06-19 00:45 - 2014-07-09 21:20 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-06-19 00:35 - 2014-07-09 21:20 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-06-19 00:34 - 2014-07-09 21:20 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-06-19 00:15 - 2014-07-09 21:20 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-06-19 00:13 - 2014-07-09 21:20 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-06-19 00:09 - 2014-07-09 21:20 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-06-19 00:07 - 2014-07-09 21:20 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-06-18 20:20 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-06-18 20:20 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2014-06-17 00:26 - 2014-07-09 21:21 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2014-06-17 00:24 - 2014-07-09 21:21 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2014-06-11 19:11 - 2014-06-11 19:11 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
Some content of TEMP:
====================
C:\Users\Johannes\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-01 21:12
==================== End Of Log ============================ --- --- ---
--- --- --- |