Code:
# AdwCleaner v4.208 - Bericht erstellt 30/07/2015 um 09:30:58
# Aktualisiert 09/07/2015 von Xplode
# Datenbank : 2015-07-09.2 [Lokal]
# Betriebssystem : Windows 8.1 Pro (x64)
# Benutzername : Chris - CHRIS-PC
# Gestarted von : C:\Users\Chris\Downloads\AdwCleaner_4.208.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\5741758994098468501
Ordner Gelöscht : C:\Program Files (x86)\Innovative Solutions
Ordner Gelöscht : C:\Program Files (x86)\DeaalEoxxppReses
Ordner Gelöscht : C:\Program Files (x86)\EnjoyCoUpon
Ordner Gelöscht : C:\Program Files (x86)\unniSealeS
Ordner Gelöscht : C:\Users\Chris\AppData\Local\Hola
Ordner Gelöscht : C:\Users\Chris\AppData\Roaming\EZDownloader
Ordner Gelöscht : C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\Extensions\u@G3LMy.net
Ordner Gelöscht : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik
Ordner Gelöscht : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh
Ordner Gelöscht : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcdjadjbdihbaodagojiomdljhjhjfho
Ordner Gelöscht : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihhdcjefkafghalpbdjebmfnjbgfgkpo
Ordner Gelöscht : C:\ProgramData\dollkehfngcomhmnlijbkjjfkaeihhck
Ordner Gelöscht : C:\ProgramData\plkonbchbhonniageapkkddedalpfngh
Datei Gelöscht : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage
Datei Gelöscht : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage-journal
Datei Gelöscht : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0
Datei Gelöscht : C:\Users\Chris\Favorites\Startfenster.lnk
Datei Gelöscht : C:\Users\Chris\Favorites\Links\Startfenster.lnk
Datei Gelöscht : C:\WINDOWS\Reimage.ini
Datei Gelöscht : C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\foxydeal.sqlite
Datei Gelöscht : C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\invalidprefs.js
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D37BD00-E9FD-40D1-80E7-1795E510ECAA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Reimage
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Schlüssel Gelöscht : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17840
-\\ Mozilla Firefox v39.0 (x86 de)
-\\ Google Chrome v
[C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : jpfpebmajhhopeonhlcgidhclcccjcik
[C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : lmjegmlicamnimmfhcmpkclmigmmcbeh
[C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : fcdjadjbdihbaodagojiomdljhjhjfho
[C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : ihhdcjefkafghalpbdjebmfnjbgfgkpo
[C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : dollkehfngcomhmnlijbkjjfkaeihhck
[C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : plkonbchbhonniageapkkddedalpfngh
*************************
AdwCleaner[R0].txt - [7008 Bytes] - [30/07/2015 09:29:14]
AdwCleaner[S0].txt - [6385 Bytes] - [30/07/2015 09:30:58]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6444 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.4 (07.27.2015:1)
OS: Windows 8.1 Pro x64
Ran by Chris on 30.07.2015 at 11:39:29,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CF49125D-FBA8-47CD-B46F-628DEEE6C6B8}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{CF49125D-FBA8-47CD-B46F-628DEEE6C6B8}
~~~ Files
Successfully deleted: [File] C:\Users\Chris\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage
Successfully deleted: [File] C:\Users\Chris\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage-journal
~~~ Folders
Successfully deleted: [Folder] C:\Users\Chris\AppData\Roaming\.ACEStream
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Chris\AppData\Roaming\mozilla\firefox\profiles\xm08fntw.default-1421229481667\extensions\toolbar@web.de
Successfully deleted the following from C:\Users\Chris\AppData\Roaming\mozilla\firefox\profiles\xm08fntw.default-1421229481667\prefs.js
user_pref(browser.newtab.url, chrome://fvd.speeddial/content/fvd_about_blank.html);
user_pref(browser.uiCustomization.state, {\placements\:{\PanelUI-contents\:[\edit-controls\,\zoom-controls\,\new-window-button\,\privatebrowsing-button\,\save-
user_pref(extensions.speeddial.currentVersion, 0.9.6.17);
user_pref(extensions.speeddial.group-1-columns, 3);
user_pref(extensions.speeddial.group-1-rows, 3);
user_pref(extensions.speeddial.maximumWidth, 2400);
user_pref(extensions.speeddial.thumbnailImageHeight, 800);
user_pref(extensions.speeddial.thumbnailImageWidth, 800);
user_pref(extensions.speeddial.widthModifier, 80);
Emptied folder: C:\Users\Chris\AppData\Roaming\mozilla\firefox\profiles\xm08fntw.default-1421229481667\minidumps [2 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Chris\Appdata\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio
[C:\Users\Chris\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Chris\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
gkojfkhlekighikafcpjkiklfbnlmeio
[C:\Users\Chris\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Chris\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
gkojfkhlekighikafcpjkiklfbnlmeio
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.07.2015 at 11:42:54,73
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 30.07.2015
Suchlaufzeit: 11:55
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.07.30.02
Rootkit-Datenbank: v2015.07.29.02
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Chris
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 384540
Abgelaufene Zeit: 7 Min., 40 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 3
PUP.Optional.ServiceRNDM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Glamorous Anger, In Quarantäne, [a8429a4dd6b4d95ddc674b7cbd44f010],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [915993544842cd69ef2f415bc73d59a7],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [d31739ae90fa9d99f529316b42c2f30d],
Registrierungswerte: 2
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [915993544842cd69ef2f415bc73d59a7]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [d31739ae90fa9d99f529316b42c2f30d]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 7
PUP.Optional.ServiceRNDM.A, C:\Program Files (x86)\Glamorous Anger\Glamorous Anger.exe, In Quarantäne, [a8429a4dd6b4d95ddc674b7cbd44f010],
PUP.Optional.ServiceRNDM.A, C:\Users\Chris\AppData\Local\Temp\1790.exe, In Quarantäne, [b337cf182b5f53e3e261a1261ce5b34d],
PUP.Optional.ServiceRNDM.A, C:\Users\Chris\AppData\Local\Temp\55B1.exe, In Quarantäne, [0edc36b1b6d47fb7ab98c9fe7091e719],
PUP.Optional.ServiceRNDM.A, C:\Users\Chris\AppData\Local\Temp\562E.exe, In Quarantäne, [6f7b984f662412244ef54b7c728f48b8],
PUP.Optional.ServiceRNDM.A, C:\Users\Chris\AppData\Local\Temp\6E38.exe, In Quarantäne, [33b70cdb4f3b71c51a293097d32eab55],
PUP.Optional.EZDownloader.A, C:\Users\Chris\AppData\Local\Temp\83BBe63E1a\temp\EzDownloader_setup.exe, In Quarantäne, [d119eff893f706300286be6328d831cf],
PUP.Optional.MultiPlug.A, C:\Users\Chris\AppData\Local\Temp\83BBe63E1a\temp\hpds_setup.exe, In Quarantäne, [9e4cfbeca8e201358ae82eab4bb6a759],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end)
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:28-07-2015
durchgeführt von Chris (Administrator) auf CHRIS-PC (30-07-2015 12:10:29)
Gestartet von C:\Users\Chris\Downloads
Geladene Profile: Chris (Verfügbare Profile: Chris & Administrator)
Platform: Windows 8.1 Pro (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDWebCam.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPictureViewer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMovieViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDYT.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe
() C:\Program Files (x86)\Zoiper\Zoiper.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
==================== Registry (Nicht auf der Ausnahmeliste) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776 2015-07-27] (AVAST Software)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\...\Run: [HP Officejet 6500 E710n-z (NET)] => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\...\Run: [Zoiper] => C:\Program Files (x86)\Zoiper\Zoiper.exe [10413568 2014-07-02] ()
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\...\Run: [Google Update] => "C:\Users\Chris\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22012688 2015-06-20] (Google)
AppInit_DLLs-x32: AS_WAVEHook.dll => "AS_WAVEHook.dll" Datei nicht gefunden
Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - .lnk [2014-11-27]
ShortcutTarget: Tintenwarnungen überwachen - .lnk -> C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-27] (AVAST Software)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
CHR HKLM\SOFTWARE\Policies\Google: Richtlinienbeschränkung <======= ATTENTION
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype
HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1103201438-1103952896-3601248968-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-27] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-11] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-27] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-11] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
Tcpip\Parameters: [DhcpNameServer] 172.16.0.1
Tcpip\..\Interfaces\{44756532-CFB6-4DE4-A057-1FFB45C94959}: [DhcpNameServer] 172.16.0.1
FireFox:
========
FF ProfilePath: C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667
FF NewTab: chrome://fvd.speeddial/content/fvd_about_blank.html
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-11] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-1103201438-1103952896-3601248968-1000: @hola.org/vlc,version=1.8.649 -> C:\Users\Chris\AppData\Local\Hola\firefox\app\vlc Keine Datei
FF Plugin HKU\S-1-5-21-1103201438-1103952896-3601248968-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Chris\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1103201438-1103952896-3601248968-1000: @talk.google.com/O1DPlugin -> C:\Users\Chris\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1103201438-1103952896-3601248968-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Chris\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1103201438-1103952896-3601248968-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Chris\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1103201438-1103952896-3601248968-1000: SkypePlugin -> C:\Users\Chris\AppData\Local\SkypePlugin\7.3.0.501\npGatewayNpapi.dll [2015-06-05] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-1103201438-1103952896-3601248968-1000: SkypePlugin64 -> C:\Users\Chris\AppData\Local\SkypePlugin\7.3.0.501\npGatewayNpapi-x64.dll [2015-06-05] (Skype Technologies S.A.)
FF Plugin ProgramFiles/Appdata: C:\Users\Chris\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Chris\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Extension: Hola Better Internet - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-07-30]
FF Extension: Speed Dial [FVD] - New Tab Page, Sync... - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\Extensions\pavel.sherbakov@gmail.com [2015-07-27]
FF Extension: ProxTube - Unblock YouTube - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\Extensions\ich@maltegoetz.de.xpi [2015-01-14]
FF Extension: ProxMate - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2015-01-14]
FF Extension: Adblock Edge - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xm08fntw.default-1421229481667\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2015-01-14]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-23]
Chrome:
=======
CHR dev: Chrome dev build erkannt! <======= ATTENTION
CHR Profile: C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-07-28]
CHR Extension: (Google Slides) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-02]
CHR Extension: (Google Docs) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-02]
CHR Extension: (Google Drive) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-02]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-03-19]
CHR Extension: (YouTube) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-02]
CHR Extension: (WhatsWeb) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\cebcbiddpikadcfodbjihffmddoohdma [2015-03-09]
CHR Extension: (Adblock Plus) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-03-02]
CHR Extension: (Google Search) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-02]
CHR Extension: (Avast SafePrice) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-03-02]
CHR Extension: (CyberGhost VPN - Free Proxy) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcbnikgemihknccdjaihjnfbapinljpi [2015-03-02]
CHR Extension: (Google Sheets) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-02]
CHR Extension: (Avast Online Security) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-02]
CHR Extension: (VLC) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhafecgfkakfbhlbjffclfaomoliicpm [2015-03-02]
CHR Extension: (Night Time In New York City) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek [2015-03-02]
CHR Extension: (Adblock Plus) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\jodiajlbioelncebgccbgnagibkdiaea [2015-03-05]
CHR Extension: (Hangouts) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2015-03-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2015-03-02]
CHR Extension: (Earbits Radio - Free Music) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgkjffcdjblaipglnmhanakilfbniihj [2015-03-02]
CHR Extension: (Google Wallet) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-09]
CHR Extension: (Gmail) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-02]
CHR HKU\S-1-5-21-1103201438-1103952896-3601248968-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-05-15]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-05-15]
CHR HKLM-x32\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\Chris\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2014-11-27]
==================== Services (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-11-16] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-07-27] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-07-27] (Avast Software)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
==================== Drivers (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-07-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-07-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-07-27] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048856 2015-07-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-07-27] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150160 2015-07-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-07-27] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-11-23] (Disc Soft Ltd)
S3 ggsomc; C:\Windows\System32\drivers\ggsomc.sys [30424 2015-01-29] (Sony Mobile Communications)
R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-07-27] (AVAST Software)
S3 RecFltr; C:\Windows\system32\drivers\RecFltr.sys [45440 2007-01-18] ()
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-27] (Avast Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 XENfiltv; C:\Windows\system32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-07-30 12:06 - 2015-07-30 12:06 - 00002796 _____ C:\Users\Chris\Desktop\mbam.txt
2015-07-30 11:50 - 2015-07-30 12:05 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-07-30 11:50 - 2015-07-30 11:52 - 00001154 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-30 11:50 - 2015-07-30 11:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-30 11:50 - 2015-07-30 11:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-30 11:50 - 2015-07-30 11:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-30 11:50 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-07-30 11:50 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-07-30 11:50 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-07-30 11:49 - 2015-07-30 11:49 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Chris\Downloads\mbam-setup-2.1.6.1022.exe
2015-07-30 11:42 - 2015-07-30 11:42 - 00003126 _____ C:\Users\Chris\Desktop\JRT.txt
2015-07-30 11:37 - 2015-07-30 11:37 - 01798176 _____ (Malwarebytes Corporation) C:\Users\Chris\Downloads\JRT.exe
2015-07-30 09:28 - 2015-07-30 09:31 - 00000000 ____D C:\AdwCleaner
2015-07-30 09:27 - 2015-07-30 09:27 - 02248704 _____ C:\Users\Chris\Downloads\AdwCleaner_4.208.exe
2015-07-30 09:17 - 2015-07-30 09:17 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Chris\Downloads\revosetup95.exe
2015-07-30 09:17 - 2015-07-30 09:17 - 00001320 _____ C:\Users\Chris\Desktop\Revo Uninstaller.lnk
2015-07-30 09:17 - 2015-07-30 09:17 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-30 08:42 - 2015-07-30 08:42 - 00039058 _____ C:\Users\Chris\Downloads\Shortcut.txt
2015-07-30 08:40 - 2015-07-30 12:10 - 00022371 _____ C:\Users\Chris\Downloads\FRST.txt
2015-07-30 08:40 - 2015-07-30 08:42 - 00044517 _____ C:\Users\Chris\Downloads\Addition.txt
2015-07-30 08:39 - 2015-07-30 12:10 - 00000000 ____D C:\FRST
2015-07-30 08:39 - 2015-07-30 08:39 - 02169856 _____ (Farbar) C:\Users\Chris\Downloads\FRST64.exe
2015-07-29 09:15 - 2015-07-29 09:15 - 356453379 _____ C:\Users\Chris\Downloads\d.s11e14.480p.u457238.Rapidmoviez.com.rar
2015-07-29 08:23 - 2015-07-29 08:23 - 371820465 _____ C:\Users\Chris\Downloads\d.s11e15.480p.u461465.Rapidmoviez.com.rar
2015-07-28 10:56 - 2015-07-25 15:34 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-07-28 09:23 - 2015-07-29 08:28 - 00002414 _____ C:\Users\Chris\Desktop\Google Chrome.lnk
2015-07-28 09:23 - 2015-07-28 09:23 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-28 09:22 - 2015-07-28 09:22 - 00931408 _____ (Google Inc.) C:\Users\Chris\Downloads\ChromeSetup.exe
2015-07-27 16:04 - 2015-07-28 09:21 - 00000000 ____D C:\Users\Chris\Downloads\Hola
2015-07-27 07:56 - 2015-07-27 07:56 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-07-27 07:56 - 2015-07-27 07:56 - 00115152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\ngvss.sys
2015-07-27 07:56 - 2015-07-27 07:56 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-07-23 07:11 - 2015-07-23 07:11 - 00000000 ____D C:\Program Files (x86)\Glamorous Anger
2015-07-21 13:48 - 2015-07-14 16:14 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-07-21 13:48 - 2015-07-14 16:14 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-07-21 13:48 - 2015-07-14 16:14 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-07-21 13:48 - 2015-07-14 16:13 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-07-15 08:43 - 2015-06-30 00:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-15 08:43 - 2015-06-29 17:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-07-15 08:43 - 2015-06-29 17:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-07-15 08:43 - 2015-06-29 17:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-07-15 08:43 - 2015-06-29 17:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-07-15 08:43 - 2015-06-27 01:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-07-15 08:43 - 2015-06-27 01:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-07-15 08:43 - 2015-06-25 04:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-07-15 08:43 - 2015-05-07 19:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-07-15 08:43 - 2015-05-07 19:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-15 08:43 - 2015-05-07 18:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-07-15 08:43 - 2015-05-07 18:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-07-15 08:43 - 2015-05-07 17:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-15 08:43 - 2015-05-07 17:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2015-07-15 08:43 - 2015-05-03 17:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 08:43 - 2015-05-03 16:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 08:43 - 2015-05-03 16:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-07-15 08:43 - 2015-05-03 16:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-07-15 08:43 - 2015-05-03 02:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-07-15 08:43 - 2015-04-30 01:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-15 08:43 - 2015-04-25 04:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
2015-07-15 08:43 - 2014-11-04 21:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-07-15 08:43 - 2014-11-04 21:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-07-15 08:43 - 2014-11-04 08:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-07-15 08:43 - 2014-11-04 08:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-07-15 08:43 - 2014-11-04 08:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-07-15 08:43 - 2014-11-04 08:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-07-15 08:42 - 2015-07-09 21:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-07-15 08:42 - 2015-07-09 20:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 08:42 - 2015-07-09 18:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-07-15 08:42 - 2015-07-09 17:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-07-15 08:42 - 2015-07-09 17:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-07-15 08:42 - 2015-07-09 17:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 08:42 - 2015-07-09 17:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-07-15 08:42 - 2015-07-09 17:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-07-15 08:42 - 2015-07-09 17:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-07-15 08:42 - 2015-07-09 17:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-07-15 08:42 - 2015-07-09 17:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-07-15 08:42 - 2015-07-09 17:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-07-15 08:42 - 2015-07-09 17:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-07-15 08:42 - 2015-07-02 00:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-07-15 08:42 - 2015-07-01 23:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-07-15 08:42 - 2015-06-28 07:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2015-07-15 08:42 - 2015-06-28 07:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-07-15 08:42 - 2015-06-28 07:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 08:42 - 2015-06-28 07:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2015-07-15 08:42 - 2015-06-27 18:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-07-15 08:42 - 2015-06-27 05:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-07-15 08:42 - 2015-06-27 05:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2015-07-15 08:42 - 2015-06-27 05:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2015-07-15 08:42 - 2015-06-27 05:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-07-15 08:42 - 2015-06-27 05:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-07-15 08:42 - 2015-06-27 04:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-07-15 08:42 - 2015-06-27 04:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-07-15 08:42 - 2015-06-27 04:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-07-15 08:42 - 2015-06-27 04:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-07-15 08:42 - 2015-06-27 03:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-07-15 08:42 - 2015-06-27 03:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-07-15 08:42 - 2015-06-16 00:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-07-15 08:42 - 2015-06-16 00:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-07-15 08:42 - 2015-06-15 23:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-07-15 08:42 - 2015-06-15 23:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-07-15 08:42 - 2015-06-15 22:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-07-15 08:42 - 2015-06-15 21:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-07-15 08:42 - 2015-05-30 23:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 08:42 - 2015-05-30 21:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 08:42 - 2015-05-30 21:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-07-15 08:42 - 2015-03-09 04:02 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsp.sys
2015-07-15 08:41 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-07-15 08:41 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-07-15 08:41 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-07-15 08:41 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-07-15 08:41 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-07-15 08:41 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-07-15 08:41 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-07-15 08:41 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-07-15 08:41 - 2015-06-16 07:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2015-07-15 08:41 - 2015-06-16 07:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2015-07-15 08:41 - 2015-06-16 00:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-07-15 08:41 - 2015-06-16 00:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 08:41 - 2015-06-16 00:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-07-15 08:41 - 2015-06-16 00:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-07-15 08:41 - 2015-06-16 00:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2015-07-15 08:41 - 2015-06-15 23:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2015-07-15 08:41 - 2015-06-15 23:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-07-15 08:41 - 2015-06-15 23:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-07-15 08:41 - 2015-06-15 23:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-07-15 08:41 - 2015-06-15 23:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-07-15 08:41 - 2015-06-15 23:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-07-15 08:41 - 2015-06-15 23:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-07-15 08:41 - 2015-06-15 23:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-07-15 08:41 - 2015-06-15 23:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-07-15 08:41 - 2015-06-15 23:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-07-15 08:41 - 2015-06-15 23:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-07-15 08:41 - 2015-06-15 23:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-07-15 08:41 - 2015-06-15 23:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-07-15 08:41 - 2015-06-15 23:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-07-15 08:41 - 2015-06-15 22:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 08:41 - 2015-06-15 22:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2015-07-15 08:41 - 2015-06-15 22:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2015-07-15 08:41 - 2015-06-15 22:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-07-15 08:41 - 2015-06-15 22:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-07-15 08:41 - 2015-06-15 22:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-07-15 08:41 - 2015-06-15 22:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-07-15 08:41 - 2015-06-15 22:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-07-15 08:41 - 2015-06-15 22:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-07-15 08:41 - 2015-06-15 22:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-07-15 08:41 - 2015-06-15 22:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-07-15 08:41 - 2015-06-15 22:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-07-15 08:41 - 2015-06-15 22:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-07-15 08:41 - 2015-06-15 22:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-07-15 08:41 - 2015-06-11 05:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-07-15 08:41 - 2015-06-10 18:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-07-15 08:41 - 2015-05-12 15:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-15 08:41 - 2015-05-11 18:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2015-07-15 08:41 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-07-15 08:41 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls
2015-07-15 08:41 - 2015-04-23 17:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-07-15 08:41 - 2015-04-23 17:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-07-15 08:40 - 2015-05-07 18:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2015-07-15 08:40 - 2015-05-03 17:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-15 08:40 - 2015-05-03 16:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-07-15 08:40 - 2015-05-02 01:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-07-10 19:29 - 2015-07-28 11:20 - 00000000 ___HD C:\$Windows.~BT
2015-07-08 09:47 - 2015-07-28 09:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-07-30 12:10 - 2015-03-25 14:19 - 00000000 ___RD C:\Users\Chris\OneDrive
2015-07-30 12:10 - 2014-11-23 17:08 - 00000000 ____D C:\Users\Chris\AppData\Roaming\ClassicShell
2015-07-30 12:09 - 2014-11-23 12:31 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1103201438-1103952896-3601248968-1000
2015-07-30 12:09 - 2014-08-13 10:11 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-30 12:09 - 2013-08-23 01:24 - 00764340 _____ C:\WINDOWS\system32\perfh007.dat
2015-07-30 12:09 - 2013-08-23 01:24 - 00159160 _____ C:\WINDOWS\system32\perfc007.dat
2015-07-30 12:04 - 2015-02-10 18:54 - 00000000 ___RD C:\Users\Chris\Google Drive
2015-07-30 12:04 - 2014-08-13 10:03 - 00080848 _____ C:\WINDOWS\PFRO.log
2015-07-30 12:04 - 2013-08-22 16:46 - 00110250 _____ C:\WINDOWS\setupact.log
2015-07-30 12:04 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-30 12:03 - 2014-11-23 12:06 - 01153210 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-30 12:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-07-30 11:58 - 2014-11-23 18:40 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-30 11:27 - 2015-01-29 19:08 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1103201438-1103952896-3601248968-1000UA.job
2015-07-30 10:58 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-07-30 09:27 - 2015-01-29 19:08 - 00000874 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1103201438-1103952896-3601248968-1000Core.job
2015-07-30 09:25 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-07-30 08:49 - 2014-03-08 18:47 - 00000000 ____D C:\Users\Chris\Documents\Outlook-Dateien
2015-07-30 08:33 - 2014-11-23 12:28 - 00003930 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D3CD05C5-619E-43BE-B557-DFD1C8252FF3}
2015-07-30 08:27 - 2014-11-23 12:37 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-07-29 15:26 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-07-29 11:08 - 2014-11-23 13:27 - 00000000 ____D C:\Users\Chris\AppData\Roaming\vlc
2015-07-28 11:14 - 2014-08-13 11:02 - 00000000 ___DC C:\WINDOWS\Panther
2015-07-28 10:38 - 2014-11-23 12:26 - 00249856 ___SH C:\Users\Chris\Desktop\Thumbs.db
2015-07-28 09:27 - 2014-11-23 12:34 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Mozilla
2015-07-28 09:22 - 2015-01-29 19:08 - 00003872 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1103201438-1103952896-3601248968-1000UA
2015-07-28 09:22 - 2015-01-29 19:08 - 00003492 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1103201438-1103952896-3601248968-1000Core
2015-07-28 09:16 - 2015-01-07 15:26 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-28 09:16 - 2014-11-27 17:03 - 00000000 __SHD C:\Users\Chris\AppData\Local\EmieBrowserModeList
2015-07-28 09:16 - 2014-11-23 12:28 - 00000000 __SHD C:\Users\Chris\AppData\Local\EmieUserList
2015-07-28 09:16 - 2014-11-23 12:28 - 00000000 __SHD C:\Users\Chris\AppData\Local\EmieSiteList
2015-07-28 07:46 - 2014-11-23 12:37 - 00000000 ____D C:\WINDOWS\SysWOW64\vbox
2015-07-28 07:46 - 2014-11-23 12:37 - 00000000 ____D C:\WINDOWS\system32\vbox
2015-07-27 15:41 - 2015-03-23 08:34 - 00000000 ____D C:\Users\Chris\Downloads\a s05e15 u400044 Rapidmoviez
2015-07-27 08:34 - 2015-03-20 15:32 - 00000000 ____D C:\Program Files (x86)\Bandicam
2015-07-27 07:56 - 2014-11-23 12:37 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-07-27 07:56 - 2014-11-23 12:37 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-07-27 07:56 - 2014-11-23 12:37 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-07-27 07:56 - 2014-11-23 12:37 - 00150160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-07-27 07:56 - 2014-11-23 12:37 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-07-27 07:56 - 2014-11-23 12:37 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-07-27 07:56 - 2014-11-23 12:37 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-07-27 07:56 - 2014-11-23 12:37 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-07-26 21:21 - 2015-05-01 10:38 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-07-23 16:23 - 2014-11-23 13:00 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Skype
2015-07-22 09:27 - 2013-08-22 16:44 - 00481504 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-20 08:31 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-07-15 10:00 - 2015-05-01 10:38 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-07-15 10:00 - 2014-12-10 18:08 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-07-15 10:00 - 2014-11-27 08:22 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-07-15 10:00 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-07-15 10:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\WinStore
2015-07-15 10:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-07-15 09:58 - 2014-11-23 18:40 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-07-15 09:55 - 2014-11-23 13:08 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-15 09:52 - 2014-08-13 10:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-07-15 08:22 - 2015-02-10 18:53 - 00002094 _____ C:\Users\Public\Desktop\Google Slides.lnk
2015-07-15 08:22 - 2015-02-10 18:53 - 00002092 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2015-07-15 08:22 - 2015-02-10 18:53 - 00002082 _____ C:\Users\Public\Desktop\Google Docs.lnk
2015-07-15 08:22 - 2015-02-10 18:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-07-14 07:46 - 2014-11-23 12:36 - 00000000 ____D C:\ProgramData\Skype
2015-07-13 23:10 - 2014-08-13 10:42 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-07-13 23:10 - 2014-08-13 10:42 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-09 13:06 - 2014-11-23 12:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-03 08:43 - 2014-08-13 10:31 - 130333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-07-03 07:46 - 2014-11-23 18:40 - 00000000 ____D C:\Users\Chris\AppData\Local\Adobe
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2014-11-27 12:00 - 2014-11-27 12:00 - 0000057 _____ () C:\ProgramData\Ament.ini
Einige Dateien in TEMP:
====================
C:\Users\Chris\AppData\Local\Temp\amazonicon_v10.exe
C:\Users\Chris\AppData\Local\Temp\amazoninstallernircmdc.exe
C:\Users\Chris\AppData\Local\Temp\AutoDetectUtilApp.exe
C:\Users\Chris\AppData\Local\Temp\bdcam64_0.dll
C:\Users\Chris\AppData\Local\Temp\bdfilters.dll
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.5.855.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.5.885.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.5.903.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.5.954.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.120.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.139.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.144.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.165.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.180.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.224.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.234.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.256.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.284.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.326.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.344.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.390.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.434.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.449.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.467.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.474.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.485.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.520.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.536.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.540.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.555.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.584.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.625.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.64.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.654.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.676.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.685.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.732.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.923.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.950.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.974.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.6.98.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.128.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.169.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.298.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.49.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.5.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.712.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.73.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.78.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.860.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.919.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.974.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.103.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.131.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.164.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.183.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.188.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.204.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.277.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.308.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.328.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.369.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.595.exe
C:\Users\Chris\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.649.exe
C:\Users\Chris\AppData\Local\Temp\HPUSBFW_v2.2.3.exe
C:\Users\Chris\AppData\Local\Temp\i4jdel0.exe
C:\Users\Chris\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Chris\AppData\Local\Temp\mailcheck_ff_2014_12_02.exe
C:\Users\Chris\AppData\Local\Temp\onOneWait.exe
C:\Users\Chris\AppData\Local\Temp\ose00000.exe
C:\Users\Chris\AppData\Local\Temp\proxy_vole8823910150259028291.dll
C:\Users\Chris\AppData\Local\Temp\Quarantine.exe
C:\Users\Chris\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Chris\AppData\Local\Temp\ReiSysUpdate.exe
C:\Users\Chris\AppData\Local\Temp\Samsung_Magician_Setup_v45.exe
C:\Users\Chris\AppData\Local\Temp\sdan.exe
C:\Users\Chris\AppData\Local\Temp\sdapk.exe
C:\Users\Chris\AppData\Local\Temp\sdaspwn.exe
C:\Users\Chris\AppData\Local\Temp\SoftonicAssistant_v0-1-6.exe
C:\Users\Chris\AppData\Local\Temp\sqlite3.dll
C:\Users\Chris\AppData\Local\Temp\sqlite3.exe
==================== Bamital & volsnap Check =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\System32\winlogon.exe => Datei ist digital signiert
C:\Windows\System32\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\System32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\System32\services.exe => Datei ist digital signiert
C:\Windows\System32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\System32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\System32\rpcss.dll => Datei ist digital signiert
C:\Windows\System32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-07-28 10:48
==================== Ende von log ============================ --- --- --- |