Advertisement
Guest User

Untitled

a guest
Sep 11th, 2014
303
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 45.65 KB | None | 0 0
  1. Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-09-2014
  2. Ran by illang (administrator) on ILLANG-PC on 11-09-2014 17:22:24
  3. Running from C:\Users\illang\Downloads
  4. Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
  5. Internet Explorer Version 11
  6. Boot Mode: Normal
  7.  
  8. The only official download link for FRST:
  9. Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
  10. Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
  11. Download link from any site other than Bleeping Computer is unpermitted or outdated.
  12. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
  13.  
  14. ==================== Processes (Whitelisted) =================
  15.  
  16. (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
  17.  
  18. (Lenovo.) C:\Windows\System32\ibmpmsvc.exe
  19. (Microsoft Corporation) C:\Windows\System32\wlanext.exe
  20. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
  21. (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
  22. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
  23. (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
  24. (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
  25. () C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
  26. (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
  27. (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
  28. (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
  29. (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
  30. (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
  31. (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
  32. (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
  33. (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
  34. (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\RtkBleServ.exe
  35. (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
  36. (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
  37. (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
  38. (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
  39. (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
  40. (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
  41. (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
  42. (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
  43. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
  44. (Microsoft Corporation) C:\Windows\System32\rundll32.exe
  45. (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe
  46. (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
  47. (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
  48. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
  49. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
  50. (Microsoft Corporation) C:\Windows\System32\rundll32.exe
  51. () C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
  52. (Intel Corporation) C:\Windows\System32\hkcmd.exe
  53. (Intel Corporation) C:\Windows\System32\igfxpers.exe
  54. (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
  55. (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
  56. (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
  57. (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
  58. () C:\Program Files (x86)\Integrated Camera\Monitor.exe
  59. (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
  60. (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
  61. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
  62. (Microsoft Corporation) C:\Windows\System32\rundll32.exe
  63. (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
  64. (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE
  65. (Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
  66. (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
  67. (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
  68. (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
  69. (Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe
  70.  
  71.  
  72. ==================== Registry (Whitelisted) ==================
  73.  
  74. (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
  75.  
  76. HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [280576 2013-10-21] (Realtek Semiconductor Corporation)
  77. HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [293672 2013-06-14] (Lenovo Group Limited)
  78. HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2985712 2013-06-04] (Synaptics Incorporated)
  79. HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2184520 2009-07-27] (CANON INC.)
  80. HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-03-18] (CANON INC.)
  81. HKLM\...\Run: [AcWin7Hlpr] => C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [63832 2014-03-14] (Lenovo)
  82. HKLM-x32\...\Run: [Integrated Camera_Monitor] => C:\Program Files (x86)\Integrated Camera\monitor.exe [1718648 2013-04-26] ()
  83. HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
  84. HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
  85. HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4315872 2011-06-01] (Lenovo, Inc.)
  86. HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1085744 2012-11-22] (Lenovo)
  87. HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-13] (Avira Operations GmbH & Co. KG)
  88. HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1942424 2014-08-22] (APN)
  89. HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
  90. Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
  91. HKU\S-1-5-21-3193019097-1559123384-2487284630-1000\...\MountPoints2: {417c8f46-97af-11e3-b1e4-806e6f6e6963} - Q:\LenovoQDrive.exe
  92. ShellIconOverlayIdentifiers: SugarSyncBackedUp -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
  93. ShellIconOverlayIdentifiers: SugarSyncPending -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
  94. ShellIconOverlayIdentifiers: SugarSyncRoot -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
  95. ShellIconOverlayIdentifiers: SugarSyncShared -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
  96.  
  97. ==================== Internet (Whitelisted) ====================
  98.  
  99. (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
  100.  
  101. HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13-comm.msn.com/?pc=LNJB
  102. HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/welcome/thinkpad
  103. HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad
  104. SearchScopes: HKLM - {85E000AA-ED9B-48ED-92D8-821BAD141DD6} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LNJB
  105. SearchScopes: HKLM-x32 - {85E000AA-ED9B-48ED-92D8-821BAD141DD6} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LNJB
  106. SearchScopes: HKCU - {85E000AA-ED9B-48ED-92D8-821BAD141DD6} URL =
  107. BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
  108. BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
  109. BHO-x32: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
  110. BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
  111. Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
  112. Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
  113. Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
  114.  
  115. FireFox:
  116. ========
  117. FF ProfilePath: C:\Users\illang\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhjzam.default
  118. FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
  119. FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
  120. FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  121. FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
  122. FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
  123. FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
  124. FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
  125. FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
  126. FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
  127. FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
  128. FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  129. FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
  130. FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
  131. FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
  132. FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
  133. FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
  134. FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
  135. FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
  136. FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
  137. FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\illang\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhjzam.default\Extensions\toolbar_AVIRA-V7C@apn.ask.com.xpi [2014-09-03]
  138. FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
  139.  
  140. Chrome:
  141. =======
  142. CHR HomePage: Default -> F0903E5B060AC1D2F5DFC791214BA52660E591DF4C802654BF41A5AA89F6E3AD
  143. CHR DefaultSearchKeyword: Default -> 82897061B21BFEAE1E892F814108CAEF40D4B470EF46E6CC60AF007990346CDC
  144. CHR DefaultSearchURL: Default -> 09A441CB5655DEA9AD72503397956B1EDD205FBF8E126A9427B21A93E82928FC
  145. CHR Profile: C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default
  146. CHR Extension: (Google Docs) - C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-16]
  147. CHR Extension: (Google Drive) - C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-16]
  148. CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06]
  149. CHR Extension: (YouTube) - C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-16]
  150. CHR Extension: (Google-Suche) - C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-16]
  151. CHR Extension: (Google Wallet) - C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-16]
  152. CHR Extension: (Google Mail) - C:\Users\illang\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-16]
  153.  
  154. ==================== Services (Whitelisted) =================
  155.  
  156. (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
  157.  
  158. R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [804944 2014-08-13] (Avira Operations GmbH & Co. KG)
  159. R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-13] (Avira Operations GmbH & Co. KG)
  160. R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-13] (Avira Operations GmbH & Co. KG)
  161. R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1021520 2014-08-13] (Avira Operations GmbH & Co. KG)
  162. R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-08-22] (APN LLC.)
  163. R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-05-07] (Realtek Semiconductor Corporation) [File not signed]
  164. R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [66560 2013-11-06] () [File not signed]
  165. R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [160048 2012-11-22] (Lenovo)
  166. R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
  167. S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
  168. R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-07-03] (Intel Corporation)
  169. S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
  170. R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-07-03] (Intel Corporation)
  171. R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [187688 2013-06-14] (Lenovo Group Limited)
  172. R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo Group Limited)
  173. R2 RtkBleServ; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe [42496 2013-04-25] (Realtek Semiconductor Corporation) [File not signed]
  174.  
  175. ==================== Drivers (Whitelisted) ====================
  176.  
  177. (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
  178.  
  179. R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
  180. R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-20] (Avira Operations GmbH & Co. KG)
  181. R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
  182. R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [42040 2014-07-10] (Avira Operations GmbH & Co. KG)
  183. S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [71472 2012-11-22] (Windows (R) Win 7 DDK provider)
  184. R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-16] (Intel Corporation)
  185. S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-10] (Malwarebytes Corporation)
  186. R3 RtkBtFilter; C:\Windows\System32\DRIVERS\RtkBtfilter.sys [554712 2013-11-04] (Realtek Semiconductor Corporation)
  187. R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [2974424 2013-08-03] (Realtek Semiconductor Corporation )
  188. S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
  189. R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-06-04] (Synaptics Incorporated)
  190. R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1509112 2013-06-11] (Sunplus)
  191. R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-08] (ThinkVantage Communications Utility)
  192.  
  193. ==================== NetSvcs (Whitelisted) ===================
  194.  
  195. (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
  196.  
  197.  
  198. ==================== One Month Created Files and Folders ========
  199.  
  200. (If an entry is included in the fixlist, the file\folder will be moved.)
  201.  
  202. 2014-09-11 14:27 - 2014-09-11 14:27 - 00028768 _____ () C:\Users\illang\Downloads\Addition.txt
  203. 2014-09-11 14:26 - 2014-09-11 17:22 - 00018211 _____ () C:\Users\illang\Downloads\FRST.txt
  204. 2014-09-11 14:26 - 2014-09-11 17:22 - 00000000 ____D () C:\FRST
  205. 2014-09-11 14:23 - 2014-09-11 14:23 - 02105856 _____ (Farbar) C:\Users\illang\Downloads\FRST64(1).exe
  206. 2014-09-11 08:27 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
  207. 2014-09-11 08:27 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
  208. 2014-09-11 08:27 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
  209. 2014-09-11 08:27 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
  210. 2014-09-11 08:27 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
  211. 2014-09-11 08:27 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
  212. 2014-09-11 08:27 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
  213. 2014-09-11 08:27 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
  214. 2014-09-11 08:27 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
  215. 2014-09-11 08:27 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
  216. 2014-09-11 08:27 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
  217. 2014-09-11 08:27 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
  218. 2014-09-11 08:27 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
  219. 2014-09-11 08:27 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
  220. 2014-09-11 08:27 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
  221. 2014-09-11 08:27 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
  222. 2014-09-11 08:27 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
  223. 2014-09-11 08:27 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
  224. 2014-09-11 08:27 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
  225. 2014-09-11 08:27 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
  226. 2014-09-11 08:27 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
  227. 2014-09-11 08:27 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
  228. 2014-09-11 08:27 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
  229. 2014-09-11 08:27 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
  230. 2014-09-11 08:27 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
  231. 2014-09-11 08:27 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
  232. 2014-09-11 08:27 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
  233. 2014-09-11 08:27 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
  234. 2014-09-11 08:27 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
  235. 2014-09-11 08:27 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
  236. 2014-09-11 08:27 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
  237. 2014-09-11 08:27 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
  238. 2014-09-11 08:27 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
  239. 2014-09-11 08:27 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
  240. 2014-09-11 08:27 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
  241. 2014-09-11 08:27 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
  242. 2014-09-11 08:27 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
  243. 2014-09-11 08:27 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
  244. 2014-09-11 08:27 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
  245. 2014-09-11 08:27 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
  246. 2014-09-11 08:27 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
  247. 2014-09-11 08:27 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
  248. 2014-09-11 08:27 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
  249. 2014-09-11 08:27 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
  250. 2014-09-11 08:27 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
  251. 2014-09-11 08:27 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
  252. 2014-09-11 08:27 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
  253. 2014-09-11 08:27 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
  254. 2014-09-11 08:27 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
  255. 2014-09-11 08:27 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
  256. 2014-09-11 08:27 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
  257. 2014-09-11 08:27 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
  258. 2014-09-11 08:27 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
  259. 2014-09-11 08:27 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
  260. 2014-09-11 08:27 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
  261. 2014-09-11 08:27 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
  262. 2014-09-11 08:17 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
  263. 2014-09-11 08:17 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
  264. 2014-09-11 08:12 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
  265. 2014-09-11 08:12 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
  266. 2014-09-11 08:11 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
  267. 2014-09-11 08:11 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
  268. 2014-09-11 08:11 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
  269. 2014-09-11 08:11 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
  270. 2014-09-11 08:11 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
  271. 2014-09-11 08:11 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
  272. 2014-09-11 08:11 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
  273. 2014-09-11 08:11 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
  274. 2014-09-11 08:11 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
  275. 2014-09-10 19:58 - 2014-09-10 19:58 - 00000000 __SHD () C:\Users\illang\AppData\Local\EmieUserList
  276. 2014-09-10 19:58 - 2014-09-10 19:58 - 00000000 __SHD () C:\Users\illang\AppData\Local\EmieSiteList
  277. 2014-09-10 17:05 - 2014-09-10 17:05 - 00244400 _____ () C:\Users\illang\Downloads\Firefox Setup Stub 32.0.exe
  278. 2014-09-10 16:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
  279. 2014-09-10 16:48 - 2014-09-10 16:48 - 01370467 _____ () C:\Users\illang\Downloads\AdwCleaner(12).exe
  280. 2014-09-10 13:51 - 2014-09-10 13:51 - 02105856 _____ (Farbar) C:\Users\illang\Downloads\FRST64.exe
  281. 2014-09-09 21:12 - 2014-09-09 21:12 - 00000000 ____D () C:\Users\illang\Neuer Ordner
  282. 2014-09-09 21:11 - 2014-09-09 21:11 - 00000000 ____D () C:\Users\illang\Downloads\Handelsregister Eintrag SHS
  283. 2014-08-30 14:27 - 2014-09-10 17:37 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
  284. 2014-08-30 14:27 - 2014-09-10 17:36 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
  285. 2014-08-30 14:27 - 2014-08-30 14:27 - 00001117 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  286. 2014-08-30 14:27 - 2014-08-30 14:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
  287. 2014-08-30 14:27 - 2014-08-30 14:27 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
  288. 2014-08-30 14:27 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
  289. 2014-08-30 14:27 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
  290. 2014-08-28 14:08 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
  291. 2014-08-28 14:08 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
  292. 2014-08-28 14:08 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
  293. 2014-08-26 10:58 - 2014-08-26 10:58 - 00002740 _____ () C:\Users\illang\AppData\Local\recently-used.xbel
  294. 2014-08-26 10:47 - 2014-08-26 10:47 - 00000000 ____D () C:\Users\illang\AppData\Local\webkit
  295. 2014-08-18 09:18 - 2014-08-18 09:19 - 12960536 _____ ( ) C:\Users\Esli\Downloads\systemupdate506-04-24-2014.exe
  296. 2014-08-18 08:56 - 2014-08-18 08:56 - 00111520 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
  297. 2014-08-13 17:23 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
  298. 2014-08-13 17:23 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
  299. 2014-08-13 17:23 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
  300. 2014-08-13 17:23 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
  301. 2014-08-13 17:23 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
  302. 2014-08-13 17:23 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
  303. 2014-08-13 17:23 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
  304. 2014-08-13 17:23 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
  305. 2014-08-13 09:04 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
  306. 2014-08-13 09:04 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
  307. 2014-08-13 09:04 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
  308. 2014-08-13 09:04 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
  309. 2014-08-13 09:04 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
  310. 2014-08-13 09:04 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
  311. 2014-08-13 09:04 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
  312. 2014-08-13 09:04 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
  313. 2014-08-13 09:04 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
  314. 2014-08-13 09:04 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
  315. 2014-08-13 09:04 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
  316. 2014-08-13 09:04 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
  317. 2014-08-13 09:03 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
  318. 2014-08-13 09:03 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
  319. 2014-08-13 01:00 - 2014-08-13 01:00 - 04575232 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
  320.  
  321. ==================== One Month Modified Files and Folders =======
  322.  
  323. (If an entry is included in the fixlist, the file\folder will be moved.)
  324.  
  325. 2014-09-11 17:22 - 2014-09-11 14:26 - 00018211 _____ () C:\Users\illang\Downloads\FRST.txt
  326. 2014-09-11 17:22 - 2014-09-11 14:26 - 00000000 ____D () C:\FRST
  327. 2014-09-11 17:16 - 2014-07-16 12:11 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
  328. 2014-09-11 17:16 - 2009-07-14 06:45 - 00034208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  329. 2014-09-11 17:16 - 2009-07-14 06:45 - 00034208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  330. 2014-09-11 17:12 - 2014-02-17 10:44 - 01187293 _____ () C:\Windows\WindowsUpdate.log
  331. 2014-09-11 17:09 - 2014-04-17 11:59 - 01422803 _____ () C:\Users\illang\AppData\Local\BTServer.log
  332. 2014-09-11 17:08 - 2014-07-16 12:11 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
  333. 2014-09-11 17:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
  334. 2014-09-11 17:08 - 2009-07-14 06:51 - 00088975 _____ () C:\Windows\setupact.log
  335. 2014-09-11 15:33 - 2014-04-17 16:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
  336. 2014-09-11 14:27 - 2014-09-11 14:27 - 00028768 _____ () C:\Users\illang\Downloads\Addition.txt
  337. 2014-09-11 14:23 - 2014-09-11 14:23 - 02105856 _____ (Farbar) C:\Users\illang\Downloads\FRST64(1).exe
  338. 2014-09-11 13:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
  339. 2014-09-11 08:32 - 2014-07-16 12:13 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
  340. 2014-09-11 08:27 - 2014-04-23 16:30 - 00000000 ____D () C:\ProgramData\Microsoft Help
  341. 2014-09-11 08:25 - 2014-02-17 19:10 - 00699342 _____ () C:\Windows\system32\perfh007.dat
  342. 2014-09-11 08:25 - 2014-02-17 19:10 - 00149450 _____ () C:\Windows\system32\perfc007.dat
  343. 2014-09-11 08:25 - 2014-02-17 10:51 - 01593564 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
  344. 2014-09-11 08:25 - 2009-07-14 07:13 - 01593564 _____ () C:\Windows\system32\PerfStringBackup.INI
  345. 2014-09-11 08:24 - 2014-04-18 09:53 - 00000000 ____D () C:\Windows\system32\MRT
  346. 2014-09-11 08:17 - 2014-04-18 09:53 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
  347. 2014-09-11 08:16 - 2014-05-06 11:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
  348. 2014-09-11 08:14 - 2014-04-23 16:56 - 00000000 ____D () C:\Users\illang\Documents\Outlook-Dateien
  349. 2014-09-11 07:58 - 2014-05-15 08:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
  350. 2014-09-11 07:58 - 2014-04-17 12:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
  351. 2014-09-11 07:58 - 2010-11-21 05:47 - 00346824 _____ () C:\Windows\PFRO.log
  352. 2014-09-10 19:58 - 2014-09-10 19:58 - 00000000 __SHD () C:\Users\illang\AppData\Local\EmieUserList
  353. 2014-09-10 19:58 - 2014-09-10 19:58 - 00000000 __SHD () C:\Users\illang\AppData\Local\EmieSiteList
  354. 2014-09-10 17:37 - 2014-08-30 14:27 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
  355. 2014-09-10 17:36 - 2014-08-30 14:27 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
  356. 2014-09-10 17:08 - 2014-04-17 12:23 - 00001174 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
  357. 2014-09-10 17:08 - 2014-04-17 12:23 - 00001162 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
  358. 2014-09-10 17:05 - 2014-09-10 17:05 - 00244400 _____ () C:\Users\illang\Downloads\Firefox Setup Stub 32.0.exe
  359. 2014-09-10 16:56 - 2014-06-22 15:05 - 00000000 ____D () C:\AdwCleaner
  360. 2014-09-10 16:48 - 2014-09-10 16:48 - 01370467 _____ () C:\Users\illang\Downloads\AdwCleaner(12).exe
  361. 2014-09-10 13:51 - 2014-09-10 13:51 - 02105856 _____ (Farbar) C:\Users\illang\Downloads\FRST64.exe
  362. 2014-09-09 21:33 - 2014-04-17 16:27 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
  363. 2014-09-09 21:33 - 2014-04-17 16:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
  364. 2014-09-09 21:33 - 2014-04-17 16:27 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
  365. 2014-09-09 21:12 - 2014-09-09 21:12 - 00000000 ____D () C:\Users\illang\Neuer Ordner
  366. 2014-09-09 21:12 - 2014-04-17 11:58 - 00000000 ____D () C:\Users\illang
  367. 2014-09-09 21:11 - 2014-09-09 21:11 - 00000000 ____D () C:\Users\illang\Downloads\Handelsregister Eintrag SHS
  368. 2014-09-05 04:10 - 2014-09-11 08:11 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
  369. 2014-09-05 04:05 - 2014-09-11 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
  370. 2014-08-30 15:55 - 2014-05-03 18:12 - 00049415 _____ () C:\Users\Esli\AppData\Local\BTServer.log
  371. 2014-08-30 14:27 - 2014-08-30 14:27 - 00001117 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  372. 2014-08-30 14:27 - 2014-08-30 14:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
  373. 2014-08-30 14:27 - 2014-08-30 14:27 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
  374. 2014-08-29 09:28 - 2009-07-14 06:45 - 00438912 _____ () C:\Windows\system32\FNTCACHE.DAT
  375. 2014-08-26 11:05 - 2014-06-11 12:17 - 00289792 _____ (Dr. Wuro Industries) C:\Users\Esli\Downloads\verkleinerer17b_CB-DL-Manager [1].exe
  376. 2014-08-26 11:03 - 2014-04-17 16:47 - 00000000 ____D () C:\Users\illang\.gimp-2.8
  377. 2014-08-26 10:58 - 2014-08-26 10:58 - 00002740 _____ () C:\Users\illang\AppData\Local\recently-used.xbel
  378. 2014-08-26 10:58 - 2014-04-17 16:49 - 00000000 ____D () C:\Users\illang\AppData\Local\gtk-2.0
  379. 2014-08-26 10:47 - 2014-08-26 10:47 - 00000000 ____D () C:\Users\illang\AppData\Local\webkit
  380. 2014-08-26 10:40 - 2014-05-03 18:10 - 00000000 ____D () C:\Users\Esli
  381. 2014-08-26 09:59 - 2014-04-24 14:41 - 00000000 ____D () C:\Users\illang\Documents\Eigene Dateien
  382. 2014-08-23 04:07 - 2014-08-28 14:08 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
  383. 2014-08-23 03:45 - 2014-08-28 14:08 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
  384. 2014-08-23 02:59 - 2014-08-28 14:08 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
  385. 2014-08-19 20:05 - 2014-09-11 08:27 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
  386. 2014-08-19 19:39 - 2014-09-11 08:27 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
  387. 2014-08-19 08:59 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
  388. 2014-08-19 01:01 - 2014-09-11 08:27 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
  389. 2014-08-19 00:29 - 2014-09-11 08:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
  390. 2014-08-19 00:29 - 2014-09-11 08:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
  391. 2014-08-19 00:26 - 2014-09-11 08:27 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
  392. 2014-08-19 00:20 - 2014-09-11 08:27 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
  393. 2014-08-19 00:19 - 2014-09-11 08:27 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
  394. 2014-08-19 00:15 - 2014-09-11 08:27 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
  395. 2014-08-19 00:15 - 2014-09-11 08:27 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
  396. 2014-08-19 00:14 - 2014-09-11 08:27 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
  397. 2014-08-19 00:14 - 2014-09-11 08:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
  398. 2014-08-19 00:08 - 2014-09-11 08:27 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
  399. 2014-08-19 00:08 - 2014-09-11 08:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
  400. 2014-08-19 00:08 - 2014-09-11 08:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
  401. 2014-08-19 00:05 - 2014-09-11 08:27 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
  402. 2014-08-19 00:03 - 2014-09-11 08:27 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
  403. 2014-08-19 00:03 - 2014-09-11 08:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
  404. 2014-08-19 00:03 - 2014-09-11 08:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
  405. 2014-08-18 23:57 - 2014-09-11 08:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
  406. 2014-08-18 23:56 - 2014-09-11 08:27 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
  407. 2014-08-18 23:51 - 2014-09-11 08:27 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
  408. 2014-08-18 23:46 - 2014-09-11 08:27 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
  409. 2014-08-18 23:45 - 2014-09-11 08:27 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
  410. 2014-08-18 23:45 - 2014-09-11 08:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
  411. 2014-08-18 23:44 - 2014-09-11 08:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
  412. 2014-08-18 23:44 - 2014-09-11 08:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
  413. 2014-08-18 23:42 - 2014-09-11 08:27 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
  414. 2014-08-18 23:40 - 2014-09-11 08:27 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
  415. 2014-08-18 23:39 - 2014-09-11 08:27 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
  416. 2014-08-18 23:39 - 2014-09-11 08:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
  417. 2014-08-18 23:39 - 2014-09-11 08:27 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
  418. 2014-08-18 23:38 - 2014-09-11 08:27 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
  419. 2014-08-18 23:37 - 2014-09-11 08:27 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
  420. 2014-08-18 23:36 - 2014-09-11 08:27 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
  421. 2014-08-18 23:35 - 2014-09-11 08:27 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
  422. 2014-08-18 23:27 - 2014-09-11 08:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
  423. 2014-08-18 23:25 - 2014-09-11 08:27 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
  424. 2014-08-18 23:25 - 2014-09-11 08:27 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
  425. 2014-08-18 23:23 - 2014-09-11 08:27 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
  426. 2014-08-18 23:23 - 2014-09-11 08:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
  427. 2014-08-18 23:22 - 2014-09-11 08:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
  428. 2014-08-18 23:19 - 2014-09-11 08:27 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
  429. 2014-08-18 23:17 - 2014-09-11 08:27 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
  430. 2014-08-18 23:17 - 2014-09-11 08:27 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
  431. 2014-08-18 23:16 - 2014-09-11 08:27 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
  432. 2014-08-18 23:15 - 2014-09-11 08:27 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
  433. 2014-08-18 23:15 - 2014-09-11 08:27 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
  434. 2014-08-18 23:09 - 2014-09-11 08:27 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
  435. 2014-08-18 23:08 - 2014-09-11 08:27 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
  436. 2014-08-18 23:07 - 2014-09-11 08:27 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
  437. 2014-08-18 22:55 - 2014-09-11 08:27 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
  438. 2014-08-18 22:46 - 2014-09-11 08:27 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
  439. 2014-08-18 22:38 - 2014-09-11 08:27 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
  440. 2014-08-18 22:38 - 2014-09-11 08:27 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
  441. 2014-08-18 22:36 - 2014-09-11 08:27 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
  442. 2014-08-18 17:23 - 2014-02-17 11:06 - 00000000 ____D () C:\Windows\System32\Tasks\Lenovo
  443. 2014-08-18 17:23 - 2014-02-17 10:54 - 00000000 ____D () C:\Program Files\Lenovo
  444. 2014-08-18 16:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
  445. 2014-08-18 09:19 - 2014-08-18 09:18 - 12960536 _____ ( ) C:\Users\Esli\Downloads\systemupdate506-04-24-2014.exe
  446. 2014-08-18 08:57 - 2014-02-17 18:47 - 00000000 ____D () C:\ProgramData\Lenovo
  447. 2014-08-18 08:57 - 2014-02-17 11:13 - 00000000 ____D () C:\Windows\System32\Tasks\TVT
  448. 2014-08-18 08:57 - 2014-02-17 11:05 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
  449. 2014-08-18 08:57 - 2014-02-17 10:54 - 00000000 ____D () C:\Program Files (x86)\Lenovo
  450. 2014-08-18 08:56 - 2014-08-18 08:56 - 00111520 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
  451. 2014-08-18 08:56 - 2014-02-17 11:05 - 00000000 ____D () C:\Windows\Downloaded Installations
  452. 2014-08-18 08:54 - 2014-04-17 12:04 - 00000000 ____D () C:\Users\illang\AppData\Local\Lenovo
  453. 2014-08-13 18:22 - 2014-04-17 11:59 - 00000000 ___RD () C:\Users\illang\Eigene Bilder
  454. 2014-08-13 18:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
  455. 2014-08-13 01:00 - 2014-08-13 01:00 - 04575232 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
  456.  
  457. Some content of TEMP:
  458. ====================
  459. C:\Users\Esli\AppData\Local\Temp\avgnt.exe
  460. C:\Users\Esli\AppData\Local\Temp\Quarantine.exe
  461. C:\Users\illang\AppData\Local\Temp\avgnt.exe
  462. C:\Users\illang\AppData\Local\Temp\DllMonoCtrl.dll
  463. C:\Users\illang\AppData\Local\Temp\MSETUP4.EXE
  464. C:\Users\illang\AppData\Local\Temp\Offercast_AVIRAV7_.exe
  465. C:\Users\illang\AppData\Local\Temp\Quarantine.exe
  466.  
  467.  
  468. ==================== Bamital & volsnap Check =================
  469.  
  470. (There is no automatic fix for files that do not pass verification.)
  471.  
  472. C:\Windows\System32\winlogon.exe => File is digitally signed
  473. C:\Windows\System32\wininit.exe => File is digitally signed
  474. C:\Windows\SysWOW64\wininit.exe => File is digitally signed
  475. C:\Windows\explorer.exe => File is digitally signed
  476. C:\Windows\SysWOW64\explorer.exe => File is digitally signed
  477. C:\Windows\System32\svchost.exe => File is digitally signed
  478. C:\Windows\SysWOW64\svchost.exe => File is digitally signed
  479. C:\Windows\System32\services.exe => File is digitally signed
  480. C:\Windows\System32\User32.dll => File is digitally signed
  481. C:\Windows\SysWOW64\User32.dll => File is digitally signed
  482. C:\Windows\System32\userinit.exe => File is digitally signed
  483. C:\Windows\SysWOW64\userinit.exe => File is digitally signed
  484. C:\Windows\System32\rpcss.dll => File is digitally signed
  485. C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
  486.  
  487.  
  488. LastRegBack: 2014-09-10 10:24
  489.  
  490. ==================== End Of Log ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement