hier der frst scan
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by kamilla (administrator) on 16-06-2013 09:18:34
Running from C:\Users\kamilla\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft) C:\Program Files (x86)\Heimdal\HeimdalSecureDNS\DnsService.exe
(CSIS Security Group) C:\Program Files (x86)\Heimdal\Service\HeimdalAgentService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(CSIS Security Group) C:\Program Files (x86)\Heimdal\Client\HeimdalAgent.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\system32\UI0Detect.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8123936 2009-09-29] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)
HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152544 2012-12-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Heimdal.lnk
ShortcutTarget: Heimdal.lnk -> C:\Program Files (x86)\Heimdal\Client\HeimdalAgent.exe (CSIS Security Group)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
ShortcutTarget: Logitech Desktop Messenger.lnk -> C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe ()
Startup: C:\Users\kamilla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKCU - {7D78640F-4BE7-43C9-BC30-8EA395E8DEB5} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7SKPT_de
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{BB51DB52-65BF-4D10-91F3-E3EBA90F718B}: [NameServer]127.0.0.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\kamilla\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\kamilla\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\kamilla\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Gmail) - C:\Users\kamilla\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 HeimdalSecureDNS; C:\Program Files (x86)\Heimdal\HeimdalSecureDNS\DnsService.exe [94368 2013-06-04] (Microsoft)
R2 HeimdalService; C:\Program Files (x86)\Heimdal\Service\HeimdalAgentService.exe [134304 2013-06-04] (CSIS Security Group)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
S2 SkypeUpdate; C:\Program Files (x86)\Program Files\Skype\Updater\Updater.exe [161384 2013-02-28] (Skype Technologies)
==================== Drivers (Whitelisted) ====================
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-06-15] (Duplex Secure Ltd.)
S0 TfFsMon; system32\drivers\TfFsMon.sys [x]
S3 TfNetMon; \??\C:\Windows\system32\drivers\TfNetMon.sys [x]
S0 TFSysMon; system32\drivers\TfSysMon.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-15 22:57 - 2013-06-15 22:57 - 02347384 ____A (ESET) C:\Users\kamilla\Desktop\esetsmartinstaller_enu.exe
2013-06-15 22:39 - 2013-06-15 22:39 - 00041531 ____A C:\Users\kamilla\Desktop\JRT.txt
2013-06-15 22:34 - 2013-06-15 22:34 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 22:34 - 2013-06-15 22:34 - 00000000 ____D C:\JRT
2013-06-15 22:33 - 2013-06-15 22:33 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\kamilla\Desktop\JRT.exe
2013-06-15 22:26 - 2013-06-15 22:26 - 552262366 ____A C:\Windows\MEMORY.DMP
2013-06-15 22:26 - 2013-06-15 22:26 - 00518976 ____A C:\Windows\Minidump\061513-25006-01.dmp
2013-06-15 22:26 - 2013-06-15 22:26 - 00000000 ____D C:\Windows\Minidump
2013-06-15 22:14 - 2013-06-15 22:14 - 00004109 ____A C:\AdwCleaner[S1].txt
2013-06-15 22:10 - 2013-06-15 22:10 - 00648201 ____A C:\Users\kamilla\Desktop\adwcleaner.exe
2013-06-15 22:00 - 2013-06-15 22:00 - 00000209 ____A C:\Users\kamilla\Desktop\Search.txt
2013-06-15 21:43 - 2013-06-15 21:43 - 00020177 ____A C:\Users\kamilla\Desktop\Addition.txt
2013-06-15 21:42 - 2013-06-15 21:59 - 00000000 ____D C:\FRST
2013-06-15 21:41 - 2013-06-15 21:41 - 01920546 ____A (Farbar) C:\Users\kamilla\Desktop\FRST64.exe
2013-06-15 21:06 - 2013-06-16 08:58 - 00000000 ____D C:\troja
2013-06-15 21:04 - 2013-06-15 21:04 - 00377856 ____A C:\Users\kamilla\Desktop\gmer_2.1.19163.exe
2013-06-15 20:59 - 2013-06-15 20:59 - 00068414 ____A C:\Users\kamilla\Desktop\Extras.Txt
2013-06-15 20:57 - 2013-06-15 20:57 - 00092376 ____A C:\Users\kamilla\Desktop\OTL.Txt
2013-06-15 20:48 - 2013-06-15 20:48 - 00602112 ____A (OldTimer Tools) C:\Users\kamilla\Desktop\OTL.exe
2013-06-15 20:41 - 2013-06-15 20:41 - 00000586 ____A C:\Users\kamilla\Desktop\defogger_disable.log
2013-06-15 20:41 - 2013-06-15 20:41 - 00000020 ____A C:\Users\kamilla\defogger_reenable
2013-06-15 20:40 - 2013-06-15 20:40 - 00050477 ____A C:\Users\kamilla\Desktop\Defogger.exe
2013-06-15 18:35 - 2013-06-15 18:52 - 127231689 ____A (Igor Pavlov) C:\Users\kamilla\Desktop\OTLPENet.exe
2013-06-15 18:02 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-15 18:02 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-15 18:02 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-15 18:02 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-15 18:02 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-15 18:01 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-15 18:01 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-15 18:01 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-15 18:01 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-15 18:01 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-15 18:01 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-15 18:01 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-15 18:01 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-15 18:01 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-15 18:01 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-15 18:01 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-15 18:01 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-15 17:58 - 2013-06-15 17:58 - 00834544 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
2013-06-15 17:57 - 2013-06-15 17:57 - 00000000 ____D C:\Program Files (x86)\LSoft Technologies
2013-06-13 17:23 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 17:18 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-13 17:18 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-13 17:18 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-13 17:18 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-13 17:17 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 17:17 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 17:17 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 17:17 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-13 17:17 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 17:17 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-13 17:17 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 17:17 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 17:17 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 17:17 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-13 17:17 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-13 17:17 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-13 17:16 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-13 17:16 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-05-17 23:35 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-17 23:35 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-17 23:35 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-17 23:35 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-17 23:35 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-17 23:35 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-17 23:35 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-17 23:35 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-17 23:12 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-17 23:12 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-05-17 23:12 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2013-05-17 23:11 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-17 23:11 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-05-17 23:11 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-05-17 23:08 - 2013-05-17 23:07 - 00477616 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2013-05-17 23:08 - 2013-05-17 23:07 - 00162224 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2013-05-17 23:08 - 2013-05-17 23:07 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2013-05-17 23:08 - 2013-05-17 23:07 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2013-05-17 23:07 - 2013-05-17 23:07 - 00000000 ____D C:\Program Files (x86)\Java
2013-05-17 23:03 - 2013-06-04 19:25 - 00000000 ____D C:\Program Files (x86)\Heimdal
2013-05-17 23:03 - 2013-05-17 23:03 - 00000000 ____D C:\ProgramData\CSIS
2013-05-17 22:19 - 2013-05-17 22:19 - 00000488 ____A C:\Windows\System32\.crusader
2013-05-17 21:03 - 2013-05-17 21:03 - 00000000 ____D C:\Windows\pss
2013-05-17 19:51 - 2013-05-17 22:23 - 00000000 ____D C:\ProgramData\HitmanPro
==================== One Month Modified Files and Folders =======
2013-06-16 08:58 - 2013-06-15 21:06 - 00000000 ____D C:\troja
2013-06-16 08:34 - 2012-12-03 15:24 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-16 08:31 - 2011-07-23 09:59 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-16 07:45 - 2012-08-10 19:12 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4188504125-4069441578-2337564504-1000UA.job
2013-06-16 06:01 - 2011-07-03 20:49 - 01623958 ____A C:\Windows\WindowsUpdate.log
2013-06-15 22:57 - 2013-06-15 22:57 - 02347384 ____A (ESET) C:\Users\kamilla\Desktop\esetsmartinstaller_enu.exe
2013-06-15 22:39 - 2013-06-15 22:39 - 00041531 ____A C:\Users\kamilla\Desktop\JRT.txt
2013-06-15 22:34 - 2013-06-15 22:34 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 22:34 - 2013-06-15 22:34 - 00000000 ____D C:\JRT
2013-06-15 22:34 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-15 22:34 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-15 22:33 - 2013-06-15 22:33 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\kamilla\Desktop\JRT.exe
2013-06-15 22:26 - 2013-06-15 22:26 - 552262366 ____A C:\Windows\MEMORY.DMP
2013-06-15 22:26 - 2013-06-15 22:26 - 00518976 ____A C:\Windows\Minidump\061513-25006-01.dmp
2013-06-15 22:26 - 2013-06-15 22:26 - 00000000 ____D C:\Windows\Minidump
2013-06-15 22:26 - 2011-07-23 09:59 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-15 22:26 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-15 22:26 - 2009-07-14 06:51 - 00059718 ____A C:\Windows\setupact.log
2013-06-15 22:14 - 2013-06-15 22:14 - 00004109 ____A C:\AdwCleaner[S1].txt
2013-06-15 22:10 - 2013-06-15 22:10 - 00648201 ____A C:\Users\kamilla\Desktop\adwcleaner.exe
2013-06-15 22:00 - 2013-06-15 22:00 - 00000209 ____A C:\Users\kamilla\Desktop\Search.txt
2013-06-15 21:59 - 2013-06-15 21:42 - 00000000 ____D C:\FRST
2013-06-15 21:43 - 2013-06-15 21:43 - 00020177 ____A C:\Users\kamilla\Desktop\Addition.txt
2013-06-15 21:41 - 2013-06-15 21:41 - 01920546 ____A (Farbar) C:\Users\kamilla\Desktop\FRST64.exe
2013-06-15 21:04 - 2013-06-15 21:04 - 00377856 ____A C:\Users\kamilla\Desktop\gmer_2.1.19163.exe
2013-06-15 20:59 - 2013-06-15 20:59 - 00068414 ____A C:\Users\kamilla\Desktop\Extras.Txt
2013-06-15 20:57 - 2013-06-15 20:57 - 00092376 ____A C:\Users\kamilla\Desktop\OTL.Txt
2013-06-15 20:48 - 2013-06-15 20:48 - 00602112 ____A (OldTimer Tools) C:\Users\kamilla\Desktop\OTL.exe
2013-06-15 20:41 - 2013-06-15 20:41 - 00000586 ____A C:\Users\kamilla\Desktop\defogger_disable.log
2013-06-15 20:41 - 2013-06-15 20:41 - 00000020 ____A C:\Users\kamilla\defogger_reenable
2013-06-15 20:41 - 2011-07-03 21:04 - 00000000 ____D C:\users\kamilla
2013-06-15 20:40 - 2013-06-15 20:40 - 00050477 ____A C:\Users\kamilla\Desktop\Defogger.exe
2013-06-15 20:25 - 2012-09-23 10:38 - 00000474 ____A C:\Users\kamilla\Desktop\tt-info Home.website
2013-06-15 19:17 - 2012-08-10 19:12 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4188504125-4069441578-2337564504-1000Core.job
2013-06-15 18:52 - 2013-06-15 18:35 - 127231689 ____A (Igor Pavlov) C:\Users\kamilla\Desktop\OTLPENet.exe
2013-06-15 18:39 - 2009-10-24 17:51 - 00654166 ____A C:\Windows\System32\perfh007.dat
2013-06-15 18:39 - 2009-10-24 17:51 - 00130006 ____A C:\Windows\System32\perfc007.dat
2013-06-15 18:39 - 2009-07-14 07:13 - 01498506 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-15 18:03 - 2011-07-24 11:13 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-15 17:58 - 2013-06-15 17:58 - 00834544 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
2013-06-15 17:57 - 2013-06-15 17:57 - 00000000 ____D C:\Program Files (x86)\LSoft Technologies
2013-06-15 17:57 - 2011-07-23 15:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-11 22:40 - 2012-04-12 02:54 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-11 22:40 - 2011-07-23 15:11 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-10 22:58 - 2012-09-13 21:46 - 00000000 ____D C:\Users\kamilla\Documents\Schule
2013-06-09 18:10 - 2012-09-15 14:21 - 00000000 ____D C:\SCHULE
2013-06-09 15:08 - 2012-10-26 22:02 - 00000000 ____D C:\Users\kamilla\AppData\Local\Microsoft Help
2013-06-08 16:08 - 2013-06-15 18:01 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-15 18:01 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-15 18:01 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-15 18:01 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-15 18:01 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-15 18:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-15 18:01 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-15 18:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-07 08:35 - 2012-09-02 09:49 - 00002185 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-04 19:25 - 2013-05-17 23:03 - 00000000 ____D C:\Program Files (x86)\Heimdal
2013-06-03 20:27 - 2011-07-23 10:54 - 00026070 ____A C:\Windows\PFRO.log
2013-06-03 20:19 - 2011-07-03 21:12 - 00000000 ____D C:\Users\kamilla\AppData\Roaming\Skype
2013-06-02 09:43 - 2011-07-23 09:07 - 00000000 ____D C:\ProgramData\Skype
2013-05-18 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-05-18 09:16 - 2009-07-14 06:45 - 00435568 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-18 08:49 - 2012-10-26 22:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-05-17 23:07 - 2013-05-17 23:08 - 00477616 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2013-05-17 23:07 - 2013-05-17 23:08 - 00162224 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2013-05-17 23:07 - 2013-05-17 23:08 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2013-05-17 23:07 - 2013-05-17 23:08 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2013-05-17 23:07 - 2013-05-17 23:07 - 00000000 ____D C:\Program Files (x86)\Java
2013-05-17 23:07 - 2011-07-23 18:39 - 00473520 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2013-05-17 23:03 - 2013-05-17 23:03 - 00000000 ____D C:\ProgramData\CSIS
2013-05-17 22:33 - 2011-07-24 15:23 - 00000000 ____D C:\ProgramData\Adobe
2013-05-17 22:23 - 2013-05-17 19:51 - 00000000 ____D C:\ProgramData\HitmanPro
2013-05-17 22:19 - 2013-05-17 22:19 - 00000488 ____A C:\Windows\System32\.crusader
2013-05-17 21:03 - 2013-05-17 21:03 - 00000000 ____D C:\Windows\pss
2013-05-17 03:25 - 2013-06-15 18:02 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-05-17 03:25 - 2013-06-15 18:01 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-17 03:25 - 2013-06-15 18:01 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-05-17 02:59 - 2013-06-15 18:02 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-17 02:59 - 2013-06-15 18:01 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-05-17 02:58 - 2013-06-15 18:01 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-13 18:00
==================== End Of Log ============================
--- --- ---