Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-07-2013 01
Ran by Evelyn (administrator) on 12-07-2013 12:31:03
Running from C:\Users\Evelyn\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PskSvc.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\TPSrvWow.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Panda Security, S.L.) C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA GLOBAL PROTECTION 2012\WebProxy.exe
(AMD) C:\Windows\system32\atieclxx.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\Lingvo\15.0\Licensing\NetworkLicenseServer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PsCtrls.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PavFnSvr.exe
(Panda Security, S.L.) C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\pavsrvx86.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\AVENGINE.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(Panda Security International) c:\program files (x86)\panda security\panda global protection 2012\firewall\PSHOST.EXE
(Panda Security S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PsImSvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Synaptics, Inc.) C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CANON INC.) C:\Windows\System32\spool\drivers\x64\3\CNAP2LAK.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Huawei Technologies Co., Ltd.) C:\Users\Evelyn\AppData\Roaming\tele.ring Verbindungsmanager\ouc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
(CANON INC.) C:\Windows\system32\spool\DRIVERS\x64\3\CNAC8SWK.EXE
(CANON INC.) C:\Windows\system32\spool\DRIVERS\x64\3\CNAC8SWK.EXE
(ABBYY (BIT Software)) C:\Program Files (x86)\ABBYY Lingvo x5\LvAgent.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\ApVxdWin.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Dropbox, Inc.) C:\Users\Evelyn\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(ABBYY (BIT Software)) C:\Program Files (x86)\ABBYY Lingvo x5\LvAgent64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\SRVLOAD.EXE
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PavBckPT.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
(Panda Security, S.L.) C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA GLOBAL PROTECTION 2012\TPSRVAUX.EXE
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe
(Panda Security, S.L.) C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA GLOBAL PROTECTION 2012\TPSRVAUX.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2277992 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2283816 2010-11-18] (Synaptics Incorporated)
HKLM\...\Run: [CNAP2 Launcher] - C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [406944 2007-09-05] (CANON INC.)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2277992 2011-11-15] (Realtek Semiconductor)
Winlogon\Notify\avldr: avldr64.dll (On-Access Anti-Malware Scanner Sync)
HKCU\...\Run: [CNAP2 Launcher] - C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [406944 2007-09-05] (CANON INC.)
HKCU\...\Run: [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-03-03] (Google Inc.)
HKCU\...\Run: [HW_OPENEYE_OUC_tele.ring Verbindungsmanager] - "C:\Program Files (x86)\tele.ring Verbindungsmanager\UpdateDog\ouc.exe" [110592 2009-12-31] (Huawei Technologies Co., Ltd.)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
MountPoints2: {21d237cf-f24c-11e0-a188-90004efefdb8} - F:\smartAP.exe
MountPoints2: {599e8fc6-faf6-11e1-b5f7-90004efefdb8} - E:\AutoRun.exe
MountPoints2: {64ada2e4-fa64-11e1-8b99-90004efefdb8} - F:\AutoRun.exe
MountPoints2: {69aa40ae-b97d-11e2-bed0-90004efefdb8} - E:\AutoRun.exe
MountPoints2: {69aa40b1-b97d-11e2-bed0-90004efefdb8} - E:\AutoRun.exe
MountPoints2: {6b54e588-2cd8-11e2-8217-90004efefdb8} - E:\AutoRun.exe
MountPoints2: {ba424e1e-f8b2-11e1-b39a-90004efefdb8} - E:\AutoRun.exe
MountPoints2: {ba424e29-f8b2-11e1-b39a-90004efefdb8} - E:\AutoRun.exe
MountPoints2: {fd07645c-f5e7-11e1-87dd-90004efefdb8} - E:\AutoRun.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [673168 2010-11-17] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM-x32\...\Run: [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [TaskTray] - [x]
HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-01-27] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Lingvo Launcher] - "C:\Program Files (x86)\ABBYY Lingvo x5\LvAgent.exe" /STARTUP [639240 2011-05-26] (ABBYY (BIT Software))
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [APVXDWIN] - "C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\APVXDWIN.EXE" /s [1000768 2011-04-13] (Panda Security, S.L.)
HKLM-x32\...\Run: [SCANINICIO] - "C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\Inicio.exe" [70464 2011-02-02] (Panda Security, S.L.)
HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\tele.ring Verbindungsmanager\DataCardMonitor.exe [253952 2012-09-09] (Huawei Technologies Co., Ltd.)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [TkBellExe] - "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [295512 2013-04-15] (RealNetworks, Inc.)
HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Evelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Evelyn\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about :blank
URLSearchHook: (No Name) - {1d8566bd-f06f-4029-a3be-ba80af5a09f3} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {1292D470-FFDA-4F86-8F5B-10D222DF15B3} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-16/4?mpre=hxxp://shop.ebay.de/?_nkw={searchTerms}
SearchScopes: HKCU - {1AF48959-7966-4F5E-B429-8EC8F011C648} URL = hxxp://de.shopping.com/?linkin_id=8056363
SearchScopes: HKCU - {74D316EC-C7C0-4DA9-ACD1-D8405F91842C} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKCU - {8395F5A6-73A3-4A47-A365-F6E1115E72BB} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10397&src=kw&q={searchTerms}&locale=de_AT&apn_ptnrs=^ABV&apn_dtid=^YYYYYY^YY^AT&apn_uid=3c24d325-7097-4877-9d57-f98e853b133c&apn_sauid=AA6B45E9-ED13-453B-8BF6-FB331C28E714
SearchScopes: HKCU - {92578690-9DEF-489D-8517-AC74C5F11A05} URL = hxxp://searchya.com/?chnl=fxtb-01&s=1&cr=896739976&cd=2XzutAtN2Y1L1Qzu0FtD0B0FzyyBtCyDtBtCyCyBtD0A0FtD0AtN0D0TzutBtDtCtBtDtBtDyE&q={searchTerms}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {1D8566BD-F06F-4029-A3BE-BA80AF5A09F3} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{45BB4420-ED5E-4022-B8F7-1C0A810B747C}: [NameServer]213.162.69.170 213.162.69.169
FireFox:
========
FF ProfilePath: C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\w6rp2pst.default
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.1.18 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.1.18 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon
FF HKLM-x32\...\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKCU\...\Firefox\Extensions: [autolyrics@man-soft.net] C:\Program Files (x86)\AutoLyrics\FF\
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll No File
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
==================== Services (Whitelisted) =================
R2 ABBYY.Licensing.Lingvo.Desktop.15.0; C:\Program Files (x86)\Common Files\ABBYY\Lingvo\15.0\Licensing\NetworkLicenseServer.exe [816904 2011-05-17] (ABBYY)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S4 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-09-14] ()
S4 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [75048 2011-10-12] (CyberLink)
S4 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [292136 2011-10-12] (CyberLink)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Panda Software Controller; C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PsCtrls.exe [173312 2009-08-10] (Panda Security, S.L.)
R2 PAVFNSVR; C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PavFnSvr.exe [202016 2012-10-17] (Panda Security, S.L.)
R2 PavPrSrv; C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe [62768 2008-02-04] (Panda Security, S.L.)
R2 PAVSRV; C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\pavsrvx86.exe [314176 2010-06-04] (Panda Security, S.L.)
R2 PSHost; c:\program files (x86)\panda security\panda global protection 2012\firewall\PSHOST.EXE [226560 2009-11-26] (Panda Security International)
R2 PSIMSVC; C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PsImSvc.exe [108288 2008-06-19] (Panda Security S.L.)
R2 PskSvcRetail; C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\PskSvc.exe [28992 2010-08-16] (Panda Security, S.L.)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 ScrybeUpdater; C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe [1300264 2011-05-11] (Synaptics, Inc.)
R2 TPSrv; C:\Program Files (x86)\Panda Security\Panda Global Protection 2012\TPSrvWow.exe [173888 2011-04-14] (Panda Security, S.L.)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation)
==================== Drivers (Whitelisted) ====================
R2 AmFSM; C:\Windows\System32\DRIVERS\amm6460.sys [65608 2010-05-21] (Panda Security, S.L.)
R2 APPFLT; C:\Windows\system32\Drivers\APPFLT64.SYS [129096 2011-01-31] (Panda Security, S.L.)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.)
R2 ComFiltr; C:\Windows\system32\DRIVERS\COMFiltr.sys [15928 2012-08-30] ()
R2 ComFiltr; C:\Windows\system32\DRIVERS\COMFiltr.sys [15928 2012-08-30] ()
R2 DSAFLT; C:\Windows\system32\Drivers\DSAFLT64.SYS [82952 2009-09-25] (Panda Security, S.L.)
R2 FNETMON; C:\Windows\system32\Drivers\fnetm64.SYS [31752 2009-09-25] (Panda Security, S.L.)
R2 IDSFLT; C:\Windows\system32\Drivers\IDSFLT64.SYS [78920 2010-09-09] (Panda Security, S.L.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R2 NETFLTDI; C:\Windows\system32\Drivers\NETTDI64.SYS [170504 2009-09-25] (Panda Security, S.L.)
R3 NETIMFLT01060044; C:\Windows\System32\DRIVERS\n64i1644.sys [216648 2010-09-01] (Panda Security, S.L.)
R2 ntk_PowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [75248 2011-09-14] (Cyberlink Corp.)
R2 ntk_PowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [75248 2011-09-14] (Cyberlink Corp.)
R0 pavboot; C:\Windows\System32\Drivers\pavboot64.sys [30792 2010-06-22] (Panda Security, S.L.)
R2 risdsnpe; C:\Windows\system32\drivers\risdsnxc64.sys [98816 2010-12-27] (REDC)
R1 ShldFlt; C:\Windows\System32\DRIVERS\ShldFlt.sys [48136 2009-10-27] (Panda Security, S.L.)
S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [203320 2011-12-08] (DEVGURU Co., LTD.(www.devguru.co.kr))
R1 tcpipBM; C:\Windows\System32\Drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.)
R2 WNMFLT; C:\Windows\system32\Drivers\WNMFLT64.SYS [74760 2009-09-25] (Panda Security, S.L.)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-09-16] (CyberLink Corp.)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-09-16] (CyberLink Corp.)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 PavTPK.sys; \??\C:\Windows\system32\PavTPK.sys [x]
R3 Prot6Flt; system32\DRIVERS\Prot6Flt.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-12 12:30 - 2013-07-12 12:30 - 01778143 _____ (Farbar) C:\Users\Evelyn\Desktop\FRST64.exe
2013-07-11 12:55 - 2013-07-11 12:55 - 00000000 ____D C:\Windows\ERUNT
2013-07-11 12:54 - 2013-07-11 12:54 - 00559306 _____ (Oleg N. Scherbakov) C:\Users\Evelyn\Desktop\JRT.exe
2013-07-11 12:53 - 2013-07-11 12:53 - 00013354 _____ C:\Users\Evelyn\Desktop\AdwCleaner[S1].txt
2013-07-11 12:09 - 2013-07-11 12:09 - 00013354 _____ C:\AdwCleaner[S1].txt
2013-07-11 12:07 - 2013-07-11 12:07 - 00650027 _____ C:\Users\Evelyn\Desktop\adwcleaner.exe
2013-07-11 11:06 - 2013-07-11 11:07 - 00027997 _____ C:\Users\Evelyn\Desktop\Addition.txt
2013-07-11 11:05 - 2013-07-11 11:05 - 00000000 ____D C:\FRST
2013-07-11 10:35 - 2013-07-11 10:35 - 00072721 _____ C:\Users\Evelyn\Desktop\logfiles.zip
2013-07-11 03:06 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-11 03:06 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-11 03:06 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-11 03:06 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-11 03:06 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-11 03:06 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-11 03:06 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-11 03:06 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-11 03:06 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-11 03:06 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-11 03:06 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-11 03:06 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-11 03:06 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-11 03:06 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 03:06 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 03:06 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-11 03:06 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 03:06 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-11 03:06 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-11 03:06 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-11 03:06 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 03:06 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-10 22:53 - 2013-07-10 22:53 - 00377856 _____ C:\Users\Evelyn\Desktop\gmer_2.1.19163.exe
2013-07-10 22:41 - 2013-07-10 22:41 - 00602112 _____ (OldTimer Tools) C:\Users\Evelyn\Desktop\OTL.exe
2013-07-10 22:40 - 2013-07-10 22:40 - 00000474 _____ C:\Users\Evelyn\Desktop\defogger_disable.log
2013-07-10 22:40 - 2013-07-10 22:40 - 00000000 _____ C:\Users\Evelyn\defogger_reenable
2013-07-10 22:38 - 2013-07-10 22:38 - 00050477 _____ C:\Users\Evelyn\Desktop\Defogger.exe
2013-07-10 16:14 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-10 16:14 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-10 16:12 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-10 16:12 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-10 16:04 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-10 15:58 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-10 15:58 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-10 09:59 - 2013-07-10 10:00 - 00000000 ____D C:\Users\Evelyn\AppData\Roaming\Mozilla
2013-07-10 09:59 - 2013-07-10 09:59 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-10 09:59 - 2013-07-10 09:59 - 00000000 ____D C:\Users\Evelyn\AppData\Local\Mozilla
2013-07-10 09:59 - 2013-07-10 09:59 - 00000000 ____D C:\ProgramData\Mozilla
2013-07-10 09:59 - 2013-07-10 09:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-10 09:57 - 2013-07-10 09:57 - 00280368 _____ (Mozilla) C:\Users\Evelyn\Downloads\Firefox Setup Stub 22.0.exe
2013-07-06 10:00 - 2013-07-06 10:00 - 00042496 _____ C:\Users\Evelyn\Downloads\Alltagsvokabular_Teil1.xls
2013-07-05 17:14 - 2013-07-05 17:14 - 00000000 ____D C:\telso
2013-07-05 17:13 - 2013-07-08 18:31 - 00000000 ____D C:\Program Files (x86)\Fotobuch-Home
2013-07-05 17:13 - 2013-07-05 17:13 - 00001036 _____ C:\Users\Evelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FotoSort.lnk
2013-07-05 17:13 - 2013-07-05 17:13 - 00001036 _____ C:\Users\Evelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fotobuch-Home.lnk
2013-07-05 17:12 - 2013-07-05 17:12 - 57270118 _____ C:\Users\Evelyn\Downloads\fotobuch-home.exe
2013-07-03 10:39 - 2013-07-03 10:41 - 27701754 _____ C:\Users\Evelyn\Downloads\IMG_7883.zip
2013-07-03 10:38 - 2013-07-03 10:38 - 00000629 _____ C:\Users\Evelyn\Downloads\mail_ru_attachments.htm
2013-06-27 19:34 - 2013-06-27 19:34 - 00022011 _____ C:\Users\Evelyn\Downloads\WG_ AW_ Theateraufführungen (2).msg
2013-06-27 19:34 - 2013-06-27 19:34 - 00022011 _____ C:\Users\Evelyn\Downloads\WG_ AW_ Theateraufführungen (1).msg
2013-06-27 19:34 - 2013-06-27 19:34 - 00000983 _____ C:\Users\Evelyn\Downloads\DVD und Hüllen.txt
2013-06-27 19:33 - 2013-06-27 19:33 - 00022011 _____ C:\Users\Evelyn\Downloads\WG_ AW_ Theateraufführungen.msg
2013-06-26 15:46 - 2013-06-26 15:46 - 00025726 _____ C:\Users\Evelyn\Downloads\Turda.zip
2013-06-14 15:09 - 2013-06-14 15:09 - 00036207 _____ C:\Users\Evelyn\Downloads\Kontakt.zip
2013-06-14 15:09 - 2013-06-14 15:09 - 00035259 _____ C:\Users\Evelyn\Downloads\Bettina Mayr.vcf
2013-06-14 15:09 - 2013-06-14 15:09 - 00035259 _____ C:\Users\Evelyn\Downloads\Bettina Mayr (1).vcf
2013-06-13 08:03 - 2013-06-13 08:03 - 00014458 _____ C:\Users\Evelyn\Downloads\Мы говорим по (2).d ocx
2013-06-12 21:34 - 2013-05-13 07:51 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-06-12 21:34 - 2013-05-13 07:51 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-06-12 21:34 - 2013-05-13 07:51 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-06-12 21:34 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-06-12 21:34 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 21:34 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 21:34 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 21:34 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-06-12 21:34 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 21:34 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 21:34 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-06-12 21:34 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 21:34 - 2013-05-08 08:39 - 01910632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-06-12 21:34 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-06-12 21:34 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 21:34 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 21:34 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 21:34 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-06-12 21:34 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
==================== One Month Modified Files and Folders =======
2013-07-12 12:30 - 2013-07-12 12:30 - 01778143 _____ (Farbar) C:\Users\Evelyn\Desktop\FRST64.exe
2013-07-12 12:13 - 2011-03-03 05:20 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-12 11:13 - 2012-08-30 10:41 - 00008627 _____ C:\Windows\SysWOW64\PAV_FOG.OPC
2013-07-12 09:49 - 2011-09-10 15:16 - 01733439 _____ C:\Windows\WindowsUpdate.log
2013-07-12 09:15 - 2012-08-30 10:11 - 00000216 _____ C:\Windows\system32\Drivers\etc\NetAdapt.cfg.bck
2013-07-12 09:15 - 2012-08-30 10:11 - 00000216 _____ C:\Windows\system32\Drivers\etc\NetAdapt.cfg
2013-07-11 17:13 - 2011-03-03 05:20 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-11 12:56 - 2013-03-27 10:05 - 00000000 ___RD C:\Users\Evelyn\Dropbox
2013-07-11 12:56 - 2013-03-27 10:02 - 00000000 ____D C:\Users\Evelyn\AppData\Roaming\Dropbox
2013-07-11 12:56 - 2012-08-30 10:38 - 00000252 _____ C:\Windows\system32\Drivers\etc\IdsFlt.cfg.bck
2013-07-11 12:56 - 2012-08-30 10:38 - 00000252 _____ C:\Windows\system32\Drivers\etc\IdsFlt.cfg
2013-07-11 12:56 - 2012-08-30 10:38 - 00000176 _____ C:\Windows\system32\Drivers\etc\NetLoc.wlt.bck
2013-07-11 12:56 - 2012-08-30 10:38 - 00000176 _____ C:\Windows\system32\Drivers\etc\NetLoc.wlt
2013-07-11 12:56 - 2012-08-30 10:38 - 00000068 _____ C:\Windows\system32\Drivers\etc\NetFlt.cfg.bck
2013-07-11 12:56 - 2012-08-30 10:38 - 00000068 _____ C:\Windows\system32\Drivers\etc\NetFlt.cfg
2013-07-11 12:56 - 2012-08-30 10:38 - 00000056 _____ C:\Windows\system32\Drivers\etc\WnmFlt.cfg.bck
2013-07-11 12:56 - 2012-08-30 10:38 - 00000056 _____ C:\Windows\system32\Drivers\etc\WnmFlt.cfg
2013-07-11 12:56 - 2012-08-30 10:38 - 00000056 _____ C:\Windows\system32\Drivers\etc\DsaFlt.cfg.bck
2013-07-11 12:56 - 2012-08-30 10:38 - 00000056 _____ C:\Windows\system32\Drivers\etc\DsaFlt.cfg
2013-07-11 12:56 - 2012-08-30 09:39 - 00424704 _____ C:\Windows\system32\Drivers\APPFCONT.DAT.bck
2013-07-11 12:56 - 2012-08-30 09:39 - 00424704 _____ C:\Windows\system32\Drivers\APPFCONT.DAT
2013-07-11 12:56 - 2012-08-30 09:39 - 00303044 _____ C:\Windows\system32\Drivers\etc\DsaFlt.rls.bck
2013-07-11 12:56 - 2012-08-30 09:39 - 00303044 _____ C:\Windows\system32\Drivers\etc\DsaFlt.rls
2013-07-11 12:56 - 2012-08-30 09:39 - 00001132 _____ C:\Windows\system32\Drivers\APPFLTR.CFG.bck
2013-07-11 12:56 - 2012-08-30 09:39 - 00001132 _____ C:\Windows\system32\Drivers\APPFLTR.CFG
2013-07-11 12:55 - 2013-07-11 12:55 - 00000000 ____D C:\Windows\ERUNT
2013-07-11 12:54 - 2013-07-11 12:54 - 00559306 _____ (Oleg N. Scherbakov) C:\Users\Evelyn\Desktop\JRT.exe
2013-07-11 12:53 - 2013-07-11 12:53 - 00013354 _____ C:\Users\Evelyn\Desktop\AdwCleaner[S1].txt
2013-07-11 12:18 - 2009-07-14 06:45 - 00013872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-11 12:18 - 2009-07-14 06:45 - 00013872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-11 12:11 - 2012-08-30 10:11 - 00000064 _____ C:\Windows\system32\Drivers\etc\NetAR.wlt.bck
2013-07-11 12:11 - 2012-08-30 10:11 - 00000064 _____ C:\Windows\system32\Drivers\etc\NetAR.wlt
2013-07-11 12:11 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-11 12:11 - 2009-07-14 06:51 - 00148397 _____ C:\Windows\setupact.log
2013-07-11 12:09 - 2013-07-11 12:09 - 00013354 _____ C:\AdwCleaner[S1].txt
2013-07-11 12:07 - 2013-07-11 12:07 - 00650027 _____ C:\Users\Evelyn\Desktop\adwcleaner.exe
2013-07-11 11:07 - 2013-07-11 11:06 - 00027997 _____ C:\Users\Evelyn\Desktop\Addition.txt
2013-07-11 11:05 - 2013-07-11 11:05 - 00000000 ____D C:\FRST
2013-07-11 10:35 - 2013-07-11 10:35 - 00072721 _____ C:\Users\Evelyn\Desktop\logfiles.zip
2013-07-11 10:07 - 2013-05-10 09:47 - 00232044 _____ C:\test.xml
2013-07-11 03:30 - 2009-07-14 06:45 - 00473376 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 03:29 - 2012-05-22 22:42 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 03:29 - 2012-05-22 22:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-11 03:28 - 2011-01-13 14:21 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 03:28 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-11 03:28 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-11 03:11 - 2011-03-03 13:42 - 00658392 _____ C:\Windows\system32\perfh007.dat
2013-07-11 03:11 - 2011-03-03 13:42 - 00131474 _____ C:\Windows\system32\perfc007.dat
2013-07-11 03:11 - 2009-07-14 07:13 - 01531070 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-11 03:07 - 2011-09-10 16:05 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-11 03:07 - 2011-09-10 15:30 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-11 00:00 - 2012-08-30 09:39 - 00000520 _____ C:\Windows\Tasks\Grundlegende Bereinigung.job
2013-07-10 22:53 - 2013-07-10 22:53 - 00377856 _____ C:\Users\Evelyn\Desktop\gmer_2.1.19163.exe
2013-07-10 22:41 - 2013-07-10 22:41 - 00602112 _____ (OldTimer Tools) C:\Users\Evelyn\Desktop\OTL.exe
2013-07-10 22:40 - 2013-07-10 22:40 - 00000474 _____ C:\Users\Evelyn\Desktop\defogger_disable.log
2013-07-10 22:40 - 2013-07-10 22:40 - 00000000 _____ C:\Users\Evelyn\defogger_reenable
2013-07-10 22:40 - 2011-09-10 15:21 - 00000000 ____D C:\Users\Evelyn
2013-07-10 22:38 - 2013-07-10 22:38 - 00050477 _____ C:\Users\Evelyn\Desktop\Defogger.exe
2013-07-10 10:00 - 2013-07-10 09:59 - 00000000 ____D C:\Users\Evelyn\AppData\Roaming\Mozilla
2013-07-10 09:59 - 2013-07-10 09:59 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-10 09:59 - 2013-07-10 09:59 - 00000000 ____D C:\Users\Evelyn\AppData\Local\Mozilla
2013-07-10 09:59 - 2013-07-10 09:59 - 00000000 ____D C:\ProgramData\Mozilla
2013-07-10 09:59 - 2013-07-10 09:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-10 09:59 - 2012-02-04 20:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-10 09:57 - 2013-07-10 09:57 - 00280368 _____ (Mozilla) C:\Users\Evelyn\Downloads\Firefox Setup Stub 22.0.exe
2013-07-10 09:55 - 2013-04-15 17:33 - 00000000 ____D C:\Windows\22B3AE667A374118BADB3680C15CA366.TMP
2013-07-10 09:52 - 2011-09-10 15:30 - 00000000 ____D C:\Users\Evelyn\AppData\Local\Google
2013-07-09 10:26 - 2011-09-10 15:24 - 00003946 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{2FBE20BA-D123-4A6D-9B65-FB289306359B}
2013-07-08 18:32 - 2011-09-10 15:33 - 00000000 ____D C:\Users\Evelyn\AppData\Roaming\SoftGrid Client
2013-07-08 18:31 - 2013-07-05 17:13 - 00000000 ____D C:\Program Files (x86)\Fotobuch-Home
2013-07-07 20:57 - 2012-11-03 21:31 - 00000000 ____D C:\Users\Evelyn\AppData\Roaming\vlc
2013-07-06 10:56 - 2012-11-18 17:58 - 00164036 ____H C:\Windows\SysWOW64\mlfcache.dat
2013-07-06 10:00 - 2013-07-06 10:00 - 00042496 _____ C:\Users\Evelyn\Downloads\Alltagsvokabular_Teil1.xls
2013-07-05 17:20 - 2011-09-10 15:21 - 00131624 _____ C:\Users\Evelyn\AppData\Local\GDIPFONTCACHEV1.DAT
2013-07-05 17:14 - 2013-07-05 17:14 - 00000000 ____D C:\telso
2013-07-05 17:13 - 2013-07-05 17:13 - 00001036 _____ C:\Users\Evelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FotoSort.lnk
2013-07-05 17:13 - 2013-07-05 17:13 - 00001036 _____ C:\Users\Evelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fotobuch-Home.lnk
2013-07-05 17:12 - 2013-07-05 17:12 - 57270118 _____ C:\Users\Evelyn\Downloads\fotobuch-home.exe
2013-07-03 10:41 - 2013-07-03 10:39 - 27701754 _____ C:\Users\Evelyn\Downloads\IMG_7883.zip
2013-07-03 10:38 - 2013-07-03 10:38 - 00000629 _____ C:\Users\Evelyn\Downloads\mail_ru_attachments.htm
2013-07-02 16:58 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-07-02 11:45 - 2012-11-03 21:32 - 00000000 ____D C:\Users\Evelyn\AppData\Roaming\dvdcss
2013-06-29 10:25 - 2011-03-03 05:48 - 00037222 _____ C:\Windows\PFRO.log
2013-06-27 19:34 - 2013-06-27 19:34 - 00022011 _____ C:\Users\Evelyn\Downloads\WG_ AW_ Theateraufführungen (2).msg
2013-06-27 19:34 - 2013-06-27 19:34 - 00022011 _____ C:\Users\Evelyn\Downloads\WG_ AW_ Theateraufführungen (1).msg
2013-06-27 19:34 - 2013-06-27 19:34 - 00000983 _____ C:\Users\Evelyn\Downloads\DVD und Hüllen.txt
2013-06-27 19:33 - 2013-06-27 19:33 - 00022011 _____ C:\Users\Evelyn\Downloads\WG_ AW_ Theateraufführungen.msg
2013-06-26 15:46 - 2013-06-26 15:46 - 00025726 _____ C:\Users\Evelyn\Downloads\Turda.zip
2013-06-14 15:09 - 2013-06-14 15:09 - 00036207 _____ C:\Users\Evelyn\Downloads\Kontakt.zip
2013-06-14 15:09 - 2013-06-14 15:09 - 00035259 _____ C:\Users\Evelyn\Downloads\Bettina Mayr.vcf
2013-06-14 15:09 - 2013-06-14 15:09 - 00035259 _____ C:\Users\Evelyn\Downloads\Bettina Mayr (1).vcf
2013-06-13 08:03 - 2013-06-13 08:03 - 00014458 _____ C:\Users\Evelyn\Downloads\Мы говорим по (2).d ocx
2013-06-13 07:46 - 2011-09-10 15:22 - 00000000 ___RD C:\Users\Evelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-06-13 07:45 - 2013-03-27 10:03 - 00000000 ____D C:\Users\Evelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-06-12 01:43 - 2013-07-11 03:06 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 01:43 - 2013-07-11 03:06 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 01:43 - 2013-07-11 03:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 01:43 - 2013-07-11 03:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 01:43 - 2013-07-11 03:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 01:43 - 2013-07-11 03:06 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 01:43 - 2013-07-11 03:06 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 01:42 - 2013-07-11 03:06 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 01:42 - 2013-07-11 03:06 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 01:42 - 2013-07-11 03:06 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-12 01:42 - 2013-07-11 03:06 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 01:42 - 2013-07-11 03:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 01:42 - 2013-07-11 03:06 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 01:26 - 2013-07-11 03:06 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-06-12 01:26 - 2013-07-11 03:06 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-06-12 01:26 - 2013-07-11 03:06 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-06-12 01:25 - 2013-07-11 03:06 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-06-12 01:25 - 2013-07-11 03:06 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-06-12 00:51 - 2013-07-11 03:06 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 00:50 - 2013-07-11 03:06 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-03 09:19
==================== End Of Log ============================