|
Log-Analyse und Auswertung: Windows 7, PC langsam und diverse Funde durch Malwarebytes AntimalwareWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
12.10.2013, 18:40 | #1 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Hallo liebes Torjaner-Board, vor ein paar Monaten hat einer von Euch meinem Schwager sehr zügig geholfen einen Trojaner von seinem PC zu bekommen. Er hat mir empfohlen dieses Forum mit meinem aktuelle Problem um Rat bzw. Hilfe zu fragen. Außerdem sagte er mir, ich solle schonmal einen MBAM-Scan machen, was ich auch getan habe. Hier die Log-Datei: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.11.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 a :: A-PC [Administrator] Schutz: Aktiviert 12.10.2013 14:51:31 MBAM-log-2013-10-12 (19-15-04).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 95326 Laufzeit: 28 Minute(n), 43 Sekunde(n) [Abgebrochen] Infizierte Speicherprozesse: 2 C:\Program Files\IB Updater\ExtensionUpdaterService.exe (PUP.Optional.SweetPacks.A) -> 1424 -> Keine Aktion durchgeführt. C:\Windows\SysWOW64\jmdp\stij.exe (PUP.Optional.InstallBrain.A) -> 1804 -> Keine Aktion durchgeführt. Infizierte Speichermodule: 1 C:\Windows\SysWOW64\jmdp\lmrn.dll (PUP.Optional.Sweetpacks) -> Keine Aktion durchgeführt. Infizierte Registrierungsschlüssel: 39 HKLM\SYSTEM\CurrentControlSet\Services\IB Updater (PUP.Optional.SweetPacks.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\SWEETIE.IEToolbar.1 (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\SWEETIE.IEToolbar (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\Toolbar3.SWEETIE.1 (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\Toolbar3.SWEETIE (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. HKCR\CLSID\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{008f6853-9cb4-41c5-a950-39d55e5e06ba} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\TypeLib\{33D0AD98-3347-4A54-8929-5163EBEB9F72} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\AlxTB2.TBLayoutBHO.1 (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\AlxTB2.TBLayoutBHO (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{F443A627-5009-4323-9C1D-7FD598D0D712} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\AlxTB2.AlxHelper.1 (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\AlxTB2.AlxHelper (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F443A627-5009-4323-9C1D-7FD598D0D712} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{F443A627-5009-4323-9C1D-7FD598D0D712} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F443A627-5009-4323-9C1D-7FD598D0D712} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\MgMediaPlayer.GifAnimator.1 (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\MgMediaPlayer.GifAnimator (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1 (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35D-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 9 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SweetIM (PUP.Optional.SweetIM) -> Daten: C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Sweetpacks Communicator (PUP.Optional.SweetIM) -> Daten: C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Daten: 썛愘ᇜ犜ጀ유䞘 -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Daten: -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Daten: -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Daten: -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{EEE6C35D-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Daten: -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGHELPERAPP.EXE (PUP.Optional.SweetIM) -> Daten: 1 -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGTOOLBARPROXY.DLL (PUP.Optional.SweetIM) -> Daten: 1 -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 44 C:\Program Files\IB Updater\ExtensionUpdaterService.exe (PUP.Optional.SweetPacks.A) -> Keine Aktion durchgeführt. C:\Windows\SysWOW64\jmdp\stij.exe (PUP.Optional.InstallBrain.A) -> Keine Aktion durchgeführt. C:\Windows\SysWOW64\jmdp\lmrn.dll (PUP.Optional.Sweetpacks) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (PUP.Optional.SweetPacks) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll (PUP.Optional.AmazonTB.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Amazon Browser Bar\search_protect.exe (PUP.Optional.Searchprotect) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\mgSqlite3.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\ContentPackagesActivationHandler.exe (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgArchive.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgcommon.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgcommunication.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgconfig.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgFlashPlayer.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mghooking.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgICQAuto.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgICQMessengerAdapter.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mglogger.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgMediaPlayer.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgMsnAuto.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgMsnMessengerAdapter.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgsimcommon.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgSweetIM.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgUpdateSupport.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgxml_wrapper.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgYahooAuto.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\mgYahooMessengerAdapter.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Messenger\resources\sqlite\mgSqlite3.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. (Ende) Viele Grüße Stephie |
12.10.2013, 22:10 | #2 |
/// the machine /// TB-Ausbilder | Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
12.10.2013, 23:12 | #3 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Guten Abend Schrauber,
__________________vielen dank für Deine schnelle Hilfe! Hier sind die Ergebnisse des Programmes FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by a (administrator) on A-PC on 12-10-2013 23:47:37 Running from C:\Users\a\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files\IB Updater\ExtensionUpdaterService.exe () C:\Windows\system32\dmwu.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe () C:\Windows\SysWOW64\jmdp\stij.exe () C:\Windows\System32\ljkb\stij.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [AutoStartNPSAgent] - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-04] (Samsung Electronics Co., Ltd.) HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-16] (Google Inc.) HKCU\...\Policies\Explorer: [NoInternetOpenWith] 1 HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SweetIM] - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [NPSStartup] - [x] HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1646216 2013-04-01] (Ask) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9817545DADAECC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.gmx.net/br/ie9_startpage HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File URLSearchHook: (No Name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - No File SearchScopes: HKCU - {09038620-190C-402B-A92F-18864E6AB22F} URL = hxxp://go.1und1.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {35AAD74D-1BA4-4DF2-95D5-C38867FCE180} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=e6b4ee46-438c-4890-a35a-7398f556e670&apn_sauid=0BB6692A-037F-415C-A713-7C91CED8A635 SearchScopes: HKCU - {5A817CF6-92D5-4DE5-AC38-82DF8A73EF28} URL = hxxp://go.gmx.net/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {6B1D1FB7-7233-4F7C-802C-21A1DDB12754} URL = hxxp://go.web.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {81CE708B-5104-4C62-B333-94B417473B29} URL = hxxp://go.mail.com/br/ie8_search_web/?su={searchTerms} SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = hxxp://www.daemon-search.com/search?q={searchTerms} SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/?a=6R8OJ0Pb4s&loc=skw&search={searchTerms} BHO: IB Updater - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension64.dll () BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: IB Updater - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll () BHO-x32: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll (Montera Technologeis LTD) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: AdobeAir - {DCA971EE-CB86-4592-AE52-A45B2E257A12} - C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAir.dll (Adobe Systems Inc.) BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) BHO-x32: AlxHelper Class - {F443A627-5009-4323-9C1D-7FD598D0D712} - C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll (Amazon.com) Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () Toolbar: HKLM-x32 - Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll (Montera Technologeis LTD) Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - Amazon Browser Bar - {EA582743-9076-4178-9AA6-7393FDF4D5CE} - C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll (Amazon.com) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default FF user.js: detected! => C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\user.js FF SelectedSearchEngine: Ask.com FF Homepage: hxxp://search.avira.com/?l=dis&o=APN10261&gct=hp&dc=EU&locale=de_DE FF NetworkProxy: "type", 0 FF SearchEngineOrder.1: Ask.com FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\daemon-search.xml FF SearchPlugin: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\MyStart Search.xml FF SearchPlugin: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\MyStart.xml FF SearchPlugin: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\sweetim.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\abb@amazon.com FF Extension: AdobeAir - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\air3@adobe.com FF Extension: No Name - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\DTToolbar@toolbarnet.com FF Extension: incredibar.com - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\ffxtlbr@incredibar.com FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\toolbar@ask.com FF Extension: SweetPacks Toolbar for Firefox - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox FF Extension: IB Updater - C:\Program Files\IB Updater\Firefox FF HKLM\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\IB Updater\Firefox FF Extension: IB Updater - C:\Program Files\IB Updater\Firefox FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox FF Extension: IB Updater - C:\Program Files\IB Updater\Firefox FF HKLM-x32\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\IB Updater\Firefox FF Extension: IB Updater - C:\Program Files\IB Updater\Firefox Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://mystart.incredibar.com/?a=6R8OJ0Pb4s&loc=skw", "hxxp://www.google.com/" CHR DefaultSearchURL: (MyStart) - hxxp://mystart.incredibar.com/?a=6R8OJ0Pb4s&loc=skw&search={searchTerms} CHR DefaultSuggestURL: (MyStart) - "suggest_url": "" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) CHR Plugin: (NPCIG.dll) - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdobeAir) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdalfokaihlahnhdieedhgfekidifmfa\3.0.21_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (Amazon for Chrome) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\2.2.2012.272_0 CHR Extension: (Gmail) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx CHR HKLM-x32\...\Chrome\Extension: [gdalfokaihlahnhdieedhgfekidifmfa] - C:\Users\a\AppData\LocalLow\AdobeAir\CHROME\AdobeAir.crx CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx CHR HKLM-x32\...\Chrome\Extension: [niogeckbkdcabhnapjbkeiklablhjoca] - C:\Program Files (x86)\Perion\ChromeInfoBar\ChromeInfoBar.crx ==================== Services (Whitelisted) ================= R2 AdobeAirUpdater; C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe [18432 2011-11-03] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG) R2 IB Updater; C:\Program Files\IB Updater\ExtensionUpdaterService.exe [188760 2013-01-29] () R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1762608 2013-09-15] () R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 Updater Service for AMZN; C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe [222368 2013-03-21] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-11-29] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U4 SR; S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-12 23:42 - 2013-10-12 23:42 - 00000000 ___DC C:\FRST 2013-10-12 23:40 - 2013-10-12 23:40 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-11 22:45 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-11 22:45 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-11 22:45 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-11 22:45 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 22:45 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-11 22:45 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-11 22:45 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-11 12:49 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 12:49 - 2013-07-12 12:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-11 12:49 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-11 12:49 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-11 12:49 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 12:49 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-11 12:49 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 12:49 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 12:49 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-11 12:49 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-11 12:49 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-11 12:49 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-11 12:48 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 12:48 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 12:48 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-11 12:48 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-11 12:48 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-11 12:48 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-11 12:48 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-11 12:48 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-11 12:48 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 12:48 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-11 12:48 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 12:48 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 12:48 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 20:59 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 18:33 - 2013-10-12 23:31 - 00000280 _____ C:\Windows\setupact.log 2013-10-09 18:33 - 2013-10-11 12:20 - 00046252 _____ C:\Windows\PFRO.log 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:29 - 2013-10-09 18:30 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:27 - 2013-10-09 18:28 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:26 - 2013-10-09 18:27 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:24 - 2013-10-09 18:30 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:24 - 2013-10-09 18:29 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:24 - 2013-10-09 18:25 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-08 15:27 - 2013-10-09 18:49 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-10-08 15:26 - 2013-10-08 15:26 - 00000000 ____D C:\Users\a\AppData\Local\Amazon Browser Bar 2013-10-08 15:24 - 2013-10-08 15:26 - 00000000 ____D C:\Program Files (x86)\Amazon Browser Bar 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 15:22 - 2013-10-09 18:43 - 00000000 ____D C:\Users\a\AppData\Roaming\Systweak 2013-10-08 15:22 - 2013-08-22 18:36 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe 2013-10-08 14:57 - 2013-10-08 14:58 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:31 - 2013-10-05 12:50 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:28 - 2013-10-09 18:23 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\SysWOW64\jmdp 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb ==================== One Month Modified Files and Folders ======= 2013-10-12 23:46 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-12 23:46 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-12 23:45 - 2012-04-11 22:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-12 23:45 - 2011-11-29 17:31 - 01846883 _____ C:\Windows\WindowsUpdate.log 2013-10-12 23:42 - 2013-10-12 23:42 - 00000000 ___DC C:\FRST 2013-10-12 23:40 - 2013-10-12 23:40 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-12 23:39 - 2011-12-02 13:36 - 00003898 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E1F44A7E-8E42-42AB-865E-6B52309A825A} 2013-10-12 23:32 - 2011-11-29 17:49 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-12 23:31 - 2013-10-09 18:33 - 00000280 _____ C:\Windows\setupact.log 2013-10-12 23:31 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-12 20:59 - 2011-11-29 17:49 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-12 19:16 - 2011-11-30 20:17 - 00000000 ____D C:\Neuer Ordner 2013-10-12 11:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-10-12 09:01 - 2010-11-21 08:50 - 00699738 _____ C:\Windows\system32\perfh007.dat 2013-10-12 09:01 - 2010-11-21 08:50 - 00149600 _____ C:\Windows\system32\perfc007.dat 2013-10-12 09:01 - 2009-07-14 07:13 - 01621320 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-12 08:55 - 2011-11-29 17:24 - 00000000 ____D C:\Windows\Panther 2013-10-12 08:52 - 2009-07-14 06:45 - 00298072 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-11 22:40 - 2011-11-29 18:02 - 01599214 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-11 22:30 - 2013-08-15 22:31 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 22:26 - 2011-12-04 11:46 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-11 12:20 - 2013-10-09 18:33 - 00046252 _____ C:\Windows\PFRO.log 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 18:49 - 2013-10-08 15:27 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-10-09 18:49 - 2011-11-29 17:40 - 00000000 ___RD C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-09 18:43 - 2013-10-08 15:22 - 00000000 ____D C:\Users\a\AppData\Roaming\Systweak 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:30 - 2013-10-09 18:29 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:30 - 2013-10-09 18:24 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:29 - 2013-10-09 18:24 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:28 - 2013-10-09 18:27 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:27 - 2013-10-09 18:26 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:27 - 2011-12-03 16:30 - 00000000 ____D C:\ProgramData\f-secure 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:25 - 2013-10-09 18:24 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 18:23 - 2013-10-05 12:28 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-09 18:00 - 2011-12-04 11:47 - 00000000 ____D C:\Users\a\AppData\Roaming\Media Player Classic 2013-10-09 17:58 - 2013-07-20 22:13 - 00000000 ____D C:\Windows\Minidump 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 17:39 - 2011-11-29 17:49 - 00000000 ____D C:\Program Files\CCleaner 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 15:43 - 2012-04-11 22:09 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-08 15:26 - 2013-10-08 15:26 - 00000000 ____D C:\Users\a\AppData\Local\Amazon Browser Bar 2013-10-08 15:26 - 2013-10-08 15:24 - 00000000 ____D C:\Program Files (x86)\Amazon Browser Bar 2013-10-08 15:26 - 2011-12-27 20:30 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 14:58 - 2013-10-08 14:57 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:50 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:32 - 2011-11-29 17:39 - 00000000 ____D C:\Users\a 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:07 - 2013-07-16 12:30 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:18 - 2012-07-18 13:29 - 00000000 ____D C:\Program Files (x86)\ALDI Bestellsoftware 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-10-01 11:05 - 2013-05-07 17:23 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-23 01:28 - 2013-10-11 22:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-11 22:45 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-11 22:45 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-21 05:38 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-11 22:45 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-11 22:45 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-18 07:49 - 2012-10-22 21:53 - 00000000 ____D C:\Windows\SysWOW64\WNLT 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\SysWOW64\jmdp 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb 2013-09-17 16:13 - 2013-04-10 20:58 - 00000000 ____D C:\Windows\SysWOW64\ARFC 2013-09-15 14:21 - 2013-03-29 12:55 - 01762608 _____ C:\Windows\system32\dmwu.exe 2013-09-15 14:16 - 2013-03-29 12:55 - 00033792 _____ (IncrediMail, Ltd.) C:\Windows\system32\ImHttpComm.dll 2013-09-14 03:10 - 2013-10-11 12:48 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-09-12 17:49 - 2011-11-29 17:40 - 00000000 ___RD C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 17:38 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5912.dll Some content of TEMP: ==================== C:\Users\a\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-12 11:23 ==================== End Of Log ============================ --- --- --- [/CODE] Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013 Ran by a at 2013-10-12 23:49:33 Running from C:\Users\a\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x32) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) Adobe AIR (x32 Version: 3.8.0.870) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8) Adobe Shockwave Player 11.5 (x32 Version: 11.5.9.620) ALDI Bestellsoftware 4.12.2 (x32 Version: 4.12.2) Amazon Browser Bar (x32 Version: 3.0) Amazon MP3-Downloader 1.0.17 (x32 Version: 1.0.17) Amazon Music Importer (x32 Version: 2.0.1) Ask Toolbar (x32 Version: 1.15.24.0) Avira Free Antivirus (x32 Version: 14.0.0.383) Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.2.5.42066) AVM FRITZ!Box Dokumentation (x32) AVM FRITZ!Box Druckeranschluss (x32) Canon Easy-PhotoPrint EX (x32) CANON iMAGE GATEWAY MyCamera Download Plugin (x32 Version: 3.1.1.2) CANON iMAGE GATEWAY Task for ZoomBrowser EX (x32 Version: 1.9.0.9) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32) Canon MOV Decoder (x32 Version: 1.8.0.7) Canon MOV Encoder (x32 Version: 1.6.0.1) Canon MovieEdit Task for ZoomBrowser EX (x32 Version: 3.7.0.4) Canon MP Navigator EX 3.0 (x32) Canon MP560 series Benutzerregistrierung (x32) Canon MP560 series MP Drivers Canon My Printer (x32) Canon Utilities Digital Photo Professional 3.10 (x32 Version: 3.10.2.0) Canon Utilities EOS Sample Music (x32 Version: 1.0.0.204) Canon Utilities EOS Utility (x32 Version: 2.10.2.0) Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX (x32 Version: 1.0.0.10) Canon Utilities Movie Uploader for YouTube (x32 Version: 1.2.0.7) Canon Utilities PhotoStitch (x32 Version: 3.1.22.46) Canon Utilities Picture Style Editor (x32 Version: 1.9.0.0) Canon Utilities Solution Menu (x32) Canon Utilities ZoomBrowser EX (x32 Version: 6.7.0.24) Canon ZoomBrowser EX Memory Card Utility (x32 Version: 1.5.0.9) CCleaner (Version: 4.06) DAEMON Tools Lite (x32 Version: 4.40.2.0131) DAEMON Tools Toolbar (x32 Version: 1.1.4.0024) Google Chrome (x32 Version: 30.0.1599.69) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4601.54) Google Update Helper (x32 Version: 1.3.21.153) HashCheck Shell Extension (x86-32) (x32 Version: 2.1.11.1) IB Updater 2.0.0.575 (Version: 2.0.0.575) IB Updater Service (x32 Version: 4.0.7.3) Incredibar Toolbar on IE (x32) Internet Explorer Toolbar 4.6 by SweetPacks (x32 Version: 4.6.0004) Java(TM) 6 Update 24 (x32 Version: 6.0.240) K-Lite Codec Pack (64-bit) v4.5.0 (Version: 4.5.0) K-Lite Codec Pack 7.0.0 (Full) (x32 Version: 7.0.0) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office XP Professional mit FrontPage (x32 Version: 10.0.6626.0) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox (3.6.15) (x32 Version: 3.6.15 (de)) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Nero - Burning Rom (x32 Version: 5.5.9.9) Picasa 3 (x32 Version: 3.9) RocketDock 1.3.5 (x32) Samsung New PC Studio (x32 Version: 1.00.0000) SAMSUNG USB Driver for Mobile Phones (Version: 1.3.650.0) SpeedCommander 13 (x64) (Version: 13.40.6300) SweetIM for Messenger 3.7 (x32 Version: 3.7.0007) SweetPacks bundle uninstaller (x32 Version: 1.0.0000) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Update Manager for SweetPacks 1.1 (x32 Version: 1.1.0008) Visual C++ 9.0 ATL (x86) WinSXS MSM (x32 Version: 9.0) WinRAR 4.00 (64-Bit) (Version: 4.00.0) ==================== Restore Points ========================= 11-10-2013 20:13:25 Windows Update 12-10-2013 19:28:33 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {20AE6C6E-E703-40B9-9345-48F932485AD7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-29] (Google Inc.) Task: {22807743-235A-4535-BC14-5773377758A9} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-04-01] () Task: {524FAE51-B82A-4F99-A01F-ED415EA55E47} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {5541DA16-7703-4DB2-A7BA-77E6205F3997} - System32\Tasks\{F37821B4-1F1B-4B1D-A1A2-3EA07507929C} => C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe Task: {7F478BD9-F619-4246-B042-DD73EF32DF02} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd) Task: {920AFF1F-4578-4CA2-BD69-A5AE8A09C844} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => d:\program files\windows defender\MpCmdRun.exe Task: {ACE4FEE9-188D-454A-8C1C-A3588E7796A9} - System32\Tasks\{3B2A741B-4572-4677-8F63-75499A66A2E2} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.2.0.169/de/abandoninstall?source=lightinstaller&page=tsMain&installinfo=google-toolbar:notoffered;toolbarpresent,google-chrome:notoffered;alreadyoffered Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => d:\program files\windows defender\MpCmdRun.exe Task: {D9358542-86E4-4CC5-94FB-F56399F5C2A8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-29] (Google Inc.) Task: {E6B79F9E-2579-451A-BDFB-9674A6E63783} - System32\Tasks\{D8F4D06C-84F6-49C1-9037-0730447FE437} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=4.2.0.169&LastError=404 Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-15 14:32 - 2013-09-15 14:32 - 01321472 _____ () C:\Windows\System32\ljkb\lmrn.dll 2013-04-19 09:40 - 2013-04-18 20:06 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-09-15 14:30 - 2013-09-15 14:30 - 01062912 _____ () C:\Windows\SysWOW64\jmdp\lmrn.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:DBC416F8 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/12/2013 11:45:34 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FRST64.exe, Version: 3.3.8.1, Zeitstempel: 0x4f25bafd Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c92c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000035ce6 ID des fehlerhaften Prozesses: 0x578 Startzeit der fehlerhaften Anwendung: 0xFRST64.exe0 Pfad der fehlerhaften Anwendung: FRST64.exe1 Pfad des fehlerhaften Moduls: FRST64.exe2 Berichtskennung: FRST64.exe3 Error: (10/12/2013 11:44:25 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: SweetIM.exe, Version: 3.7.0.7, Zeitstempel: 0x506d9e00 Name des fehlerhaften Moduls: ole32.DLL, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039342 ID des fehlerhaften Prozesses: 0x590 Startzeit der fehlerhaften Anwendung: 0xSweetIM.exe0 Pfad der fehlerhaften Anwendung: SweetIM.exe1 Pfad des fehlerhaften Moduls: SweetIM.exe2 Berichtskennung: SweetIM.exe3 Error: (10/12/2013 11:33:53 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2013 02:49:25 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: SweetIM.exe, Version: 3.7.0.7, Zeitstempel: 0x506d9e00 Name des fehlerhaften Moduls: RPCRT4.dll, Version: 6.1.7601.18205, Zeitstempel: 0x51db9710 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039153 ID des fehlerhaften Prozesses: 0x890 Startzeit der fehlerhaften Anwendung: 0xSweetIM.exe0 Pfad der fehlerhaften Anwendung: SweetIM.exe1 Pfad des fehlerhaften Moduls: SweetIM.exe2 Berichtskennung: SweetIM.exe3 Error: (10/12/2013 08:58:02 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: SweetPacksUpdateManager.exe, Version: 1.1.0.8, Zeitstempel: 0x502bc905 Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039342 ID des fehlerhaften Prozesses: 0x7dc Startzeit der fehlerhaften Anwendung: 0xSweetPacksUpdateManager.exe0 Pfad der fehlerhaften Anwendung: SweetPacksUpdateManager.exe1 Pfad des fehlerhaften Moduls: SweetPacksUpdateManager.exe2 Berichtskennung: SweetPacksUpdateManager.exe3 Error: (10/12/2013 08:53:39 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2013 08:47:28 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/11/2013 10:49:52 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C} Error: (10/11/2013 00:34:47 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: SweetIM.exe, Version: 3.7.0.7, Zeitstempel: 0x506d9e00 Name des fehlerhaften Moduls: ole32.DLL, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0003aff2 ID des fehlerhaften Prozesses: 0xa84 Startzeit der fehlerhaften Anwendung: 0xSweetIM.exe0 Pfad der fehlerhaften Anwendung: SweetIM.exe1 Pfad des fehlerhaften Moduls: SweetIM.exe2 Berichtskennung: SweetIM.exe3 Error: (10/11/2013 00:22:46 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (10/12/2013 09:25:00 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst IPBusEnum erreicht. Error: (10/12/2013 08:16:58 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (10/12/2013 10:10:19 AM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (10/12/2013 08:48:43 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/12/2013 08:48:43 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira Browser-Schutz erreicht. Error: (10/11/2013 10:51:53 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243) Error: (10/10/2013 08:25:04 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 107. Error: (10/10/2013 08:25:04 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Eine SSL 3.0-Verbindungsanforderung wurde von einer Remoteclientanwendung übermittelt, jedoch werden keine der Verschlüsselungssammlungen, die von der Clientanwendung unterstützt werden, vom Server unterstützt. Fehler bei der SSL-Verbindungsanforderung. Error: (10/09/2013 06:48:24 PM) (Source: Service Control Manager) (User: ) Description: Dienst "Computer Backup (MyPC Backup)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/09/2013 06:39:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" ist vom Dienst "Peernetzwerkidentitäts-Manager" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1053 Microsoft Office Sessions: ========================= Error: (10/12/2013 11:45:34 PM) (Source: Application Error)(User: ) Description: FRST64.exe3.3.8.14f25bafdole32.dll6.1.7601.175144ce7c92cc00000050000000000035ce657801cec793f321d973C:\Users\a\Desktop\FRST64.exeC:\Windows\system32\ole32.dll9f2b8df5-3387-11e3-96db-002622d7bd9c Error: (10/12/2013 11:44:25 PM) (Source: Application Error)(User: ) Description: SweetIM.exe3.7.0.7506d9e00ole32.DLL6.1.7601.175144ce7b96fc00000050003934259001cec792819dc7aaC:\Program Files (x86)\SweetIM\Messenger\SweetIM.exeC:\Windows\syswow64\ole32.DLL75b314af-3387-11e3-96db-002622d7bd9c Error: (10/12/2013 11:33:53 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2013 02:49:25 PM) (Source: Application Error)(User: ) Description: SweetIM.exe3.7.0.7506d9e00RPCRT4.dll6.1.7601.1820551db9710c00000050003915389001cec7183f629029C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exeC:\Windows\syswow64\RPCRT4.dllb92d2628-333c-11e3-9865-002622d7bd9c Error: (10/12/2013 08:58:02 AM) (Source: Application Error)(User: ) Description: SweetPacksUpdateManager.exe1.1.0.8502bc905ole32.dll6.1.7601.175144ce7b96fc0000005000393427dc01cec718401e9cdfC:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exeC:\Windows\syswow64\ole32.dlla2bec440-330b-11e3-9865-002622d7bd9c Error: (10/12/2013 08:53:39 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2013 08:47:28 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/11/2013 10:49:52 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C}(NULL)(NULL)(NULL)(NULL)(NULL) Error: (10/11/2013 00:34:47 PM) (Source: Application Error)(User: ) Description: SweetIM.exe3.7.0.7506d9e00ole32.DLL6.1.7601.175144ce7b96fc00000050003aff2a8401cec66c3d307875C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exeC:\Windows\syswow64\ole32.DLLbfbddd14-3260-11e3-9ddb-002622d7bd9c Error: (10/11/2013 00:22:46 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 73% Total physical RAM: 984.57 MB Available physical RAM: 261.43 MB Total Pagefile: 2040.57 MB Available Pagefile: 592.26 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:133.31 GB) (Free:63.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 35BC8FF5) Partition 1: (Active) - (Size=15 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=133 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ Ich danke Dir schonmal vielmals!!! Viele Grüße Stephie |
13.10.2013, 14:07 | #4 |
/// the machine /// TB-Ausbilder | Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware MBAM updaten, scannen, Funde löschen lassen. Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.10.2013, 22:10 | #5 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Hallo Schrauber!! Leider habe ich zunächst den ersten Satz nicht gelesen und sofort den adwcleaner durchlaufen lassen. Mit diesem Ergebnis: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.007 - Bericht erstellt am 13/10/2013 um 20:43:10 # Updated 09/10/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : a - A-PC # Gestartet von : C:\Users\a\Desktop\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** Dienst Gefunden : IB Updater Dienst Gefunden : IBUpdaterService Dienst Gefunden : Updater Service for AMZN ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\Askcom.xml Datei Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\daemon-search.xml Datei Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\MyStart Search.xml Datei Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\MyStart.xml Datei Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\searchplugins\SweetIm.xml Datei Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\user.js Datei Gefunden : C:\Windows\System32\dmwu.exe Datei Gefunden : C:\Windows\System32\ImhxxpComm.dll Datei Gefunden : C:\Windows\System32\roboot64.exe Datei Gefunden : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar Ordner Gefunden : C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam Ordner Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847} Ordner Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\DTToolbar@toolbarnet.com Ordner Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\ffxtlbr@incredibar.com Ordner Gefunden : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\toolbar@ask.com Ordner Gefunden C:\Program Files (x86)\Amazon Browser Bar Ordner Gefunden C:\Program Files (x86)\Ask.com Ordner Gefunden C:\Program Files (x86)\DAEMON Tools Toolbar Ordner Gefunden C:\Program Files (x86)\incredibar.com Ordner Gefunden C:\Program Files (x86)\MyPC Backup Ordner Gefunden C:\Program Files (x86)\MyPC Backup Ordner Gefunden C:\Program Files (x86)\Perion Ordner Gefunden C:\Program Files (x86)\SweetIM Ordner Gefunden C:\Program Files\IB Updater Ordner Gefunden C:\ProgramData\SweetIM Ordner Gefunden C:\Users\a\appData\Local\Amazon Browser Bar Ordner Gefunden C:\Users\a\appData\Local\AskToolbar Ordner Gefunden C:\Users\a\appData\LocalLow\AskToolbar Ordner Gefunden C:\Users\a\appData\LocalLow\incredibar.com Ordner Gefunden C:\Users\a\appData\LocalLow\SweetIM Ordner Gefunden C:\Users\a\appData\Roaming\Systweak Ordner Gefunden C:\Windows\Installer\{A0C9DF2B-89B5-4483-8983-18A68200F1B4} Ordner Gefunden C:\Windows\System32\ARFC Ordner Gefunden C:\Windows\SysWOW64\ARFC Ordner Gefunden C:\Windows\SysWOW64\jmdp Ordner Gefunden C:\Windows\SysWOW64\WNLT ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\Alexa Internet Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gefunden : HKCU\Software\Ask.com Schlüssel Gefunden : HKCU\Software\AskToolbar Schlüssel Gefunden : HKCU\Software\BI Schlüssel Gefunden : HKCU\Software\distromatic Schlüssel Gefunden : HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam Schlüssel Gefunden : HKCU\Software\IM Schlüssel Gefunden : HKCU\Software\ImInstaller Schlüssel Gefunden : HKCU\Software\incredibar.com Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EA582743-9076-4178-9AA6-7393FDF4D5CE} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F443A627-5009-4323-9C1D-7FD598D0D712} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA582743-9076-4178-9AA6-7393FDF4D5CE} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35D-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F443A627-5009-4323-9C1D-7FD598D0D712} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gefunden : HKCU\Software\Softonic Schlüssel Gefunden : HKCU\Software\wnlt Schlüssel Gefunden : [x64] HKCU\Software\Alexa Internet Schlüssel Gefunden : [x64] HKCU\Software\Ask.com Schlüssel Gefunden : [x64] HKCU\Software\AskToolbar Schlüssel Gefunden : [x64] HKCU\Software\BI Schlüssel Gefunden : [x64] HKCU\Software\distromatic Schlüssel Gefunden : [x64] HKCU\Software\IM Schlüssel Gefunden : [x64] HKCU\Software\ImInstaller Schlüssel Gefunden : [x64] HKCU\Software\incredibar.com Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gefunden : [x64] HKCU\Software\Softonic Schlüssel Gefunden : [x64] HKCU\Software\wnlt Schlüssel Gefunden : HKLM\Software\AskToolbar Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AlxSSB.AlxTBSSB Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AlxSSB.AlxTBSSB.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AlxTB2.ToolBarProxy Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AlxTB2.ToolBarProxy.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{1F02FB61-2BE5-4C16-8199-AEAA16EB0342} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{05366194-3126-4601-AC1A-DDE573E093DC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{061F450C-37B9-4330-9235-0F25D9F75B33} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{26249267-15F4-4DA3-8247-C5A78E4FA918} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{39B217B4-8C69-4E45-A8DC-8CC4DAD3CF0A} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3CB4CE45-8849-4638-9226-D6B615A15827} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{43AB7B5D-4C40-4103-A549-7002A116A7D5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{69A72A8A-84ED-4A75-8CE7-263DBEF3E5D3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{996ED20F-A740-47A2-A7EF-9620D422BB4E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{C1545464-C77C-4130-A572-1C619E2895FE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E57091A7-B5F0-4C42-9329-72ED3E59ED31} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EA582743-9076-4178-9AA6-7393FDF4D5CE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EF7FEC6D-451B-4452-9D26-7E10C6B5DB6E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F443A627-5009-4323-9C1D-7FD598D0D712} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj Schlüssel Gefunden : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\escort.escortIEPane Schlüssel Gefunden : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc Schlüssel Gefunden : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Schlüssel Gefunden : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\I Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Incredibar.dskBnd Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Incredibar.dskBnd.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\IncredibarApp.appCore Schlüssel Gefunden : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1 Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\9EE58E3C298524145B73CBBED3CAC4D3 Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\B2FD9C0A5B9838449838816A28001F4B Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\B6EF34C0188ECFA43B48A4BE9C00748E Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\EB6AF8AEEB922FA4392548F13812E50B Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\9EE58E3C298524145B73CBBED3CAC4D3 Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\B2FD9C0A5B9838449838816A28001F4B Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\B6EF34C0188ECFA43B48A4BE9C00748E Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\EB6AF8AEEB922FA4392548F13812E50B Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{061F450C-37B9-4330-9235-0F25D9F75B33} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{51F04BD6-3888-4849-864C-617FAE709CE0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8C953EC4-8CFA-44FB-B32E-1249E5505091} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E4E394E0-D331-431F-B76D-E3A19193D5F6} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Schlüssel Gefunden : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Schlüssel Gefunden : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHost.Tool Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\sim-packages Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Schlüssel Gefunden : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{1D55DAA5-04AC-4036-B0BE-DA81EE9676CD} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{33D0AD98-3347-4A54-8929-5163EBEB9F72} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{58CBF821-A0C7-4AE8-9430-77DD1AF38E99} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{72BCBFF7-2837-4CA0-B3B5-3DAED7F54601} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{824125FD-7732-4DA2-9277-3A7D0A0A0813} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{DA9FC525-41ED-4C00-B046-946DA7CDD305} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn Schlüssel Gefunden : HKLM\Software\IB Updater Schlüssel Gefunden : HKLM\Software\incredibar.com Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E57091A7-B5F0-4C42-9329-72ED3E59ED31} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bluetooth-driver-installer[1]_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bluetooth-driver-installer[1]_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F443A627-5009-4323-9C1D-7FD598D0D712} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0C43FE6B-E881-4AFC-B384-4AEBC90047E8} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{c3e85ee9-5892-4142-b537-bceb3dac4c3d} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ea8fa6be-29be-4af2-9352-841f83215eb0} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Amazon Browser Bar Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\incredibar Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wnlt Schlüssel Gefunden : HKLM\Software\systweak Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Amazon Browser Bar Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : [x64] HKLM\SOFTWARE\IB Updater Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Schlüssel Gefunden : [x64] HKLM\SOFTWARE\wnlt Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EA582743-9076-4178-9AA6-7393FDF4D5CE}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{F9639E4A-801B-4843-AEE3-03D9DA199E77}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SweetIM] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Sweetpacks Communicator] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll] Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}] Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}] Wert Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}] Wert Gefunden : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}] Wert Gefunden : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}] ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v3.6.15 (de) [ Datei : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\prefs.js ] Zeile gefunden : user_pref("browser.startup.homepage", "hxxp://search.avira.com/?l=dis&o=APN10261&gct=hp&dc=EU&locale=de_DE"); Zeile gefunden : user_pref("extensions.asktb.ff-original-keyword-url", ""); -\\ Google Chrome v30.0.1599.69 [ Datei : C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gefunden : icon_url Gefunden : search_url Gefunden : keyword Gefunden : urls_to_restore_on_startup Gefunden : icon_url Gefunden : search_url Gefunden : keyword Gefunden : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [33244 octets] - [13/10/2013 20:43:10] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [33305 octets] ########## [/CODE] Dann habe ich MBAM durchlaufen lassen und die Funde gelöscht. Als nächstes habe erneut den adwcleaner suchen lassen, da ich nicht wusste ob es für das Ergebnis ausschlaggebend ist. Dabei habe ich dieses Ergebnis erhalten: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.007 - Bericht erstellt am 13/10/2013 um 22:29:59 # Updated 09/10/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : a - A-PC # Gestartet von : C:\Users\a\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v3.6.15 (de) [ Datei : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\prefs.js ] -\\ Google Chrome v30.0.1599.69 [ Datei : C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [33634 octets] - [13/10/2013 20:43:10] AdwCleaner[R1].txt - [1144 octets] - [13/10/2013 22:29:11] AdwCleaner[S0].txt - [32828 octets] - [13/10/2013 20:45:05] AdwCleaner[S1].txt - [1066 octets] - [13/10/2013 22:29:59] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1126 octets] ########## [/CODE] Anschließend habe ich Junkware Removal Tool runter geladen und gestartet. Hier die Auswertung: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.4 (10.06.2013:1) OS: Windows 7 Ultimate x64 Ran by a on 13.10.2013 at 22:50:53,44 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3935806917-3379319047-1528668094-1001\Software\IB Updater Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3935806917-3379319047-1528668094-1001\Software\SweetIM Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ConfigTask_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ConfigTask_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ConfigTask_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ConfigTask_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{35AAD74D-1BA4-4DF2-95D5-C38867FCE180} ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [File] C:\user.js ~~~ Chrome Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\niogeckbkdcabhnapjbkeiklablhjoca ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.10.2013 at 23:01:34,75 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Hier das Ergebnis: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by a (administrator) on A-PC on 13-10-2013 23:05:15 Running from C:\Users\a\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [AutoStartNPSAgent] - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-04] (Samsung Electronics Co., Ltd.) HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-16] (Google Inc.) HKCU\...\Run: [Odcuip] - C:\Users\a\AppData\Roaming\Ilyzet\mycu.exe [415329 2013-03-31] (AVAST Software) HKCU\...\Policies\Explorer: [NoInternetOpenWith] 1 HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NPSStartup] - [x] HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9817545DADAECC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.gmx.net/br/ie9_startpage HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File SearchScopes: HKCU - {09038620-190C-402B-A92F-18864E6AB22F} URL = hxxp://go.1und1.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {5A817CF6-92D5-4DE5-AC38-82DF8A73EF28} URL = hxxp://go.gmx.net/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {6B1D1FB7-7233-4F7C-802C-21A1DDB12754} URL = hxxp://go.web.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {81CE708B-5104-4C62-B333-94B417473B29} URL = hxxp://go.mail.com/br/ie8_search_web/?su={searchTerms} BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: AdobeAir - {DCA971EE-CB86-4592-AE52-A45B2E257A12} - C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAir.dll (Adobe Systems Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No File Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default FF SelectedSearchEngine: Ask.com FF NetworkProxy: "type", 0 FF SearchEngineOrder.1: Ask.com FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\abb@amazon.com FF Extension: AdobeAir - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\air3@adobe.com FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (MyStart) - hxxp://www.google.com CHR DefaultSuggestURL: (MyStart) - "suggest_url": "" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) CHR Plugin: (NPCIG.dll) - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdobeAir) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdalfokaihlahnhdieedhgfekidifmfa\3.0.21_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (Gmail) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [gdalfokaihlahnhdieedhgfekidifmfa] - C:\Users\a\AppData\LocalLow\AdobeAir\CHROME\AdobeAir.crx ==================== Services (Whitelisted) ================= R2 AdobeAirUpdater; C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe [18432 2011-11-03] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-11-29] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U4 SR; S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-13 23:01 - 2013-10-13 23:01 - 00002108 _____ C:\Users\a\Desktop\JRT.txt 2013-10-13 22:50 - 2013-10-13 22:50 - 00000000 ____D C:\Windows\ERUNT 2013-10-13 22:46 - 2013-10-13 22:46 - 01032220 _____ (Thisisu) C:\Users\a\Desktop\JRT.exe 2013-10-13 22:34 - 2013-10-13 22:34 - 00001206 _____ C:\Users\a\Desktop\AdwCleaner[S1].txt 2013-10-13 21:02 - 2013-10-13 21:02 - 00033634 _____ C:\Users\a\Desktop\AdwCleaner[R0].txt 2013-10-13 20:42 - 2013-10-13 22:30 - 00000000 ___DC C:\AdwCleaner 2013-10-13 20:41 - 2013-10-13 20:41 - 01048960 _____ C:\Users\a\Desktop\adwcleaner.exe 2013-10-13 12:10 - 2013-10-13 12:31 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet 2013-10-12 23:49 - 2013-10-12 23:50 - 00019742 _____ C:\Users\a\Desktop\Addition.txt 2013-10-12 23:42 - 2013-10-12 23:42 - 00000000 ___DC C:\FRST 2013-10-12 23:40 - 2013-10-12 23:40 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-11 22:45 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-11 22:45 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-11 22:45 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-11 22:45 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 22:45 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-11 22:45 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-11 22:45 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-11 12:49 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 12:49 - 2013-07-12 12:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-11 12:49 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-11 12:49 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-11 12:49 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 12:49 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-11 12:49 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 12:49 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 12:49 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-11 12:49 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-11 12:49 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-11 12:49 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-11 12:48 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 12:48 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 12:48 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-11 12:48 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-11 12:48 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-11 12:48 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-11 12:48 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-11 12:48 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-11 12:48 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 12:48 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-11 12:48 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 12:48 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 12:48 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 20:59 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 18:33 - 2013-10-13 22:32 - 00060616 _____ C:\Windows\PFRO.log 2013-10-09 18:33 - 2013-10-13 22:32 - 00000448 _____ C:\Windows\setupact.log 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:29 - 2013-10-09 18:30 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:27 - 2013-10-09 18:28 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:26 - 2013-10-09 18:27 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:24 - 2013-10-09 18:30 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:24 - 2013-10-09 18:29 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:24 - 2013-10-09 18:25 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 14:57 - 2013-10-08 14:58 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:31 - 2013-10-05 12:50 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:28 - 2013-10-09 18:23 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb ==================== One Month Modified Files and Folders ======= 2013-10-13 23:01 - 2013-10-13 23:01 - 00002108 _____ C:\Users\a\Desktop\JRT.txt 2013-10-13 22:59 - 2011-11-29 17:49 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-13 22:50 - 2013-10-13 22:50 - 00000000 ____D C:\Windows\ERUNT 2013-10-13 22:47 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-13 22:47 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-13 22:46 - 2013-10-13 22:46 - 01032220 _____ (Thisisu) C:\Users\a\Desktop\JRT.exe 2013-10-13 22:43 - 2012-04-11 22:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-13 22:43 - 2011-11-29 17:31 - 01901613 _____ C:\Windows\WindowsUpdate.log 2013-10-13 22:34 - 2013-10-13 22:34 - 00001206 _____ C:\Users\a\Desktop\AdwCleaner[S1].txt 2013-10-13 22:33 - 2011-11-29 17:49 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-13 22:32 - 2013-10-09 18:33 - 00060616 _____ C:\Windows\PFRO.log 2013-10-13 22:32 - 2013-10-09 18:33 - 00000448 _____ C:\Windows\setupact.log 2013-10-13 22:32 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-13 22:30 - 2013-10-13 20:42 - 00000000 ___DC C:\AdwCleaner 2013-10-13 21:02 - 2013-10-13 21:02 - 00033634 _____ C:\Users\a\Desktop\AdwCleaner[R0].txt 2013-10-13 20:41 - 2013-10-13 20:41 - 01048960 _____ C:\Users\a\Desktop\adwcleaner.exe 2013-10-13 12:31 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet 2013-10-12 23:50 - 2013-10-12 23:49 - 00019742 _____ C:\Users\a\Desktop\Addition.txt 2013-10-12 23:42 - 2013-10-12 23:42 - 00000000 ___DC C:\FRST 2013-10-12 23:40 - 2013-10-12 23:40 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-12 23:39 - 2011-12-02 13:36 - 00003898 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E1F44A7E-8E42-42AB-865E-6B52309A825A} 2013-10-12 19:16 - 2011-11-30 20:17 - 00000000 ____D C:\Neuer Ordner 2013-10-12 11:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-10-12 09:01 - 2010-11-21 08:50 - 00699738 _____ C:\Windows\system32\perfh007.dat 2013-10-12 09:01 - 2010-11-21 08:50 - 00149600 _____ C:\Windows\system32\perfc007.dat 2013-10-12 09:01 - 2009-07-14 07:13 - 01621320 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-12 08:55 - 2011-11-29 17:24 - 00000000 ____D C:\Windows\Panther 2013-10-12 08:52 - 2009-07-14 06:45 - 00298072 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-11 22:40 - 2011-11-29 18:02 - 01599214 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-11 22:30 - 2013-08-15 22:31 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 22:26 - 2011-12-04 11:46 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 18:49 - 2011-11-29 17:40 - 00000000 ___RD C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:30 - 2013-10-09 18:29 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:30 - 2013-10-09 18:24 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:29 - 2013-10-09 18:24 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:28 - 2013-10-09 18:27 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:27 - 2013-10-09 18:26 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:27 - 2011-12-03 16:30 - 00000000 ____D C:\ProgramData\f-secure 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:25 - 2013-10-09 18:24 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 18:23 - 2013-10-05 12:28 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-09 18:00 - 2011-12-04 11:47 - 00000000 ____D C:\Users\a\AppData\Roaming\Media Player Classic 2013-10-09 17:58 - 2013-07-20 22:13 - 00000000 ____D C:\Windows\Minidump 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 17:39 - 2011-11-29 17:49 - 00000000 ____D C:\Program Files\CCleaner 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 15:43 - 2012-04-11 22:09 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-08 15:26 - 2011-12-27 20:30 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 14:58 - 2013-10-08 14:57 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:50 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:32 - 2011-11-29 17:39 - 00000000 ____D C:\Users\a 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:07 - 2013-07-16 12:30 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:18 - 2012-07-18 13:29 - 00000000 ____D C:\Program Files (x86)\ALDI Bestellsoftware 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-10-01 11:05 - 2013-05-07 17:23 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-23 01:28 - 2013-10-11 22:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-11 22:45 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-11 22:45 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-21 05:38 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-11 22:45 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-11 22:45 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb 2013-09-14 03:10 - 2013-10-11 12:48 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5912.dll Some content of TEMP: ==================== C:\Users\a\AppData\Local\Temp\avgnt.exe C:\Users\a\AppData\Local\Temp\monarbi.exe C:\Users\a\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-12 11:23 ==================== End Of Log ============================ --- --- --- Vielen lieben Dank für deine Hilfe!! Lieben Dank Stephie |
14.10.2013, 13:02 | #6 |
/// the machine /// TB-Ausbilder | Windows 7, PC langsam und diverse Funde durch Malwarebytes AntimalwareESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware |
14.10.2013, 17:57 | #7 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Guten Abend Schrauber, vielen Dank für die schnellen Antworten!! Hier kommt das Ergebnis des Eset online Scanners: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=4df18c2c1dbe544ba65e2a0de32584d8 # engine=15479 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-14 04:34:07 # local_time=2013-10-14 06:34:07 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 96 23136 152436152 15757 0 # compatibility_mode=5893 16776574 100 94 8215055 133398297 0 0 # scanned=161146 # found=2 # cleaned=0 # scan_time=4090 sh=15F57B6CDD3220B1D52967E5AB1B9904AC3BE368 ft=1 fh=06e633d71da42ac3 vn="a variant of Win32/Kryptik.BMMB trojan" ac=I fn="C:\Users\a\AppData\Local\Temp\monarbi.exe" sh=5D316ED99C2ACD07B3D6C9ACC0DD4B5AC0DD7352 ft=1 fh=06e633d71da42ac3 vn="a variant of Win32/Kryptik.BMMB trojan" ac=I fn="C:\Users\a\AppData\Roaming\Ilyzet\mycu.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java(TM) 6 Update 24 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (3.6.15) Firefox out of Date! Google Chrome 29.0.1547.76 Google Chrome 30.0.1599.69 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Als letztes noch das Ergebnis des FRST FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by a (administrator) on A-PC on 14-10-2013 18:52:57 Running from C:\Users\a\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [AutoStartNPSAgent] - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-04] (Samsung Electronics Co., Ltd.) HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-16] (Google Inc.) HKCU\...\Run: [Odcuip] - C:\Users\a\AppData\Roaming\Ilyzet\mycu.exe [415329 2013-03-31] (AVAST Software) HKCU\...\Policies\Explorer: [NoInternetOpenWith] 1 HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NPSStartup] - [x] HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9817545DADAECC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.gmx.net/br/ie9_startpage HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File SearchScopes: HKCU - {09038620-190C-402B-A92F-18864E6AB22F} URL = hxxp://go.1und1.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {5A817CF6-92D5-4DE5-AC38-82DF8A73EF28} URL = hxxp://go.gmx.net/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {6B1D1FB7-7233-4F7C-802C-21A1DDB12754} URL = hxxp://go.web.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {81CE708B-5104-4C62-B333-94B417473B29} URL = hxxp://go.mail.com/br/ie8_search_web/?su={searchTerms} BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: AdobeAir - {DCA971EE-CB86-4592-AE52-A45B2E257A12} - C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAir.dll (Adobe Systems Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No File Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default FF SelectedSearchEngine: Ask.com FF NetworkProxy: "type", 0 FF SearchEngineOrder.1: Ask.com FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\abb@amazon.com FF Extension: AdobeAir - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\air3@adobe.com FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (MyStart) - hxxp://www.google.com CHR DefaultSuggestURL: (MyStart) - "suggest_url": "" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) CHR Plugin: (NPCIG.dll) - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdobeAir) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdalfokaihlahnhdieedhgfekidifmfa\3.0.21_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (Gmail) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [gdalfokaihlahnhdieedhgfekidifmfa] - C:\Users\a\AppData\LocalLow\AdobeAir\CHROME\AdobeAir.crx ==================== Services (Whitelisted) ================= R2 AdobeAirUpdater; C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe [18432 2011-11-03] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-11-29] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U4 SR; S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-14 18:49 - 2013-10-14 18:49 - 00001203 _____ C:\Users\a\Desktop\checkup.txt 2013-10-14 18:45 - 2013-10-14 18:45 - 00891167 _____ C:\Users\a\Desktop\SecurityCheck.exe 2013-10-13 23:12 - 2013-10-13 23:12 - 00040571 _____ C:\Users\a\Desktop\FRST_13-10-2013_23-06-14.txt 2013-10-13 23:01 - 2013-10-13 23:01 - 00002108 _____ C:\Users\a\Desktop\JRT.txt 2013-10-13 22:50 - 2013-10-13 22:50 - 00000000 ____D C:\Windows\ERUNT 2013-10-13 22:46 - 2013-10-13 22:46 - 01032220 _____ (Thisisu) C:\Users\a\Desktop\JRT.exe 2013-10-13 22:34 - 2013-10-13 22:34 - 00001206 _____ C:\Users\a\Desktop\AdwCleaner[S1].txt 2013-10-13 21:02 - 2013-10-13 21:02 - 00033634 _____ C:\Users\a\Desktop\AdwCleaner[R0].txt 2013-10-13 20:42 - 2013-10-13 22:30 - 00000000 ___DC C:\AdwCleaner 2013-10-13 20:41 - 2013-10-13 20:41 - 01048960 _____ C:\Users\a\Desktop\adwcleaner.exe 2013-10-13 12:10 - 2013-10-14 12:32 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet 2013-10-12 23:49 - 2013-10-12 23:50 - 00019742 _____ C:\Users\a\Desktop\Addition.txt 2013-10-12 23:42 - 2013-10-12 23:42 - 00000000 ___DC C:\FRST 2013-10-12 23:40 - 2013-10-12 23:40 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-11 22:45 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-11 22:45 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-11 22:45 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-11 22:45 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 22:45 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-11 22:45 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-11 22:45 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-11 12:49 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 12:49 - 2013-07-12 12:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-11 12:49 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-11 12:49 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-11 12:49 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 12:49 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-11 12:49 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 12:49 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 12:49 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-11 12:49 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-11 12:49 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-11 12:49 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-11 12:48 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 12:48 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 12:48 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-11 12:48 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-11 12:48 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-11 12:48 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-11 12:48 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-11 12:48 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-11 12:48 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 12:48 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-11 12:48 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 12:48 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 12:48 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 20:59 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 18:33 - 2013-10-14 12:06 - 00000504 _____ C:\Windows\setupact.log 2013-10-09 18:33 - 2013-10-13 22:32 - 00060616 _____ C:\Windows\PFRO.log 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:29 - 2013-10-09 18:30 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:27 - 2013-10-09 18:28 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:26 - 2013-10-09 18:27 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:24 - 2013-10-09 18:30 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:24 - 2013-10-09 18:29 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:24 - 2013-10-09 18:25 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 14:57 - 2013-10-08 14:58 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:31 - 2013-10-05 12:50 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:28 - 2013-10-09 18:23 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb ==================== One Month Modified Files and Folders ======= 2013-10-14 18:49 - 2013-10-14 18:49 - 00001203 _____ C:\Users\a\Desktop\checkup.txt 2013-10-14 18:45 - 2013-10-14 18:45 - 00891167 _____ C:\Users\a\Desktop\SecurityCheck.exe 2013-10-14 18:43 - 2012-04-11 22:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-14 18:32 - 2011-11-29 17:31 - 01937000 _____ C:\Windows\WindowsUpdate.log 2013-10-14 18:01 - 2011-11-29 17:49 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-14 17:59 - 2011-11-29 17:49 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-14 12:32 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-14 12:23 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-14 12:23 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-14 12:18 - 2011-12-02 13:36 - 00003898 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E1F44A7E-8E42-42AB-865E-6B52309A825A} 2013-10-14 12:06 - 2013-10-09 18:33 - 00000504 _____ C:\Windows\setupact.log 2013-10-14 12:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-13 23:12 - 2013-10-13 23:12 - 00040571 _____ C:\Users\a\Desktop\FRST_13-10-2013_23-06-14.txt 2013-10-13 23:01 - 2013-10-13 23:01 - 00002108 _____ C:\Users\a\Desktop\JRT.txt 2013-10-13 22:50 - 2013-10-13 22:50 - 00000000 ____D C:\Windows\ERUNT 2013-10-13 22:46 - 2013-10-13 22:46 - 01032220 _____ (Thisisu) C:\Users\a\Desktop\JRT.exe 2013-10-13 22:34 - 2013-10-13 22:34 - 00001206 _____ C:\Users\a\Desktop\AdwCleaner[S1].txt 2013-10-13 22:32 - 2013-10-09 18:33 - 00060616 _____ C:\Windows\PFRO.log 2013-10-13 22:30 - 2013-10-13 20:42 - 00000000 ___DC C:\AdwCleaner 2013-10-13 21:02 - 2013-10-13 21:02 - 00033634 _____ C:\Users\a\Desktop\AdwCleaner[R0].txt 2013-10-13 20:41 - 2013-10-13 20:41 - 01048960 _____ C:\Users\a\Desktop\adwcleaner.exe 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet 2013-10-12 23:50 - 2013-10-12 23:49 - 00019742 _____ C:\Users\a\Desktop\Addition.txt 2013-10-12 23:42 - 2013-10-12 23:42 - 00000000 ___DC C:\FRST 2013-10-12 23:40 - 2013-10-12 23:40 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-12 19:16 - 2011-11-30 20:17 - 00000000 ____D C:\Neuer Ordner 2013-10-12 11:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-10-12 09:01 - 2010-11-21 08:50 - 00699738 _____ C:\Windows\system32\perfh007.dat 2013-10-12 09:01 - 2010-11-21 08:50 - 00149600 _____ C:\Windows\system32\perfc007.dat 2013-10-12 09:01 - 2009-07-14 07:13 - 01621320 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-12 08:55 - 2011-11-29 17:24 - 00000000 ____D C:\Windows\Panther 2013-10-12 08:52 - 2009-07-14 06:45 - 00298072 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-11 22:40 - 2011-11-29 18:02 - 01599214 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-11 22:30 - 2013-08-15 22:31 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 22:26 - 2011-12-04 11:46 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 18:49 - 2011-11-29 17:40 - 00000000 ___RD C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:30 - 2013-10-09 18:29 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:30 - 2013-10-09 18:24 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:29 - 2013-10-09 18:24 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:28 - 2013-10-09 18:27 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:27 - 2013-10-09 18:26 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:27 - 2011-12-03 16:30 - 00000000 ____D C:\ProgramData\f-secure 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:25 - 2013-10-09 18:24 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 18:23 - 2013-10-05 12:28 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-09 18:00 - 2011-12-04 11:47 - 00000000 ____D C:\Users\a\AppData\Roaming\Media Player Classic 2013-10-09 17:58 - 2013-07-20 22:13 - 00000000 ____D C:\Windows\Minidump 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 17:39 - 2011-11-29 17:49 - 00000000 ____D C:\Program Files\CCleaner 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 15:43 - 2012-04-11 22:09 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-08 15:26 - 2011-12-27 20:30 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 14:58 - 2013-10-08 14:57 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:50 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:32 - 2011-11-29 17:39 - 00000000 ____D C:\Users\a 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:07 - 2013-07-16 12:30 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:18 - 2012-07-18 13:29 - 00000000 ____D C:\Program Files (x86)\ALDI Bestellsoftware 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-10-01 11:05 - 2013-05-07 17:23 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-23 01:28 - 2013-10-11 22:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-11 22:45 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-11 22:45 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-21 05:38 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-11 22:45 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-11 22:45 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb 2013-09-14 03:10 - 2013-10-11 12:48 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5912.dll Some content of TEMP: ==================== C:\Users\a\AppData\Local\Temp\avgnt.exe C:\Users\a\AppData\Local\Temp\monarbi.exe C:\Users\a\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-12 11:23 ==================== End Of Log ============================ --- --- --- [/CODE] Schon mal vielen Dank für Deine Hilfe! Schönen Abend!! Stephie |
15.10.2013, 09:06 | #8 |
/// the machine /// TB-Ausbilder | Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Java, Adobe und Firefox updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\a\AppData\Roaming\Ilyzet HKCU\...\Run: [Odcuip] - C:\Users\a\AppData\Roaming\Ilyzet\mycu.exe [415329 2013-03-31] (AVAST Software) 2013-10-13 12:10 - 2013-10-14 12:32 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.10.2013, 16:28 | #9 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Hallo Schrauber!! Leider habe ich erst alles durchgeführt was du mir geschrieben hast bevor ich es dir Schritt für Schritt poste. Duch das Starten und abschließen des Delfix.exe ist dann natürlich alles gelöscht worden :-( Endschuldige aber daran hatte ich nicht gedacht. Ich weiss nicht ob du mit dem Ergebnis des Delfix etwas anfangen kannst? Daher poste ich es dir einfach mal Code:
ATTFilter # DelFix v10.4 - Datei am 15/10/2013 um 17:14:43 erstellt # Aktualisiert am 19/07/2013 von Xplode # Benutzer : a - A-PC # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) ~ Aktiviere die Benutzerkontensteuerung ... OK ~ Entferne die Bereinigungsprogramme ... Gelöscht : C:\FRST Gelöscht : C:\Users\a\Desktop\adwcleaner.exe Gelöscht : C:\Users\a\Desktop\FRST64.exe Gelöscht : C:\Users\a\Desktop\JRT.exe Gelöscht : C:\Users\a\Desktop\SecurityCheck.exe Gelöscht : C:\Users\a\Desktop\TFC.exe Gelöscht : HKLM\SOFTWARE\OldTimer Tools Gelöscht : HKLM\SOFTWARE\AdwCleaner ~ Erstelle ein Backup der Registrierungsdatenbank ... OK ~ Lösche die Wiederherstellungspunkte ... Gelöscht : RP #118 [Windows Update | 10/11/2013 20:13:25] Gelöscht : RP #119 [Windows Update | 10/12/2013 19:28:33] Gelöscht : RP #120 [Windows-Sicherung | 10/13/2013 17:00:27] Gelöscht : RP #121 [Installed Java 7 Update 40 (64-bit) | 10/15/2013 13:24:44] Gelöscht : RP #122 [Windows Update | 10/15/2013 13:37:49] Gelöscht : RP #123 [Windows Modules Installer | 10/15/2013 14:50:28] Ein neuer Wiederherstellungspunkt wurde erstellt ! ~ Stelle die Systemeinstellungen wieder her ... OK ########## - EOF - ########## Liebe Grüße Stephie87 |
16.10.2013, 08:30 | #10 |
/// the machine /// TB-Ausbilder | Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Nee passt, fertig
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.10.2013, 09:34 | #11 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Hallo Schrauber, erstmal möchte ich mich vielmals für die ganze Mühe bedanken!! Ich hatte zwischenzeitlich auch das Gefühl das mein Laptop jetzt schneller läuft aber das ist jetzt definitiv nicht mehr der Fall. Ich frage mich ob ich vieleicht ein anderes betriebssystem brauche oder sonst etwas machen kann damit er schneller wird. Er braucht ca. 20 min. um hochzufahren, 30 sec. um nur ein neues Fenster zu öffnen und schon beim schreiben dieses Textes gibt er auf und schließt automatisch das Fenster. Also noch nicht wirklich gut. ich hoffe du hast noch eine Idee!! Lieben Gruß und Vielen Dank Stephie87 |
16.10.2013, 11:21 | #12 |
/// the machine /// TB-Ausbilder | Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Poste nochmal ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.10.2013, 15:13 | #13 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Hallo schrauber, hier der FRST log : FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by a (administrator) on A-PC on 16-10-2013 16:07:23 Running from C:\Users\a\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= () C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSI_TRAY.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\avgnt.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe () C:\Users\a\Downloads\FRST64.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-16] (Google Inc.) HKCU\...\Run: [Odcuip] - C:\Users\a\AppData\Roaming\Ilyzet\mycu.exe [415329 2013-03-31] (AVAST Software) HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [441408 2013-09-24] (BillP Studios) HKCU\...\Policies\Explorer: [NoInternetOpenWith] 1 HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NPSStartup] - [x] HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9817545DADAECC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.gmx.net/br/ie9_startpage HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File SearchScopes: HKCU - {09038620-190C-402B-A92F-18864E6AB22F} URL = hxxp://go.1und1.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {5A817CF6-92D5-4DE5-AC38-82DF8A73EF28} URL = hxxp://go.gmx.net/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {6B1D1FB7-7233-4F7C-802C-21A1DDB12754} URL = hxxp://go.web.de/br/ie9_search_web/?su={searchTerms} SearchScopes: HKCU - {81CE708B-5104-4C62-B333-94B417473B29} URL = hxxp://go.mail.com/br/ie8_search_web/?su={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: AdobeAir - {DCA971EE-CB86-4592-AE52-A45B2E257A12} - C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAir.dll (Adobe Systems Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No File Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default FF DefaultSearchEngine: Ask.com FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Ask.com FF Homepage: google.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\abb@amazon.com FF Extension: AdobeAir - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\62rwwqbf.default\Extensions\air3@adobe.com Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (MyStart) - hxxp://www.google.com CHR DefaultSuggestURL: (MyStart) - "suggest_url": "" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) CHR Plugin: (NPCIG.dll) - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdobeAir) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdalfokaihlahnhdieedhgfekidifmfa\3.0.21_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (Gmail) - C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [gdalfokaihlahnhdieedhgfekidifmfa] - C:\Users\a\AppData\LocalLow\AdobeAir\CHROME\AdobeAir.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AdobeAirUpdater; C:\Users\a\AppData\LocalLow\AdobeAir\IE\AdobeAirUpdater.exe [18432 2011-11-03] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1164360 2013-10-01] (Avira Operations GmbH & Co. KG) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [83160 2013-10-01] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-11-29] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U4 SR; S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-16 16:06 - 2013-10-16 16:06 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-16 11:07 - 2013-10-16 11:12 - 122946048 _____ C:\Users\a\Downloads\avira14_free_antivirus_de(1).exe 2013-10-16 10:54 - 2013-10-16 10:57 - 122946048 _____ C:\Users\a\Downloads\avira14_free_antivirus_de.exe 2013-10-16 10:13 - 2013-10-16 10:13 - 02434048 _____ C:\Users\a\Downloads\msxml(2).msi 2013-10-15 18:33 - 2013-10-15 18:34 - 00338944 _____ C:\Users\a\Desktop\Anleitung spywareblaster 2013-10-15 18:17 - 2013-10-15 18:17 - 00000000 ____D C:\ProgramData\Licenses 2013-10-15 18:16 - 2013-10-15 18:31 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster 2013-10-15 18:16 - 2013-10-15 18:26 - 00001083 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk 2013-10-15 18:12 - 2013-10-15 18:12 - 02434048 _____ C:\Users\a\Downloads\msxml(1).msi 2013-10-15 18:09 - 2013-10-15 18:08 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-10-15 18:09 - 2013-10-15 18:08 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-15 18:08 - 2013-10-15 18:08 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-15 18:08 - 2013-10-15 18:08 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-15 18:08 - 2013-10-15 18:08 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-15 18:07 - 2013-10-15 18:07 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-15 18:06 - 2013-10-15 18:06 - 02434048 _____ C:\Users\a\Downloads\msxml.msi 2013-10-15 18:04 - 2013-10-15 18:04 - 00818944 _____ C:\Users\a\Downloads\adblockplus-2.2.4.xpi.zip 2013-10-15 18:03 - 2013-10-15 18:03 - 00000000 ____D C:\Program Files (x86)\MPC-HC 2013-10-15 17:39 - 2013-10-15 17:40 - 00000000 ____D C:\Users\a\AppData\Roaming\WinPatrol 2013-10-15 17:37 - 2013-10-15 18:35 - 00000000 ____D C:\ProgramData\InstallMate 2013-10-15 17:37 - 2013-10-15 17:37 - 00000000 ____D C:\Program Files (x86)\BillP Studios 2013-10-15 17:31 - 2013-10-15 17:31 - 00000000 ____D C:\Users\a\AppData\Local\Secunia PSI 2013-10-15 17:30 - 2013-10-15 17:30 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-10-15 17:14 - 2013-10-15 17:16 - 00001233 ____C C:\DelFix.txt 2013-10-15 16:43 - 2013-10-15 16:43 - 00000000 ____D C:\Users\a\AppData\Local\Macromedia 2013-10-15 16:38 - 2013-10-15 16:38 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-10-15 16:38 - 2013-10-15 16:38 - 00000000 ____D C:\ProgramData\Mozilla 2013-10-15 16:38 - 2013-10-15 16:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-15 15:41 - 2013-10-15 15:41 - 03272136 _____ (Secunia) C:\Users\a\Desktop\Secuna Persolal Software Inspector.exe 2013-10-15 15:37 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-15 15:37 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-15 15:37 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-15 15:37 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-15 15:37 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-15 15:37 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-15 15:37 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-15 15:32 - 2013-10-15 15:32 - 00907304 _____ (BillP Studios) C:\Users\a\Desktop\Win Patrol.exe 2013-10-15 15:27 - 2013-10-15 15:26 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-10-15 15:27 - 2013-10-15 15:26 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-10-15 15:27 - 2013-10-15 15:26 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-15 15:27 - 2013-10-15 15:26 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-15 15:27 - 2013-10-15 15:26 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-15 15:27 - 2013-10-15 15:26 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-15 15:25 - 2013-10-15 15:25 - 00000000 ____D C:\Program Files\Java 2013-10-15 15:23 - 2013-10-15 15:23 - 30669224 _____ (Oracle Corporation) C:\Users\a\Desktop\Java 64 bits.exe 2013-10-13 22:50 - 2013-10-15 17:14 - 00000000 ____D C:\Windows\ERUNT 2013-10-13 20:42 - 2013-10-13 22:30 - 00000000 ___DC C:\AdwCleaner 2013-10-13 12:10 - 2013-10-14 21:41 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet 2013-10-12 23:42 - 2013-10-16 16:06 - 00000000 ___DC C:\FRST 2013-10-11 22:45 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-11 22:45 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 22:45 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-11 22:45 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 22:45 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-11 22:45 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 22:45 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-11 12:49 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-11 12:49 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 12:49 - 2013-07-12 12:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-11 12:49 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 12:49 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-11 12:49 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-11 12:49 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-11 12:49 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-11 12:49 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-11 12:49 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 12:49 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-11 12:49 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 12:49 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 12:49 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 12:49 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-11 12:49 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-11 12:49 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-11 12:49 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-11 12:49 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-11 12:48 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 12:48 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 12:48 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-11 12:48 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-11 12:48 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-11 12:48 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-11 12:48 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-11 12:48 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-11 12:48 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-11 12:48 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-11 12:48 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-11 12:48 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-11 12:48 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-11 12:48 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 12:48 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-11 12:48 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 12:48 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 12:48 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 20:59 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 18:33 - 2013-10-16 09:56 - 00000784 _____ C:\Windows\setupact.log 2013-10-09 18:33 - 2013-10-15 20:15 - 00063810 _____ C:\Windows\PFRO.log 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:29 - 2013-10-09 18:30 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:27 - 2013-10-09 18:28 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:26 - 2013-10-09 18:27 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:24 - 2013-10-09 18:30 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:24 - 2013-10-09 18:29 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:24 - 2013-10-09 18:29 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:24 - 2013-10-09 18:25 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 14:57 - 2013-10-08 14:58 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:31 - 2013-10-05 12:50 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:28 - 2013-10-09 18:23 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb ==================== One Month Modified Files and Folders ======= 2013-10-16 16:06 - 2013-10-16 16:06 - 01954124 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe 2013-10-16 16:06 - 2013-10-12 23:42 - 00000000 ___DC C:\FRST 2013-10-16 15:43 - 2012-04-11 22:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-16 15:19 - 2011-11-29 17:49 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-16 11:14 - 2013-04-19 09:44 - 00002070 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-10-16 11:12 - 2013-10-16 11:07 - 122946048 _____ C:\Users\a\Downloads\avira14_free_antivirus_de(1).exe 2013-10-16 10:58 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-16 10:58 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-16 10:57 - 2013-10-16 10:54 - 122946048 _____ C:\Users\a\Downloads\avira14_free_antivirus_de.exe 2013-10-16 10:13 - 2013-10-16 10:13 - 02434048 _____ C:\Users\a\Downloads\msxml(2).msi 2013-10-16 10:01 - 2011-11-29 17:31 - 01100400 _____ C:\Windows\WindowsUpdate.log 2013-10-16 09:56 - 2013-10-09 18:33 - 00000784 _____ C:\Windows\setupact.log 2013-10-16 09:56 - 2011-11-29 17:49 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-16 09:56 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-15 20:15 - 2013-10-09 18:33 - 00063810 _____ C:\Windows\PFRO.log 2013-10-15 18:35 - 2013-10-15 17:37 - 00000000 ____D C:\ProgramData\InstallMate 2013-10-15 18:34 - 2013-10-15 18:33 - 00338944 _____ C:\Users\a\Desktop\Anleitung spywareblaster 2013-10-15 18:31 - 2013-10-15 18:16 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster 2013-10-15 18:26 - 2013-10-15 18:16 - 00001083 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk 2013-10-15 18:17 - 2013-10-15 18:17 - 00000000 ____D C:\ProgramData\Licenses 2013-10-15 18:12 - 2013-10-15 18:12 - 02434048 _____ C:\Users\a\Downloads\msxml(1).msi 2013-10-15 18:08 - 2013-10-15 18:09 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-10-15 18:08 - 2013-10-15 18:09 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-15 18:08 - 2013-10-15 18:08 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-15 18:08 - 2013-10-15 18:08 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-15 18:08 - 2013-10-15 18:08 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-15 18:08 - 2011-11-29 18:06 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-10-15 18:07 - 2013-10-15 18:07 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-15 18:07 - 2011-11-29 17:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-15 18:06 - 2013-10-15 18:06 - 02434048 _____ C:\Users\a\Downloads\msxml.msi 2013-10-15 18:04 - 2013-10-15 18:04 - 00818944 _____ C:\Users\a\Downloads\adblockplus-2.2.4.xpi.zip 2013-10-15 18:04 - 2011-11-29 18:03 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-10-15 18:03 - 2013-10-15 18:03 - 00000000 ____D C:\Program Files (x86)\MPC-HC 2013-10-15 17:40 - 2013-10-15 17:39 - 00000000 ____D C:\Users\a\AppData\Roaming\WinPatrol 2013-10-15 17:37 - 2013-10-15 17:37 - 00000000 ____D C:\Program Files (x86)\BillP Studios 2013-10-15 17:31 - 2013-10-15 17:31 - 00000000 ____D C:\Users\a\AppData\Local\Secunia PSI 2013-10-15 17:30 - 2013-10-15 17:30 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-10-15 17:16 - 2013-10-15 17:14 - 00001233 ____C C:\DelFix.txt 2013-10-15 17:14 - 2013-10-13 22:50 - 00000000 ____D C:\Windows\ERUNT 2013-10-15 16:43 - 2013-10-15 16:43 - 00000000 ____D C:\Users\a\AppData\Local\Macromedia 2013-10-15 16:38 - 2013-10-15 16:38 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-10-15 16:38 - 2013-10-15 16:38 - 00000000 ____D C:\ProgramData\Mozilla 2013-10-15 16:38 - 2013-10-15 16:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-15 15:41 - 2013-10-15 15:41 - 03272136 _____ (Secunia) C:\Users\a\Desktop\Secuna Persolal Software Inspector.exe 2013-10-15 15:32 - 2013-10-15 15:32 - 00907304 _____ (BillP Studios) C:\Users\a\Desktop\Win Patrol.exe 2013-10-15 15:26 - 2013-10-15 15:27 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-10-15 15:26 - 2013-10-15 15:27 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-10-15 15:26 - 2013-10-15 15:27 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-15 15:26 - 2013-10-15 15:27 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-15 15:26 - 2013-10-15 15:27 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-15 15:26 - 2013-10-15 15:27 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-15 15:25 - 2013-10-15 15:25 - 00000000 ____D C:\Program Files\Java 2013-10-15 15:23 - 2013-10-15 15:23 - 30669224 _____ (Oracle Corporation) C:\Users\a\Desktop\Java 64 bits.exe 2013-10-15 14:14 - 2011-12-02 13:36 - 00003898 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E1F44A7E-8E42-42AB-865E-6B52309A825A} 2013-10-14 23:14 - 2011-11-29 17:49 - 00004096 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-14 23:14 - 2011-11-29 17:49 - 00003844 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-14 21:41 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 22:30 - 2013-10-13 20:42 - 00000000 ___DC C:\AdwCleaner 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet 2013-10-12 19:16 - 2011-11-30 20:17 - 00000000 ____D C:\Neuer Ordner 2013-10-12 11:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-10-12 09:01 - 2010-11-21 08:50 - 00699738 _____ C:\Windows\system32\perfh007.dat 2013-10-12 09:01 - 2010-11-21 08:50 - 00149600 _____ C:\Windows\system32\perfc007.dat 2013-10-12 09:01 - 2009-07-14 07:13 - 01621320 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-12 08:55 - 2011-11-29 17:24 - 00000000 ____D C:\Windows\Panther 2013-10-12 08:52 - 2009-07-14 06:45 - 00298072 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 08:45 - 2013-03-30 18:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-11 22:40 - 2011-11-29 18:02 - 01599214 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-11 22:30 - 2013-08-15 22:31 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 22:26 - 2011-12-04 11:46 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 21:00 - 2013-10-09 21:00 - 00000000 ____D C:\Users\a\AppData\Roaming\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 20:59 - 2013-10-09 20:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-09 18:49 - 2011-11-29 17:40 - 00000000 ___RD C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-09 18:33 - 2013-10-09 18:33 - 00000000 _____ C:\Windows\setuperr.log 2013-10-09 18:30 - 2013-10-09 18:29 - 00183036 _____ C:\Windows\fsmsiuninstall.log 2013-10-09 18:30 - 2013-10-09 18:24 - 00098823 _____ C:\Windows\uninstaller.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00003778 _____ C:\Windows\FSGKIAIN.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00001752 _____ C:\Windows\FSLDIN.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00001297 _____ C:\Windows\fsdgunst.log 2013-10-09 18:29 - 2013-10-09 18:29 - 00000800 _____ C:\Windows\daasunin.LOG 2013-10-09 18:29 - 2013-10-09 18:29 - 00000603 _____ C:\Windows\HELPINST.LOG 2013-10-09 18:29 - 2013-10-09 18:24 - 74233362 _____ C:\Windows\FSISU.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00839694 _____ C:\Windows\FSDEPH.log 2013-10-09 18:29 - 2013-10-09 18:24 - 00591835 _____ C:\Windows\FSUNINST.log 2013-10-09 18:28 - 2013-10-09 18:28 - 00000884 _____ C:\Windows\FSGUIINS.LOG 2013-10-09 18:28 - 2013-10-09 18:28 - 00000681 _____ C:\Windows\fstnbins.LOG 2013-10-09 18:28 - 2013-10-09 18:27 - 00016158 _____ C:\Windows\FSAUA_UN.LOG 2013-10-09 18:27 - 2013-10-09 18:26 - 00028642 _____ C:\Windows\fsavunin.log 2013-10-09 18:27 - 2011-12-03 16:30 - 00000000 ____D C:\ProgramData\f-secure 2013-10-09 18:26 - 2013-10-09 18:26 - 00006823 _____ C:\Windows\FSSSINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00006076 _____ C:\Windows\FSSCINST.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00005629 _____ C:\Windows\fwesinst.log 2013-10-09 18:26 - 2013-10-09 18:26 - 00001979 _____ C:\Windows\FSPSUNI.LOG 2013-10-09 18:26 - 2013-10-09 18:26 - 00000110 _____ C:\Windows\FSAVES_inst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00005180 _____ C:\Windows\fwinst.log 2013-10-09 18:25 - 2013-10-09 18:25 - 00002713 _____ C:\Windows\FSPCUNIN.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00001307 _____ C:\Windows\FSGEMINST.LOG 2013-10-09 18:25 - 2013-10-09 18:25 - 00000154 _____ C:\Windows\fsgadget.log 2013-10-09 18:25 - 2013-10-09 18:24 - 00001710 _____ C:\Windows\FSASWUNI.LOG 2013-10-09 18:23 - 2013-10-05 12:28 - 00000000 ____D C:\Program Files\GIMP 2 2013-10-09 18:00 - 2011-12-04 11:47 - 00000000 ____D C:\Users\a\AppData\Roaming\Media Player Classic 2013-10-09 17:58 - 2013-07-20 22:13 - 00000000 ____D C:\Windows\Minidump 2013-10-09 17:39 - 2013-10-09 17:39 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-10-09 17:39 - 2013-10-09 17:39 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-09 17:39 - 2011-11-29 17:49 - 00000000 ____D C:\Program Files\CCleaner 2013-10-09 15:43 - 2013-10-09 15:43 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 15:43 - 2012-04-11 22:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 15:43 - 2012-04-11 22:09 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-08 15:26 - 2011-12-27 20:30 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-10-08 15:24 - 2013-10-08 15:24 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.5912.dll 2013-10-08 14:58 - 2013-10-08 14:57 - 00000000 ____D C:\ProgramData\DriverGenius 2013-10-05 12:50 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\.gimp-2.8 2013-10-05 12:44 - 2013-10-05 12:44 - 00000000 ____D C:\Users\a\AppData\Local\webkit 2013-10-05 12:35 - 2013-10-05 12:35 - 00000850 _____ C:\Users\a\AppData\Local\recently-used.xbel 2013-10-05 12:35 - 2013-10-05 12:35 - 00000000 ____D C:\Users\a\AppData\Local\gtk-2.0 2013-10-05 12:32 - 2011-11-29 17:39 - 00000000 ____D C:\Users\a 2013-10-05 12:31 - 2013-10-05 12:31 - 00000000 ____D C:\Users\a\AppData\Local\gegl-0.2 2013-10-05 12:07 - 2013-07-16 12:30 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-03 17:18 - 2013-10-03 17:18 - 00001155 _____ C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2013-10-03 17:18 - 2012-07-18 13:29 - 00000000 ____D C:\Program Files (x86)\ALDI Bestellsoftware 2013-10-03 17:04 - 2013-10-03 17:04 - 00000000 ____D C:\Windows\Sun 2013-10-01 11:05 - 2013-05-07 17:22 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-01 11:05 - 2013-04-19 09:40 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-23 01:28 - 2013-10-11 22:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-11 22:45 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-11 22:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-11 22:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-11 22:45 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-11 22:45 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-21 05:38 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-11 22:45 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-17 16:33 - 2013-09-17 16:33 - 00000000 ____D C:\Windows\system32\ljkb Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5912.dll Some content of TEMP: ==================== C:\Users\a\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-12 11:23 ==================== End Of Log ============================ [/CODE] Liebe Gruß Stephie87 |
17.10.2013, 08:27 | #14 |
/// the machine /// TB-Ausbilder | Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKCU\...\Run: [Odcuip] - C:\Users\a\AppData\Roaming\Ilyzet\mycu.exe [415329 2013-03-31] (AVAST Software) HKLM-x32\...\Run: [NPSStartup] - [x] HKLM-x32\...\Run: [] - [x] 2013-10-13 12:10 - 2013-10-14 21:41 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.10.2013, 09:25 | #15 |
| Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware hallo Schrauber, hier kommt die Fixlog Datei : Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013 Ran by a at 2013-10-17 10:21:10 Run:1 Running from C:\Users\a\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [Odcuip] - C:\Users\a\AppData\Roaming\Ilyzet\mycu.exe [415329 2013-03-31] (AVAST Software) HKLM-x32\...\Run: [NPSStartup] - [x] HKLM-x32\...\Run: [] - [x] 2013-10-13 12:10 - 2013-10-14 21:41 - 00000000 ____D C:\Users\a\AppData\Roaming\Bevo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Iptyo 2013-10-13 12:10 - 2013-10-13 12:10 - 00000000 ____D C:\Users\a\AppData\Roaming\Ilyzet ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Odcuip => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. C:\Users\a\AppData\Roaming\Bevo => Moved successfully. C:\Users\a\AppData\Roaming\Iptyo => Moved successfully. C:\Users\a\AppData\Roaming\Ilyzet => Moved successfully. ==== End of Fixlog ==== Stephie87 |
Themen zu Windows 7, PC langsam und diverse Funde durch Malwarebytes Antimalware |
.dll, abgebrochen, anti-malware, antimalware, browser, diverse, explorer, frage, log-datei, malwarebytes, messenger, pc langsam, pup.optional.amazontb.a, pup.optional.installbrain.a, pup.optional.searchprotect, pup.optional.sweetim, pup.optional.sweetpacks, pup.optional.sweetpacks.a, software, win32/kryptik.bmmb, windows |