|
Plagegeister aller Art und deren Bekämpfung: Nach SUMo Softwareupdater FundeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
13.11.2013, 11:31 | #1 |
| Nach SUMo Softwareupdater Funde Hallo, habe mir SUMo Softwareupdater runter geladen. Diese ging einher mit einigen komischen Toolbars. Siehe Bild. Nun meine Frage was ist davon zu halten? Kritisch? Malwarebytes sagt: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.13.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 xxxxx :: [Administrator] 13.11.2013 11:01:05 MBAM-log-2013-11-13 (11-05-46).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 228889 Laufzeit: 4 Minute(n), 7 Sekunde(n) Infizierte Speicherprozesse: 3 C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe (PUP.Optional.Iminent) -> 2468 -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.exe (PUP.Optional.Iminent.A) -> 5356 -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (PUP.Optional.Iminent.A) -> 5868 -> Keine Aktion durchgeführt. Infizierte Speichermodule: 3 C:\Program Files (x86)\Iminent\f_in_box.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.WinCore.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\System.Data.SQLite.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. Infizierte Registrierungsschlüssel: 90 HKLM\SYSTEM\CurrentControlSet\Services\SProtection (PUP.Optional.Iminent) -> Keine Aktion durchgeführt. HKCR\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Keine Aktion durchgeführt. HKCR\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} (Adware.Agent) -> Keine Aktion durchgeführt. HKCR\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8} (Adware.Agent) -> Keine Aktion durchgeführt. HKCR\PricePeep.PricePeepBho.1 (Adware.Agent) -> Keine Aktion durchgeführt. HKCR\PricePeep.PricePeepBho (Adware.Agent) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Keine Aktion durchgeführt. HKCR\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892} (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{01A602A0-D0B9-445B-8081-719E4177C4A7} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.ShowControlCenterCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{112BA211-334C-4A90-90EC-2AD1CDAB287C} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\iminent.iminentHlpr.1 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\iminent.iminentHlpr (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{112BA211-334C-4A90-90EC-2AD1CDAB287C} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{1FAFD711-ABF9-4F6A-8130-5166C7371427} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\iminent.iminentdskBnd.1 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\iminent.iminentdskBnd (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\IminentWebBooster.ScriptExtender.1 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\IminentWebBooster.ScriptExtender (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\IminentWebBooster.BrowserHelperObject.1 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\IminentWebBooster.BrowserHelperObject (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKCR\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKCR\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8} (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKCR\PricePeep.PricePeepBho.1 (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKCR\PricePeep.PricePeepBho (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0af350d9-3916-454b-ac53-0b0b65f41301} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Business.Tinyfying.DownloadArgs (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Business.Tinyfying.LinkToPromoteArgs (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Business.Tinyfying.RawDataArgs (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Business.Tinyfying.TinyUrlArgs (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Business.Tinyfying.ViralLinkArgs (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.ClientCallback (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.ContractBase (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.AddToUserContentCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.CheckLoginStatusCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.CleanCacheCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.GameOverCallback (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.GetCreditCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.GetInstallationContextCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.GetLoginStatusCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.GetLoginStatusResult (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.GetVariableCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.GetVariableResult (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.InstallationContextResult (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.LoadContentCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.LoadContentCommandResult (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.LoginCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.LoginStatusChangedCallback (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.LogoutCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.MergeIdentityCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.MyAccountCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.PlayContentCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.PostContentCallback (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.RecycleViewsCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.SetVariableCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.ShowBrowserWindowCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.ShowPluginWindowCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.TestContentCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.UserContentChangedCallback (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.VariableChangedCallback (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.WarmUpCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.DataContracts.WelcomeCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.ServerCommand (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.Communication.ServerResult (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.LightContent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.LightUri (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\Iminent.Mediator.MediatorServiceProxy (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\AppID\Iminent.WebBooster.InternetExplorer.DLL (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\AppID\PricePeep.DLL (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\IMINENT (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\UMBRELLA (PUP.Optional.Umbrella.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\IMINENT (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{A2CC3C46-143B-4142-9D5A-B8543F0A6F55} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\iminent.iminentappCore.1 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\iminent.iminentappCore (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{9FD0C1D9-180B-4834-B80B-4B7325AF90E1} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\i (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\TypeLib\{8E9F2D02-6B06-4EBA-92C2-68438EADED28} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 10 HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{1FAFD711-ABF9-4F6A-8130-5166C7371427} (PUP.Optional.Iminent.A) -> Daten: Iminent Toolbar -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} (PUP.Optional.Iminent.A) -> Daten: -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{84FF7BD6-B47F-46F8-9130-01B2696B36CB} (PUP.Optional.Iminent.A) -> Daten: -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{1FAFD711-ABF9-4F6A-8130-5166C7371427} (PUP.Optional.Iminent.A) -> Daten: -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|IminentMessenger (PUP.Optional.Iminent.A) -> Daten: C:\Program Files (x86)\Iminent\Iminent.Messengers.exe -> Keine Aktion durchgeführt. HKCU\Software\Iminent|SearchEngineOptin (PUP.Optional.Iminent.A) -> Daten: 0 -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Umbrella|MUpdBlock (PUP.Optional.Umbrella.A) -> Daten: { "MASSUPDATE" : { "CHROME_MBAR" : { "Checked" : 1, "RetryIdx" : 0, "Version" : 1 }, "FIREFOX_MBAR" : { "Checked" : 1, "RetryIdx" : 0, "Version" : 1 } } } -> Keine Aktion durchgeführt. HKLM\SYSTEM\CurrentControlSet\Services\SProtection|ImagePath (PUP.Optional.Iminent.A) -> Daten: C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe -> Keine Aktion durchgeführt. HKLM\Software\Iminent|RefererId (PUP.Optional.Iminent.A) -> Daten: 1088 -> Keine Aktion durchgeführt. HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Iminent (PUP.Optional.Iminent.A) -> Daten: C:\Program Files (x86)\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C" -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 28 C:\Program Files (x86)\Iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\inst (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\inst\Bootstrapper (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\ro (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\tr (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\PricePeep (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Iminent\Mediator (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Iminent\Mediator\Datas (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Iminent\Mediator\Datas\Cache (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Iminent\Mediator\Datas\Cache\apix.iminent.com (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\MaTo\AppData\Roaming\Iminent\Mediator (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\MaTo\AppData\Roaming\Iminent\Mediator\Datas (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\bh (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Temp\Iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Temp\Iminent\Log (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Temp\mt_ffx\iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Temp\mt_ffx\iminent\iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Temp\mt_ffx\iminent\iminent\1.8.26.8 (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 119 C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe (PUP.Optional.Iminent) -> Keine Aktion durchgeführt. C:\Program Files (x86)\PricePeep\pricepeep.dll (Adware.Agent) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\bh\iminent.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\iminentTlbr.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.WebBooster.InternetExplorer.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\PricePeep\pricepeep.dll (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. C:\Windows\Installer\4ca23d.msi (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\SearchTheWeb.xml (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\f_in_box.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.AxImp.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Booster.UI.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Business.Connect.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Business.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Business.tlb (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Entity.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.exe (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.exe.config (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.InstallLog (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.InstallState (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Mediator.ActivePlayers.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Mediator.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Mediator.tlb (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Messengers.exe.config (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Services.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.WinCore.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.WinCore.WLM.WinEvents.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.WinCore.WLM15.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.WinCore.Yahoo.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Windows.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Iminent.Workflow.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Microsoft.DirectX.AudioVideoPlayback.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\Microsoft.Expression.Interactions.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\StartWeb.xml (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\System.Data.SQLite.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\System.Data.SQLite.xml (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\System.Windows.Interactivity.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\System.Windows.Interactivity.xml (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\USearch.xml (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\WPFLocalizeExtension.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\WPFLocalizeExtension.xml (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de\Iminent.Booster.UI.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de\Iminent.Business.Connect.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de\Iminent.Messengers.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de\Iminent.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de\Iminent.Services.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de\Microsoft.Expression.Interactions.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\de\System.Windows.Interactivity.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en\Iminent.Booster.UI.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en\Iminent.Business.Connect.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en\Iminent.Messengers.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en\Iminent.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en\Iminent.Services.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en\Microsoft.Expression.Interactions.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\en\System.Windows.Interactivity.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es\Iminent.Booster.UI.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es\Iminent.Business.Connect.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es\Iminent.Messengers.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es\Iminent.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es\Iminent.Services.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es\Microsoft.Expression.Interactions.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\es\System.Windows.Interactivity.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr\Iminent.Booster.UI.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr\Iminent.Business.Connect.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr\Iminent.Messengers.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr\Iminent.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr\Iminent.Services.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr\Microsoft.Expression.Interactions.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\fr\System.Windows.Interactivity.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\inst\main.ico (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\inst\msacm32.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\inst\SearchTheWeb.ico (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\inst\Universely.ico (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exe (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it\Iminent.Booster.UI.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it\Iminent.Business.Connect.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it\Iminent.Messengers.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it\Iminent.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it\Iminent.Services.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it\Microsoft.Expression.Interactions.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\it\System.Windows.Interactivity.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\ro\Iminent.Booster.UI.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\ro\Iminent.Messengers.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\ro\Iminent.Services.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\tr\Iminent.Booster.UI.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\tr\Iminent.Business.Connect.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\tr\Iminent.Messengers.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\tr\Iminent.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Iminent\tr\Iminent.Services.resources.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Mozilla Firefox\defaults\pref\all-iminent.js (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\PricePeep\installer.ico (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\PricePeep\uninstall.exe (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\PricePeep\unutil.exe (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent\SearchTheWeb.lnk (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent\Blog.lnk (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent\FAQ.lnk (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent\Help.lnk (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent\Iminent.lnk (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\ProgramData\Iminent\Mediator\Datas\Cache\apix.iminent.com\1031.11575f00-7bdc-4181-ba0a-b298aeab228c.dat (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\MaTo\AppData\Roaming\Iminent\Mediator\Datas\globalcache.dat (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\MaTo\AppData\Roaming\Iminent\Mediator\Datas\user.dat (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\appCntrl.js (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\bg.html (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\bg.js (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\CrmAdpt.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\ct.js (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\CTB.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\dpk.js (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\hprtkMsg.htm (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\hprtkMsg.js (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\json2.min.js (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\logo.png (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\manifest.json (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\Markus\AppData\Local\Google\Chrome\User Data\default\extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\pref.json (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\iminent.crx (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\iminentApp.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\iminentEng.dll (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\iminentsrv.exe (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar\1.8.26.8\uninstall.exe (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. (Ende)
__________________ Grüße blamato ------------ HP Workstation / Win 7 (64) / Avast I.S. |
13.11.2013, 11:50 | #2 |
/// the machine /// TB-Ausbilder | Nach SUMo Softwareupdater Funde hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
13.11.2013, 12:00 | #3 |
| Nach SUMo Softwareupdater Funde FRST
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-11-2013 Ran by MaTo (ATTENTION: The logged in user is not administrator) on HPXWPROLOG on 13-11-2013 11:55:16 Running from C:\Users\MaTo\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (SPAMfighter ApS) C:\Program Files (x86)\Fighters\Tray\FightersTray.exe (SPAMfighter ApS) C:\Program Files (x86)\Fighters\SPAMfighter\sfagent.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (SPAMfighter ApS) C:\Program Files (x86)\Fighters\SPAMfighter\x64\LiveKitLoader64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8317472 2009-11-03] (Realtek Semiconductor) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKLM-x32\...\Run: [SSBkgdUpdate] - C:\Program Files (x86)\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [210472 2006-10-25] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PaperPort PTD] - C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PPort11reminder] - C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini [324 2012-12-29] () HKLM-x32\...\Run: [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1167360 2009-08-03] (Brother Industries, Ltd.) HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [CommonToolkitTray] - C:\Program Files (x86)\Fighters\Tray\FightersTray.exe [1497120 2013-06-19] (SPAMfighter ApS) HKLM-x32\...\Run: [sfagent] - C:\Program Files (x86)\Fighters\SPAMfighter\sfagent.exe [1063968 2013-09-24] (SPAMfighter ApS) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-19] (Apple Inc.) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB5DD7559F214CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.iminent.com/?appId=EA44267A-B92D-4D04-AD1E-F5E4A60ABB5B HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - URL hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q={searchTerms} SearchScopes: HKLM-x32 - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=66920&gid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&dbCode=1&command={searchTerms} SearchScopes: HKLM-x32 - TopResultURLFallback hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q={searchTerms} SearchScopes: HKCU - DefaultScope {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=EA44267A-B92D-4D04-AD1E-F5E4A60ABB5B&ref=toolbox&q={searchTerms} SearchScopes: HKCU - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=EA44267A-B92D-4D04-AD1E-F5E4A60ABB5B&ref=toolbox&q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 14\SPMIEToolbar64.dll (Steganos Software GmbH) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default FF NewTab: hxxp://www.google.de FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF NetworkProxy: "gopher", "" FF NetworkProxy: "gopher_port", 0 FF NetworkProxy: "share_proxy_settings", true FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Deutsches Wörterbuch, klassisch und reformiert - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\alterechtschreibung@gmail.com FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\de_DE@dicts.j3e.de FF Extension: Dr.Web Anti-Virus Link Checker - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5} FF Extension: jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc@jetpack.xpi FF Extension: PageRank - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\PageRank@addonfactory.in.xpi FF Extension: toolbar - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\toolbar@alexa.com.xpi FF Extension: adblocker - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 14\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 14\spmplugin3 FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-08-30] (AVAST Software) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1830768 2013-08-12] (SurfRight B.V.) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 SPAMfighter Update Service; C:\Program Files (x86)\Fighters\SPAMfighter\sfus.exe [212000 2013-09-24] (SPAMfighter ApS) R2 Suite Service; C:\Program Files (x86)\Fighters\FighterSuiteService.exe [1281568 2013-05-29] (SPAMfighter ApS) S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [x] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R1 aswFW; C:\Windows\System32\Drivers\aswFW.sys [131232 2013-08-30] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2013-07-17] (ALWIL Software) R0 aswNdis2; C:\Windows\System32\drivers\aswNdis2.sys [270824 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () S3 cleanhlp; C:\EEK\RUN\cleanhlp64.sys [57024 2013-08-21] (Emsisoft GmbH) R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [17416 2013-08-12] () R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-04-24] (AnchorFree Inc.) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) S3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-13 11:55 - 2013-11-13 11:55 - 00016630 _____ C:\Users\MaTo\Downloads\FRST.txt 2013-11-13 11:55 - 2013-11-13 11:55 - 00000000 ____D C:\FRST 2013-11-13 11:54 - 2013-11-13 11:54 - 01957610 _____ (Farbar) C:\Users\MaTo\Downloads\FRST64.exe 2013-11-13 10:19 - 2013-11-13 11:12 - 00001725 _____ C:\Users\MaTo\daemonprocess.txt 2013-11-13 10:09 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-11-13 10:09 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-11-13 10:09 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-11-13 10:09 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-11-13 10:09 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-11-13 10:09 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-11-13 10:09 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-11-13 10:09 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2013-11-13 10:09 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-11-13 10:09 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-11-13 10:09 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-11-13 10:09 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-11-13 10:09 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-11-13 10:09 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-11-13 10:09 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2013-11-13 10:09 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-11-13 10:09 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-11-13 10:09 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-11-13 10:08 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2013-11-13 10:08 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2013-11-13 09:37 - 2013-11-13 11:13 - 00000000 ____D C:\Users\Markus\AppData\Local\Mobogenie 2013-11-13 09:37 - 2013-11-13 10:03 - 00001380 _____ C:\Users\Markus\daemonprocess.txt 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\Documents\Mobogenie 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\AppData\Local\cache 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\.android 2013-11-13 09:36 - 2013-11-13 11:15 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-11-13 09:36 - 2013-11-13 11:15 - 00000000 ____D C:\Program Files (x86)\Iminent 2013-11-13 09:36 - 2013-11-13 11:12 - 00000000 ____D C:\Program Files (x86)\IminentToolbar 2013-11-13 09:36 - 2013-11-13 09:36 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Iminent 2013-11-13 09:33 - 2013-11-13 09:33 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\KC Softwares 2013-11-13 09:29 - 2013-11-13 09:29 - 01574068 _____ (KC Softwares ) C:\Users\MaTo\Downloads\sumo39_nork.exe 2013-11-13 08:40 - 2013-11-13 08:40 - 170750620 _____ (bitfarm Informationssysteme GmbH) C:\Users\MaTo\Downloads\bitfarm-archiv-dms-gpl-server-3.4.4.exe 2013-11-13 08:19 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 08:19 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 08:19 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 08:19 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 08:19 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 08:19 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 08:19 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 08:19 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 08:19 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 08:19 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 08:19 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 08:19 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 08:19 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 08:19 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 08:19 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 08:19 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 08:19 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 08:19 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 08:19 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 08:19 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 08:19 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 08:19 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 08:19 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 08:19 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 08:19 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 08:19 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 08:19 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 08:19 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 08:19 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 08:19 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-12 21:36 - 2013-11-12 21:36 - 00000252 _____ C:\Users\MaTo\Desktop\VIRUS.txt 2013-11-09 12:52 - 2013-11-09 12:52 - 00591910 _____ C:\Users\MaTo\Downloads\MicrosoftFixIt.zip 2013-11-07 22:52 - 2013-11-13 11:07 - 00001946 _____ C:\Windows\PFRO.log 2013-11-07 20:31 - 2013-11-07 20:31 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-07 20:30 - 2013-11-07 20:33 - 00008372 _____ C:\Windows\IE11_main.log 2013-11-07 14:51 - 2013-11-13 11:07 - 00000952 _____ C:\Windows\setupact.log 2013-11-07 14:51 - 2013-11-07 14:51 - 00000000 _____ C:\Windows\setuperr.log 2013-11-07 14:48 - 2013-11-07 14:48 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51005.msi 2013-11-07 14:46 - 2013-11-07 14:46 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51004.msi 2013-11-07 08:40 - 2013-11-07 08:40 - 04379048 _____ (Piriform Ltd) C:\Users\MaTo\Downloads\ccsetup407.exe 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-04 13:43 - 2013-11-04 13:43 - 02434048 _____ C:\Users\Markus\Downloads\msxml.msi 2013-11-01 16:09 - 2013-11-04 13:48 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Opera Software 2013-11-01 16:09 - 2013-11-04 13:48 - 00000000 ____D C:\Users\MaTo\AppData\Local\Opera Software 2013-11-01 15:51 - 2013-11-01 15:51 - 00985600 _____ C:\Users\Markus\Downloads\MicrosoftFixit50123.msi 2013-11-01 14:30 - 2013-11-01 14:30 - 00003140 _____ C:\Users\Markus\Documents\cc_20131101_143039.reg 2013-10-31 09:36 - 2013-10-31 09:36 - 00001264 _____ C:\Users\Markus\Desktop\Revo Uninstaller.lnk 2013-10-31 09:36 - 2013-10-31 09:36 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-10-31 09:06 - 2013-10-31 09:06 - 13079688 _____ (Microsoft Corporation) C:\Users\MaTo\Downloads\Silverlight_x64.exe 2013-10-30 20:15 - 2013-10-30 20:15 - 00000000 ____D C:\Program Files (x86)\Opera x64 2013-10-27 12:22 - 2013-10-27 12:23 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-10-27 12:22 - 2013-10-27 12:23 - 00000000 ____D C:\Program Files\iTunes 2013-10-27 12:22 - 2013-10-27 12:23 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-10-27 12:22 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files\iPod 2013-10-26 18:37 - 2013-10-26 18:37 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-10-25 15:41 - 2013-11-10 16:22 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-10-25 15:41 - 2013-08-30 08:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-10-25 15:41 - 2013-08-30 08:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-25 15:40 - 2013-10-25 15:40 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-25 15:40 - 2013-08-30 08:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00270824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdis2.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2013-10-25 15:40 - 2013-08-30 08:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-25 15:40 - 2013-08-30 08:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-25 15:40 - 2013-07-17 10:17 - 00012368 _____ (ALWIL Software) C:\Windows\system32\Drivers\aswNdis.sys 2013-10-25 15:26 - 2013-10-25 15:26 - 00000035 _____ C:\Windows\avast5.ini 2013-10-25 15:18 - 2013-10-23 08:44 - 161978728 _____ C:\Users\Markus\Downloads\avast_internet_security_setup_801497.exe 2013-10-25 15:17 - 2013-11-13 11:11 - 00760833 _____ C:\Windows\WindowsUpdate.log 2013-10-25 15:17 - 2013-10-25 15:17 - 00000034 _____ C:\Windows\AvastEmUpdate.ini 2013-10-25 15:13 - 2013-10-25 15:13 - 00000000 ____D C:\Users\Markus\AppData\Local\Mozilla 2013-10-25 14:59 - 2013-10-25 15:02 - 108831448 _____ C:\Users\MaTo\Downloads\avast_internet_security_setup(1).exe.part 2013-10-24 22:16 - 2013-10-24 22:16 - 00000160 _____ C:\Users\MaTo\Desktop\XHamster.txt 2013-10-24 22:15 - 2013-10-24 22:15 - 00001409 _____ C:\Users\MaTo\Desktop\Internet Explorer.lnk 2013-10-23 09:30 - 2013-10-23 09:33 - 121680752 _____ (AVAST Software) C:\Users\Markus\Downloads\avast_internet_security_setup.exe 2013-10-23 09:18 - 2013-10-23 09:18 - 00000000 ____D C:\Users\Markus\AppData\Roaming\AVAST Software 2013-10-23 08:33 - 2013-10-23 09:26 - 00000000 ____D C:\Users\MaTo\Downloads\AVAST 2013-10-23 08:32 - 2013-10-23 08:32 - 00000782 _____ C:\Users\MaTo\Desktop\AVAST.txt 2013-10-22 10:48 - 2013-10-22 10:53 - 185167736 _____ (DATA BECKER ) C:\Users\MaTo\Downloads\graphicworks10_r1.exe 2013-10-22 10:12 - 2013-10-22 10:27 - 00000000 ____D C:\Office Manager DMS 2013-10-22 10:11 - 2013-10-22 10:11 - 00000000 ____D C:\Program Files (x86)\Krekeler 2013-10-22 09:43 - 2013-10-22 09:44 - 38158888 _____ (Softwarebüro Krekeler) C:\Users\MaTo\Downloads\ompro.exe 2013-10-22 08:56 - 2013-10-22 08:56 - 00001705 _____ C:\Users\MaTo\Downloads\license.avastlic 2013-10-20 20:39 - 2013-10-20 20:39 - 05831344 _____ (TeamViewer GmbH) C:\Users\MaTo\Downloads\TeamViewer_Setup_de.exe 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Canneverbe Limited 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Program Files\CDBurnerXP 2013-10-16 12:20 - 2013-10-16 12:20 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\AVAST Software 2013-10-16 12:17 - 2013-10-23 09:39 - 00002032 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk ==================== One Month Modified Files and Folders ======= 2013-11-13 11:55 - 2013-11-13 11:55 - 00016630 _____ C:\Users\MaTo\Downloads\FRST.txt 2013-11-13 11:55 - 2013-11-13 11:55 - 00000000 ____D C:\FRST 2013-11-13 11:54 - 2013-11-13 11:54 - 01957610 _____ (Farbar) C:\Users\MaTo\Downloads\FRST64.exe 2013-11-13 11:50 - 2013-01-01 15:42 - 00000000 ____D C:\ProgramData\SecTaskMan 2013-11-13 11:45 - 2012-12-22 18:43 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Skype 2013-11-13 11:44 - 2012-12-23 13:17 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-13 11:41 - 2013-03-21 11:18 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\FileZilla 2013-11-13 11:34 - 2013-01-10 20:01 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-13 11:15 - 2013-11-13 09:36 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-11-13 11:15 - 2013-11-13 09:36 - 00000000 ____D C:\Program Files (x86)\Iminent 2013-11-13 11:15 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-13 11:15 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-13 11:13 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\AppData\Local\Mobogenie 2013-11-13 11:12 - 2013-11-13 10:19 - 00001725 _____ C:\Users\MaTo\daemonprocess.txt 2013-11-13 11:12 - 2013-11-13 09:36 - 00000000 ____D C:\Program Files (x86)\IminentToolbar 2013-11-13 11:11 - 2013-10-25 15:17 - 00760833 _____ C:\Windows\WindowsUpdate.log 2013-11-13 11:09 - 2012-12-23 13:17 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-13 11:07 - 2013-11-07 22:52 - 00001946 _____ C:\Windows\PFRO.log 2013-11-13 11:07 - 2013-11-07 14:51 - 00000952 _____ C:\Windows\setupact.log 2013-11-13 11:07 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-13 10:38 - 2013-07-13 20:38 - 00458752 ___SH C:\Users\MaTo\Downloads\Thumbs.db 2013-11-13 10:19 - 2012-12-22 13:45 - 00000000 ____D C:\Users\MaTo 2013-11-13 10:03 - 2013-11-13 09:37 - 00001380 _____ C:\Users\Markus\daemonprocess.txt 2013-11-13 10:02 - 2013-07-15 09:06 - 00000000 ____D C:\Windows\system32\MRT 2013-11-13 10:02 - 2012-12-22 14:22 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-13 10:00 - 2012-12-22 12:33 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\Documents\Mobogenie 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\AppData\Local\cache 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\.android 2013-11-13 09:37 - 2012-12-22 11:50 - 00000000 ____D C:\Users\Markus 2013-11-13 09:36 - 2013-11-13 09:36 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Iminent 2013-11-13 09:33 - 2013-11-13 09:33 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\KC Softwares 2013-11-13 09:29 - 2013-11-13 09:29 - 01574068 _____ (KC Softwares ) C:\Users\MaTo\Downloads\sumo39_nork.exe 2013-11-13 08:40 - 2013-11-13 08:40 - 170750620 _____ (bitfarm Informationssysteme GmbH) C:\Users\MaTo\Downloads\bitfarm-archiv-dms-gpl-server-3.4.4.exe 2013-11-12 21:36 - 2013-11-12 21:36 - 00000252 _____ C:\Users\MaTo\Desktop\VIRUS.txt 2013-11-12 19:06 - 2010-11-21 07:50 - 00660680 _____ C:\Windows\system32\perfh007.dat 2013-11-12 19:06 - 2010-11-21 07:50 - 00132704 _____ C:\Windows\system32\perfc007.dat 2013-11-12 19:06 - 2009-07-14 06:13 - 01516816 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-10 16:24 - 2012-12-23 09:08 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Skype 2013-11-10 16:23 - 2012-12-22 11:50 - 00001421 _____ C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-10 16:22 - 2013-10-25 15:41 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-11-10 16:22 - 2012-12-22 12:28 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-11-10 16:20 - 2013-06-29 22:02 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\streamripper 2013-11-10 16:20 - 2012-12-28 15:10 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Winamp 2013-11-10 16:20 - 2010-11-21 08:00 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-11-10 16:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-11-10 16:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat 2013-11-09 12:52 - 2013-11-09 12:52 - 00591910 _____ C:\Users\MaTo\Downloads\MicrosoftFixIt.zip 2013-11-07 23:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-07 20:37 - 2012-12-22 11:33 - 00000000 ____D C:\Windows\Panther 2013-11-07 20:33 - 2013-11-07 20:30 - 00008372 _____ C:\Windows\IE11_main.log 2013-11-07 20:31 - 2013-11-07 20:31 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-07 15:57 - 2013-01-22 20:51 - 00001456 _____ C:\Users\MaTo\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2013-11-07 14:51 - 2013-11-07 14:51 - 00000000 _____ C:\Windows\setuperr.log 2013-11-07 14:48 - 2013-11-07 14:48 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51005.msi 2013-11-07 14:46 - 2013-11-07 14:46 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51004.msi 2013-11-07 08:41 - 2013-02-26 19:42 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-11-07 08:41 - 2013-02-26 19:42 - 00000000 ____D C:\Program Files\CCleaner 2013-11-07 08:40 - 2013-11-07 08:40 - 04379048 _____ (Piriform Ltd) C:\Users\MaTo\Downloads\ccsetup407.exe 2013-11-06 16:47 - 2012-12-24 11:58 - 00002258 ____H C:\Users\MaTo\Documents\Default.rdp 2013-11-06 09:04 - 2012-12-22 18:43 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-06 09:04 - 2012-12-22 18:43 - 00000000 ____D C:\ProgramData\Skype 2013-11-05 22:06 - 2013-05-27 11:58 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Steganos 2013-11-05 21:34 - 2012-12-22 17:41 - 00000600 _____ C:\Users\MaTo\AppData\Roaming\winscp.rnd 2013-11-05 13:12 - 2012-12-22 13:45 - 00001421 _____ C:\Users\MaTo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-05 12:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-04 13:48 - 2013-11-01 16:09 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Opera Software 2013-11-04 13:48 - 2013-11-01 16:09 - 00000000 ____D C:\Users\MaTo\AppData\Local\Opera Software 2013-11-04 13:43 - 2013-11-04 13:43 - 02434048 _____ C:\Users\Markus\Downloads\msxml.msi 2013-11-01 15:51 - 2013-11-01 15:51 - 00985600 _____ C:\Users\Markus\Downloads\MicrosoftFixit50123.msi 2013-11-01 14:30 - 2013-11-01 14:30 - 00003140 _____ C:\Users\Markus\Documents\cc_20131101_143039.reg 2013-10-31 09:36 - 2013-10-31 09:36 - 00001264 _____ C:\Users\Markus\Desktop\Revo Uninstaller.lnk 2013-10-31 09:36 - 2013-10-31 09:36 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-10-31 09:18 - 2013-10-10 22:05 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-31 09:18 - 2012-12-22 17:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-31 09:06 - 2013-10-31 09:06 - 13079688 _____ (Microsoft Corporation) C:\Users\MaTo\Downloads\Silverlight_x64.exe 2013-10-30 20:23 - 2012-12-23 11:58 - 00000000 ____D C:\Users\MaTo\AppData\Local\Opera 2013-10-30 20:22 - 2012-12-23 11:58 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Opera 2013-10-30 20:15 - 2013-10-30 20:15 - 00000000 ____D C:\Program Files (x86)\Opera x64 2013-10-30 08:02 - 2013-03-09 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-29 22:36 - 2013-03-10 16:40 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-10-29 22:36 - 2013-03-10 16:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-27 12:23 - 2013-10-27 12:22 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-10-27 12:23 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files\iTunes 2013-10-27 12:23 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-10-27 12:22 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files\iPod 2013-10-27 12:22 - 2013-03-22 23:01 - 00000000 ____D C:\ProgramData\Apple Computer 2013-10-26 18:37 - 2013-10-26 18:37 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-10-25 15:40 - 2013-10-25 15:40 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-25 15:40 - 2012-12-22 12:27 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-25 15:26 - 2013-10-25 15:26 - 00000035 _____ C:\Windows\avast5.ini 2013-10-25 15:17 - 2013-10-25 15:17 - 00000034 _____ C:\Windows\AvastEmUpdate.ini 2013-10-25 15:13 - 2013-10-25 15:13 - 00000000 ____D C:\Users\Markus\AppData\Local\Mozilla 2013-10-25 15:13 - 2013-03-13 14:35 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Mozilla 2013-10-25 15:02 - 2013-10-25 14:59 - 108831448 _____ C:\Users\MaTo\Downloads\avast_internet_security_setup(1).exe.part 2013-10-24 22:16 - 2013-10-24 22:16 - 00000160 _____ C:\Users\MaTo\Desktop\XHamster.txt 2013-10-24 22:15 - 2013-10-24 22:15 - 00001409 _____ C:\Users\MaTo\Desktop\Internet Explorer.lnk 2013-10-23 09:39 - 2013-10-16 12:17 - 00002032 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk 2013-10-23 09:33 - 2013-10-23 09:30 - 121680752 _____ (AVAST Software) C:\Users\Markus\Downloads\avast_internet_security_setup.exe 2013-10-23 09:26 - 2013-10-23 08:33 - 00000000 ____D C:\Users\MaTo\Downloads\AVAST 2013-10-23 09:21 - 2012-12-22 11:50 - 00000000 ___RD C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-23 09:21 - 2012-12-22 11:50 - 00000000 ___RD C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-23 09:18 - 2013-10-23 09:18 - 00000000 ____D C:\Users\Markus\AppData\Roaming\AVAST Software 2013-10-23 08:44 - 2013-10-25 15:18 - 161978728 _____ C:\Users\Markus\Downloads\avast_internet_security_setup_801497.exe 2013-10-23 08:32 - 2013-10-23 08:32 - 00000782 _____ C:\Users\MaTo\Desktop\AVAST.txt 2013-10-22 10:53 - 2013-10-22 10:48 - 185167736 _____ (DATA BECKER ) C:\Users\MaTo\Downloads\graphicworks10_r1.exe 2013-10-22 10:27 - 2013-10-22 10:12 - 00000000 ____D C:\Office Manager DMS 2013-10-22 10:11 - 2013-10-22 10:11 - 00000000 ____D C:\Program Files (x86)\Krekeler 2013-10-22 09:44 - 2013-10-22 09:43 - 38158888 _____ (Softwarebüro Krekeler) C:\Users\MaTo\Downloads\ompro.exe 2013-10-22 08:56 - 2013-10-22 08:56 - 00001705 _____ C:\Users\MaTo\Downloads\license.avastlic 2013-10-20 20:39 - 2013-10-20 20:39 - 05831344 _____ (TeamViewer GmbH) C:\Users\MaTo\Downloads\TeamViewer_Setup_de.exe 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Canneverbe Limited 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Program Files\CDBurnerXP 2013-10-17 23:38 - 2013-01-18 23:11 - 00001742 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2013-10-17 22:56 - 2013-09-30 09:24 - 00000000 ____D C:\Users\MaTo\Downloads\Briefvorlagen 2013-10-17 13:20 - 2013-01-14 16:05 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Dropbox 2013-10-16 12:20 - 2013-10-16 12:20 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\AVAST Software 2013-10-14 18:00 - 2013-02-27 14:42 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ --- --- --- Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-11-2013 Ran by MaTo at 2013-11-13 11:56:12 Running from C:\Users\MaTo\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Internet Security (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Internet Security (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: avast! Internet Security (Enabled) {131692B0-0864-D491-4E21-3A3A1D8BBB47} ==================== Installed Programs ====================== 2007 Microsoft Office system (x32 Version: 12.0.6612.1000) Adobe Community Help (x32 Version: 3.0.0) Adobe Community Help (x32 Version: 3.0.0.400) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Media Player (x32 Version: 1.8) Adobe Photoshop CS5 (x32 Version: 12.0) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Adobe Shockwave Player 12.0 (x32 Version: 12.0.5.146) AMD Accelerated Video Transcoding (Version: 12.5.100.21116) AMD APP SDK Runtime (Version: 10.0.937.2) AMD Catalyst Install Manager (Version: 8.0.877.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71116.1554) Any Video Converter 5 5.0.4 (x32) Apple Application Support (x32 Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (x32 Version: 2.1.3.127) avast! Internet Security (x32 Version: 8.0.1497.0) Bonjour (Version: 3.0.0.10) Brother MFL-Pro Suite MFC-5895CW (x32 Version: 1.0.2.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1116.1515.27190) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1116.1515.27190) Catalyst Control Center InstallProxy (x32 Version: 2012.1116.1515.27190) Catalyst Control Center Localization All (x32 Version: 2012.1116.1515.27190) CCC Help Chinese Standard (x32 Version: 2012.1116.1514.27190) CCC Help Chinese Traditional (x32 Version: 2012.1116.1514.27190) CCC Help Czech (x32 Version: 2012.1116.1514.27190) CCC Help Danish (x32 Version: 2012.1116.1514.27190) CCC Help Dutch (x32 Version: 2012.1116.1514.27190) CCC Help English (x32 Version: 2012.1116.1514.27190) CCC Help Finnish (x32 Version: 2012.1116.1514.27190) CCC Help French (x32 Version: 2012.1116.1514.27190) CCC Help German (x32 Version: 2012.1116.1514.27190) CCC Help Greek (x32 Version: 2012.1116.1514.27190) CCC Help Hungarian (x32 Version: 2012.1116.1514.27190) CCC Help Italian (x32 Version: 2012.1116.1514.27190) CCC Help Japanese (x32 Version: 2012.1116.1514.27190) CCC Help Korean (x32 Version: 2012.1116.1514.27190) CCC Help Norwegian (x32 Version: 2012.1116.1514.27190) CCC Help Polish (x32 Version: 2012.1116.1514.27190) CCC Help Portuguese (x32 Version: 2012.1116.1514.27190) CCC Help Russian (x32 Version: 2012.1116.1514.27190) CCC Help Spanish (x32 Version: 2012.1116.1514.27190) CCC Help Swedish (x32 Version: 2012.1116.1514.27190) CCC Help Thai (x32 Version: 2012.1116.1514.27190) CCC Help Turkish (x32 Version: 2012.1116.1514.27190) ccc-utility64 (Version: 2012.1116.1515.27190) CCleaner (Version: 4.07) CDBurnerXP (Version: 4.5.2.4291) CDBurnerXP (x32 Version: 4.5.0.3717) Dropbox (HKCU Version: 2.0.22) Google Chrome (x32 Version: 30.0.1599.101) Google Update Helper (x32 Version: 1.3.21.165) HD Tune 2.55 (x32) HitmanPro.Alert (Version: 2.0.10.45) iTunes (Version: 11.1.2.31) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320) Microsoft Corporation (Version: 9.1.0.0) Microsoft Corporation (x32 Version: 9.1.0.0) Microsoft LifeCam (Version: 3.60.253.0) Microsoft Office 2003 Web Components (x32 Version: 11.0.8003.0) Microsoft Office 2007 Primary Interop Assemblies (x32 Version: 12.0.4518.1014) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Professional Hybrid 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Small Business Connectivity Components (x32 Version: 2.0.7024.0) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office XP Professional mit FrontPage (x32 Version: 10.0.6626.0) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Mozilla Firefox 24.1.0 (x86 de) (x32 Version: 24.1.0) Mozilla Maintenance Service (x32 Version: 24.1.0) Mozilla Thunderbird 24.0 (x86 de) (x32 Version: 24.0) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Notepad++ (x32 Version: 6.3.3) Opera Stable 17.0.1241.53 (x32 Version: 17.0.1241.53) PaperPort Image Printer 64-bit (Version: 1.00.0000) PDF Settings CS5 (x32 Version: 10.0) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5973) Revo Uninstaller 1.95 (x32 Version: 1.95) ScanSoft PaperPort 11 (x32 Version: 11.2.0000) Security Task Manager 1.8f (x32 Version: 1.8f) Skype Click to Call (x32 Version: 6.3.11079) Skype™ 6.10 (x32 Version: 6.10.104) SPAMfighter (x32 Version: 7.6.67) Steganos Password Manager 14 (x32 Version: 14.1) Streamripper (Remove only) (x32) swMSM (x32 Version: 12.0.0.1) TSPrint Client (x32 Version: 1.9.7.5) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VLC media player 2.1.0 (x32 Version: 2.1.0) Winamp (x32 Version: 5.63 ) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR 5.00 (64-Bit) (Version: 5.00.0) WinSCP 5.1.6 (x32 Version: 5.1.6) Yahoo! Messenger (x32) ==================== Restore Points ========================= Could not list Restore Points. Check WMI. ==================== Hosts content: ========================== 2013-03-20 12:36 - 2013-03-20 12:36 - 00002969 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 hl2rcv.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 3dns.adobe.com 127.0.0.1 3dns-1.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-4.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-1.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 adobe-dns-4.adobe.com 127.0.0.1 adobe-dns-5.adobe.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com There are 34 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ? Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ? Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ? ==================== Loaded Modules (whitelisted) ============= 2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll 2012-11-16 15:09 - 2012-11-16 15:09 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= Name: PS/2-kompatible Maus Description: PS/2-kompatible Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Unknown Device Description: Unknown Device Class Guid: {36fc9e60-c465-11cf-8056-444553540000} Manufacturer: (Standard-USB-Hostcontroller) Service: Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Event log errors: ========================= Application errors: ================== Error: (11/13/2013 11:09:26 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 10:20:06 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 10:06:20 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 08:14:23 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/12/2013 09:32:17 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 12.0.6680.5000, Zeitstempel: 0x51c3d112 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc000041d Fehleroffset: 0x77ac11f1 ID des fehlerhaften Prozesses: 0x1a9c Startzeit der fehlerhaften Anwendung: 0xOUTLOOK.EXE0 Pfad der fehlerhaften Anwendung: OUTLOOK.EXE1 Pfad des fehlerhaften Moduls: OUTLOOK.EXE2 Berichtskennung: OUTLOOK.EXE3 Error: (11/12/2013 07:03:46 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/12/2013 09:20:48 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/11/2013 09:14:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/11/2013 09:37:31 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/10/2013 07:16:31 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (11/13/2013 11:07:57 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Hotspot Shield Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/13/2013 10:18:41 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Hotspot Shield Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/13/2013 10:05:04 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Hotspot Shield Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/13/2013 09:36:09 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (11/13/2013 08:12:56 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Hotspot Shield Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/12/2013 07:02:21 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Hotspot Shield Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/12/2013 09:19:21 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Hotspot Shield Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/11/2013 10:19:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst Gruppenrichtlinienclient konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (11/11/2013 10:18:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (11/11/2013 09:20:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1070 Microsoft Office Sessions: ========================= Error: (02/28/2013 06:48:56 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 181 seconds with 180 seconds of active time. This session ended with a crash. Error: (02/27/2013 09:57:15 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1212 seconds with 180 seconds of active time. This session ended with a crash. Error: (02/27/2013 09:22:52 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 155 seconds with 60 seconds of active time. This session ended with a crash. Error: (01/02/2013 11:02:26 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error: (12/25/2012 01:04:09 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2013-11-13 11:53:35.216 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-13 11:37:27.840 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-13 09:58:17.413 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-13 09:26:29.264 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-13 08:40:44.895 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-13 08:32:20.782 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-12 21:36:34.304 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-12 21:12:26.567 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-12 20:51:41.133 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-12 16:26:47.001 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 30% Total physical RAM: 8175.34 MB Available physical RAM: 5692.65 MB Total Pagefile: 16348.86 MB Available Pagefile: 13512.82 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:99.9 GB) (Free:31.35 GB) NTFS Drive d: () (Fixed) (Total:1297.26 GB) (Free:1117.98 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================
__________________ |
14.11.2013, 08:52 | #4 |
/// the machine /// TB-Ausbilder | Nach SUMo Softwareupdater Funde hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.11.2013, 11:31 | #5 |
| Nach SUMo Softwareupdater Funde Hallo schrauber hier das Combofix Log. Es hat etwas gedauert. Ich habe es aber aus dem "Download Ordner" gestartet, hoffe das ist jetzt nicht so schlimm... Code:
ATTFilter ComboFix 13-11-12.01 - Name 14.11.2013 9:31.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8175.5991 [GMT 1:00] ausgeführt von:: c:\users\MaTo\Downloads\ComboFix.exe AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\MaTo\AppData\Local\assembly\tmp c:\windows\SysWow64\FlashPlayerApp.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-10-14 bis 2013-11-14 )))))))))))))))))))))))))))))) . . 2013-11-14 08:47 . 2013-11-14 08:47 -------- d-----w- c:\users\Markus\AppData\Local\temp 2013-11-14 08:47 . 2013-11-14 08:47 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-11-14 08:33 . 2013-11-14 08:33 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2FE5CE26-3B48-4E2B-9CCE-DD062255ED40}\offreg.dll 2013-11-13 10:55 . 2013-11-13 10:55 -------- d-----w- C:\FRST 2013-11-13 09:08 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll 2013-11-13 09:08 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll 2013-11-13 08:37 . 2013-11-13 08:37 -------- d-----w- c:\users\Markus\.android 2013-11-13 08:37 . 2013-11-13 08:37 -------- d-----w- c:\users\Markus\AppData\Local\cache 2013-11-13 08:37 . 2013-11-13 10:13 -------- d-----w- c:\users\Markus\AppData\Local\Mobogenie 2013-11-13 08:36 . 2013-11-13 10:12 -------- d-----w- c:\program files (x86)\IminentToolbar 2013-11-13 08:36 . 2013-11-13 08:36 -------- d-----w- c:\users\MaTo\AppData\Roaming\Iminent 2013-11-13 08:33 . 2013-11-13 08:33 -------- d-----w- c:\users\MaTo\AppData\Roaming\KC Softwares 2013-11-12 10:34 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2FE5CE26-3B48-4E2B-9CCE-DD062255ED40}\mpengine.dll 2013-11-05 11:14 . 2013-11-05 11:14 97880 ----a-w- c:\program files (x86)\Internet Explorer\pdmproxy100.dll 2013-11-05 11:14 . 2013-11-05 11:14 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-05 11:14 . 2013-11-05 11:14 542272 ----a-w- c:\program files\Internet Explorer\pdm.dll 2013-11-05 11:14 . 2013-11-05 11:14 410680 ----a-w- c:\program files (x86)\Internet Explorer\pdm.dll 2013-11-05 11:14 . 2013-11-05 11:14 400968 ----a-w- c:\program files\Internet Explorer\msdbg2.dll 2013-11-05 11:14 . 2013-11-05 11:14 312392 ----a-w- c:\program files (x86)\Internet Explorer\msdbg2.dll 2013-11-05 11:14 . 2013-11-05 11:14 105568 ----a-w- c:\program files\Internet Explorer\pdmproxy100.dll 2013-11-01 15:09 . 2013-11-04 12:48 -------- d-----w- c:\users\MaTo\AppData\Local\Opera Software 2013-11-01 15:09 . 2013-11-04 12:48 -------- d-----w- c:\users\MaTo\AppData\Roaming\Opera Software 2013-10-31 08:36 . 2013-10-31 08:36 -------- d-----w- c:\program files (x86)\VS Revo Group 2013-10-30 19:15 . 2013-10-30 19:15 -------- d-----w- c:\program files (x86)\Opera x64 2013-10-29 21:36 . 2013-10-22 09:46 271984 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll 2013-10-27 11:22 . 2013-10-27 11:23 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-10-27 11:22 . 2013-10-27 11:23 -------- d-----w- c:\program files\iTunes 2013-10-27 11:22 . 2013-10-27 11:23 -------- d-----w- c:\program files (x86)\iTunes 2013-10-27 11:22 . 2013-10-27 11:22 -------- d-----w- c:\program files\iPod 2013-10-26 17:37 . 2013-10-26 17:37 -------- d-----w- c:\windows\SysWow64\Adobe 2013-10-25 14:41 . 2013-08-30 07:48 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-10-25 14:41 . 2013-08-30 07:48 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-10-25 14:13 . 2013-10-25 14:13 -------- d-----w- c:\users\Markus\AppData\Local\Mozilla 2013-10-23 08:18 . 2013-10-23 08:18 -------- d-----w- c:\users\Markus\AppData\Roaming\AVAST Software 2013-10-22 09:12 . 2013-10-22 09:27 -------- d-----w- C:\Office Manager DMS 2013-10-22 09:11 . 2013-10-22 09:11 -------- d-----w- c:\program files (x86)\Krekeler 2013-10-17 22:38 . 2013-10-17 22:38 -------- d-----w- c:\users\Markus\AppData\Roaming\Canneverbe Limited 2013-10-17 22:38 . 2013-10-17 22:38 -------- d-----w- c:\program files\CDBurnerXP 2013-10-16 11:20 . 2013-10-16 11:20 -------- d-----w- c:\users\MaTo\AppData\Roaming\AVAST Software . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-11-13 16:04 . 2013-01-01 14:18 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-11-13 09:00 . 2012-12-22 11:33 82896128 ----a-w- c:\windows\system32\MRT.exe 2013-10-14 17:00 . 2013-02-27 13:42 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2013-10-10 22:36 . 2013-10-10 22:36 50053120 ----a-w- c:\program files (x86)\GUT98D6.tmp 2013-10-09 12:39 . 2013-10-09 12:39 17813896 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-09-08 02:30 . 2013-10-09 07:19 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-09-08 02:27 . 2013-10-09 07:19 327168 ----a-w- c:\windows\system32\mswsock.dll 2013-09-08 02:03 . 2013-10-09 07:19 231424 ----a-w- c:\windows\SysWow64\mswsock.dll 2013-09-04 12:12 . 2013-10-09 07:19 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2013-09-04 12:11 . 2013-10-09 07:19 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2013-09-04 12:11 . 2013-10-09 07:19 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2013-09-04 12:11 . 2013-10-09 07:19 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys 2013-09-04 12:11 . 2013-10-09 07:19 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2013-09-04 12:11 . 2013-10-09 07:19 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2013-09-04 12:11 . 2013-10-09 07:19 7808 ----a-w- c:\windows\system32\drivers\usbd.sys 2013-09-03 12:35 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-08-29 02:17 . 2013-10-09 07:19 5549504 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-08-29 02:16 . 2013-10-09 07:19 1732032 ----a-w- c:\windows\system32\ntdll.dll 2013-08-29 02:16 . 2013-10-09 07:19 243712 ----a-w- c:\windows\system32\wow64.dll 2013-08-29 02:16 . 2013-10-09 07:19 859648 ----a-w- c:\windows\system32\tdh.dll 2013-08-29 02:13 . 2013-10-09 07:19 878080 ----a-w- c:\windows\system32\advapi32.dll 2013-08-29 01:51 . 2013-10-09 07:19 3969472 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-08-29 01:51 . 2013-10-09 07:19 3914176 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-08-29 01:50 . 2013-10-09 07:19 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-08-29 01:50 . 2013-10-09 07:19 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll 2013-08-29 01:50 . 2013-10-09 07:19 619520 ----a-w- c:\windows\SysWow64\tdh.dll 2013-08-29 01:48 . 2013-10-09 07:19 640512 ----a-w- c:\windows\SysWow64\advapi32.dll 2013-08-29 01:48 . 2013-10-09 07:19 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-08-29 00:49 . 2013-10-09 07:19 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-08-29 00:49 . 2013-10-09 07:19 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-08-29 00:49 . 2013-10-09 07:19 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-08-29 00:49 . 2013-10-09 07:19 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-08-28 01:21 . 2013-10-09 07:19 3155968 ----a-w- c:\windows\system32\win32k.sys 2013-08-28 01:12 . 2013-10-09 07:19 461312 ----a-w- c:\windows\system32\scavengeui.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-10-21 20549280] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "PaperPort PTD"="c:\program files (x86)\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984] "IndexSearch"="c:\program files (x86)\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368] "PPort11reminder"="c:\program files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992] "BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-08-03 1167360] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-12-13 135536] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-16 641704] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "CommonToolkitTray"="c:\program files (x86)\Fighters\Tray\FightersTray.exe" [2013-06-19 1497120] "sfagent"="c:\program files (x86)\Fighters\SPAMfighter\sfagent.exe" [2013-09-24 1063968] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-08-30 4858968] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-10-19 152392] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files (x86)\Microsoft Office-Front Page\Office10\OSA.EXE -b -l [2001-2-13 83360] TSPrintUser.lnk - c:\program files (x86)\TerminalWorks\TSPrint\TSPrintUser.exe [2013-1-3 7680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 hshld;Hotspot Shield Service;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe [x] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 cleanhlp;cleanhlp;c:\eek\RUN\cleanhlp64.sys;c:\eek\RUN\cleanhlp64.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x] R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x] R3 MHIKEY10;MHIKEY10;c:\windows\system32\Drivers\MHIKEY10x64.sys;c:\windows\SYSNATIVE\Drivers\MHIKEY10x64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdis.sys [x] S0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys;c:\windows\SYSNATIVE\drivers\aswNdis2.sys [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswFW;avast! TDI Firewall driver; [x] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys;c:\windows\SYSNATIVE\DRIVERS\hssdrv6.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x] S2 hmpalert;HitmanPro.Alert Support Driver;c:\windows\system32\drivers\hmpalert.sys;c:\windows\SYSNATIVE\drivers\hmpalert.sys [x] S2 hmpalertsvc;HitmanPro.Alert Service;c:\program files (x86)\HitmanPro.Alert\hmpalert.exe;c:\program files (x86)\HitmanPro.Alert\hmpalert.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files (x86)\Fighters\SPAMfighter\sfus.exe;c:\program files (x86)\Fighters\SPAMfighter\sfus.exe [x] S2 Suite Service;Suite Service;c:\program files (x86)\Fighters\FighterSuiteService.exe;c:\program files (x86)\Fighters\FighterSuiteService.exe [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-11-13 11:26 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.48\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\MaTo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\MaTo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\MaTo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\MaTo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-11-03 8317472] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com uDefault_Search_URL = hxxp://www.google.com mDefault_Search_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com mSearch Bar = hxxp://www.google.com IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\mk4bxm16.default\ FF - prefs.js: browser.startup.homepage - FF - prefs.js: browser.search.selectedEngine - FF - ExtSQL: 2013-10-25 16:40; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF FF - user.js: extensions.iminent.tlbrSrchUrl - hxxp://start.iminent.com/?ref=toolbarm#q= FF - user.js: extensions.iminent.id - d2309d9300000000000000215ac5691e FF - user.js: extensions.iminent.appId - {0E4B2CAB-B859-4C57-B96E-63DDEC692BC4} FF - user.js: extensions.iminent.instlDay - 16022 FF - user.js: extensions.iminent.vrsn - 1.8.26.8 FF - user.js: extensions.iminent.vrsni - 1.8.26.8 FF - user.js: extensions.iminent.vrsnTs - 1.8.26.89:36 FF - user.js: extensions.iminent.prtnrId - iminent FF - user.js: extensions.iminent.prdct - iminent FF - user.js: extensions.iminent.aflt - orgnl FF - user.js: extensions.iminent.smplGrp - none FF - user.js: extensions.iminent.tlbrId - base FF - user.js: extensions.iminent.instlRef - FF - user.js: extensions.iminent.dfltLng - FF - user.js: extensions.iminent.excTlbr - false FF - user.js: extensions.iminent.ffxUnstlRst - false FF - user.js: extensions.iminent.admin - false FF - user.js: extensions.iminent.autoRvrt - false FF - user.js: extensions.iminent.rvrt - false FF - user.js: extensions.iminent.newTab - false user_pref(extensions.poweraddon.cid,210); . - - - - Entfernte verwaiste Registrierungseinträge - - - - . ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) Wow6432Node-HKLM-Run-mobilegeni daemon - c:\program files (x86)\Mobogenie\DaemonProcess.exe SafeBoot-CleanHlp SafeBoot-CleanHlp.sys HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-11-14 10:23:20 ComboFix-quarantined-files.txt 2013-11-14 09:23 . Vor Suchlauf: 15 Verzeichnis(se), 31.315.038.208 Bytes frei Nach Suchlauf: 20 Verzeichnis(se), 31.030.136.832 Bytes frei . - - End Of File - - 4A1E5BF64D7C671ECC0BF8D7B8295D9A A36C5E4F47E84449FF07ED3517B43A31 Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.14.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Name :: xxxxxx [Administrator] 14.11.2013 11:19:34 MBAM-log-2013-11-14 (11-24-48).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 233902 Laufzeit: 3 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 4 HKCR\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892} (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKCR\AppID\PricePeep.DLL (PUP.Optional.PricePeep.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 3 C:\Users\MaTo\AppData\Roaming\Iminent\Mediator (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\MaTo\AppData\Roaming\Iminent\Mediator\Datas (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\IminentToolbar (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 2 C:\Users\MaTo\AppData\Roaming\Iminent\Mediator\Datas\globalcache.dat (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. C:\Users\MaTo\AppData\Roaming\Iminent\Mediator\Datas\user.dat (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. (Ende) Code:
ATTFilter # AdwCleaner v3.012 - Bericht erstellt am 14/11/2013 um 11:26:17 # Updated 11/11/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : xxxxxxxx # Gestartet von : C:\Users\MaTo\Downloads\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** Dienst Gefunden : hshld Dienst Gefunden : HssSrv ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Web Search.xml Datei Gefunden : C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage Datei Gefunden : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\mk4bxm16.default\searchplugins\iminent.xml Datei Gefunden : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\mk4bxm16.default\user.js Datei Gefunden : C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\toolbar@alexa.com.xpi Datei Gefunden : C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\searchplugins\Web Search.xml Ordner Gefunden C:\Program Files (x86)\hotspot shield Ordner Gefunden C:\Program Files (x86)\IminentToolbar Ordner Gefunden C:\Program Files (x86)\myfree codec Ordner Gefunden C:\ProgramData\hotspot shield Ordner Gefunden C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gefunden C:\Users\Markus\AppData\LocalLow\SimplyTech Ordner Gefunden C:\Users\MaTo\AppData\LocalLow\SimplyTech Ordner Gefunden C:\Users\MaTo\AppData\Roaming\Iminent ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\FoxyDeal Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Schlüssel Gefunden : HKCU\Software\Myfree Codec Schlüssel Gefunden : HKCU\Software\powerpack Schlüssel Gefunden : [x64] HKCU\Software\FoxyDeal Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : [x64] HKCU\Software\Myfree Codec Schlüssel Gefunden : [x64] HKCU\Software\powerpack Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\PricePeep.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{E69D4A59-73DE-4E38-9FB3-740EC4D9060D} Schlüssel Gefunden : HKLM\Software\Iminent Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gefunden : HKLM\Software\Myfree Codec Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052 Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar] - hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q= Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page] - hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q= Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052 Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052 Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar] - hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q= Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page] - hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q= Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)] - hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q=%s Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)] - hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q=%s -\\ Mozilla Firefox v24.1.0 (de) [ Datei : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\mk4bxm16.default\prefs.js ] [ Datei : C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\prefs.js ] Zeile gefunden : user_pref("wtb6787.homepage", "hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052"); Zeile gefunden : user_pref("wtb6787.newtab", "hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052"); -\\ Google Chrome v31.0.1650.48 [ Datei : C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1779 octets] - [20/08/2013 20:10:42] AdwCleaner[R1].txt - [3496 octets] - [02/09/2013 20:38:52] AdwCleaner[R2].txt - [3053 octets] - [02/09/2013 20:45:44] AdwCleaner[R3].txt - [1133 octets] - [07/09/2013 12:05:07] AdwCleaner[R4].txt - [17063 octets] - [13/11/2013 12:51:46] AdwCleaner[R5].txt - [16680 octets] - [14/11/2013 11:26:17] AdwCleaner[S0].txt - [2946 octets] - [02/09/2013 20:46:38] ########## EOF - \AdwCleaner\AdwCleaner[R5].txt - [16801 octets] ##########
__________________ Grüße blamato ------------ HP Workstation / Win 7 (64) / Avast I.S. |
15.11.2013, 09:44 | #6 |
/// the machine /// TB-Ausbilder | Nach SUMo Softwareupdater Funde MBAm und ADw auch löschen lassen, dann: Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Nach SUMo Softwareupdater Funde |
15.11.2013, 14:39 | #7 |
| Nach SUMo Softwareupdater Funde JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x64 Ran by xxxxx on 15.11.2013 at 11:35:03,17 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 15.11.2013 at 11:35:03,37 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=057f02338edadf409eaa8b6dd45b97d0 # engine=15895 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-15 11:23:17 # local_time=2013-11-15 12:23:17 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=772 16777213 83 94 1802559 161224469 0 0 # compatibility_mode=5893 16776573 100 94 8157 136144447 0 0 # scanned=69118 # found=0 # cleaned=0 # scan_time=2453 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=057f02338edadf409eaa8b6dd45b97d0 # engine=15895 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-15 12:56:49 # local_time=2013-11-15 01:56:49 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=772 16777213 83 94 1808171 161230081 0 0 # compatibility_mode=5893 16776573 100 94 13769 136150059 0 0 # scanned=408289 # found=0 # cleaned=0 # scan_time=5510 Code:
ATTFilter Results of screen317's Security Check version 0.99.76 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` avast! Internet Security Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 11.9.900.152 Adobe Reader XI Mozilla Firefox 24.1.0 Firefox out of Date! Mozilla Thunderbird (24.0.) Google Chrome 31.0.1650.48 Google Chrome 31.0.1650.57 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast afwServ.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-11-2013 Ran by MaTo (ATTENTION: The logged in user is not administrator) on HPXWPROLOG on 15-11-2013 14:36:14 Running from C:\Users\MaTo\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (SPAMfighter ApS) C:\Program Files (x86)\Fighters\Tray\FightersTray.exe (SPAMfighter ApS) C:\Program Files (x86)\Fighters\SPAMfighter\sfagent.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (SPAMfighter ApS) C:\Program Files (x86)\Fighters\SPAMfighter\x64\LiveKitLoader64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8317472 2009-11-03] (Realtek Semiconductor) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation) HKLM-x32\...\RunOnce: [InnoSetupRegFile.0000000001] - "C:\Windows\is-33PCB.exe" /REG /REGSVRMODE [1160576 2013-11-15] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKLM-x32\...\Run: [SSBkgdUpdate] - C:\Program Files (x86)\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [210472 2006-10-25] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PaperPort PTD] - C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PPort11reminder] - C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini [324 2012-12-29] () HKLM-x32\...\Run: [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1167360 2009-08-03] (Brother Industries, Ltd.) HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [CommonToolkitTray] - C:\Program Files (x86)\Fighters\Tray\FightersTray.exe [1497120 2013-06-19] (SPAMfighter ApS) HKLM-x32\...\Run: [sfagent] - C:\Program Files (x86)\Fighters\SPAMfighter\sfagent.exe [1063968 2013-09-24] (SPAMfighter ApS) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-19] (Apple Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB5DD7559F214CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - URL hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q={searchTerms} SearchScopes: HKLM-x32 - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=66920&gid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&dbCode=1&command={searchTerms} SearchScopes: HKLM-x32 - TopResultURLFallback hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1381313936107&tguid=66920-6787-1381313936107-6BEE54CEFC5B96EA24A53FEA5E138052&q={searchTerms} SearchScopes: HKCU - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=EA44267A-B92D-4D04-AD1E-F5E4A60ABB5B&ref=toolbox&q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 14\SPMIEToolbar64.dll (Steganos Software GmbH) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default FF NewTab: hxxp://www.google.de FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF NetworkProxy: "gopher", "" FF NetworkProxy: "gopher_port", 0 FF NetworkProxy: "share_proxy_settings", true FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Deutsches Wörterbuch, klassisch und reformiert - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\alterechtschreibung@gmail.com FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\de_DE@dicts.j3e.de FF Extension: Dr.Web Anti-Virus Link Checker - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5} FF Extension: jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc@jetpack.xpi FF Extension: PageRank - C:\Users\MaTo\AppData\Roaming\Mozilla\Firefox\Profiles\y7vyiho2.default\Extensions\PageRank@addonfactory.in.xpi FF Extension: adblocker - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 14\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 14\spmplugin3 FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-08-30] (AVAST Software) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1830768 2013-08-12] (SurfRight B.V.) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-11-04] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-11-04] (Secunia) R2 SPAMfighter Update Service; C:\Program Files (x86)\Fighters\SPAMfighter\sfus.exe [212000 2013-09-24] (SPAMfighter ApS) R2 Suite Service; C:\Program Files (x86)\Fighters\FighterSuiteService.exe [1281568 2013-05-29] (SPAMfighter ApS) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R1 aswFW; C:\Windows\System32\Drivers\aswFW.sys [131232 2013-08-30] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2013-07-17] (ALWIL Software) R0 aswNdis2; C:\Windows\System32\drivers\aswNdis2.sys [270824 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () S3 cleanhlp; C:\EEK\RUN\cleanhlp64.sys [57024 2013-08-21] (Emsisoft GmbH) R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [17416 2013-08-12] () R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-04-24] (AnchorFree Inc.) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) S3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-11-04] (Secunia) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-15 14:11 - 2013-11-15 14:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-15 14:11 - 2013-11-15 14:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-15 14:07 - 2013-11-15 14:07 - 01160576 _____ C:\Windows\is-33PCB.exe 2013-11-15 14:07 - 2013-11-15 14:07 - 00025213 _____ C:\Windows\is-33PCB.msg 2013-11-15 14:07 - 2013-11-15 14:07 - 00000258 _____ C:\Windows\is-33PCB.lst 2013-11-15 14:06 - 2013-11-15 14:06 - 00265752 _____ (Secure By Design Inc.) C:\Users\MaTo\Downloads\Ninite Chrome FileZilla Notepad WinSCP Installer.exe 2013-11-15 13:59 - 2013-11-15 13:59 - 00891184 _____ C:\Users\MaTo\Downloads\SecurityCheck.exe 2013-11-15 11:35 - 2013-11-15 11:35 - 00000626 _____ C:\Users\Markus\Desktop\JRT.txt 2013-11-15 11:30 - 2013-11-15 11:30 - 01034531 _____ (Thisisu) C:\Users\MaTo\Downloads\JRT.exe 2013-11-14 10:24 - 2013-11-14 10:24 - 00024341 _____ C:\ComboFix.txt 2013-11-14 09:30 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-11-14 09:25 - 2013-11-14 10:13 - 00000000 ____D C:\Windows\erdnt 2013-11-13 12:26 - 2013-11-15 10:53 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-13 12:24 - 2013-11-13 12:24 - 00265752 _____ (Secure By Design Inc.) C:\Users\MaTo\Downloads\Ninite Chrome Installer.exe 2013-11-13 11:56 - 2013-11-13 11:56 - 00023006 _____ C:\Users\MaTo\Downloads\Addition.txt 2013-11-13 11:55 - 2013-11-15 14:36 - 00015813 _____ C:\Users\MaTo\Downloads\FRST.txt 2013-11-13 11:55 - 2013-11-13 11:55 - 00000000 ____D C:\FRST 2013-11-13 11:54 - 2013-11-13 11:54 - 01957610 _____ (Farbar) C:\Users\MaTo\Downloads\FRST64.exe 2013-11-13 10:19 - 2013-11-13 11:12 - 00001725 _____ C:\Users\MaTo\daemonprocess.txt 2013-11-13 10:09 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-11-13 10:09 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-11-13 10:09 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-11-13 10:09 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-11-13 10:09 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-11-13 10:09 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-11-13 10:09 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-11-13 10:09 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2013-11-13 10:09 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-11-13 10:09 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-11-13 10:09 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-11-13 10:09 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-11-13 10:09 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-11-13 10:09 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-11-13 10:09 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2013-11-13 10:09 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-11-13 10:09 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-11-13 10:09 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-11-13 10:08 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2013-11-13 10:08 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2013-11-13 09:37 - 2013-11-13 11:13 - 00000000 ____D C:\Users\Markus\AppData\Local\Mobogenie 2013-11-13 09:37 - 2013-11-13 10:03 - 00001380 _____ C:\Users\Markus\daemonprocess.txt 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\Documents\Mobogenie 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\AppData\Local\cache 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\.android 2013-11-13 09:36 - 2013-11-13 11:15 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-11-13 09:33 - 2013-11-13 09:33 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\KC Softwares 2013-11-13 08:19 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 08:19 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 08:19 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 08:19 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 08:19 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 08:19 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 08:19 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 08:19 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 08:19 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 08:19 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 08:19 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 08:19 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 08:19 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 08:19 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 08:19 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 08:19 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 08:19 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 08:19 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 08:19 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 08:19 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 08:19 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 08:19 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 08:19 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 08:19 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 08:19 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 08:19 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 08:19 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 08:19 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 08:19 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 08:19 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-12 21:36 - 2013-11-12 21:36 - 00000252 _____ C:\Users\MaTo\Desktop\VIRUS.txt 2013-11-09 12:52 - 2013-11-09 12:52 - 00591910 _____ C:\Users\MaTo\Downloads\MicrosoftFixIt.zip 2013-11-07 22:52 - 2013-11-15 11:12 - 00007300 _____ C:\Windows\PFRO.log 2013-11-07 20:31 - 2013-11-07 20:31 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-07 20:30 - 2013-11-07 20:33 - 00008372 _____ C:\Windows\IE11_main.log 2013-11-07 14:51 - 2013-11-15 14:29 - 00001456 _____ C:\Windows\setupact.log 2013-11-07 14:51 - 2013-11-07 14:51 - 00000000 _____ C:\Windows\setuperr.log 2013-11-07 14:48 - 2013-11-07 14:48 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51005.msi 2013-11-07 14:46 - 2013-11-07 14:46 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51004.msi 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-04 13:43 - 2013-11-04 13:43 - 02434048 _____ C:\Users\Markus\Downloads\msxml.msi 2013-11-04 13:42 - 2013-11-04 13:42 - 00018456 _____ (Secunia) C:\Windows\system32\Drivers\psi_mf_amd64.sys 2013-11-01 16:09 - 2013-11-04 13:48 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Opera Software 2013-11-01 16:09 - 2013-11-04 13:48 - 00000000 ____D C:\Users\MaTo\AppData\Local\Opera Software 2013-11-01 15:51 - 2013-11-01 15:51 - 00985600 _____ C:\Users\Markus\Downloads\MicrosoftFixit50123.msi 2013-11-01 14:30 - 2013-11-01 14:30 - 00003140 _____ C:\Users\Markus\Documents\cc_20131101_143039.reg 2013-10-31 09:36 - 2013-10-31 09:36 - 00001264 _____ C:\Users\Markus\Desktop\Revo Uninstaller.lnk 2013-10-31 09:36 - 2013-10-31 09:36 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-10-31 09:06 - 2013-10-31 09:06 - 13079688 _____ (Microsoft Corporation) C:\Users\MaTo\Downloads\Silverlight_x64.exe 2013-10-30 20:15 - 2013-10-30 20:15 - 00000000 ____D C:\Program Files (x86)\Opera x64 2013-10-27 12:22 - 2013-10-27 12:23 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-10-27 12:22 - 2013-10-27 12:23 - 00000000 ____D C:\Program Files\iTunes 2013-10-27 12:22 - 2013-10-27 12:23 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-10-27 12:22 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files\iPod 2013-10-26 18:37 - 2013-10-26 18:37 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-10-25 15:41 - 2013-11-10 16:22 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-10-25 15:41 - 2013-08-30 08:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-10-25 15:41 - 2013-08-30 08:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-25 15:40 - 2013-10-25 15:40 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-25 15:40 - 2013-08-30 08:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00270824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdis2.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-25 15:40 - 2013-08-30 08:48 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2013-10-25 15:40 - 2013-08-30 08:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-25 15:40 - 2013-08-30 08:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-25 15:40 - 2013-07-17 10:17 - 00012368 _____ (ALWIL Software) C:\Windows\system32\Drivers\aswNdis.sys 2013-10-25 15:26 - 2013-10-25 15:26 - 00000035 _____ C:\Windows\avast5.ini 2013-10-25 15:18 - 2013-10-23 08:44 - 161978728 _____ C:\Users\Markus\Downloads\avast_internet_security_setup_801497.exe 2013-10-25 15:17 - 2013-11-15 14:33 - 00859674 _____ C:\Windows\WindowsUpdate.log 2013-10-25 15:17 - 2013-10-25 15:17 - 00000034 _____ C:\Windows\AvastEmUpdate.ini 2013-10-25 15:13 - 2013-10-25 15:13 - 00000000 ____D C:\Users\Markus\AppData\Local\Mozilla 2013-10-24 22:16 - 2013-10-24 22:16 - 00000160 _____ C:\Users\MaTo\Desktop\XHamster.txt 2013-10-24 22:15 - 2013-10-24 22:15 - 00001409 _____ C:\Users\MaTo\Desktop\Internet Explorer.lnk 2013-10-23 09:30 - 2013-10-23 09:33 - 121680752 _____ (AVAST Software) C:\Users\Markus\Downloads\avast_internet_security_setup.exe 2013-10-23 09:18 - 2013-10-23 09:18 - 00000000 ____D C:\Users\Markus\AppData\Roaming\AVAST Software 2013-10-23 08:33 - 2013-11-14 12:40 - 00000000 ____D C:\Users\MaTo\Downloads\AVAST 2013-10-23 08:32 - 2013-11-14 12:57 - 00000879 _____ C:\Users\MaTo\Desktop\AVAST.txt 2013-10-22 10:48 - 2013-10-22 10:53 - 185167736 _____ (DATA BECKER ) C:\Users\MaTo\Downloads\graphicworks10_r1.exe 2013-10-22 10:12 - 2013-10-22 10:27 - 00000000 ____D C:\Office Manager DMS 2013-10-22 10:11 - 2013-10-22 10:11 - 00000000 ____D C:\Program Files (x86)\Krekeler 2013-10-22 08:56 - 2013-10-22 08:56 - 00001705 _____ C:\Users\MaTo\Downloads\license.avastlic 2013-10-20 20:39 - 2013-10-20 20:39 - 05831344 _____ (TeamViewer GmbH) C:\Users\MaTo\Downloads\TeamViewer_Setup_de.exe 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Canneverbe Limited 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Program Files\CDBurnerXP 2013-10-16 12:20 - 2013-10-16 12:20 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\AVAST Software 2013-10-16 12:17 - 2013-10-23 09:39 - 00002032 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk ==================== One Month Modified Files and Folders ======= 2013-11-15 14:36 - 2013-11-13 11:55 - 00015813 _____ C:\Users\MaTo\Downloads\FRST.txt 2013-11-15 14:36 - 2013-10-25 15:17 - 00859674 _____ C:\Windows\WindowsUpdate.log 2013-11-15 14:34 - 2013-11-14 09:25 - 00000000 ____D C:\Windows\erdnt 2013-11-15 14:31 - 2012-12-22 18:43 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Skype 2013-11-15 14:29 - 2013-11-07 14:51 - 00001456 _____ C:\Windows\setupact.log 2013-11-15 14:29 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-15 14:23 - 2013-07-13 20:38 - 00502272 ___SH C:\Users\MaTo\Downloads\Thumbs.db 2013-11-15 14:22 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-15 14:22 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-15 14:14 - 2013-11-15 14:11 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-15 14:14 - 2012-12-22 14:30 - 00000000 ____D C:\Program Files (x86)\WinSCP 2013-11-15 14:11 - 2013-11-15 14:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-15 14:11 - 2013-01-01 15:18 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-15 14:07 - 2013-11-15 14:07 - 01160576 _____ C:\Windows\is-33PCB.exe 2013-11-15 14:07 - 2013-11-15 14:07 - 00025213 _____ C:\Windows\is-33PCB.msg 2013-11-15 14:07 - 2013-11-15 14:07 - 00000258 _____ C:\Windows\is-33PCB.lst 2013-11-15 14:06 - 2013-11-15 14:06 - 00265752 _____ (Secure By Design Inc.) C:\Users\MaTo\Downloads\Ninite Chrome FileZilla Notepad WinSCP Installer.exe 2013-11-15 14:06 - 2012-12-22 14:30 - 00000979 _____ C:\Users\Public\Desktop\WinSCP.lnk 2013-11-15 13:59 - 2013-11-15 13:59 - 00891184 _____ C:\Users\MaTo\Downloads\SecurityCheck.exe 2013-11-15 11:35 - 2013-11-15 11:35 - 00000626 _____ C:\Users\Markus\Desktop\JRT.txt 2013-11-15 11:30 - 2013-11-15 11:30 - 01034531 _____ (Thisisu) C:\Users\MaTo\Downloads\JRT.exe 2013-11-15 11:18 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-11-15 11:12 - 2013-11-07 22:52 - 00007300 _____ C:\Windows\PFRO.log 2013-11-15 10:53 - 2013-11-13 12:26 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-14 16:39 - 2013-01-22 20:51 - 00001456 _____ C:\Users\MaTo\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2013-11-14 12:57 - 2013-10-23 08:32 - 00000879 _____ C:\Users\MaTo\Desktop\AVAST.txt 2013-11-14 12:40 - 2013-10-23 08:33 - 00000000 ____D C:\Users\MaTo\Downloads\AVAST 2013-11-14 10:24 - 2013-11-14 10:24 - 00024341 _____ C:\ComboFix.txt 2013-11-14 09:48 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-11-13 19:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-13 17:05 - 2012-12-23 09:08 - 00000000 ____D C:\Users\Markus\AppData\Local\Adobe 2013-11-13 15:43 - 2013-01-01 15:42 - 00000000 ____D C:\ProgramData\SecTaskMan 2013-11-13 12:24 - 2013-11-13 12:24 - 00265752 _____ (Secure By Design Inc.) C:\Users\MaTo\Downloads\Ninite Chrome Installer.exe 2013-11-13 11:56 - 2013-11-13 11:56 - 00023006 _____ C:\Users\MaTo\Downloads\Addition.txt 2013-11-13 11:55 - 2013-11-13 11:55 - 00000000 ____D C:\FRST 2013-11-13 11:54 - 2013-11-13 11:54 - 01957610 _____ (Farbar) C:\Users\MaTo\Downloads\FRST64.exe 2013-11-13 11:41 - 2013-03-21 11:18 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\FileZilla 2013-11-13 11:15 - 2013-11-13 09:36 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-11-13 11:13 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\AppData\Local\Mobogenie 2013-11-13 11:12 - 2013-11-13 10:19 - 00001725 _____ C:\Users\MaTo\daemonprocess.txt 2013-11-13 10:19 - 2012-12-22 13:45 - 00000000 ____D C:\Users\MaTo 2013-11-13 10:03 - 2013-11-13 09:37 - 00001380 _____ C:\Users\Markus\daemonprocess.txt 2013-11-13 10:02 - 2013-07-15 09:06 - 00000000 ____D C:\Windows\system32\MRT 2013-11-13 10:02 - 2012-12-22 14:22 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-13 10:00 - 2012-12-22 12:33 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\Documents\Mobogenie 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\AppData\Local\cache 2013-11-13 09:37 - 2013-11-13 09:37 - 00000000 ____D C:\Users\Markus\.android 2013-11-13 09:37 - 2012-12-22 11:50 - 00000000 ____D C:\Users\Markus 2013-11-13 09:33 - 2013-11-13 09:33 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\KC Softwares 2013-11-12 21:36 - 2013-11-12 21:36 - 00000252 _____ C:\Users\MaTo\Desktop\VIRUS.txt 2013-11-12 19:06 - 2010-11-21 07:50 - 00660680 _____ C:\Windows\system32\perfh007.dat 2013-11-12 19:06 - 2010-11-21 07:50 - 00132704 _____ C:\Windows\system32\perfc007.dat 2013-11-12 19:06 - 2009-07-14 06:13 - 01516816 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-10 16:24 - 2012-12-23 09:08 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Skype 2013-11-10 16:23 - 2012-12-22 11:50 - 00001421 _____ C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-10 16:22 - 2013-10-25 15:41 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-11-10 16:22 - 2012-12-22 12:28 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-11-10 16:20 - 2013-06-29 22:02 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\streamripper 2013-11-10 16:20 - 2012-12-28 15:10 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Winamp 2013-11-10 16:20 - 2010-11-21 08:00 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-11-10 16:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-11-10 16:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat 2013-11-09 12:52 - 2013-11-09 12:52 - 00591910 _____ C:\Users\MaTo\Downloads\MicrosoftFixIt.zip 2013-11-07 20:37 - 2012-12-22 11:33 - 00000000 ____D C:\Windows\Panther 2013-11-07 20:33 - 2013-11-07 20:30 - 00008372 _____ C:\Windows\IE11_main.log 2013-11-07 20:31 - 2013-11-07 20:31 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-07 20:31 - 2013-11-07 20:31 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-07 20:31 - 2013-11-07 20:31 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-07 20:31 - 2013-11-07 20:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-07 20:31 - 2013-11-07 20:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-07 20:31 - 2013-11-07 20:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-07 20:31 - 2013-11-07 20:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-07 14:51 - 2013-11-07 14:51 - 00000000 _____ C:\Windows\setuperr.log 2013-11-07 14:48 - 2013-11-07 14:48 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51005.msi 2013-11-07 14:46 - 2013-11-07 14:46 - 01056768 _____ C:\Users\MaTo\Downloads\MicrosoftFixit51004.msi 2013-11-07 08:41 - 2013-02-26 19:42 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-11-07 08:41 - 2013-02-26 19:42 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 16:47 - 2012-12-24 11:58 - 00002258 ____H C:\Users\MaTo\Documents\Default.rdp 2013-11-06 09:04 - 2012-12-22 18:43 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-06 09:04 - 2012-12-22 18:43 - 00000000 ____D C:\ProgramData\Skype 2013-11-05 22:06 - 2013-05-27 11:58 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Steganos 2013-11-05 21:34 - 2012-12-22 17:41 - 00000600 _____ C:\Users\MaTo\AppData\Roaming\winscp.rnd 2013-11-05 13:12 - 2012-12-22 13:45 - 00001421 _____ C:\Users\MaTo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-05 12:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-05 12:14 - 2013-11-05 12:14 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-04 13:48 - 2013-11-01 16:09 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Opera Software 2013-11-04 13:48 - 2013-11-01 16:09 - 00000000 ____D C:\Users\MaTo\AppData\Local\Opera Software 2013-11-04 13:43 - 2013-11-04 13:43 - 02434048 _____ C:\Users\Markus\Downloads\msxml.msi 2013-11-04 13:42 - 2013-11-04 13:42 - 00018456 _____ (Secunia) C:\Windows\system32\Drivers\psi_mf_amd64.sys 2013-11-01 15:51 - 2013-11-01 15:51 - 00985600 _____ C:\Users\Markus\Downloads\MicrosoftFixit50123.msi 2013-11-01 14:30 - 2013-11-01 14:30 - 00003140 _____ C:\Users\Markus\Documents\cc_20131101_143039.reg 2013-10-31 09:36 - 2013-10-31 09:36 - 00001264 _____ C:\Users\Markus\Desktop\Revo Uninstaller.lnk 2013-10-31 09:36 - 2013-10-31 09:36 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-10-31 09:18 - 2013-10-10 22:05 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-31 09:18 - 2012-12-22 17:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-31 09:06 - 2013-10-31 09:06 - 13079688 _____ (Microsoft Corporation) C:\Users\MaTo\Downloads\Silverlight_x64.exe 2013-10-30 20:23 - 2012-12-23 11:58 - 00000000 ____D C:\Users\MaTo\AppData\Local\Opera 2013-10-30 20:22 - 2012-12-23 11:58 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Opera 2013-10-30 20:15 - 2013-10-30 20:15 - 00000000 ____D C:\Program Files (x86)\Opera x64 2013-10-30 08:02 - 2013-03-09 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-29 22:36 - 2013-03-10 16:40 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-10-29 22:36 - 2013-03-10 16:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-27 12:23 - 2013-10-27 12:22 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-10-27 12:23 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files\iTunes 2013-10-27 12:23 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-10-27 12:22 - 2013-10-27 12:22 - 00000000 ____D C:\Program Files\iPod 2013-10-27 12:22 - 2013-03-22 23:01 - 00000000 ____D C:\ProgramData\Apple Computer 2013-10-26 18:37 - 2013-10-26 18:37 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-10-25 15:40 - 2013-10-25 15:40 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-25 15:40 - 2012-12-22 12:27 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-25 15:26 - 2013-10-25 15:26 - 00000035 _____ C:\Windows\avast5.ini 2013-10-25 15:17 - 2013-10-25 15:17 - 00000034 _____ C:\Windows\AvastEmUpdate.ini 2013-10-25 15:13 - 2013-10-25 15:13 - 00000000 ____D C:\Users\Markus\AppData\Local\Mozilla 2013-10-25 15:13 - 2013-03-13 14:35 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Mozilla 2013-10-24 22:16 - 2013-10-24 22:16 - 00000160 _____ C:\Users\MaTo\Desktop\XHamster.txt 2013-10-24 22:15 - 2013-10-24 22:15 - 00001409 _____ C:\Users\MaTo\Desktop\Internet Explorer.lnk 2013-10-23 09:39 - 2013-10-16 12:17 - 00002032 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk 2013-10-23 09:33 - 2013-10-23 09:30 - 121680752 _____ (AVAST Software) C:\Users\Markus\Downloads\avast_internet_security_setup.exe 2013-10-23 09:21 - 2012-12-22 11:50 - 00000000 ___RD C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-23 09:21 - 2012-12-22 11:50 - 00000000 ___RD C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-23 09:18 - 2013-10-23 09:18 - 00000000 ____D C:\Users\Markus\AppData\Roaming\AVAST Software 2013-10-23 08:44 - 2013-10-25 15:18 - 161978728 _____ C:\Users\Markus\Downloads\avast_internet_security_setup_801497.exe 2013-10-22 10:53 - 2013-10-22 10:48 - 185167736 _____ (DATA BECKER ) C:\Users\MaTo\Downloads\graphicworks10_r1.exe 2013-10-22 10:27 - 2013-10-22 10:12 - 00000000 ____D C:\Office Manager DMS 2013-10-22 10:11 - 2013-10-22 10:11 - 00000000 ____D C:\Program Files (x86)\Krekeler 2013-10-22 08:56 - 2013-10-22 08:56 - 00001705 _____ C:\Users\MaTo\Downloads\license.avastlic 2013-10-20 20:39 - 2013-10-20 20:39 - 05831344 _____ (TeamViewer GmbH) C:\Users\MaTo\Downloads\TeamViewer_Setup_de.exe 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Canneverbe Limited 2013-10-17 23:38 - 2013-10-17 23:38 - 00000000 ____D C:\Program Files\CDBurnerXP 2013-10-17 23:38 - 2013-01-18 23:11 - 00001742 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2013-10-17 22:56 - 2013-09-30 09:24 - 00000000 ____D C:\Users\MaTo\Downloads\Briefvorlagen 2013-10-17 13:20 - 2013-01-14 16:05 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\Dropbox 2013-10-16 12:20 - 2013-10-16 12:20 - 00000000 ____D C:\Users\MaTo\AppData\Roaming\AVAST Software Some content of TEMP: ==================== C:\Users\Markus\AppData\Local\Temp\npp.6.5.1.Installer.exe C:\Users\Markus\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ --- --- --- Ich würde sagen keine Probs mehr keine Anzeichen mehr für PUP und Adware. Sagst du das auch?
__________________ Grüße blamato ------------ HP Workstation / Win 7 (64) / Avast I.S. |
16.11.2013, 12:04 | #8 |
/// the machine /// TB-Ausbilder | Nach SUMo Softwareupdater Funde Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.11.2013, 13:41 | #9 |
| Nach SUMo Softwareupdater Funde VIELEN DANK @schrauber hast mir echt geholfen! Ja ich habe die Schritte ausgeführt. Meine Updates sind immer auf Automatisch und ich nutze Avast wegen der Sandbox so hatte ich seit dem nie mehr Probleme mit DivebyViren. Mein Prob war nur das Programm SUMo was ich bei Chip geladen haben...dort wurden dann zusätzliche Programme sogar mit Adware geladen. Warum Chip so einen Mist empfiehlt ist mir unklar. Aber dieser Fall ist Dank Dir zu meiner vollen Zufriedenheit beendet....DANKE nochmal!
__________________ Grüße blamato ------------ HP Workstation / Win 7 (64) / Avast I.S. |
17.11.2013, 06:50 | #10 |
/// the machine /// TB-Ausbilder | Nach SUMo Softwareupdater Funde Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Nach SUMo Softwareupdater Funde |
administrator, adware.agent, anti-malware, appdata, autostart, bootstrapper, explorer, install, install.exe, komische, microsoft, mozilla, pup.optional.iminent, pup.optional.iminent.a, pup.optional.pricepeep.a, pup.optional.umbrella.a, roaming, service, services, temp, uninstall.exe, version |