|
Plagegeister aller Art und deren Bekämpfung: yourfile downloaderWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.04.2014, 02:54 | #1 |
| yourfile downloader Hi Leute kann das Programm Yourfile Downloader nicht entfernen.Desweiteren hat Avira folgende Funde angezeigt.ADWARE/Adware.Gen7 und ADWARE/AgentCV.A.2919 Malewarebyts hat nix gefunden, wobei ich mir nicht sicher bin ob das Programm noch aktuell ist.Hab mir dann unhackme 7 runtergeladen der hat auch was gefunden,finde aber keine Logdatei. Hoffe ihr könnt mir mal wieder helfen. Desweiteren ist jetzt websearches meine Suchmaschine und irgend so ein Geschwindigkeitstest läuft hier auf dem Desktop.Allerdings nur wenn ich mich auf meinem Adminkonto (A) anmelde. Auf dem anderen Konto (B) fällt mir nix auf.Habe die oben genannten Schritte nur auf Konto B ausgeführt.Auf Konto A habe ich noch Garnichts gemacht.Nach dem Windows wird gestartet steht da kurz:RegRun Partizan - Bootwatch AntiRootkit. Greatis Software . Gruss Meister G. Geändert von Meister G. (26.04.2014 um 03:29 Uhr) |
26.04.2014, 06:51 | #2 |
/// the machine /// TB-Ausbilder | yourfile downloader hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
26.04.2014, 09:52 | #3 |
| yourfile downloader Ist das egal über welches Konto ich die Programme ausführe?
__________________Code:
ATTFilter can result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 01 Ran by Michael (ATTENTION: The logged in user is not administrator) on MICHAEL-PC on 26-04-2014 10:43:15 Running from C:\Users\Michael\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe () C:\Windows\SysWOW64\C2MP\UpdateChecker.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\splwow64.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_13_0_0_182_ActiveX.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-01-12] (Google Inc.) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SecureBanking] => C:\Program Files (x86)\Secure Banking\SecureBanking.exe HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\MountPoints2: D - D:\AutoRun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF0375161D297CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited) BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Michael\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [994360 2011-10-14] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [399416 2011-10-14] (Secunia) S2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe -service [X] ==================== Drivers (Whitelisted) ==================== S3 athrusb; C:\Windows\System32\DRIVERS\athrxusb.sys [1075712 2008-07-29] (Atheros Communications, Inc.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-04-06] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32000 2013-05-04] () R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-04-06] () U0 Partizan; C:\Windows\SysWOW64\drivers\Partizan.sys [35816 2014-04-26] (Greatis Software) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-26 10:43 - 2014-04-26 10:43 - 00013466 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-04-26 10:41 - 2014-04-26 10:43 - 00000000 ____D () C:\FRST 2014-04-26 10:40 - 2014-04-26 10:41 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe 2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2 2014-04-26 03:30 - 2014-04-26 03:30 - 00001025 _____ () C:\Users\Michael\Desktop\Register UnHackMe.lnk 2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe 2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI 2014-04-26 03:22 - 2014-04-26 03:26 - 00000000 ____D () C:\Users\Public\Documents\regruninfo 2014-04-26 03:22 - 2014-04-26 03:24 - 00000000 ____D () C:\Program Files (x86)\UnHackMe 2014-04-26 03:22 - 2014-04-26 03:22 - 00035816 _____ (Greatis Software) C:\Windows\SysWOW64\Drivers\Partizan.sys 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe 2014-04-26 03:22 - 2014-03-28 13:01 - 00012800 _____ (Greatis Software, LLC.) C:\Windows\SysWOW64\Drivers\UnHackMeDrv.sys 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache 2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender 2014-04-26 02:56 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\WPM 2014-04-26 02:56 - 2014-04-26 02:56 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader 2014-04-26 02:52 - 2014-04-26 02:53 - 06326720 _____ (hxxp://yourfiledownloader.com) C:\Users\Michael\Downloads\YourFile_downloader.exe 2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403} 2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154} 2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111} 2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930} 2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725} 2014-04-23 09:04 - 2014-04-23 09:05 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C} 2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC} 2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6} 2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3} 2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A} 2014-04-20 09:37 - 2014-04-20 09:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352} 2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3} 2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2} 2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028} 2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188} 2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B} 2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102 2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip 2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip 2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F} 2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C} 2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8} 2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075} 2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe 2014-04-11 22:32 - 2014-04-11 22:35 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe 2014-04-10 16:41 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 16:41 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 16:41 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 16:41 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611} 2014-04-10 16:38 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 16:38 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 16:38 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 16:38 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 16:38 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 16:38 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 16:38 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 16:38 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 16:38 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 16:38 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 16:38 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 16:38 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 16:38 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0} 2014-04-07 17:28 - 2014-04-07 17:29 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8} 2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24} 2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC} 2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14} 2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01} 2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C} 2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B} 2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\Windows\SysWOW64\C2MP 2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack 2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe 2014-03-30 18:33 - 2014-04-09 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\Program Files (x86)\Haali 2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip 2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859} 2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862} 2014-03-28 18:24 - 2014-03-28 18:24 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52E18A02-578D-4E68-B51A-2E678315822A} 2014-03-27 19:03 - 2014-03-27 19:03 - 00000000 ____D () C:\Users\Michael\AppData\Local\{72D89DAE-C80B-4812-886D-3B7DBF94847F} ==================== One Month Modified Files and Folders ======= 2014-04-26 10:43 - 2014-04-26 10:43 - 00013466 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-04-26 10:43 - 2014-04-26 10:41 - 00000000 ____D () C:\FRST 2014-04-26 10:42 - 2012-01-03 22:43 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-26 10:42 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-26 10:42 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-26 10:41 - 2014-04-26 10:40 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe 2014-04-26 10:38 - 2011-10-31 15:07 - 01224592 _____ () C:\Windows\WindowsUpdate.log 2014-04-26 10:37 - 2012-01-03 22:43 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-26 10:34 - 2012-03-06 21:39 - 00103996 _____ () C:\Windows\setupact.log 2014-04-26 10:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-26 07:13 - 2012-12-31 20:08 - 00000936 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000UA.job 2014-04-26 06:30 - 2013-12-10 21:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-26 04:08 - 2012-04-03 21:23 - 00178328 _____ () C:\Windows\PFRO.log 2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2 2014-04-26 03:30 - 2014-04-26 03:30 - 00001025 _____ () C:\Users\Michael\Desktop\Register UnHackMe.lnk 2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe 2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI 2014-04-26 03:26 - 2014-04-26 03:22 - 00000000 ____D () C:\Users\Public\Documents\regruninfo 2014-04-26 03:24 - 2014-04-26 03:22 - 00000000 ____D () C:\Program Files (x86)\UnHackMe 2014-04-26 03:22 - 2014-04-26 03:22 - 00035816 _____ (Greatis Software) C:\Windows\SysWOW64\Drivers\Partizan.sys 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache 2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender 2014-04-26 02:59 - 2014-04-26 02:56 - 00000000 ____D () C:\ProgramData\WPM 2014-04-26 02:56 - 2014-04-26 02:56 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader 2014-04-26 02:53 - 2014-04-26 02:52 - 06326720 _____ (hxxp://yourfiledownloader.com) C:\Users\Michael\Downloads\YourFile_downloader.exe 2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403} 2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154} 2014-04-24 23:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\Users\Michael\Documents\MailStore Home 2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\ProgramData\firebird 2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111} 2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930} 2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725} 2014-04-23 21:42 - 2013-06-01 09:27 - 00002134 _____ () C:\Windows\Sandboxie.ini 2014-04-23 19:13 - 2012-12-31 20:08 - 00000914 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000Core.job 2014-04-23 09:05 - 2014-04-23 09:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C} 2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC} 2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6} 2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3} 2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A} 2014-04-20 09:38 - 2014-04-20 09:37 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352} 2014-04-20 09:38 - 2009-07-14 19:58 - 00699884 _____ () C:\Windows\system32\perfh007.dat 2014-04-20 09:38 - 2009-07-14 19:58 - 00149766 _____ () C:\Windows\system32\perfc007.dat 2014-04-20 09:38 - 2009-07-14 07:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3} 2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2} 2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028} 2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188} 2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B} 2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102 2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip 2014-04-14 13:11 - 2011-10-31 15:13 - 00000000 ____D () C:\Users\Michael 2014-04-14 13:11 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip 2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F} 2014-04-13 11:02 - 2011-10-31 16:21 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\SoftGrid Client 2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C} 2014-04-13 07:19 - 2013-12-10 21:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-13 07:19 - 2013-12-10 21:28 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8} 2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075} 2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe 2014-04-11 22:35 - 2014-04-11 22:32 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe 2014-04-11 21:22 - 2013-10-17 23:33 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-04-10 19:15 - 2013-08-15 16:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 19:14 - 2011-10-31 17:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611} 2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0} 2014-04-09 18:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-09 18:26 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor 2014-04-07 17:29 - 2014-04-07 17:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8} 2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24} 2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC} 2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14} 2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01} 2014-04-02 11:23 - 2011-10-31 15:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google 2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C} 2014-03-31 03:16 - 2014-04-10 16:41 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 16:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 16:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 16:41 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B} 2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\Windows\SysWOW64\C2MP 2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack 2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\Program Files (x86)\Haali 2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip 2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859} 2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862} 2014-03-28 18:24 - 2014-03-28 18:24 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52E18A02-578D-4E68-B51A-2E678315822A} 2014-03-28 13:01 - 2014-04-26 03:22 - 00012800 _____ (Greatis Software, LLC.) C:\Windows\SysWOW64\Drivers\UnHackMeDrv.sys 2014-03-27 19:03 - 2014-03-27 19:03 - 00000000 ____D () C:\Users\Michael\AppData\Local\{72D89DAE-C80B-4812-886D-3B7DBF94847F} Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\avgnt.exe C:\Users\Michael\AppData\Local\Temp\drm_dialogs.dll C:\Users\Michael\AppData\Local\Temp\drm_dyndata_7330014.dll C:\Users\Michael\AppData\Local\Temp\MSETUP4.EXE C:\Users\Michael\AppData\Local\Temp\SandboxieInstall.exe C:\Users\Michael\AppData\Local\Temp\ubi8A75.tmp.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-04-2014 01 Ran by Michael at 2014-04-26 10:44:01 Running from C:\Users\Michael\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 3GP Media Player 1.0.1 (HKLM-x32\...\3GP Media Player_is1) (Version: - vsevensoft.com) Adobe Flash Player 13 ActiveX (HKLM-x32\...\{8F9B1C8E-F50E-4139-8701-45016021E102}) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Reader XI (11.0.03) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{3C378793-5288-0165-FCA4-D319D5E4A490}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - ATI Technologies Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.3.5.0 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.0.0 - Canon Inc.) Canon MG2200 series Benutzerregistrierung (HKLM-x32\...\Canon MG2200 series Benutzerregistrierung) (Version: - Canon Inc.) Canon MG2200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2200_series) (Version: 1.00 - Canon Inc.) Canon MG2200 series On-screen Manual (HKLM-x32\...\Canon MG2200 series On-screen Manual) (Version: 7.5.0 - Canon Inc.) Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 1.0.0 - Canon Inc.) Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 1.0.0 - Canon Inc.) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.) Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.0.0 - Canon Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Company of Heroes - FAKEMSI (x32 Version: 2.0.0.0 - THQ Inc.) Hidden Company of Heroes (HKLM-x32\...\Company of Heroes) (Version: 2.602.0 - THQ Inc.) Company of Heroes 2 (HKLM-x32\...\Steam App 231430) (Version: - Relic Entertainment) ContentMod2.6 (HKLM-x32\...\ContentMod_2.6) (Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Defraggler (HKLM\...\Defraggler) (Version: 2.14 - Piriform) Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05 - Electronic Arts, Inc.) Empire Earth (HKLM-x32\...\{2447500B-22D7-47BD-9B13-1A927F43A267}) (Version: - ) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Freemake Video Converter Version 3.1.2 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.1.2 - Ellora Assets Corporation) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Gothic III (HKLM-x32\...\{02B244A2-7F6A-42E8-A36F-8C385D7A1625}) (Version: 1.0.0 - JoWooD Productions Software AG) Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - ) Heroes of Might & Magic V: Hammers of Fate (HKLM-x32\...\{66FF4C48-0083-4E60-8556-B883AB200091}) (Version: - ) Heroes of Might and Magic V - Tribes of the East (HKLM-x32\...\{66FF4C48-0083-4E60-8556-B883AB200092}) (Version: - ) Heroes of Might and Magic V (HKLM-x32\...\{20071984-5EB1-4881-8EDB-082532ACEC6D}) (Version: - ) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden MailStore Home 8.0.4.8653 (HKLM-x32\...\MailStore Home_universal1) (Version: 8.0.4.8653 - MailStore Software GmbH) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE (HKLM-x32\...\{F97E3841-CA9D-4964-9D64-26066241D26F}) (Version: 3.3.24.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{8FB1B528-E260-451E-9B55-E9152F94B80B}) (Version: 3.2.3.0 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Rise Of Nations (HKLM-x32\...\RiseOfNations 1.0) (Version: - Microsoft) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Might & Magic Heroes VI - Shades of Darkness (HKLM-x32\...\{745D37C2-26F4-4B65-BA13-F9840EBFA75B}) (Version: 2.1.0 - Ubisoft) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML4 Parser (HKLM-x32\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios) NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation) Password Safe (HKLM-x32\...\Password Safe) (Version: - ) PokerStars (HKLM-x32\...\PokerStars) (Version: - PokerStars) Questpaket 4 Update 2 Deinstallation (HKLM-x32\...\G3QP231012008_is1) (Version: 4.2.0.0 - Humanforce) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6410 - Realtek Semiconductor Corp.) Risen (HKLM-x32\...\{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}) (Version: 1.00.0000 - Deep Silver) Risen 2 - Dark Waters (HKLM-x32\...\Steam App 40390) (Version: - ) Sacred (HKLM-x32\...\Sacred_is1) (Version: - Ascaron Entertainment GmbH) Sacred 2 - Fallen Angel (HKCU\...\{7D0AEAD8-07FA-4C4D-9347-E7FBC5534B73}) (Version: 2.43.0.0 - Deep Silver) Sacred Underworld (HKLM-x32\...\Sacred Underworld_is1) (Version: - Ascaron Entertainment GmbH) Sandboxie 4.08 (64-bit) (HKLM\...\Sandboxie) (Version: 4.08 - Sandboxie Holdings, LLC) Secunia PSI (3.0.0.6001) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.6001 - Secunia) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) UnHackMe 7.11 release (HKLM-x32\...\UnHackMe_is1) (Version: - Greatis Software, LLC.) Windows 7 Codec Pack 4.0.8 (HKLM-x32\...\Windows 7 - Codec Pack) (Version: 4.0.8 - Windows 7 Codec Pack) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinZip 18.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DF}) (Version: 18.0.10661 - WinZip Computing, S.L. ) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ? Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000Core.job => C:\Users\Michael\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000UA.job => C:\Users\Michael\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ? Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ? ==================== Loaded Modules (whitelisted) ============= 2013-08-29 21:36 - 2013-08-29 21:36 - 00048200 _____ () C:\Windows\SysWOW64\C2MP\UpdateChecker.exe ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Michael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup MSCONFIG\startupreg: Facebook Update => "C:\Users\Michael\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/26/2014 03:27:52 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x9b8 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/24/2014 11:11:50 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/13/2014 10:39:58 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: MSHTML.dll, Version: 11.0.9600.16659, Zeitstempel: 0x5338aef8 Ausnahmecode: 0xc0000005 Fehleroffset: 0x001e57c9 ID des fehlerhaften Prozesses: 0x1724 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/10/2014 07:05:34 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/09/2014 06:37:46 PM) (Source: Application Hang) (User: ) Description: Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: b58 Startzeit: 01cf541033fa12e2 Endzeit: 1005 Anwendungspfad: C:\Windows\Explorer.EXE Berichts-ID: 429fb269-c005-11e3-93ce-5404a67f4cb8 Error: (04/09/2014 06:34:58 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Error: (04/08/2014 11:42:32 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/03/2014 05:03:20 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/02/2014 11:54:14 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/02/2014 06:32:43 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FreemakeVC.exe, Version: 3.1.2.0, Zeitstempel: 0x505ad7fa Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc000041d Fehleroffset: 0x735f4f0d ID des fehlerhaften Prozesses: 0x130 Startzeit der fehlerhaften Anwendung: 0xFreemakeVC.exe0 Pfad der fehlerhaften Anwendung: FreemakeVC.exe1 Pfad des fehlerhaften Moduls: FreemakeVC.exe2 Berichtskennung: FreemakeVC.exe3 System errors: ============= Error: (04/26/2014 10:34:56 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "IePlugin Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/26/2014 05:24:28 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "IePlugin Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/26/2014 04:24:35 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1053 Error: (04/26/2014 04:24:35 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/26/2014 04:24:35 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Funktionssuche-Ressourcenveröffentlichung erreicht. Error: (04/26/2014 04:22:29 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "IePlugin Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/26/2014 04:21:52 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (04/26/2014 04:21:52 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinHttpAutoProxySvc" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1352 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (04/26/2014 04:21:30 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "IePlugin Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/26/2014 04:08:17 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "IePlugin Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (04/26/2014 03:27:52 AM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399unknown0.0.0.000000000c0000005000000009b801cf60ece7c969f4C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEunknownfba9e485-cce1-11e3-97ae-5404a67f4cb8 Error: (04/24/2014 11:11:50 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (04/13/2014 10:39:58 AM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399MSHTML.dll11.0.9600.166595338aef8c0000005001e57c9172401cf56ef9b8f5513C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\system32\MSHTML.dll315a58c3-c2e7-11e3-8fb7-5404a67f4cb8 Error: (04/10/2014 07:05:34 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (04/09/2014 06:37:46 PM) (Source: Application Hang)(User: ) Description: Explorer.EXE6.1.7601.17567b5801cf541033fa12e21005C:\Windows\Explorer.EXE429fb269-c005-11e3-93ce-5404a67f4cb8 Error: (04/09/2014 06:34:58 PM) (Source: CVHSVC)(User: ) Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Error: (04/08/2014 11:42:32 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (04/03/2014 05:03:20 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (04/02/2014 11:54:14 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (04/02/2014 06:32:43 PM) (Source: Application Error)(User: ) Description: FreemakeVC.exe3.1.2.0505ad7faunknown0.0.0.000000000c000041d735f4f0d13001cf4e7e70cbec20C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exeunknown69b9ffaa-ba84-11e3-83be-5404a67f4cb8 ==================== Memory info =========================== Percentage of memory in use: 21% Total physical RAM: 8173.25 MB Available physical RAM: 6421.36 MB Total Pagefile: 32171.43 MB Available Pagefile: 30133.61 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:724.65 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================ |
26.04.2014, 18:27 | #4 |
/// the machine /// TB-Ausbilder | yourfile downloader hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.04.2014, 19:55 | #5 |
| yourfile downloader Hi hab den Echtzeitscanner von Avira ausgestellt, kam während des Combofix eine Meldung von Avira irgendwas mit Registerywarnung Code:
ATTFilter ComboFix 14-04-26.01 - Ich ohne Admin 26.04.2014 20:41:52.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8173.6204 [GMT 2:00] ausgeführt von:: c:\users\Michael\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Ich ohne Admin\AppData\Local\lollipop c:\users\Ich ohne Admin\AppData\Local\lollipop\logo.ico c:\users\Ich ohne Admin\AppData\Local\lollipop\lollipop.bat c:\users\Ich ohne Admin\AppData\Local\lollipop\lollipop.dat c:\users\Ich ohne Admin\AppData\Local\lollipop\Lollipop.exe c:\users\Ich ohne Admin\AppData\Local\lollipop\lollipop.lpd c:\users\Ich ohne Admin\AppData\Local\lollipop\lollipop_cfg.lpd c:\users\Ich ohne Admin\AppData\Local\lollipop\lollipop_ps.lpd c:\users\Ich ohne Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\TowerTilt_iels c:\windows\IsUn0407.exe c:\windows\SYSTEM3LOGARTIZAN.EXE c:\windows\SysWow64\DEBUG.log . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-26 bis 2014-04-26 )))))))))))))))))))))))))))))) . . 2014-04-26 18:46 . 2014-04-26 18:46 -------- d-----w- c:\users\Ich ohne Admin\AppData\Local\temp 2014-04-26 18:46 . 2014-04-26 18:46 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-04-26 08:41 . 2014-04-26 08:44 -------- d-----w- C:\FRST 2014-04-26 01:27 . 2014-04-26 01:27 40720 ----a-w- c:\windows\system32\Partizan.exe 2014-04-26 01:22 . 2014-04-26 01:22 35816 ----a-w- c:\windows\SysWow64\drivers\Partizan.sys 2014-04-26 01:22 . 2014-04-26 01:22 2 --shatr- c:\windows\winstart.bat 2014-04-26 01:22 . 2014-03-28 11:01 12800 ----a-w- c:\windows\SysWow64\drivers\UnHackMeDrv.sys 2014-04-26 01:22 . 2014-04-26 01:24 -------- d-----w- c:\program files (x86)\UnHackMe 2014-04-26 01:00 . 2014-04-26 01:00 -------- d-----w- c:\users\Michael\AppData\Local\HitsBlender 2014-04-26 01:00 . 2014-04-26 01:00 -------- d-----w- c:\users\Michael\AppData\Local\cache 2014-04-26 00:59 . 2014-04-26 00:59 -------- d-----w- c:\programdata\HitsBlender 2014-04-26 00:56 . 2014-04-26 00:56 -------- d-----w- c:\program files (x86)\SupTab 2014-04-26 00:56 . 2014-04-26 00:56 -------- d-----w- c:\users\Ich ohne Admin\AppData\Roaming\SupTab 2014-04-26 00:56 . 2014-04-26 00:59 -------- d-----w- c:\programdata\WPM 2014-04-26 00:55 . 2014-04-26 00:55 -------- d-----w- c:\users\Ich ohne Admin\AppData\Roaming\YourFileDownloader 2014-04-26 00:55 . 2014-04-26 00:55 -------- d-----w- c:\program files (x86)\YourFileDownloader 2014-04-26 00:55 . 2014-04-26 00:55 -------- d-----w- c:\program files (x86)\YourFileDownloader Updater 2014-04-22 19:14 . 2014-04-26 02:08 -------- d-----w- c:\users\Ich ohne Admin\AppData\Local\PasswordSafe 2014-04-14 11:11 . 2014-04-14 11:11 -------- d-----w- c:\users\Michael\AppData\Local\WinZip 2014-04-14 11:11 . 2014-04-14 11:11 -------- d-----w- c:\programdata\WinZip 2014-04-14 11:11 . 2014-04-14 11:11 -------- d-----w- c:\program files\WinZip 2014-04-11 20:36 . 2014-04-11 20:36 -------- d-----w- c:\program files (x86)\Password Safe 2014-04-10 14:41 . 2014-03-31 01:16 23134208 ----a-w- c:\windows\system32\mshtml.dll 2014-04-10 14:41 . 2014-03-31 01:13 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-04-10 14:41 . 2014-03-31 00:13 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-03-30 17:35 . 2014-03-30 17:36 -------- d-----w- c:\windows\SysWow64\C2MP 2014-03-30 16:33 . 2014-03-30 16:33 -------- d-----w- c:\program files (x86)\Haali . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-13 05:19 . 2013-12-10 19:28 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-04-13 05:19 . 2013-12-10 19:28 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-04-10 17:14 . 2011-10-31 15:14 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-04 09:17 . 2014-04-10 14:38 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-03-01 05:16 . 2014-03-11 22:10 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-03-01 04:58 . 2014-03-11 22:10 2765824 ----a-w- c:\windows\system32\iertutil.dll 2014-03-01 04:52 . 2014-03-11 22:10 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-03-01 04:51 . 2014-03-11 22:10 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-03-01 04:42 . 2014-03-11 22:10 53760 ----a-w- c:\windows\system32\jsproxy.dll 2014-03-01 04:40 . 2014-03-11 22:10 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-03-01 04:37 . 2014-03-11 22:10 574976 ----a-w- c:\windows\system32\ieui.dll 2014-03-01 04:33 . 2014-03-11 22:10 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-01 04:33 . 2014-03-11 22:10 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-03-01 04:32 . 2014-03-11 22:10 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2014-03-01 04:23 . 2014-03-11 22:10 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-03-01 04:17 . 2014-03-11 22:10 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2014-03-01 04:02 . 2014-03-11 22:10 195584 ----a-w- c:\windows\system32\msrating.dll 2014-03-01 03:54 . 2014-03-11 22:10 5768704 ----a-w- c:\windows\system32\jscript9.dll 2014-03-01 03:52 . 2014-03-11 22:10 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-03-01 03:51 . 2014-03-11 22:10 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-03-01 03:42 . 2014-03-11 22:10 627200 ----a-w- c:\windows\system32\msfeeds.dll 2014-03-01 03:38 . 2014-03-11 22:10 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-03-01 03:37 . 2014-03-11 22:10 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-03-01 03:35 . 2014-03-11 22:10 2041856 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-01 03:18 . 2014-03-11 22:10 13051904 ----a-w- c:\windows\system32\ieframe.dll 2014-03-01 03:14 . 2014-03-11 22:10 4244480 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-03-01 03:10 . 2014-03-11 22:10 2334208 ----a-w- c:\windows\system32\wininet.dll 2014-03-01 03:00 . 2014-03-11 22:10 1964032 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-03-01 02:38 . 2014-03-11 22:10 1393664 ----a-w- c:\windows\system32\urlmon.dll 2014-03-01 02:32 . 2014-03-11 22:10 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2014-03-01 02:25 . 2014-03-11 22:10 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2014-02-07 01:23 . 2014-03-11 22:10 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-11 22:07 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:32 . 2014-03-11 22:07 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-11 22:07 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-11 22:07 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-01-29 02:32 . 2014-03-11 22:10 484864 ----a-w- c:\windows\system32\wer.dll 2014-01-29 02:06 . 2014-03-11 22:10 381440 ----a-w- c:\windows\SysWow64\wer.dll 2014-01-28 02:32 . 2014-03-11 22:10 228864 ----a-w- c:\windows\system32\wwansvc.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}] 2014-04-11 02:05 513648 ----a-w- c:\program files (x86)\SupTab\SupTab.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-02-20 689744] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "CanonQuickMenu"="c:\program files (x86)\Canon\Quick Menu\CNQMMAIN.EXE" [2012-04-03 1273448] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-12-06 766208] . c:\users\Ich ohne Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Password Safe.lnk - c:\program files (x86)\Password Safe\pwsafe.exe -s [2014-2-7 4425728] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ CodecPackUpdateChecker.lnk - c:\windows\SysWOW64\C2MP\UpdateChecker.exe [2013-8-29 48200] Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2012-11-26 573024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 IePluginService;IePlugin Service;c:\programdata\IePluginService\PluginService.exe;c:\programdata\IePluginService\PluginService.exe [x] R3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\DRIVERS\athrxusb.sys;c:\windows\SYSNATIVE\DRIVERS\athrxusb.sys [x] R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 DAUpdaterSvc;Dragon Age: Origins - Inhaltsupdater;c:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe;c:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [x] S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x] S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . Inhalt des "geplante Tasks" Ordners . 2014-04-26 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10 05:19] . 2014-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000Core.job - c:\users\Michael\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-12-31 18:08] . 2014-04-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000UA.job - c:\users\Michael\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-12-31 18:08] . 2014-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-03 20:43] . 2014-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-03 20:43] . . --------- X64 Entries ----------- . . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 mDefault_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} mDefault_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 mStart Page = hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572 mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms} TCP: DhcpNameServer = 192.168.178.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-lollipop - c:\users\ich ohne admin\appdata\local\lollipop\lollipop.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-ContentMod_2.5 - c:\program files (x86)\Gothic III\Uninstall_CM_2.6.exe AddRemove-lollipop - c:\users\ich ohne admin\appdata\local\lollipop\lollipop.bat . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3315472771-574270051-2816021824-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3315472771-574270051-2816021824-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-3315472771-574270051-2816021824-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:d3,44,b7,80,fe,6e,5c,ed,86,42,22,2d,1b,59,32,ef,ac,34,9d,dd,3f,ec,fd, dc,8e,76,0f,55,23,71,77,9a,cb,6e,a5,fc,bc,6a,97,e3,2f,ea,52,26,19,a4,ec,e3,\ "??"=hex:e2,06,90,c3,a9,ab,f7,ca,1c,f7,63,d7,3e,f2,89,5d . [HKEY_USERS\S-1-5-21-3315472771-574270051-2816021824-1000_Classes\CLSID] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-04-26 20:47:16 ComboFix-quarantined-files.txt 2014-04-26 18:47 . Vor Suchlauf: 13 Verzeichnis(se), 777.748.414.464 Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 778.137.436.160 Bytes frei . - - End Of File - - 1EA16AC0C717D20AF8F0DBE41A5FBA58 A36C5E4F47E84449FF07ED3517B43A31 |
27.04.2014, 18:27 | #6 |
/// the machine /// TB-Ausbilder | yourfile downloader Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> yourfile downloader |
27.04.2014, 19:31 | #7 |
| yourfile downloaderCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 27.04.2014 Suchlauf-Zeit: 19:58:46 Logdatei: mbam.txt Administrator: Nein Version: 2.00.1.1004 Malware Datenbank: v2014.04.27.05 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Michael Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 191183 Verstrichene Zeit: 5 Min, 32 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 2 PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799], Registrierungsschlüssel: 6 PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799], PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [86cb63cc68130d29b0af03a512f157a9], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, Löschen bei Neustart, [f958ae81b5c6ba7cfa6d97e2df236997], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [4908949b631874c28ed1b1f74db6f010], PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, Löschen bei Neustart, [1a37111ebcbf33030618e69da75b8c74], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 6 PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572),Löschen bei Neustart,[72df60cfbfbcd2649f18012662a242be] PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Löschen bei Neustart,[80d18ba4a2d9a690c32543ee2cd87888] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms}),Löschen bei Neustart,[e76a979888f3ba7c8f2687a060a4ed13] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572),Löschen bei Neustart,[e56c131c473446f0feb569beb4508878] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572),Löschen bei Neustart,[193833fcaccfe84ef0c724035ea6ad53] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Löschen bei Neustart,[a5aca48b96e53bfb3cac08294eb6669a] Ordner: 27 PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader, Löschen bei Neustart, [dd74d956007bd06620f0b4e63fc42ad6], PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\language, Löschen bei Neustart, [dd74d956007bd06620f0b4e63fc42ad6], Dateien: 63 PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799], PUP.Optional.YourFileDownloader, C:\Users\Michael\Downloads\YourFile_downloader.exe, In Quarantäne, [73deff30dc9f072f6d99f42aa25e4cb4], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54], PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\htmlayout.dll, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6], PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\Downloader.exe, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6], PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\uninstall.exe, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6], PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\YourFile.exe, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.204 - Bericht erstellt am 27/04/2014 um 20:05:07 # Aktualisiert 26/04/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Ich ohne Admin - MICHAEL-PC # Gestartet von : C:\Users\Michael\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : IePluginService ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files (x86)\SupTab Ordner Gelöscht : C:\Program Files (x86)\yourfiledownloader Ordner Gelöscht : C:\Users\Ich ohne Admin\AppData\Roaming\SupTab Ordner Gelöscht : C:\Users\Ich ohne Admin\AppData\Roaming\yourfiledownloader Datei Gelöscht : C:\Users\Ich ohne Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\lollipop.lnk ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg Schlüssel Gelöscht : HKCU\Software\Classes\Applications\lollipop.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : HKCU\Software\lollipop Schlüssel Gelöscht : HKLM\Software\supTab Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\Software\webssearchesSoftware Schlüssel Gelöscht : HKLM\Software\Wpm Schlüssel Gelöscht : HKLM\Software\YourFileDownloader Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\YourFileDownloader ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] ************************* AdwCleaner[R0].txt - [4547 octets] - [27/04/2014 20:04:36] AdwCleaner[S0].txt - [3703 octets] - [27/04/2014 20:05:07] ########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [3763 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by Ich ohne Admin on 27.04.2014 at 20:10:28,60 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.04.2014 at 20:13:58,55 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 01 Ran by Michael (ATTENTION: The logged in user is not administrator) on MICHAEL-PC on 27-04-2014 20:18:02 Running from C:\Users\Michael\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe () C:\Windows\SysWOW64\C2MP\UpdateChecker.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\splwow64.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_13_0_0_182_ActiveX.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-01-12] (Google Inc.) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SecureBanking] => C:\Program Files (x86)\Secure Banking\SecureBanking.exe HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\MountPoints2: D - D:\AutoRun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF0375161D297CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Michael\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [994360 2011-10-14] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [399416 2011-10-14] (Secunia) ==================== Drivers (Whitelisted) ==================== S3 athrusb; C:\Windows\System32\DRIVERS\athrxusb.sys [1075712 2008-07-29] (Atheros Communications, Inc.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-04-06] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32000 2013-05-04] () R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-04-06] () R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U0 Partizan; system32\drivers\Partizan.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-27 20:09 - 2014-04-27 20:09 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-04-27 20:04 - 2014-04-27 20:05 - 00000000 ____D () C:\AdwCleaner 2014-04-27 20:03 - 2014-04-27 20:04 - 01329501 _____ () C:\Users\Michael\Desktop\adwcleaner.exe 2014-04-27 19:49 - 2014-04-27 19:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-27 19:48 - 2014-04-27 19:48 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-27 19:48 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-27 19:48 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-27 19:45 - 2014-04-27 19:47 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieUserList 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieSiteList 2014-04-27 03:00 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-27 03:00 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-27 03:00 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-27 03:00 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-27 03:00 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-27 03:00 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-27 03:00 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-27 03:00 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-27 03:00 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-27 03:00 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-27 03:00 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-27 03:00 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-27 03:00 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-27 03:00 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-27 03:00 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-27 03:00 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-27 03:00 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-27 03:00 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-27 03:00 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-27 03:00 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-27 03:00 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-27 03:00 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-27 03:00 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-27 03:00 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-27 03:00 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-27 03:00 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-27 03:00 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-27 03:00 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-27 03:00 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-27 03:00 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-27 03:00 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-27 03:00 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-27 03:00 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-27 03:00 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-27 03:00 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-27 03:00 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-27 03:00 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-27 03:00 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-27 03:00 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-27 03:00 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-27 03:00 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-27 03:00 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-27 03:00 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-27 03:00 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-27 03:00 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-27 03:00 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-27 03:00 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-27 03:00 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-26 21:11 - 2014-04-27 19:38 - 00000250 _____ () C:\Windows\SYSTEMLOGPARTIZAN.EXE 2014-04-26 20:47 - 2014-04-26 20:47 - 00021931 _____ () C:\ComboFix.txt 2014-04-26 20:40 - 2014-04-26 20:47 - 00000000 ____D () C:\Qoobox 2014-04-26 20:40 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-26 20:40 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-26 20:40 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-26 20:39 - 2014-04-26 20:46 - 00000000 ____D () C:\Windows\erdnt 2014-04-26 20:37 - 2014-04-26 20:37 - 05196309 ____R (Swearware) C:\Users\Michael\Desktop\ComboFix.exe 2014-04-26 18:11 - 2014-04-26 18:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DD052F0D-B654-45FF-8BED-04F98063DBC3} 2014-04-26 11:21 - 2014-04-26 11:21 - 00000000 ____D () C:\Users\Michael\AppData\Local\{860BFC87-A6D8-4AFC-91F8-750932FF51E4} 2014-04-26 10:44 - 2014-04-26 10:44 - 00032697 _____ () C:\Users\Michael\Desktop\Addition.txt 2014-04-26 10:43 - 2014-04-27 20:18 - 00011034 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-04-26 10:41 - 2014-04-27 20:18 - 00000000 ____D () C:\FRST 2014-04-26 10:40 - 2014-04-26 10:41 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe 2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2 2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe 2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI 2014-04-26 03:22 - 2014-04-27 19:43 - 00000000 ____D () C:\Program Files (x86)\UnHackMe 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache 2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender 2014-04-26 02:56 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\WPM 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater 2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403} 2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154} 2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111} 2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930} 2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725} 2014-04-23 09:04 - 2014-04-23 09:05 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C} 2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC} 2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6} 2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3} 2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A} 2014-04-20 09:37 - 2014-04-20 09:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352} 2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3} 2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2} 2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028} 2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188} 2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B} 2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102 2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip 2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip 2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F} 2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C} 2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8} 2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075} 2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe 2014-04-11 22:32 - 2014-04-11 22:35 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe 2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611} 2014-04-10 16:38 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 16:38 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 16:38 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 16:38 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 16:38 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 16:38 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 16:38 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 16:38 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 16:38 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 16:38 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 16:38 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 16:38 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 16:38 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0} 2014-04-07 17:28 - 2014-04-07 17:29 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8} 2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24} 2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC} 2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14} 2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01} 2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C} 2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B} 2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\Windows\SysWOW64\C2MP 2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack 2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe 2014-03-30 18:33 - 2014-04-09 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip 2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859} 2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862} 2014-03-28 18:24 - 2014-03-28 18:24 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52E18A02-578D-4E68-B51A-2E678315822A} ==================== One Month Modified Files and Folders ======= 2014-04-27 20:18 - 2014-04-26 10:43 - 00011034 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-04-27 20:18 - 2014-04-26 10:41 - 00000000 ____D () C:\FRST 2014-04-27 20:17 - 2012-01-03 22:43 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-27 20:13 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-27 20:13 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-27 20:09 - 2014-04-27 20:09 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-04-27 20:06 - 2012-03-06 21:39 - 00104444 _____ () C:\Windows\setupact.log 2014-04-27 20:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-27 20:05 - 2014-04-27 20:04 - 00000000 ____D () C:\AdwCleaner 2014-04-27 20:05 - 2012-04-03 21:23 - 00179190 _____ () C:\Windows\PFRO.log 2014-04-27 20:05 - 2011-10-31 15:07 - 01342461 _____ () C:\Windows\WindowsUpdate.log 2014-04-27 20:04 - 2014-04-27 20:03 - 01329501 _____ () C:\Users\Michael\Desktop\adwcleaner.exe 2014-04-27 19:51 - 2014-04-27 19:49 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-27 19:48 - 2014-04-27 19:48 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2013-07-02 04:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-27 19:47 - 2014-04-27 19:45 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-27 19:43 - 2014-04-26 03:22 - 00000000 ____D () C:\Program Files (x86)\UnHackMe 2014-04-27 19:42 - 2012-01-03 22:43 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-27 19:38 - 2014-04-26 21:11 - 00000250 _____ () C:\Windows\SYSTEMLOGPARTIZAN.EXE 2014-04-27 16:13 - 2012-12-31 20:08 - 00000936 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000UA.job 2014-04-27 15:30 - 2013-12-10 21:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieUserList 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieSiteList 2014-04-27 03:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-26 21:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-26 21:15 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-26 21:12 - 2013-06-01 09:27 - 00002182 _____ () C:\Windows\Sandboxie.ini 2014-04-26 20:47 - 2014-04-26 20:47 - 00021931 _____ () C:\ComboFix.txt 2014-04-26 20:47 - 2014-04-26 20:40 - 00000000 ____D () C:\Qoobox 2014-04-26 20:47 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-26 20:46 - 2014-04-26 20:39 - 00000000 ____D () C:\Windows\erdnt 2014-04-26 20:46 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-26 20:37 - 2014-04-26 20:37 - 05196309 ____R (Swearware) C:\Users\Michael\Desktop\ComboFix.exe 2014-04-26 18:11 - 2014-04-26 18:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DD052F0D-B654-45FF-8BED-04F98063DBC3} 2014-04-26 11:21 - 2014-04-26 11:21 - 00000000 ____D () C:\Users\Michael\AppData\Local\{860BFC87-A6D8-4AFC-91F8-750932FF51E4} 2014-04-26 10:44 - 2014-04-26 10:44 - 00032697 _____ () C:\Users\Michael\Desktop\Addition.txt 2014-04-26 10:41 - 2014-04-26 10:40 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe 2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2 2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe 2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache 2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender 2014-04-26 02:59 - 2014-04-26 02:56 - 00000000 ____D () C:\ProgramData\WPM 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater 2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403} 2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154} 2014-04-24 23:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\Users\Michael\Documents\MailStore Home 2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\ProgramData\firebird 2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111} 2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930} 2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725} 2014-04-23 19:13 - 2012-12-31 20:08 - 00000914 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000Core.job 2014-04-23 09:05 - 2014-04-23 09:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C} 2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC} 2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6} 2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3} 2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A} 2014-04-20 09:38 - 2014-04-20 09:37 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352} 2014-04-20 09:38 - 2009-07-14 19:58 - 00699884 _____ () C:\Windows\system32\perfh007.dat 2014-04-20 09:38 - 2009-07-14 19:58 - 00149766 _____ () C:\Windows\system32\perfc007.dat 2014-04-20 09:38 - 2009-07-14 07:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3} 2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2} 2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028} 2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188} 2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B} 2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102 2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip 2014-04-14 13:11 - 2011-10-31 15:13 - 00000000 ____D () C:\Users\Michael 2014-04-14 13:11 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip 2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F} 2014-04-13 11:02 - 2011-10-31 16:21 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\SoftGrid Client 2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C} 2014-04-13 07:19 - 2013-12-10 21:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-13 07:19 - 2013-12-10 21:28 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8} 2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075} 2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe 2014-04-11 22:35 - 2014-04-11 22:32 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe 2014-04-11 21:22 - 2013-10-17 23:33 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-04-10 19:15 - 2013-08-15 16:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 19:14 - 2011-10-31 17:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611} 2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0} 2014-04-09 18:26 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor 2014-04-07 17:29 - 2014-04-07 17:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8} 2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24} 2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC} 2014-04-03 09:51 - 2014-04-27 19:48 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-27 19:48 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-27 19:48 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14} 2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01} 2014-04-02 11:23 - 2011-10-31 15:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google 2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C} 2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B} 2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\Windows\SysWOW64\C2MP 2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack 2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip 2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859} 2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862} 2014-03-28 18:24 - 2014-03-28 18:24 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52E18A02-578D-4E68-B51A-2E678315822A} Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ --- --- --- --- --- --- |
28.04.2014, 08:54 | #8 |
/// the machine /// TB-Ausbilder | yourfile downloaderESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.04.2014, 15:58 | #9 |
| yourfile downloaderCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=54ca165b574b044597784719ee90563e # engine=18057 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-28 01:33:13 # local_time=2014-04-28 03:33:13 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 96 4895 169359698 0 0 # compatibility_mode=5893 16776574 100 94 25138631 150321843 0 0 # scanned=214935 # found=0 # cleaned=0 # scan_time=4245 Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Secunia PSI (3.0.0.6001) Java 7 Update 51 Java version out of Date! Adobe Reader XI ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter can result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 01 Ran by Michael (ATTENTION: The logged in user is not administrator) on MICHAEL-PC on 28-04-2014 16:51:57 Running from C:\Users\Michael\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe () C:\Windows\SysWOW64\C2MP\UpdateChecker.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\splwow64.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_13_0_0_182_ActiveX.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-01-12] (Google Inc.) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SecureBanking] => C:\Program Files (x86)\Secure Banking\SecureBanking.exe HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\MountPoints2: D - D:\AutoRun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF0375161D297CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Michael\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [994360 2011-10-14] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [399416 2011-10-14] (Secunia) ==================== Drivers (Whitelisted) ==================== S3 athrusb; C:\Windows\System32\DRIVERS\athrxusb.sys [1075712 2008-07-29] (Atheros Communications, Inc.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-04-06] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32000 2013-05-04] () R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-04-06] () R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U0 Partizan; system32\drivers\Partizan.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-28 16:50 - 2014-04-28 16:50 - 00855379 _____ () C:\Users\Michael\Desktop\SecurityCheck.exe 2014-04-28 14:15 - 2014-04-28 14:15 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-28 14:08 - 2014-04-28 14:08 - 00000000 ____D () C:\Users\Michael\AppData\Local\{13C3C362-3C71-4541-80DF-0DDB94DFAED1} 2014-04-27 20:21 - 2014-04-27 20:21 - 00016651 _____ () C:\Users\Michael\Desktop\mbam.txt 2014-04-27 20:09 - 2014-04-27 20:09 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-04-27 20:04 - 2014-04-27 20:05 - 00000000 ____D () C:\AdwCleaner 2014-04-27 20:03 - 2014-04-27 20:04 - 01329501 _____ () C:\Users\Michael\Desktop\adwcleaner.exe 2014-04-27 19:49 - 2014-04-27 19:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-27 19:48 - 2014-04-27 19:48 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-27 19:48 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-27 19:48 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-27 19:45 - 2014-04-27 19:47 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieUserList 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieSiteList 2014-04-27 03:00 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-27 03:00 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-27 03:00 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-27 03:00 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-27 03:00 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-27 03:00 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-27 03:00 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-27 03:00 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-27 03:00 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-27 03:00 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-27 03:00 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-27 03:00 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-27 03:00 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-27 03:00 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-27 03:00 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-27 03:00 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-27 03:00 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-27 03:00 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-27 03:00 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-27 03:00 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-27 03:00 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-27 03:00 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-27 03:00 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-27 03:00 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-27 03:00 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-27 03:00 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-27 03:00 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-27 03:00 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-27 03:00 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-27 03:00 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-27 03:00 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-27 03:00 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-27 03:00 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-27 03:00 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-27 03:00 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-27 03:00 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-27 03:00 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-27 03:00 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-27 03:00 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-27 03:00 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-27 03:00 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-27 03:00 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-27 03:00 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-27 03:00 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-27 03:00 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-27 03:00 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-27 03:00 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-27 03:00 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-26 21:11 - 2014-04-27 19:38 - 00000250 _____ () C:\Windows\SYSTEMLOGPARTIZAN.EXE 2014-04-26 20:47 - 2014-04-26 20:47 - 00021931 _____ () C:\ComboFix.txt 2014-04-26 20:40 - 2014-04-26 20:47 - 00000000 ____D () C:\Qoobox 2014-04-26 20:40 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-26 20:40 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-26 20:40 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-26 20:40 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-26 20:39 - 2014-04-26 20:46 - 00000000 ____D () C:\Windows\erdnt 2014-04-26 20:37 - 2014-04-26 20:37 - 05196309 ____R (Swearware) C:\Users\Michael\Desktop\ComboFix.exe 2014-04-26 18:11 - 2014-04-26 18:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DD052F0D-B654-45FF-8BED-04F98063DBC3} 2014-04-26 11:21 - 2014-04-26 11:21 - 00000000 ____D () C:\Users\Michael\AppData\Local\{860BFC87-A6D8-4AFC-91F8-750932FF51E4} 2014-04-26 10:44 - 2014-04-26 10:44 - 00032697 _____ () C:\Users\Michael\Desktop\Addition.txt 2014-04-26 10:43 - 2014-04-28 16:51 - 00011091 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-04-26 10:41 - 2014-04-28 16:51 - 00000000 ____D () C:\FRST 2014-04-26 10:40 - 2014-04-26 10:41 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe 2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2 2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe 2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI 2014-04-26 03:22 - 2014-04-27 19:43 - 00000000 ____D () C:\Program Files (x86)\UnHackMe 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache 2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender 2014-04-26 02:56 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\WPM 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater 2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403} 2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154} 2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111} 2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930} 2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725} 2014-04-23 09:04 - 2014-04-23 09:05 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C} 2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC} 2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6} 2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3} 2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A} 2014-04-20 09:37 - 2014-04-20 09:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352} 2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3} 2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2} 2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028} 2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188} 2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B} 2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102 2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip 2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip 2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F} 2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C} 2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8} 2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075} 2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe 2014-04-11 22:32 - 2014-04-11 22:35 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe 2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611} 2014-04-10 16:38 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 16:38 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 16:38 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 16:38 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 16:38 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 16:38 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 16:38 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 16:38 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 16:38 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 16:38 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 16:38 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 16:38 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 16:38 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 16:38 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0} 2014-04-07 17:28 - 2014-04-07 17:29 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8} 2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24} 2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC} 2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14} 2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01} 2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C} 2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B} 2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\Windows\SysWOW64\C2MP 2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack 2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe 2014-03-30 18:33 - 2014-04-09 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip 2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859} 2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862} ==================== One Month Modified Files and Folders ======= 2014-04-28 16:52 - 2014-04-26 10:43 - 00011091 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-04-28 16:51 - 2014-04-26 10:41 - 00000000 ____D () C:\FRST 2014-04-28 16:50 - 2014-04-28 16:50 - 00855379 _____ () C:\Users\Michael\Desktop\SecurityCheck.exe 2014-04-28 16:42 - 2012-01-03 22:43 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-28 16:42 - 2012-01-03 22:43 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-28 16:30 - 2013-12-10 21:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-28 16:13 - 2012-12-31 20:08 - 00000936 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000UA.job 2014-04-28 15:21 - 2011-10-31 15:07 - 01375489 _____ () C:\Windows\WindowsUpdate.log 2014-04-28 14:15 - 2014-04-28 14:15 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-28 14:13 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-28 14:13 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-28 14:08 - 2014-04-28 14:08 - 00000000 ____D () C:\Users\Michael\AppData\Local\{13C3C362-3C71-4541-80DF-0DDB94DFAED1} 2014-04-28 14:06 - 2012-03-06 21:39 - 00104556 _____ () C:\Windows\setupact.log 2014-04-28 14:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-27 21:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-27 20:21 - 2014-04-27 20:21 - 00016651 _____ () C:\Users\Michael\Desktop\mbam.txt 2014-04-27 20:09 - 2014-04-27 20:09 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-04-27 20:05 - 2014-04-27 20:04 - 00000000 ____D () C:\AdwCleaner 2014-04-27 20:05 - 2012-04-03 21:23 - 00179190 _____ () C:\Windows\PFRO.log 2014-04-27 20:04 - 2014-04-27 20:03 - 01329501 _____ () C:\Users\Michael\Desktop\adwcleaner.exe 2014-04-27 19:51 - 2014-04-27 19:49 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-27 19:48 - 2014-04-27 19:48 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-27 19:48 - 2013-07-02 04:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-27 19:47 - 2014-04-27 19:45 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-27 19:43 - 2014-04-26 03:22 - 00000000 ____D () C:\Program Files (x86)\UnHackMe 2014-04-27 19:38 - 2014-04-26 21:11 - 00000250 _____ () C:\Windows\SYSTEMLOGPARTIZAN.EXE 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieUserList 2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieSiteList 2014-04-27 03:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-26 21:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-26 21:15 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-26 21:12 - 2013-06-01 09:27 - 00002182 _____ () C:\Windows\Sandboxie.ini 2014-04-26 20:47 - 2014-04-26 20:47 - 00021931 _____ () C:\ComboFix.txt 2014-04-26 20:47 - 2014-04-26 20:40 - 00000000 ____D () C:\Qoobox 2014-04-26 20:47 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-26 20:46 - 2014-04-26 20:39 - 00000000 ____D () C:\Windows\erdnt 2014-04-26 20:46 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-26 20:37 - 2014-04-26 20:37 - 05196309 ____R (Swearware) C:\Users\Michael\Desktop\ComboFix.exe 2014-04-26 18:11 - 2014-04-26 18:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DD052F0D-B654-45FF-8BED-04F98063DBC3} 2014-04-26 11:21 - 2014-04-26 11:21 - 00000000 ____D () C:\Users\Michael\AppData\Local\{860BFC87-A6D8-4AFC-91F8-750932FF51E4} 2014-04-26 10:44 - 2014-04-26 10:44 - 00032697 _____ () C:\Users\Michael\Desktop\Addition.txt 2014-04-26 10:41 - 2014-04-26 10:40 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe 2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2 2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe 2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT 2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender 2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache 2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender 2014-04-26 02:59 - 2014-04-26 02:56 - 00000000 ____D () C:\ProgramData\WPM 2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater 2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403} 2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154} 2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\Users\Michael\Documents\MailStore Home 2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\ProgramData\firebird 2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111} 2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930} 2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725} 2014-04-23 19:13 - 2012-12-31 20:08 - 00000914 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000Core.job 2014-04-23 09:05 - 2014-04-23 09:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C} 2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC} 2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6} 2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3} 2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A} 2014-04-20 09:38 - 2014-04-20 09:37 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352} 2014-04-20 09:38 - 2009-07-14 19:58 - 00699884 _____ () C:\Windows\system32\perfh007.dat 2014-04-20 09:38 - 2009-07-14 19:58 - 00149766 _____ () C:\Windows\system32\perfc007.dat 2014-04-20 09:38 - 2009-07-14 07:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3} 2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2} 2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028} 2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188} 2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B} 2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102 2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip 2014-04-14 13:11 - 2011-10-31 15:13 - 00000000 ____D () C:\Users\Michael 2014-04-14 13:11 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip 2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F} 2014-04-13 11:02 - 2011-10-31 16:21 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\SoftGrid Client 2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C} 2014-04-13 07:19 - 2013-12-10 21:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-13 07:19 - 2013-12-10 21:28 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8} 2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075} 2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe 2014-04-11 22:35 - 2014-04-11 22:32 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe 2014-04-11 21:22 - 2013-10-17 23:33 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-04-10 19:15 - 2013-08-15 16:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 19:14 - 2011-10-31 17:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611} 2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0} 2014-04-09 18:26 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor 2014-04-07 17:29 - 2014-04-07 17:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8} 2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24} 2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC} 2014-04-03 09:51 - 2014-04-27 19:48 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-27 19:48 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-27 19:48 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14} 2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01} 2014-04-02 11:23 - 2011-10-31 15:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google 2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C} 2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B} 2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\Windows\SysWOW64\C2MP 2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack 2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip 2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859} 2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862} Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ |
29.04.2014, 17:00 | #10 |
/// the machine /// TB-Ausbilder | yourfile downloader Java updaten. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.04.2014, 18:12 | #11 |
| yourfile downloader jo kann zu,besten dank für deine Hilfe |
30.04.2014, 23:36 | #12 |
/// the machine /// TB-Ausbilder | yourfile downloader Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |