AdwCleaner Logfile:
Code:
# AdwCleaner v2.303 - Datei am 27/06/2013 um 15:20:42 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Business Service Pack 2 (32 bits)
# Benutzer : Verwalter - INTERSELL
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Intersell\Downloads\adwcleaner.exe
# Option [Suche]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Results of screen317's Security Check version 0.99.68
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Norton Internet Security
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
CCleaner
JavaFX 2.1.1
Java 7 Update 21
Java(TM) 6 Update 7
Java version out of Date!
Adobe Flash Player 11.7.700.224
Mozilla Firefox 21.0 Firefox out of Date!
Google Chrome 27.0.1453.110
Google Chrome 27.0.1453.116
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Spybot Teatimer.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
---
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-06-2013 01
Ran by Intersell (ATTENTION: The logged in user is not administrator) on 27-06-2013 17:58:48
Running from C:\Users\Intersell\Desktop
Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe [318488 2008-04-07] (PDF Complete Inc)
HKLM\...\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe [525824 2003-11-20] (Hewlett-Packard Company)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [x]
HKCU\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-09] (Hewlett-Packard)
MountPoints2: {cbb14ac9-7776-11df-add9-002264239b0b} - G:\LaunchU3.exe -a
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=all&pf=cmdt
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=all&pf=cmdt
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU -No Name - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://webzugang.brnet.de/dana-cached/sc/JuniperSetupClient.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pandasecurity.com/activescan - C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\Intersell\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Visualisateur 3D de 20-20 - C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: No Name - C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
FF Extension: No Name - C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default\Extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll No File
CHR Plugin: (Panda ActiveScan 2.0) - C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (YouTube) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Norton Identity Protection) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0
CHR Extension: (Gmail) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
========================== Services (Whitelisted) =================
R2 iphlpsvc; C:\Windows\System32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [576024 2008-04-07] (PDF Complete Inc)
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20130620.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-05-17] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-01-17] (Symantec Corporation)
R1 FSLX; C:\Windows\system32\drivers\fslx.sys [191872 2008-07-11] (Altiris, Inc.)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20130626.001\IDSvix86.sys [386720 2013-01-16] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130626.022\NAVENG.SYS [93272 2013-06-19] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130626.022\NAVEX15.SYS [1611992 2013-06-19] (Symantec Corporation)
R1 NEOFLTR_700_16499; C:\Windows\system32\Drivers\NEOFLTR_700_16499.SYS [84336 2010-08-27] (Juniper Networks)
R0 pavboot; C:\Windows\System32\drivers\pavboot.sys [28552 2009-06-30] (Panda Security, S.L.)
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-27 17:53 - 2013-06-27 17:53 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck(1).exe
2013-06-27 17:50 - 2013-06-27 17:50 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck.exe
2013-06-27 15:48 - 2013-06-27 15:48 - 00000000 ____D C:\Program Files\ESET
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\Windows\ERUNT
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\JRT
2013-06-27 15:29 - 2013-06-27 17:46 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT(1).exe
2013-06-27 15:26 - 2013-06-27 15:26 - 00001388 ____A C:\Users\Intersell\AdwCleaner[R1].txt
2013-06-27 15:24 - 2013-06-27 15:25 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT.exe
2013-06-27 15:20 - 2013-06-27 15:21 - 00001388 ____A C:\AdwCleaner[R1].txt
2013-06-27 15:16 - 2013-06-27 15:17 - 00001333 ____A C:\AdwCleaner[S2].txt
2013-06-27 15:15 - 2013-06-27 15:15 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner(1).exe
2013-06-27 14:53 - 2013-06-27 14:54 - 00013292 ____A C:\AdwCleaner[S1].txt
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(3).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(2).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner.exe
2013-06-27 14:51 - 2013-06-27 14:51 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(1).exe
2013-06-27 14:50 - 2013-06-27 14:50 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup.exe
2013-06-25 18:03 - 2013-06-25 18:03 - 00022220 ____A C:\Users\Intersell\Desktop\FRST2.txt
2013-06-25 17:45 - 2013-06-25 17:45 - 00016289 ____A C:\Users\Intersell\Desktop\Addition.txt
2013-06-25 17:43 - 2013-06-25 17:43 - 00000000 ____D C:\FRST
2013-06-25 17:41 - 2013-06-25 17:41 - 01370263 ____A (Farbar) C:\Users\Intersell\Desktop\FRST.exe
2013-06-25 17:39 - 2013-06-25 17:39 - 01370263 ____A (Farbar) C:\Users\Intersell\Downloads\FRST.exe
2013-06-25 10:38 - 2013-06-27 15:18 - 00002190 ____A C:\Windows\PFRO.log
2013-06-24 18:14 - 2013-06-24 18:14 - 00036094 ____A C:\Users\Intersell\Desktop\Extras.Txt
2013-06-24 18:13 - 2013-06-24 18:13 - 00051548 ____A C:\Users\Intersell\Desktop\OTL.Txt
2013-06-24 18:12 - 2013-06-24 18:12 - 00036094 ____A C:\Users\Intersell\Downloads\Extras.Txt
2013-06-24 18:10 - 2013-06-24 18:10 - 00051548 ____A C:\Users\Intersell\Downloads\OTL.Txt
2013-06-24 17:58 - 2013-06-24 17:58 - 00602112 ____A (OldTimer Tools) C:\Users\Intersell\Downloads\OTL.exe
2013-06-24 17:57 - 2013-06-24 17:57 - 00000480 ____A C:\Windows\System32\defogger_disable.log
2013-06-24 17:56 - 2013-06-24 17:56 - 00050477 ____A C:\Users\Intersell\Downloads\Defogger.exe
2013-06-24 17:53 - 2013-06-24 17:53 - 00016739 ____A C:\Users\Intersell\Desktop\get-mirror-server.html
2013-06-12 21:05 - 2013-06-12 21:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(2).exe
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(1).exe
2013-06-12 17:01 - 2013-06-12 17:01 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68.exe
2013-06-12 14:45 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 14:45 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 14:45 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 14:45 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 14:45 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 14:45 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-12 14:45 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-12 14:45 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 14:45 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 14:45 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-12 14:45 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-12 14:45 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 14:45 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 14:45 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-12 14:45 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 14:45 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-12 08:42 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 08:42 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-12 08:42 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-12 08:42 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 08:42 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 08:42 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 08:42 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-07 20:52 - 2013-06-07 20:52 - 01488280 ____A (Bandoo Media Inc) C:\Users\Intersell\Downloads\iLividSetup-r341-n-bf.exe
2013-06-01 19:33 - 2013-06-01 19:33 - 00727616 ____A () C:\Users\Intersell\Downloads\BestCodecsPackSetup.exe
==================== One Month Modified Files and Folders ========
2013-06-27 17:53 - 2013-06-27 17:53 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck(1).exe
2013-06-27 17:51 - 2011-07-05 15:39 - 00001100 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-27 17:50 - 2013-06-27 17:50 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck.exe
2013-06-27 17:47 - 2012-01-23 22:51 - 01657277 ____A C:\Windows\WindowsUpdate.log
2013-06-27 17:46 - 2013-06-27 15:29 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT(1).exe
2013-06-27 17:44 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-27 17:44 - 2006-11-02 14:47 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-27 17:44 - 2006-11-02 14:47 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-27 17:41 - 2006-11-02 15:01 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-27 17:30 - 2011-07-05 15:40 - 00001104 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-27 17:27 - 2013-02-18 11:14 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-27 15:48 - 2013-06-27 15:48 - 00000000 ____D C:\Program Files\ESET
2013-06-27 15:47 - 2006-11-02 12:33 - 01474912 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\Windows\ERUNT
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\JRT
2013-06-27 15:26 - 2013-06-27 15:26 - 00001388 ____A C:\Users\Intersell\AdwCleaner[R1].txt
2013-06-27 15:26 - 2009-10-01 18:18 - 00000000 ____D C:\users\Intersell
2013-06-27 15:25 - 2013-06-27 15:24 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT.exe
2013-06-27 15:21 - 2013-06-27 15:20 - 00001388 ____A C:\AdwCleaner[R1].txt
2013-06-27 15:18 - 2013-06-25 10:38 - 00002190 ____A C:\Windows\PFRO.log
2013-06-27 15:17 - 2013-06-27 15:16 - 00001333 ____A C:\AdwCleaner[S2].txt
2013-06-27 15:15 - 2013-06-27 15:15 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner(1).exe
2013-06-27 14:54 - 2013-06-27 14:53 - 00013292 ____A C:\AdwCleaner[S1].txt
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(3).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(2).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner.exe
2013-06-27 14:51 - 2013-06-27 14:51 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(1).exe
2013-06-27 14:50 - 2013-06-27 14:50 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup.exe
2013-06-27 14:32 - 2009-10-01 13:38 - 00002735 ____A C:\Users\Intersell\Desktop\Microsoft Office Outlook 2007.lnk
2013-06-25 19:29 - 2013-01-17 17:49 - 00000680 ____A C:\Users\Intersell\AppData\Local\d3d9caps.dat
2013-06-25 18:03 - 2013-06-25 18:03 - 00022220 ____A C:\Users\Intersell\Desktop\FRST2.txt
2013-06-25 17:45 - 2013-06-25 17:45 - 00016289 ____A C:\Users\Intersell\Desktop\Addition.txt
2013-06-25 17:43 - 2013-06-25 17:43 - 00000000 ____D C:\FRST
2013-06-25 17:41 - 2013-06-25 17:41 - 01370263 ____A (Farbar) C:\Users\Intersell\Desktop\FRST.exe
2013-06-25 17:39 - 2013-06-25 17:39 - 01370263 ____A (Farbar) C:\Users\Intersell\Downloads\FRST.exe
2013-06-24 18:14 - 2013-06-24 18:14 - 00036094 ____A C:\Users\Intersell\Desktop\Extras.Txt
2013-06-24 18:13 - 2013-06-24 18:13 - 00051548 ____A C:\Users\Intersell\Desktop\OTL.Txt
2013-06-24 18:12 - 2013-06-24 18:12 - 00036094 ____A C:\Users\Intersell\Downloads\Extras.Txt
2013-06-24 18:10 - 2013-06-24 18:10 - 00051548 ____A C:\Users\Intersell\Downloads\OTL.Txt
2013-06-24 17:58 - 2013-06-24 17:58 - 00602112 ____A (OldTimer Tools) C:\Users\Intersell\Downloads\OTL.exe
2013-06-24 17:57 - 2013-06-24 17:57 - 00000480 ____A C:\Windows\System32\defogger_disable.log
2013-06-24 17:57 - 2009-10-01 13:54 - 00000000 ____D C:\users\Verwalter
2013-06-24 17:56 - 2013-06-24 17:56 - 00050477 ____A C:\Users\Intersell\Downloads\Defogger.exe
2013-06-24 17:53 - 2013-06-24 17:53 - 00016739 ____A C:\Users\Intersell\Desktop\get-mirror-server.html
2013-06-24 16:50 - 2010-09-29 12:39 - 30729303 ____A C:\immudebug.log
2013-06-24 16:21 - 2009-10-01 17:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-06-24 16:19 - 2010-04-10 20:48 - 00000000 ____D C:\Windows\Minidump
2013-06-24 16:16 - 2011-01-05 18:41 - 00000804 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-24 16:16 - 2009-10-01 18:18 - 00000000 ____D C:\Program Files\CCleaner
2013-06-21 08:35 - 2011-07-05 15:42 - 00001971 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-21 08:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-06-20 07:51 - 2013-01-17 11:42 - 00000000 ____D C:\Windows\System32\Drivers\NIS
2013-06-20 07:50 - 2013-01-17 11:44 - 00002213 ____A C:\Users\Public\Desktop\Norton Internet Security.lnk
2013-06-19 08:44 - 2013-01-17 11:44 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-19 08:44 - 2013-01-17 11:44 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-13 07:53 - 2012-07-17 17:03 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-06-12 21:06 - 2013-06-12 21:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(2).exe
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(1).exe
2013-06-12 17:01 - 2013-06-12 17:01 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68.exe
2013-06-12 15:29 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-12 15:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-12 14:46 - 2009-10-01 13:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-06-12 14:43 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2013-06-12 10:27 - 2013-02-18 11:14 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-12 10:27 - 2013-02-18 11:14 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-11 14:23 - 2009-10-01 13:38 - 00002631 ____A C:\Users\Intersell\Desktop\Microsoft Office Word 2007.lnk
2013-06-09 22:41 - 2010-02-02 13:22 - 00000000 ____D C:\Users\Intersell\AppData\Local\CrashDumps
2013-06-07 20:52 - 2013-06-07 20:52 - 01488280 ____A (Bandoo Media Inc) C:\Users\Intersell\Downloads\iLividSetup-r341-n-bf.exe
2013-06-01 19:33 - 2013-06-01 19:33 - 00727616 ____A () C:\Users\Intersell\Downloads\BestCodecsPackSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
***** [Registrierungsdatenbank] *****
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16490
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v21.0 (de)
Datei : C:\Users\Verwalter\AppData\Roaming\Mozilla\Firefox\Profiles\ms48tnib.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default\prefs.js
[OK] Die Datei ist sauber.
-\\ Google Chrome v27.0.1453.116
Datei : C:\Users\Verwalter\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[R1].txt - [1140 octets] - [27/06/2013 15:20:42]
AdwCleaner[S1].txt - [13292 octets] - [27/06/2013 14:53:50]
AdwCleaner[S2].txt - [1333 octets] - [27/06/2013 15:16:16]
########## EOF - \AdwCleaner[R1].txt - [1321 octets] ##########
--- --- ---
JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows Vista (TM) Business x86
Ran by Verwalter on 27.06.2013 at 15:30:28,31
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0BAA656A-039D-4495-95F8-9FBD95EDB033}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2ACE97A7-BF74-43C7-BF49-E3F70C656151}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.06.2013 at 15:33:44,56
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=9a880dae7525ad40b863d27aa586edc5
# engine=14170
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-27 03:36:49
# local_time=2013-06-27 05:36:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=3591 16777213 100 93 197904 134943994 0 0
# compatibility_mode=5892 16776574 100 100 77761088 209880111 0 0
# scanned=168379
# found=8
# cleaned=0
# scan_time=6383
sh=F95B2DA4964C1C830E17278BC9D52AEF25A49D5C ft=1 fh=f5563287369decb3 vn="Win32/Adware.1ClickDownload.AI application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\ckdO_8zF.exe.part"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\CMxKwxXK.exe.part"
sh=F95B2DA4964C1C830E17278BC9D52AEF25A49D5C ft=1 fh=f5563287369decb3 vn="Win32/Adware.1ClickDownload.AI application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\i+aLOAfw.exe.part"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\tgoiigZf.exe.part"
sh=F95B2DA4964C1C830E17278BC9D52AEF25A49D5C ft=1 fh=f5563287369decb3 vn="Win32/Adware.1ClickDownload.AI application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\v7py+mkV.exe.part"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\Downloads\lshunterApps_Install68(1).exe"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\Downloads\lshunterApps_Install68(2).exe"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\Downloads\lshunterApps_Install68.exe"
----
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=9a880dae7525ad40b863d27aa586edc5
# engine=14170
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-27 03:36:49
# local_time=2013-06-27 05:36:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=3591 16777213 100 93 197904 134943994 0 0
# compatibility_mode=5892 16776574 100 100 77761088 209880111 0 0
# scanned=168379
# found=8
# cleaned=0
# scan_time=6383
sh=F95B2DA4964C1C830E17278BC9D52AEF25A49D5C ft=1 fh=f5563287369decb3 vn="Win32/Adware.1ClickDownload.AI application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\ckdO_8zF.exe.part"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\CMxKwxXK.exe.part"
sh=F95B2DA4964C1C830E17278BC9D52AEF25A49D5C ft=1 fh=f5563287369decb3 vn="Win32/Adware.1ClickDownload.AI application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\i+aLOAfw.exe.part"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\tgoiigZf.exe.part"
sh=F95B2DA4964C1C830E17278BC9D52AEF25A49D5C ft=1 fh=f5563287369decb3 vn="Win32/Adware.1ClickDownload.AI application" ac=I fn="C:\Users\Intersell\AppData\Local\Temp\v7py+mkV.exe.part"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\Downloads\lshunterApps_Install68(1).exe"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\Downloads\lshunterApps_Install68(2).exe"
sh=A7917E5933BCEB9470D68C8D864D99B65EB1D674 ft=1 fh=171b0515a656f20d vn="Win32/Adware.1ClickDownload.AJ application" ac=I fn="C:\Users\Intersell\Downloads\lshunterApps_Install68.exe"
---
FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-06-2013 01
Ran by Intersell (ATTENTION: The logged in user is not administrator) on 27-06-2013 17:58:48
Running from C:\Users\Intersell\Desktop
Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe [318488 2008-04-07] (PDF Complete Inc)
HKLM\...\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe [525824 2003-11-20] (Hewlett-Packard Company)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [x]
HKCU\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-09] (Hewlett-Packard)
MountPoints2: {cbb14ac9-7776-11df-add9-002264239b0b} - G:\LaunchU3.exe -a
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=all&pf=cmdt
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=all&pf=cmdt
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU -No Name - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://webzugang.brnet.de/dana-cached/sc/JuniperSetupClient.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pandasecurity.com/activescan - C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\Intersell\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Visualisateur 3D de 20-20 - C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: No Name - C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
FF Extension: No Name - C:\Users\Intersell\AppData\Roaming\Mozilla\Firefox\Profiles\bra66r8y.default\Extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.116\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll No File
CHR Plugin: (Panda ActiveScan 2.0) - C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (YouTube) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Norton Identity Protection) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0
CHR Extension: (Gmail) - C:\Users\Intersell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
========================== Services (Whitelisted) =================
R2 iphlpsvc; C:\Windows\System32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [576024 2008-04-07] (PDF Complete Inc)
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20130620.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-05-17] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-01-17] (Symantec Corporation)
R1 FSLX; C:\Windows\system32\drivers\fslx.sys [191872 2008-07-11] (Altiris, Inc.)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20130626.001\IDSvix86.sys [386720 2013-01-16] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130626.022\NAVENG.SYS [93272 2013-06-19] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130626.022\NAVEX15.SYS [1611992 2013-06-19] (Symantec Corporation)
R1 NEOFLTR_700_16499; C:\Windows\system32\Drivers\NEOFLTR_700_16499.SYS [84336 2010-08-27] (Juniper Networks)
R0 pavboot; C:\Windows\System32\drivers\pavboot.sys [28552 2009-06-30] (Panda Security, S.L.)
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-27 17:53 - 2013-06-27 17:53 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck(1).exe
2013-06-27 17:50 - 2013-06-27 17:50 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck.exe
2013-06-27 15:48 - 2013-06-27 15:48 - 00000000 ____D C:\Program Files\ESET
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\Windows\ERUNT
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\JRT
2013-06-27 15:29 - 2013-06-27 17:46 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT(1).exe
2013-06-27 15:26 - 2013-06-27 15:26 - 00001388 ____A C:\Users\Intersell\AdwCleaner[R1].txt
2013-06-27 15:24 - 2013-06-27 15:25 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT.exe
2013-06-27 15:20 - 2013-06-27 15:21 - 00001388 ____A C:\AdwCleaner[R1].txt
2013-06-27 15:16 - 2013-06-27 15:17 - 00001333 ____A C:\AdwCleaner[S2].txt
2013-06-27 15:15 - 2013-06-27 15:15 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner(1).exe
2013-06-27 14:53 - 2013-06-27 14:54 - 00013292 ____A C:\AdwCleaner[S1].txt
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(3).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(2).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner.exe
2013-06-27 14:51 - 2013-06-27 14:51 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(1).exe
2013-06-27 14:50 - 2013-06-27 14:50 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup.exe
2013-06-25 18:03 - 2013-06-25 18:03 - 00022220 ____A C:\Users\Intersell\Desktop\FRST2.txt
2013-06-25 17:45 - 2013-06-25 17:45 - 00016289 ____A C:\Users\Intersell\Desktop\Addition.txt
2013-06-25 17:43 - 2013-06-25 17:43 - 00000000 ____D C:\FRST
2013-06-25 17:41 - 2013-06-25 17:41 - 01370263 ____A (Farbar) C:\Users\Intersell\Desktop\FRST.exe
2013-06-25 17:39 - 2013-06-25 17:39 - 01370263 ____A (Farbar) C:\Users\Intersell\Downloads\FRST.exe
2013-06-25 10:38 - 2013-06-27 15:18 - 00002190 ____A C:\Windows\PFRO.log
2013-06-24 18:14 - 2013-06-24 18:14 - 00036094 ____A C:\Users\Intersell\Desktop\Extras.Txt
2013-06-24 18:13 - 2013-06-24 18:13 - 00051548 ____A C:\Users\Intersell\Desktop\OTL.Txt
2013-06-24 18:12 - 2013-06-24 18:12 - 00036094 ____A C:\Users\Intersell\Downloads\Extras.Txt
2013-06-24 18:10 - 2013-06-24 18:10 - 00051548 ____A C:\Users\Intersell\Downloads\OTL.Txt
2013-06-24 17:58 - 2013-06-24 17:58 - 00602112 ____A (OldTimer Tools) C:\Users\Intersell\Downloads\OTL.exe
2013-06-24 17:57 - 2013-06-24 17:57 - 00000480 ____A C:\Windows\System32\defogger_disable.log
2013-06-24 17:56 - 2013-06-24 17:56 - 00050477 ____A C:\Users\Intersell\Downloads\Defogger.exe
2013-06-24 17:53 - 2013-06-24 17:53 - 00016739 ____A C:\Users\Intersell\Desktop\get-mirror-server.html
2013-06-12 21:05 - 2013-06-12 21:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(2).exe
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(1).exe
2013-06-12 17:01 - 2013-06-12 17:01 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68.exe
2013-06-12 14:45 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 14:45 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 14:45 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 14:45 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 14:45 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 14:45 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-12 14:45 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-12 14:45 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 14:45 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 14:45 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-12 14:45 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-12 14:45 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 14:45 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 14:45 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-12 14:45 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 14:45 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-12 08:42 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 08:42 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-12 08:42 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-12 08:42 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 08:42 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 08:42 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 08:42 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 08:42 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-07 20:52 - 2013-06-07 20:52 - 01488280 ____A (Bandoo Media Inc) C:\Users\Intersell\Downloads\iLividSetup-r341-n-bf.exe
2013-06-01 19:33 - 2013-06-01 19:33 - 00727616 ____A () C:\Users\Intersell\Downloads\BestCodecsPackSetup.exe
==================== One Month Modified Files and Folders ========
2013-06-27 17:53 - 2013-06-27 17:53 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck(1).exe
2013-06-27 17:51 - 2011-07-05 15:39 - 00001100 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-27 17:50 - 2013-06-27 17:50 - 00890988 ____A C:\Users\Intersell\Downloads\SecurityCheck.exe
2013-06-27 17:47 - 2012-01-23 22:51 - 01657277 ____A C:\Windows\WindowsUpdate.log
2013-06-27 17:46 - 2013-06-27 15:29 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT(1).exe
2013-06-27 17:44 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-27 17:44 - 2006-11-02 14:47 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-27 17:44 - 2006-11-02 14:47 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-27 17:41 - 2006-11-02 15:01 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-27 17:30 - 2011-07-05 15:40 - 00001104 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-27 17:27 - 2013-02-18 11:14 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-27 15:48 - 2013-06-27 15:48 - 00000000 ____D C:\Program Files\ESET
2013-06-27 15:47 - 2006-11-02 12:33 - 01474912 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\Windows\ERUNT
2013-06-27 15:30 - 2013-06-27 15:30 - 00000000 ____D C:\JRT
2013-06-27 15:26 - 2013-06-27 15:26 - 00001388 ____A C:\Users\Intersell\AdwCleaner[R1].txt
2013-06-27 15:26 - 2009-10-01 18:18 - 00000000 ____D C:\users\Intersell
2013-06-27 15:25 - 2013-06-27 15:24 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Intersell\Downloads\JRT.exe
2013-06-27 15:21 - 2013-06-27 15:20 - 00001388 ____A C:\AdwCleaner[R1].txt
2013-06-27 15:18 - 2013-06-25 10:38 - 00002190 ____A C:\Windows\PFRO.log
2013-06-27 15:17 - 2013-06-27 15:16 - 00001333 ____A C:\AdwCleaner[S2].txt
2013-06-27 15:15 - 2013-06-27 15:15 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner(1).exe
2013-06-27 14:54 - 2013-06-27 14:53 - 00013292 ____A C:\AdwCleaner[S1].txt
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(3).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(2).exe
2013-06-27 14:52 - 2013-06-27 14:52 - 00648201 ____A C:\Users\Intersell\Downloads\adwcleaner.exe
2013-06-27 14:51 - 2013-06-27 14:51 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup(1).exe
2013-06-27 14:50 - 2013-06-27 14:50 - 00793536 ____A C:\Users\Intersell\Downloads\ZipOpenerSetup.exe
2013-06-27 14:32 - 2009-10-01 13:38 - 00002735 ____A C:\Users\Intersell\Desktop\Microsoft Office Outlook 2007.lnk
2013-06-25 19:29 - 2013-01-17 17:49 - 00000680 ____A C:\Users\Intersell\AppData\Local\d3d9caps.dat
2013-06-25 18:03 - 2013-06-25 18:03 - 00022220 ____A C:\Users\Intersell\Desktop\FRST2.txt
2013-06-25 17:45 - 2013-06-25 17:45 - 00016289 ____A C:\Users\Intersell\Desktop\Addition.txt
2013-06-25 17:43 - 2013-06-25 17:43 - 00000000 ____D C:\FRST
2013-06-25 17:41 - 2013-06-25 17:41 - 01370263 ____A (Farbar) C:\Users\Intersell\Desktop\FRST.exe
2013-06-25 17:39 - 2013-06-25 17:39 - 01370263 ____A (Farbar) C:\Users\Intersell\Downloads\FRST.exe
2013-06-24 18:14 - 2013-06-24 18:14 - 00036094 ____A C:\Users\Intersell\Desktop\Extras.Txt
2013-06-24 18:13 - 2013-06-24 18:13 - 00051548 ____A C:\Users\Intersell\Desktop\OTL.Txt
2013-06-24 18:12 - 2013-06-24 18:12 - 00036094 ____A C:\Users\Intersell\Downloads\Extras.Txt
2013-06-24 18:10 - 2013-06-24 18:10 - 00051548 ____A C:\Users\Intersell\Downloads\OTL.Txt
2013-06-24 17:58 - 2013-06-24 17:58 - 00602112 ____A (OldTimer Tools) C:\Users\Intersell\Downloads\OTL.exe
2013-06-24 17:57 - 2013-06-24 17:57 - 00000480 ____A C:\Windows\System32\defogger_disable.log
2013-06-24 17:57 - 2009-10-01 13:54 - 00000000 ____D C:\users\Verwalter
2013-06-24 17:56 - 2013-06-24 17:56 - 00050477 ____A C:\Users\Intersell\Downloads\Defogger.exe
2013-06-24 17:53 - 2013-06-24 17:53 - 00016739 ____A C:\Users\Intersell\Desktop\get-mirror-server.html
2013-06-24 16:50 - 2010-09-29 12:39 - 30729303 ____A C:\immudebug.log
2013-06-24 16:21 - 2009-10-01 17:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-06-24 16:19 - 2010-04-10 20:48 - 00000000 ____D C:\Windows\Minidump
2013-06-24 16:16 - 2011-01-05 18:41 - 00000804 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-24 16:16 - 2009-10-01 18:18 - 00000000 ____D C:\Program Files\CCleaner
2013-06-21 08:35 - 2011-07-05 15:42 - 00001971 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-21 08:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-06-20 07:51 - 2013-01-17 11:42 - 00000000 ____D C:\Windows\System32\Drivers\NIS
2013-06-20 07:50 - 2013-01-17 11:44 - 00002213 ____A C:\Users\Public\Desktop\Norton Internet Security.lnk
2013-06-19 08:44 - 2013-01-17 11:44 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-19 08:44 - 2013-01-17 11:44 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-13 07:53 - 2012-07-17 17:03 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-06-12 21:06 - 2013-06-12 21:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(2).exe
2013-06-12 17:08 - 2013-06-12 17:08 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68(1).exe
2013-06-12 17:01 - 2013-06-12 17:01 - 00329344 ____A C:\Users\Intersell\Downloads\lshunterApps_Install68.exe
2013-06-12 15:29 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-12 15:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-12 14:46 - 2009-10-01 13:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-06-12 14:43 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2013-06-12 10:27 - 2013-02-18 11:14 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-12 10:27 - 2013-02-18 11:14 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-11 14:23 - 2009-10-01 13:38 - 00002631 ____A C:\Users\Intersell\Desktop\Microsoft Office Word 2007.lnk
2013-06-09 22:41 - 2010-02-02 13:22 - 00000000 ____D C:\Users\Intersell\AppData\Local\CrashDumps
2013-06-07 20:52 - 2013-06-07 20:52 - 01488280 ____A (Bandoo Media Inc) C:\Users\Intersell\Downloads\iLividSetup-r341-n-bf.exe
2013-06-01 19:33 - 2013-06-01 19:33 - 00727616 ____A () C:\Users\Intersell\Downloads\BestCodecsPackSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
Results of screen317's Security Check version 0.99.68
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Norton Internet Security
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
CCleaner
JavaFX 2.1.1
Java 7 Update 21
Java(TM) 6 Update 7
Java version out of Date!
Adobe Flash Player 11.7.700.224
Mozilla Firefox 21.0
Firefox out of Date!
Google Chrome 27.0.1453.110
Google Chrome 27.0.1453.116
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Spybot Teatimer.exe is disabled! `````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
Ich hoffe, ich habe alles richtig gemacht. Der ESET Scanner findet den blöden Trojaner auch, d.h. er ist immer noch da...
Was macht der eigentlich?
Tausend Dank und Grüße!