Hallo schrauber,
nun folgen die vier Logdateien:
Combofix Code:
ComboFix 13-06-28.01 - kim 28.06.2013 19:54:23.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.1771.866 [GMT 2:00]
ausgeführt von:: c:\users\kim\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\kim\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-05-28 bis 2013-06-28 ))))))))))))))))))))))))))))))
.
.
2013-06-28 18:08 . 2013-06-28 18:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-28 17:50 . 2013-06-28 17:50 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6C42906F-6AA3-4154-8E36-6F0836EB88BA}\offreg.dll
2013-06-28 15:19 . 2013-06-28 15:19 -------- d-----w- C:\FRST
2013-06-28 13:56 . 2013-06-28 17:48 -------- d-----w- c:\users\kim\AppData\Roaming\Ibpe
2013-06-28 13:56 . 2013-06-28 13:56 -------- d-----w- c:\users\kim\AppData\Roaming\Ucolon
2013-06-28 13:56 . 2013-06-28 13:56 -------- d-----w- c:\users\kim\AppData\Roaming\Ipcyda
2013-06-28 06:13 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6C42906F-6AA3-4154-8E36-6F0836EB88BA}\mpengine.dll
2013-06-25 08:30 . 2013-06-25 08:30 -------- d-----w- c:\users\Default\AppData\Local\Google
2013-06-18 14:51 . 2013-06-18 14:55 -------- d-----w- c:\users\kim\AppData\Roaming\Aquamarin Haushaltsbuch
2013-06-18 14:49 . 2000-05-22 14:58 115920 ----a-w- c:\windows\SysWow64\msinet.ocx
2013-06-18 14:49 . 1998-06-17 22:00 16896 ----a-w- c:\windows\SysWow64\ODKOB32.DLL
2013-06-18 14:49 . 1998-06-17 22:00 32768 ----a-w- c:\windows\SysWow64\RACREG32.DLL
2013-06-13 04:27 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-06-13 04:27 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-06-13 04:27 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-13 04:27 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-06-13 04:27 . 2013-04-26 04:55 492544 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-06-13 04:27 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-06-13 04:27 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-06-13 04:26 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-06-13 04:26 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-06-13 04:26 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-06-13 04:26 . 2013-05-13 05:51 1464320 ----a-w- c:\windows\system32\crypt32.dll
2013-06-13 04:26 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-06-13 04:26 . 2013-05-13 05:51 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-13 04:26 . 2013-05-13 05:51 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-13 04:26 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-06-13 04:26 . 2013-05-13 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-06-13 04:26 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-06-13 04:26 . 2013-05-13 04:45 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-06-13 04:26 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-06-04 13:23 . 2013-06-27 19:28 -------- d-----w- c:\program files (x86)\Google
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 17:34 . 2012-08-01 08:39 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 17:34 . 2011-07-23 12:56 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-09 16:53 . 2010-06-24 18:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-03 00:12 . 2013-05-03 00:12 0 ----a-w- c:\windows\SysWow64\sho691E.tmp
2013-05-02 21:12 . 2013-05-02 21:12 0 ----a-w- c:\windows\SysWow64\sho59DB.tmp
2013-05-02 00:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-04-25 10:47 . 2013-04-25 10:47 0 ----a-w- c:\windows\SysWow64\shoD3E6.tmp
2013-04-13 05:49 . 2013-05-15 06:31 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 06:31 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 06:31 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 06:31 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 06:31 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 06:31 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-24 06:54 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 20:16 . 2013-04-10 20:16 0 ----a-w- c:\windows\SysWow64\sho81B7.tmp
2013-04-10 06:01 . 2013-05-15 06:31 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 06:31 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-15 06:28 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-04-01 06:03 . 2013-05-15 06:29 78680 ----a-w- c:\windows\system32\mcupdate_AuthenticAMD.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1ce76c93-a797-4ca2-ab3c-f4a6cfba3440}"= "c:\program files (x86)\GIGA_Deutsch\prxtbGIGA.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{1ce76c93-a797-4ca2-ab3c-f4a6cfba3440}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{1ce76c93-a797-4ca2-ab3c-f4a6cfba3440}]
2011-05-09 09:49 176936 ----a-w- c:\program files (x86)\GIGA_Deutsch\prxtbGIGA.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{1DAF9C15-2FC6-01F9-09FB-1068E649B41D}]
2013-03-31 11:38 118272 ----a-w- c:\programdata\Broowsee2sAAvye\51582025b329e.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{60B264D1-C7A0-10AF-47F4-DB516C74F178}]
2013-03-31 11:38 118272 ----a-w- c:\programdata\Seuarceh-NewwTabi\515820464a9e5.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{1ce76c93-a797-4ca2-ab3c-f4a6cfba3440}"= "c:\program files (x86)\GIGA_Deutsch\prxtbGIGA.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{1ce76c93-a797-4ca2-ab3c-f4a6cfba3440}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\kim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\kim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\kim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Embulyim"="c:\users\kim\AppData\Roaming\Ipcyda\tuuco.exe" [2012-01-25 295424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-09-28 340336]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-09-17 407920]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-09-17 201584]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"BackupManagerTray"="c:\program files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" [2011-02-15 297280]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-03-31 1092688]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-11 336384]
"ArcadeMovieService"="c:\program files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe" [2011-02-18 177448]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2012-03-30 296056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216]
.
c:\users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\kim\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe [2013-2-23 1393744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 CxAudMsg;CxAudMsg;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
S2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe;c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe [x]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-28 c:\windows\Tasks\AbelssoftPreloader.job
- c:\program files (x86)\WashAndGo\AbelssoftPreloader.exe [2012-07-14 08:00]
.
2013-06-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-01 17:34]
.
2013-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-04 13:23]
.
2013-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-04 13:23]
.
2013-06-20 c:\windows\Tasks\ReclaimerUpdateFiles_kim.job
- c:\users\kim\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe [2013-06-18 06:00]
.
2013-06-28 c:\windows\Tasks\ReclaimerUpdateXML_kim.job
- c:\users\kim\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe [2013-06-18 06:00]
.
2013-06-28 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_kim.job
- c:\users\kim\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe [2013-06-18 06:00]
.
2013-06-28 c:\windows\Tasks\schedule!3036567561.job
- c:\programdata\BetterSoft\OptimizerPro\OptimizerPro.exe [2013-03-31 19:58]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\kim\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\kim\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\kim\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\kim\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"Power Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-02-22 1796200]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://sz.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.11.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file)
AddRemove-Adobe Photoshop 6.0 - c:\windows\ISUN0407.EXE
AddRemove-Adobe SVG Viewer - c:\windows\IsUn0407.exe
AddRemove-Firebird SQL Server D - c:\program files (x86)\MAGIX\Common\Database\unwise.exe
AddRemove-MAGIX 3D Maker D - c:\program files (x86)\MAGIX\Common\3D_Maker_embeded\unwise.exe
AddRemove-MAGIX Screenshare D - c:\program files (x86)\MAGIX\PCVisit\unwise.exe
AddRemove-MAGIX Speed 2 D - c:\program files (x86)\MAGIX\Speed2_burnR_mxcdr\unwise.exe
AddRemove-MAGIX Video deluxe 15 Plus D - c:\program files (x86)\MAGIX\Video_deluxe_15_Plus\unwise.exe
AddRemove-MAGIX Xtreme Foto Designer 6 D - c:\program files (x86)\MAGIX\Xtreme_Foto_Designer_6\unwise.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-06-28 20:15:44
ComboFix-quarantined-files.txt 2013-06-28 18:15
ComboFix2.txt 2013-06-28 17:17
.
Vor Suchlauf: 8.475.037.696 Bytes frei
Nach Suchlauf: 8.280.080.384 Bytes frei
.
- - End Of File - - 7423B329E2C200B7C6712973A2294210
A36C5E4F47E84449FF07ED3517B43A31 ADWCleaner Code:
# AdwCleaner v2.303 - Datei am 28/06/2013 um 20:22:52 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : kim - KIM-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\kim\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
Datei Gelöscht : C:\user.js
Datei Gelöscht : C:\Users\kim\Desktop\eBay.lnk
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\GIGA_Deutsch
Ordner Gelöscht : C:\Program Files (x86)\Moozy
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\WebSearch
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BetterSoft
Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\ProgramData\Broowsee2sAAvye
Ordner Gelöscht : C:\ProgramData\InstallMate
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broowsee2sAAvye
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seuarceh-NewwTabi
Ordner Gelöscht : C:\ProgramData\Seuarceh-NewwTabi
Ordner Gelöscht : C:\ProgramData\SoftSafe
Ordner Gelöscht : C:\Users\kim\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gelembmjdacegpjoefdmebemendjbdkf
Ordner Gelöscht : C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmhmlblpemcphkcmpooghckjhbecbehl
Ordner Gelöscht : C:\Users\kim\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\kim\AppData\LocalLow\Broowsee2sAAvye
Ordner Gelöscht : C:\Users\kim\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\kim\AppData\LocalLow\GIGA_Deutsch
Ordner Gelöscht : C:\Users\kim\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\kim\AppData\LocalLow\Seuarceh-NewwTabi
Ordner Gelöscht : C:\Users\kim\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\kim\AppData\Roaming\NCdownloader
Ordner Gelöscht : C:\Users\kim\AppData\Roaming\pdfforge
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\GIGA_Deutsch
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\SProtector
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1DAF9C15-2FC6-01F9-09FB-1068E649B41D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{60B264D1-C7A0-10AF-47F4-DB516C74F178}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1DAF9C15-2FC6-01F9-09FB-1068E649B41D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{60B264D1-C7A0-10AF-47F4-DB516C74F178}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2967869
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3196716
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\GIGA_Deutsch
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4A1D7487-9A11-4E1F-8215-F14C94CCC7FF}
Schlüssel Gelöscht : HKLM\Software\SP Global
Schlüssel Gelöscht : HKLM\Software\SProtector
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{14F35FFC-522A-4DD1-A07E-6B8B65C6891E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1DAF9C15-2FC6-01F9-09FB-1068E649B41D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4A1D7487-9A11-4E1F-8215-F14C94CCC7FF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{60B264D1-C7A0-10AF-47F4-DB516C74F178}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{27385776-543D-4CB6-8F8F-3C46DD7E0C48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A320234E-656A-44BA-9E22-0BC6BDF37D2B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DAF9C15-2FC6-01F9-09FB-1068E649B41D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60B264D1-C7A0-10AF-47F4-DB516C74F178}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GIGA_Deutsch Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OptimizerPro
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440}]
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16618
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Google Chrome v [Version kann nicht ermittelt werden]
Datei : C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Preferences
Gelöscht [l.167] : homepage = "hxxp://websearch.pu-results.info/?pid=724&r=2013/03/31&hid=1454618593&lg=EN&cc=DE",
*************************
AdwCleaner[S1].txt - [8475 octets] - [28/06/2013 20:22:52]
########## EOF - C:\AdwCleaner[S1].txt - [8535 octets] ########## JRT Editor Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by kim on 28.06.2013 at 21:00:06,92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho1074.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho23C9.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho25C6.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2971.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho29AD.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2BA1.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3742.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho5253.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho59DB.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho691E.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho81B7.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8B97.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoD3E6.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoD931.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoEB4C.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF05D.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF8F.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\big fish games"
Successfully deleted: [Folder] "C:\Users\kim\appdata\local\software"
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{03DF3A85-B729-4C18-B677-8ED35F21ABC7}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{061E31F1-618B-4636-943B-C26DB8976E37}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{087C53D0-B656-47B0-8B92-161E9EA4CFB2}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{27E1943B-02B7-42F9-B48D-03A1A8B6874C}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{2884E199-09B1-4CCF-AA21-420AB1FA1916}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{2D4FCE83-4947-4B91-AC42-B7502A380139}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{370AF00A-8DC3-47EF-B4D1-3E493B133CAA}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{374E41A1-547C-4BF5-AD14-2F519CA25A1F}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{3C509CF8-736E-44AD-A60D-AC5172DD5F5E}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{3D1F8A9A-6651-49B2-B24F-CEC05375D0F5}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{42A8B7B2-5BF2-4DD6-9C9A-0C03151B93C0}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{62A58D65-693F-481F-8203-2B99CC39C164}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{634C18E1-9A7F-4069-8117-7B8E41C4E145}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{6C94AB6E-F144-4322-B0CD-A2C999E751CE}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{6D1C030F-34D3-4BEB-9EAA-B7674D7BA0D7}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{81978A42-3A03-4AC0-862E-0C14632FA3BE}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{8BDC5F5F-8BC0-4DCD-99A4-F94C1D923869}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{8E011EA6-56EE-4FDF-ADCF-3ED79E536C59}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{90D1E228-D9CC-4198-9B74-ADC90284AA08}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{976EC687-A746-495B-A42C-DA2AC2C6A47C}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{9D6574C2-B975-4379-BE43-42ADF50F0BDF}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{A3322CDC-5BDB-475F-8C18-29DE342BE5F1}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{A84DE924-27D3-4508-980E-9C40F2A63429}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{BC8DB6E7-8F59-40E1-BB0F-9C60CCE43093}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{BE006751-34CC-4415-93EF-AEC3F81B191E}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{C821FC4B-9470-4070-AAB4-105A2DB9741D}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{CBA31AA1-B9E3-4DC4-BDAA-E95FF5ADB1C9}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{CD0B09CF-C45A-4BD7-9746-72A2B27979EC}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{D52519BA-93D6-459B-94BB-43666637301A}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{E898A258-F1BD-4324-B76A-6710F87EE90F}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{F0CB019F-B347-4B48-AAD4-63A114DAEB55}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{F1F43096-CF81-4061-9A7A-0D486DA37044}
Successfully deleted: [Empty Folder] C:\Users\kim\appdata\local\{F6776559-9E12-438F-A4C6-7041D9C938A1}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.06.2013 at 21:13:32,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ neues FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-06-2013
Ran by kim (administrator) on 28-06-2013 21:15:11
Running from C:\Users\kim\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Microsoft) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\kim\AppData\Roaming\Ipcyda\tuuco.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Dropbox, Inc.) C:\Users\kim\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated)
HKCU\...\Run: [Embulyim] C:\Users\kim\AppData\Roaming\Ipcyda\tuuco.exe [295424 2012-01-25] (The OpenSSL Project, hxxp://www.openssl.org/)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [340336 2010-09-28] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [407920 2010-09-18] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d [201584 2010-09-18] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" -h -k [297280 2011-02-15] (NTI Corporation)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [1092688 2011-03-31] (Dritek System Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-01-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] "C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe" [177448 2011-02-18] (CyberLink Corp.)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1230704 2011-03-21] ()
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot [296056 2012-03-30] (RealNetworks, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKU\Default\...\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} [x]
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
HKU\Default User\...\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} [x]
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe ()
Startup: C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\kim\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://sz.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
DPF: HKLM {615A1925-0E5B-4767-A65E-3165AEAC32A3} hxxp://quickscan.bitdefender.com/qsax/qsax64.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
==================== Services (Whitelisted) =================
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [8704 2011-11-23] (Microsoft)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2010-08-20] ()
S2 CxAudMsg; C:\Windows\system32\CxAudMsg64.exe [x]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe [x]
S2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [x]
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [279616 2012-01-13] (DT Soft Ltd)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-28 21:13 - 2013-06-28 21:13 - 00005246 ____A C:\Users\kim\Desktop\JRT.txt
2013-06-28 20:59 - 2013-06-28 20:59 - 00000000 ____D C:\Windows\ERUNT
2013-06-28 20:59 - 2013-06-28 20:59 - 00000000 ____D C:\JRT
2013-06-28 20:58 - 2013-06-28 20:58 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\kim\Desktop\JRT.exe
2013-06-28 20:22 - 2013-06-28 20:23 - 00008594 ____A C:\AdwCleaner[S1].txt
2013-06-28 20:22 - 2013-06-28 20:22 - 00648201 ____A C:\Users\kim\Desktop\adwcleaner.exe
2013-06-28 20:15 - 2013-06-28 20:15 - 00024500 ____A C:\ComboFix.txt
2013-06-28 19:46 - 2013-06-28 19:46 - 05083661 ____R (Swearware) C:\Users\kim\Desktop\ComboFix.exe
2013-06-28 18:35 - 2013-06-28 20:15 - 00000000 ____D C:\Qoobox
2013-06-28 18:35 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-06-28 18:35 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-06-28 18:35 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-06-28 18:35 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-06-28 18:35 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-06-28 18:35 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-06-28 18:35 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-06-28 18:35 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-06-28 18:33 - 2013-06-28 19:11 - 00000000 ____D C:\Windows\erdnt
2013-06-28 17:23 - 2013-06-28 17:25 - 00026690 ____A C:\Users\kim\Desktop\Addition.txt
2013-06-28 17:19 - 2013-06-28 17:19 - 00000000 ____D C:\FRST
2013-06-28 17:17 - 2013-06-28 17:17 - 01933484 ____A (Farbar) C:\Users\kim\Desktop\FRST64.exe
2013-06-28 15:56 - 2013-06-28 19:48 - 00000000 ____D C:\Users\kim\AppData\Roaming\Ibpe
2013-06-28 15:56 - 2013-06-28 15:56 - 00000000 ____D C:\Users\kim\AppData\Roaming\Ucolon
2013-06-28 15:56 - 2013-06-28 15:56 - 00000000 ____D C:\Users\kim\AppData\Roaming\Ipcyda
2013-06-28 15:53 - 2013-06-28 15:53 - 00016190 ____A C:\Users\kim\Desktop\gmer.txt
2013-06-28 14:05 - 2013-06-28 14:05 - 00377856 ____A C:\Users\kim\Desktop\gmer_2.1.19163.exe
2013-06-27 22:40 - 2013-06-27 22:40 - 00125356 ____A C:\Users\kim\Desktop\Extras.Txt
2013-06-27 22:33 - 2013-06-27 22:33 - 00094436 ____A C:\Users\kim\Desktop\OTL.Txt
2013-06-27 22:10 - 2013-06-27 22:10 - 00602112 ____A (OldTimer Tools) C:\Users\kim\Desktop\OTL.exe
2013-06-27 22:09 - 2013-06-27 22:09 - 00000538 ____A C:\Users\kim\Desktop\defogger_disable.log
2013-06-27 22:09 - 2013-06-27 22:09 - 00000168 ____A C:\Users\kim\defogger_reenable
2013-06-27 22:08 - 2013-06-27 22:08 - 00050477 ____A C:\Users\kim\Desktop\Defogger.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-26 09:58 - 2013-06-26 09:58 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-26 09:58 - 2013-06-26 09:58 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-26 09:58 - 2013-06-26 09:58 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-06-26 09:58 - 2013-06-26 09:58 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-06-26 09:58 - 2013-06-26 09:58 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-06-26 09:58 - 2013-06-26 09:58 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2013-06-26 09:58 - 2013-06-26 09:58 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-06-26 09:58 - 2013-06-26 09:58 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-06-26 09:58 - 2013-06-26 09:58 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-06-26 09:58 - 2013-06-26 09:58 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-06-26 09:49 - 2013-06-26 10:12 - 00010557 ____A C:\Windows\IE10_main.log
2013-06-25 10:31 - 2013-06-25 10:31 - 00000000 ____D C:\Users\Default\AppData\LocalGoogle
2013-06-25 10:31 - 2013-06-25 10:31 - 00000000 ____D C:\Users\Default User\AppData\LocalGoogle
2013-06-25 10:30 - 2013-06-25 10:30 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2013-06-25 10:30 - 2013-06-25 10:30 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2013-06-20 20:50 - 2013-06-20 20:50 - 237536326 ____A C:\Windows\MEMORY.DMP
2013-06-20 20:50 - 2013-06-20 20:50 - 01700936 ____A C:\Windows\Minidump\062013-26130-01.dmp
2013-06-20 20:50 - 2013-06-20 20:50 - 00000000 ____D C:\Windows\Minidump
2013-06-18 16:51 - 2013-06-18 16:55 - 00000000 ____D C:\Users\kim\AppData\Roaming\Aquamarin Haushaltsbuch
2013-06-18 16:49 - 2000-05-22 16:58 - 00115920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msinet.ocx
2013-06-18 16:49 - 1998-06-18 00:00 - 00032768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RACREG32.DLL
2013-06-18 16:49 - 1998-06-18 00:00 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ODKOB32.DLL
2013-06-18 13:20 - 2013-06-28 20:52 - 00000368 ____A C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_kim.job
2013-06-18 13:20 - 2013-06-28 09:49 - 00000358 ____A C:\Windows\Tasks\ReclaimerUpdateXML_kim.job
2013-06-18 13:20 - 2013-06-20 12:30 - 00000362 ____A C:\Windows\Tasks\ReclaimerUpdateFiles_kim.job
2013-06-13 06:27 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-13 06:27 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-13 06:27 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 06:27 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-13 06:27 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-13 06:27 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-13 06:27 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-13 06:26 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 06:26 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 06:26 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 06:26 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-13 06:26 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 06:26 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-13 06:26 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 06:26 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 06:26 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 06:26 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-13 06:26 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-13 06:26 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-04 15:26 - 2013-06-04 15:26 - 00000000 ____D C:\Users\kim\AppData\LocalGoogle
2013-06-04 15:23 - 2013-06-28 20:51 - 00001100 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-04 15:23 - 2013-06-28 20:28 - 00001104 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-04 15:23 - 2013-06-27 21:28 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-04 15:03 - 2013-06-04 15:03 - 00781760 ____A (Google Inc.) C:\Users\kim\Downloads\googledrivesync.exe
2013-06-04 14:54 - 2013-06-27 21:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2013-06-28 21:13 - 2013-06-28 21:13 - 00005246 ____A C:\Users\kim\Desktop\JRT.txt
2013-06-28 21:00 - 2009-07-14 06:45 - 00016752 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-28 21:00 - 2009-07-14 06:45 - 00016752 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-28 20:59 - 2013-06-28 20:59 - 00000000 ____D C:\Windows\ERUNT
2013-06-28 20:59 - 2013-06-28 20:59 - 00000000 ____D C:\JRT
2013-06-28 20:58 - 2013-06-28 20:58 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\kim\Desktop\JRT.exe
2013-06-28 20:54 - 2012-10-14 11:41 - 00000000 ___RD C:\Users\kim\Dropbox
2013-06-28 20:54 - 2012-10-14 11:36 - 00000000 ____D C:\Users\kim\AppData\Roaming\Dropbox
2013-06-28 20:53 - 2011-07-01 00:46 - 00000000 ____D C:\ProgramData\clear.fi
2013-06-28 20:52 - 2013-06-18 13:20 - 00000368 ____A C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_kim.job
2013-06-28 20:51 - 2013-06-04 15:23 - 00001100 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-28 20:51 - 2013-03-31 13:03 - 00000412 ___AH C:\Windows\Tasks\schedule!3036567561.job
2013-06-28 20:51 - 2012-07-14 18:06 - 00051398 ____A C:\Windows\setupact.log
2013-06-28 20:51 - 2012-07-14 18:06 - 00033950 ____A C:\Windows\PFRO.log
2013-06-28 20:51 - 2012-07-14 14:47 - 00000274 ____A C:\Windows\Tasks\AbelssoftPreloader.job
2013-06-28 20:51 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-28 20:50 - 2012-07-14 18:09 - 01220790 ____A C:\Windows\WindowsUpdate.log
2013-06-28 20:34 - 2012-10-30 19:26 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-28 20:28 - 2013-06-04 15:23 - 00001104 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-28 20:23 - 2013-06-28 20:22 - 00008594 ____A C:\AdwCleaner[S1].txt
2013-06-28 20:22 - 2013-06-28 20:22 - 00648201 ____A C:\Users\kim\Desktop\adwcleaner.exe
2013-06-28 20:15 - 2013-06-28 20:15 - 00024500 ____A C:\ComboFix.txt
2013-06-28 20:15 - 2013-06-28 18:35 - 00000000 ____D C:\Qoobox
2013-06-28 20:08 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-06-28 19:48 - 2013-06-28 15:56 - 00000000 ____D C:\Users\kim\AppData\Roaming\Ibpe
2013-06-28 19:46 - 2013-06-28 19:46 - 05083661 ____R (Swearware) C:\Users\kim\Desktop\ComboFix.exe
2013-06-28 19:11 - 2013-06-28 18:33 - 00000000 ____D C:\Windows\erdnt
2013-06-28 19:05 - 2009-07-14 04:34 - 75235328 ____A C:\Windows\System32\config\software.bak
2013-06-28 19:05 - 2009-07-14 04:34 - 16515072 ____A C:\Windows\System32\config\system.bak
2013-06-28 19:05 - 2009-07-14 04:34 - 00524288 ____A C:\Windows\System32\config\default.bak
2013-06-28 19:05 - 2009-07-14 04:34 - 00262144 ____A C:\Windows\System32\config\security.bak
2013-06-28 19:05 - 2009-07-14 04:34 - 00262144 ____A C:\Windows\System32\config\sam.bak
2013-06-28 18:28 - 2013-04-25 12:35 - 00000000 ____D C:\Windows\rescache
2013-06-28 17:25 - 2013-06-28 17:23 - 00026690 ____A C:\Users\kim\Desktop\Addition.txt
2013-06-28 17:19 - 2013-06-28 17:19 - 00000000 ____D C:\FRST
2013-06-28 17:17 - 2013-06-28 17:17 - 01933484 ____A (Farbar) C:\Users\kim\Desktop\FRST64.exe
2013-06-28 15:56 - 2013-06-28 15:56 - 00000000 ____D C:\Users\kim\AppData\Roaming\Ucolon
2013-06-28 15:56 - 2013-06-28 15:56 - 00000000 ____D C:\Users\kim\AppData\Roaming\Ipcyda
2013-06-28 15:53 - 2013-06-28 15:53 - 00016190 ____A C:\Users\kim\Desktop\gmer.txt
2013-06-28 14:05 - 2013-06-28 14:05 - 00377856 ____A C:\Users\kim\Desktop\gmer_2.1.19163.exe
2013-06-28 13:48 - 2011-11-23 22:54 - 00000000 ____A C:\sniffer.log
2013-06-28 09:49 - 2013-06-18 13:20 - 00000358 ____A C:\Windows\Tasks\ReclaimerUpdateXML_kim.job
2013-06-28 00:25 - 2011-07-01 21:05 - 00000000 ____D C:\Users\kim\AppData\Roaming\SoftGrid Client
2013-06-27 22:40 - 2013-06-27 22:40 - 00125356 ____A C:\Users\kim\Desktop\Extras.Txt
2013-06-27 22:33 - 2013-06-27 22:33 - 00094436 ____A C:\Users\kim\Desktop\OTL.Txt
2013-06-27 22:10 - 2013-06-27 22:10 - 00602112 ____A (OldTimer Tools) C:\Users\kim\Desktop\OTL.exe
2013-06-27 22:09 - 2013-06-27 22:09 - 00000538 ____A C:\Users\kim\Desktop\defogger_disable.log
2013-06-27 22:09 - 2013-06-27 22:09 - 00000168 ____A C:\Users\kim\defogger_reenable
2013-06-27 22:09 - 2011-07-01 00:19 - 00000000 ____D C:\users\kim
2013-06-27 22:08 - 2013-06-27 22:08 - 00050477 ____A C:\Users\kim\Desktop\Defogger.exe
2013-06-27 21:39 - 2013-06-04 14:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-27 21:38 - 2012-11-12 14:52 - 00000000 ____D C:\Users\kim\AppData\Roaming\Mozilla
2013-06-27 21:35 - 2011-09-15 16:22 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-06-27 21:28 - 2013-06-04 15:23 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-27 21:28 - 2013-03-31 13:03 - 00000000 ____D C:\Users\kim\AppData\Local\Google
2013-06-27 09:50 - 2011-05-13 07:36 - 07150410 ____A C:\Windows\System32\perfh007.dat
2013-06-27 09:50 - 2011-05-13 07:36 - 02214500 ____A C:\Windows\System32\perfc007.dat
2013-06-27 09:50 - 2009-07-14 07:13 - 00006744 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-26 13:04 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-06-26 10:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-06-26 10:12 - 2013-06-26 09:49 - 00010557 ____A C:\Windows\IE10_main.log
2013-06-26 09:58 - 2013-06-26 09:58 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-26 09:58 - 2013-06-26 09:58 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-26 09:58 - 2013-06-26 09:58 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-26 09:58 - 2013-06-26 09:58 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-06-26 09:58 - 2013-06-26 09:58 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-06-26 09:58 - 2013-06-26 09:58 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-06-26 09:58 - 2013-06-26 09:58 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2013-06-26 09:58 - 2013-06-26 09:58 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-06-26 09:58 - 2013-06-26 09:58 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-06-26 09:58 - 2013-06-26 09:58 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-06-26 09:58 - 2013-06-26 09:58 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-06-26 09:58 - 2013-06-26 09:58 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-06-26 09:58 - 2013-06-26 09:58 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-06-25 10:31 - 2013-06-25 10:31 - 00000000 ____D C:\Users\Default\AppData\LocalGoogle
2013-06-25 10:31 - 2013-06-25 10:31 - 00000000 ____D C:\Users\Default User\AppData\LocalGoogle
2013-06-25 10:30 - 2013-06-25 10:30 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2013-06-25 10:30 - 2013-06-25 10:30 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2013-06-22 22:03 - 2011-07-03 19:53 - 00000000 ____D C:\Users\kim\AppData\Roaming\Skype
2013-06-20 20:50 - 2013-06-20 20:50 - 237536326 ____A C:\Windows\MEMORY.DMP
2013-06-20 20:50 - 2013-06-20 20:50 - 01700936 ____A C:\Windows\Minidump\062013-26130-01.dmp
2013-06-20 20:50 - 2013-06-20 20:50 - 00000000 ____D C:\Windows\Minidump
2013-06-20 12:30 - 2013-06-18 13:20 - 00000362 ____A C:\Windows\Tasks\ReclaimerUpdateFiles_kim.job
2013-06-18 16:55 - 2013-06-18 16:51 - 00000000 ____D C:\Users\kim\AppData\Roaming\Aquamarin Haushaltsbuch
2013-06-14 08:00 - 2011-09-15 16:30 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-06-12 19:34 - 2012-08-01 10:39 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 19:34 - 2011-07-23 14:56 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-07 13:04 - 2012-10-14 11:41 - 00001013 ____A C:\Users\kim\Desktop\Dropbox.lnk
2013-06-04 16:39 - 2013-02-03 21:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-06-04 16:39 - 2011-03-25 07:21 - 00000000 ____D C:\ProgramData\Skype
2013-06-04 15:26 - 2013-06-04 15:26 - 00000000 ____D C:\Users\kim\AppData\LocalGoogle
2013-06-04 15:26 - 2012-03-16 16:33 - 00000000 ____D C:\Users\kim\Downloads\Versicherungen
2013-06-04 15:26 - 2011-10-15 20:28 - 00156672 __ASH C:\Users\kim\Downloads\Thumbs.db
2013-06-04 15:03 - 2013-06-04 15:03 - 00781760 ____A (Google Inc.) C:\Users\kim\Downloads\googledrivesync.exe
2013-06-02 18:59 - 2011-09-21 10:13 - 00000000 ____D C:\Users\kim\Allerlei
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-23 16:24
==================== End Of Log ============================ --- --- ---
--- --- ---
Schöne Grüße und bis bald:-) |