Malwarebytes Anti-Malware (Test) 1.75.0.1300
Malwarebytes : Free anti-malware download
Datenbank Version: v2013.07.15.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
XX XXX :: XXX-08A189669 [Administrator]
Schutz: Aktiviert
15.07.2013 23:13:49
mbam-log-2013-07-15 (23-13-49).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 272474
Laufzeit: 4 Stunde(n), 23 Minute(n), 44 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
Malwarebytes:
HTML-Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.07.15.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
XX XXX :: XXX-08A189669 [Administrator]
Schutz: Aktiviert
15.07.2013 23:13:49
mbam-log-2013-07-15 (23-13-49).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 272474
Laufzeit: 4 Stunde(n), 23 Minute(n), 44 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
AdwCleaner:AdwCleaner Logfile:
Code:
# AdwCleaner v2.305 - Datei am 16/07/2013 um 06:55:17 erstellt
# Aktualisiert am 11/07/2013 von Xplode
# Betriebssystem : Microsoft Windows XP Service Pack 3 (32 bits)
# Benutzer : XX XXX - XXX-08A189669
# Bootmodus : Normal
# Ausgeführt unter : C:\Dokumente und Einstellungen\XX XXX\Eigene Dateien\ProgWeb\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\WINDOWS\system32\roboot.exe
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Schlüssel Gelöscht : HKLM\Software\systweak
***** [Internet Browser] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v22.0 (de)
Datei : C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Mozilla\Firefox\Profiles\qpolfghd.default\prefs.js
[OK] Die Datei ist sauber.
-\\ Google Chrome v28.0.1500.72
Datei : C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [1493 octets] - [16/07/2013 06:55:17]
########## EOF - C:\AdwCleaner[S1].txt - [1553 octets] ##########
--- --- ---
JRT:JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.1.1 (07.15.2013:2)
OS: Microsoft Windows XP x86
Ran by XX XXX on 16.07.2013 at 8:24:31,59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\systweak"
Successfully deleted: [Folder] "C:\Programme\eusing free registry cleaner"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.07.2013 at 8:28:26,14
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
Farbar:
Farbar Service Scanner Version: 13-07-2013
Ran by XX XXX (administrator) on 16-07-2013 at 08:33:42
Running from "C:\Dokumente und Einstellungen\XX XXX\Eigene Dateien\ProgWeb"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll
[2004-08-04 12:00] - [2008-04-14 08:52] - 0127488 ____A (Microsoft Corporation) C29A1C9B75BA38FA37F8C44405DEC360
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll
[2004-08-04 12:00] - [2009-04-20 19:17] - 0045568 ____A (Microsoft Corporation) 407F3227AC618FD1CA54B335B083DE07
C:\WINDOWS\system32\ipnathlp.dll
[2004-08-04 12:00] - [2008-04-14 08:52] - 0334336 ____A (Microsoft Corporation) CAD058D5F8B889A87CA3EB3CF624DCEF
C:\WINDOWS\system32\netman.dll
[2004-08-04 12:00] - [2008-04-14 08:52] - 0198144 ____A (Microsoft Corporation) E6D88F1F6745BF00B57E7855A2AB696C
C:\WINDOWS\system32\wbem\WMIsvc.dll
[2013-01-01 15:39] - [2008-04-14 08:52] - 0145408 ____A (Microsoft Corporation) 6F3F3973D97714CC5F906A19FE883729
C:\WINDOWS\system32\srsvc.dll
[2013-01-01 15:41] - [2008-04-14 08:52] - 0171520 ____A (Microsoft Corporation) FE77A85495065F3AD59C5C65B6C54182
C:\WINDOWS\system32\Drivers\sr.sys
[2013-01-01 15:41] - [2008-04-14 08:32] - 0073472 ____A (Microsoft Corporation) 50FA898F8C032796D3B1B9951BB5A90F
C:\WINDOWS\system32\wscsvc.dll
[2004-08-04 12:00] - [2008-04-14 08:52] - 0080896 ____A (Microsoft Corporation) 300B3E84FAF1A5C1F791C159BA28035D
C:\WINDOWS\system32\wbem\WMIsvc.dll
[2013-01-01 15:39] - [2008-04-14 08:52] - 0145408 ____A (Microsoft Corporation) 6F3F3973D97714CC5F906A19FE883729
C:\WINDOWS\system32\wuauserv.dll
[2013-01-01 15:42] - [2008-04-14 08:52] - 0006656 ____A (Microsoft Corporation) 7B4FE05202AA6BF9F4DFD0E6A0D8A085
C:\WINDOWS\system32\qmgr.dll
[2013-01-01 15:41] - [2008-04-14 08:52] - 0409088 ____A (Microsoft Corporation) D6F603772A789BB3228F310D650B8BD1
C:\WINDOWS\system32\es.dll
[2004-08-04 12:00] - [2008-07-07 22:26] - 0253952 ____A (Microsoft Corporation) AF4F6B5739D18CA7972AB53E091CBC74
C:\WINDOWS\system32\cryptsvc.dll
[2004-08-04 12:00] - [2008-04-14 08:52] - 0062464 ____A (Microsoft Corporation) 611F824E5C703A5A899F84C5F1699E4D
C:\WINDOWS\system32\svchost.exe
[2004-08-04 12:00] - [2008-04-14 08:53] - 0014336 ____A (Microsoft Corporation) 4FBC75B74479C7A6F829E0CA19DF3366
C:\WINDOWS\system32\rpcss.dll
[2004-08-04 12:00] - [2009-02-09 12:51] - 0401408 ____A (Microsoft Corporation) 3127AFBF2C1ED0AB14A1BBB7AAECB85B
C:\WINDOWS\system32\services.exe
[2004-08-04 12:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) A3EDBE9053889FB24AB22492472B39DC
Extra List:
=======
AegisP(13) Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x0C0000000500000001000000020000000300000004000000060000000700000008000000090000000A0000000B0000000D000000
IpSec Tag value is correct.
**** End of log ****
FRST:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-07-2013 02
Ran by XX XXX (administrator) on 16-07-2013 08:36:20
Running from C:\Dokumente und Einstellungen\XX XXX\Eigene Dateien\ProgWeb
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Intel Corporation ) C:\Programme\Intel\Wireless\Bin\S24EvMon.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Broadcom Corporation.) C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Intel Corporation) C:\Programme\Intel\Wireless\Bin\EvtEng.exe
(Google Inc.) C:\Programme\Google\Update\GoogleUpdate.exe
(Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Dell Inc) C:\Programme\Dell\QuickSet\quickset.exe
(Synaptics, Inc.) C:\Programme\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe
(Intel Corporation) C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe
(CANON INC.) C:\Programme\Canon\MyPrinter\BJMyPrt.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(SigmaTel, Inc.) C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe
(ATI Technologies Inc.) C:\Programme\ATI Technologies\ATI.ACE\cli.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
(Broadcom Corporation.) C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.exe
(Symantec Corporation) C:\Programme\Norton Identity Safe\Engine\2013.4.0.10\ccSvcHst.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.bin
(Dell Inc.) C:\Programme\Dell\QuickSet\NICCONFIGSVC.exe
(Intel Corporation) C:\Programme\Intel\Wireless\Bin\RegSrvc.exe
(Symantec Corporation) C:\Programme\Norton Identity Safe\Engine\2013.4.0.10\ccSvcHst.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Intel Corporation) C:\Programme\Intel\Wireless\Bin\Dot1XCfg.exe
(ATI Technologies Inc.) C:\Programme\ATI Technologies\ATI.ACE\cli.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\plugin-container.exe
(Farbar) C:\Dokumente und Einstellungen\XX XXX\Eigene Dateien\ProgWeb\FSS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Dell QuickSet] - C:\Programme\Dell\QuickSet\quickset.exe [1032192 2006-08-03] (Dell Inc)
HKLM\...\Run: [SynTPEnh] - C:\Programme\Synaptics\SynTP\SynTPEnh.exe [761947 2006-03-08] (Synaptics, Inc.)
HKLM\...\Run: [IntelZeroConfig] - "C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe" [995328 2007-10-08] (Intel Corporation)
HKLM\...\Run: [IntelWireless] - "C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless [1101824 2007-10-08] (Intel Corporation)
HKLM\...\Run: [CanonMyPrinter] - C:\Programme\Canon\MyPrinter\BJMyPrt.exe /logon [1603152 2007-04-04] (CANON INC.)
HKLM\...\Run: [Adobe ARM] - "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [SigmatelSysTrayApp] - %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe [x]
HKLM\...\Run: [ATICCC] - "C:\Programme\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay [45056 2006-01-02] (ATI Technologies Inc.)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKU\Administrator\...\Run: [Spybot-S&D Cleaning] - "C:\Programme\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [ 2012-11-13] (Safer-Networking Ltd.)
Startup: C:\Dokumente und Einstellungen\XX XXX\Startmenü\Programme\Autostart\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
StartMenuInternet: IEXPLORE.EXE - "C:\Programme\Internet Explorer\iexplore.exe"
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Programme\Norton Identity Safe\Engine\2013.4.0.10\coIEPlg.dll (Symantec Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Programme\Norton Identity Safe\Engine\2013.4.0.10\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1357054855812
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Mozilla\Firefox\Profiles\qpolfghd.default
FF Homepage: hxxp://www.spiegel.de/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Extension: DownloadHelper - C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Mozilla\Firefox\Profiles\qpolfghd.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: No Name - C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Mozilla\Firefox\Profiles\qpolfghd.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
FF Extension: Default - C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2013.4.0.10\coFFPlgn\
FF Extension: Norton Identity Safe Toolbar - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2013.4.0.10\coFFPlgn\
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Norton Identity Safe) - C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.1.1.4_0\npcoplgn.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Programme\QuickTime\plugins\npqtplugin.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Programme\QuickTime\plugins\npqtplugin2.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Programme\QuickTime\plugins\npqtplugin3.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Programme\QuickTime\plugins\npqtplugin4.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Programme\QuickTime\plugins\npqtplugin5.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Programme\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Programme\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft\u00AE DRM) - C:\Programme\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Programme\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - C:\Programme\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Dokumente und Einstellungen\XX XXX\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Programme\Google\Google Earth\plugin\npgeplugin.dll No File
CHR Plugin: (Picasa) - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (VLC Web Plugin) - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll No File
CHR Extension: (Google Drive) - C:\DOKUME~1\XXPR~1\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\DOKUME~1\XXPR~1\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\DOKUME~1\XXPR~1\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Norton Identity Protection) - C:\DOKUME~1\XXPR~1\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0
CHR Extension: (Gmail) - C:\DOKUME~1\XXPR~1\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
========================== Services (Whitelisted) =================
R2 btwdins; C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe [266295 2006-05-24] (Broadcom Corporation.)
R2 EvtEng; C:\Programme\Intel\Wireless\Bin\EvtEng.exe [794624 2007-10-08] (Intel Corporation)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2013-07-10] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2013-07-10] (Google Inc.)
S3 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [136120 2011-05-10] (Google)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [117144 2013-07-07] (Mozilla Foundation)
R2 NCO; C:\Programme\Norton Identity Safe\Engine\2013.4.0.10\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 NICCONFIGSVC; C:\Programme\Dell\QuickSet\NICCONFIGSVC.exe [380928 2006-08-03] (Dell Inc.)
R2 RegSrvc; C:\Programme\Intel\Wireless\Bin\RegSrvc.exe [483328 2007-10-08] (Intel Corporation)
R2 S24EventMonitor; C:\Programme\Intel\Wireless\Bin\S24EvMon.exe [1183744 2007-10-08] (Intel Corporation )
S2 SDScannerService; C:\Programme\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Programme\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Programme\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S2 WLANKEEPER; C:\Programme\Intel\Wireless\Bin\WLKeeper.exe [356352 2007-10-08] (Intel Corporation)
R2 JavaQuickStarterService; "C:\Programme\Java\jre7\bin\jqs.exe" -service -config "C:\Programme\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21361 2013-07-15] (Cisco Systems, Inc.)
R1 APPDRV; C:\Windows\SYSTEM32\DRIVERS\APPDRV.SYS [16128 2005-08-12] (Dell Inc)
R3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [1578496 2006-05-23] (ATI Technologies Inc.)
R3 btaudio; C:\Windows\System32\drivers\btaudio.sys [328237 2006-05-24] (Broadcom Corporation.)
S3 BTDriver; C:\Windows\System32\DRIVERS\btport.sys [30427 2006-05-24] (Broadcom Corporation.)
R3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [851434 2006-05-24] (Broadcom Corporation.)
R2 BTSERIAL; C:\WINDOWS\system32\drivers\btserial.sys [23271 2006-05-24] (Broadcom Corporation.)
S3 BTWDNDIS; C:\Windows\System32\DRIVERS\btwdndis.sys [148900 2006-05-24] (Broadcom Corporation.)
R3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [66488 2006-05-24] (Broadcom Corporation.)
R1 ccSet_NST; C:\Windows\system32\drivers\NST\7DD04000.00A\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 NETw4x32; C:\Windows\System32\DRIVERS\NETw4x32.sys [2236032 2007-09-26] (Intel Corporation)
R2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [12288 2007-08-27] (Intel Corporation)
R3 STHDA; C:\Windows\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.)
S3 catchme; \??\C:\DOKUME~1\XXPR~1\LOKALE~1\Temp\catchme.sys [x]
S4 IntelIde; No ImagePath
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-16 08:28 - 2013-07-16 08:28 - 00001083 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\JRT.txt
2013-07-16 08:24 - 2013-07-16 08:24 - 00000000 ____D C:\WINDOWS\ERUNT
2013-07-16 06:55 - 2013-07-16 07:06 - 00001604 _____ C:\AdwCleaner[S1].txt
2013-07-15 16:33 - 2013-07-15 16:33 - 00012950 _____ C:\ComboFix.txt
2013-07-15 16:06 - 2013-07-15 16:06 - 00000000 _RSHD C:\cmdcons
2013-07-15 16:06 - 2013-07-13 19:16 - 00000245 _____ C:\Boot.bak
2013-07-15 16:06 - 2004-08-03 23:00 - 00262448 __RSH C:\cmldr
2013-07-15 16:03 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-07-15 16:03 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-07-15 16:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-07-15 16:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-07-15 16:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-07-15 16:03 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-07-15 16:03 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-07-15 16:03 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-07-15 16:03 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-07-15 16:02 - 2013-07-15 16:33 - 00000000 ____D C:\Qoobox
2013-07-15 16:02 - 2013-07-15 16:02 - 00000000 ___RD C:\Dokumente und Einstellungen\XX XXX\Startmenü\Programme\Verwaltung
2013-07-15 16:01 - 2013-07-15 16:31 - 00000000 ____D C:\WINDOWS\erdnt
2013-07-15 15:34 - 2013-07-15 15:34 - 00000000 ____D C:\WINDOWS\system32\Drivers\NST
2013-07-15 15:34 - 2013-07-15 15:34 - 00000000 ____D C:\Programme\Norton Identity Safe
2013-07-15 14:55 - 2013-07-15 14:55 - 00000000 ____D C:\FRST
2013-07-15 14:31 - 2013-07-15 14:31 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-15 14:31 - 2013-07-15 14:31 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Malwarebytes
2013-07-15 14:30 - 2013-07-15 14:31 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-07-15 14:30 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\system.sav.LOG
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\software.sav.LOG
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\SECURITY.sav.LOG
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\SAM.sav.LOG
2013-07-15 12:58 - 2013-07-15 13:18 - 00002506 _____ C:\WINDOWS\system32\ASOROSet.bin
2013-07-15 12:57 - 2013-07-15 12:58 - 00000000 ____D C:\WINDOWS\system32\config\RCCBakup
2013-07-15 09:11 - 2013-07-16 06:56 - 00065536 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-07-15 09:08 - 2013-07-15 09:08 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\ATI
2013-07-15 08:50 - 2007-05-10 10:23 - 04952064 _____ (SigmaTel, Inc.) C:\WINDOWS\system32\stacgui.cpl
2013-07-15 08:50 - 2007-05-10 10:22 - 00405504 ____N (SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
2013-07-15 08:50 - 2007-04-10 17:02 - 01601536 _____ (SigmaTel, Inc.) C:\WINDOWS\system32\stlang.dll
2013-07-15 08:48 - 2007-05-10 10:23 - 00270336 _____ (SigmaTel, Inc.) C:\WINDOWS\system32\stacapi.dll
2013-07-14 17:22 - 2013-07-14 17:22 - 00001910 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\Entfernen des Avira DE-Cleaners.lnk
2013-07-14 17:22 - 2013-07-14 17:22 - 00001839 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\Avira DE-Cleaner.lnk
2013-07-14 17:11 - 2013-07-16 06:56 - 00014936 _____ C:\WINDOWS\SchedLgU.Txt
2013-07-14 13:36 - 2013-07-14 13:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB961118$
2013-07-14 09:28 - 2013-07-14 09:28 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Dell
2013-07-14 09:27 - 2013-07-14 09:27 - 00000000 ____D C:\Programme\Dell Support Center
2013-07-14 09:25 - 2013-07-14 10:33 - 00000000 ____D C:\Programme\My Dell
2013-07-14 09:18 - 2013-07-14 09:31 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\PCDr
2013-07-14 09:05 - 2013-07-14 09:05 - 00000747 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\EVEREST Home Edition.lnk
2013-07-14 09:05 - 2013-07-14 09:05 - 00000000 ____D C:\Programme\Lavalys
2013-07-14 08:38 - 2013-07-14 10:44 - 00000000 ____D C:\Programme\HealthMonitor
2013-07-14 05:50 - 2009-01-09 21:19 - 01089883 ____C C:\WINDOWS\system32\dllcache\ntprint.cat
2013-07-14 03:39 - 2013-07-14 03:39 - 00000000 ____D C:\Programme\Microsoft.NET
2013-07-14 03:30 - 2013-07-14 08:11 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Startmenü\Programme\Dell
2013-07-14 01:03 - 2013-07-14 01:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallXPSEPSCLP$
2013-07-14 01:03 - 2006-06-29 13:07 - 00014048 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg2.dll
2013-07-14 00:49 - 2013-07-14 11:17 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2013-07-14 00:49 - 2013-07-14 00:49 - 00000000 ____D C:\Programme\MSBuild
2013-07-14 00:48 - 2013-07-14 00:48 - 00000000 ____D C:\Programme\Reference Assemblies
2013-07-14 00:43 - 2013-07-14 00:47 - 00000000 ____D C:\d8739e3979e09f9b20
2013-07-14 00:43 - 2008-07-06 14:06 - 01676288 ____N (Microsoft Corporation) C:\WINDOWS\system32\xpssvcs.dll
2013-07-14 00:43 - 2008-07-06 14:06 - 01676288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpssvcs.dll
2013-07-14 00:43 - 2008-07-06 14:06 - 00575488 ____N (Microsoft Corporation) C:\WINDOWS\system32\xpsshhdr.dll
2013-07-14 00:43 - 2008-07-06 14:06 - 00575488 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpsshhdr.dll
2013-07-14 00:43 - 2008-07-06 14:06 - 00117760 ____N (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
2013-07-14 00:43 - 2008-07-06 14:06 - 00089088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\filterpipelineprintproc.dll
2013-07-14 00:43 - 2008-07-06 12:50 - 00597504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe
2013-07-14 00:36 - 2013-07-14 20:34 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-07-13 21:38 - 2013-07-16 08:19 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-13 20:03 - 2013-07-13 20:03 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys.sum
2013-07-13 20:03 - 2013-07-13 20:03 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswSP.sys.sum
2013-07-13 20:03 - 2013-07-13 20:03 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswSnx.sys.sum
2013-07-13 20:02 - 2013-05-09 10:58 - 00229648 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2013-07-13 19:53 - 2013-07-13 19:53 - 00000000 ____D C:\Programme\AVAST Software
2013-07-13 19:18 - 2013-07-13 19:18 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Eigene Dateien\ProcAlyzer Dumps
2013-07-13 13:58 - 2013-07-13 14:24 - 00000000 ____D C:\Programme\stinger
2013-07-13 13:58 - 2013-07-13 13:58 - 00000000 ____D C:\Stinger_Quarantine
2013-07-13 08:37 - 2013-07-13 08:37 - 00000000 ____D C:\WINDOWS\pss
2013-07-10 20:04 - 2013-07-10 20:04 - 00000691 _____ C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2803821_WM9$
2013-07-07 10:40 - 2013-07-07 13:25 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-06-30 12:32 - 2013-07-16 07:16 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-06-30 12:32 - 2013-07-16 07:16 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-06-30 12:32 - 2013-06-30 12:32 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2013-06-30 12:32 - 2008-04-14 07:52 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ptpusd.dll
2013-06-30 12:32 - 2001-08-18 04:54 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ptpusb.dll
2013-06-30 12:31 - 2008-04-14 00:15 - 00015104 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbscan.sys
2013-06-30 12:31 - 2008-04-14 00:15 - 00015104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbscan.sys
2013-06-23 22:36 - 2013-06-23 22:35 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-06-23 22:36 - 2013-06-23 22:35 - 00144896 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2013-06-23 22:35 - 2013-06-23 22:35 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-06-23 22:35 - 2013-06-23 22:35 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-06-23 22:35 - 2013-06-23 22:35 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
==================== One Month Modified Files and Folders =======
2013-07-16 08:36 - 2013-01-01 17:26 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Eigene Dateien\ProgWeb
2013-07-16 08:28 - 2013-07-16 08:28 - 00001083 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\JRT.txt
2013-07-16 08:28 - 2013-01-01 15:50 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Desktop
2013-07-16 08:25 - 2013-01-01 15:31 - 00000000 ___RD C:\Programme
2013-07-16 08:24 - 2013-07-16 08:24 - 00000000 ____D C:\WINDOWS\ERUNT
2013-07-16 08:19 - 2013-07-13 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-16 07:20 - 2013-01-01 15:43 - 01792325 _____ C:\WINDOWS\WindowsUpdate.log
2013-07-16 07:18 - 2004-08-04 12:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-07-16 07:16 - 2013-06-30 12:32 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-07-16 07:16 - 2013-06-30 12:32 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-07-16 07:14 - 2013-01-01 15:49 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-07-16 07:06 - 2013-07-16 06:55 - 00001604 _____ C:\AdwCleaner[S1].txt
2013-07-16 06:56 - 2013-07-15 09:11 - 00065536 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-07-16 06:56 - 2013-07-14 17:11 - 00014936 _____ C:\WINDOWS\SchedLgU.Txt
2013-07-16 06:56 - 2013-01-01 15:50 - 00000190 ___SH C:\Dokumente und Einstellungen\XX XXX\ntuser.ini
2013-07-15 19:04 - 2013-01-24 11:49 - 00262144 _____ C:\WINDOWS\system32\config\SpybotSD.evt
2013-07-15 16:33 - 2013-07-15 16:33 - 00012950 _____ C:\ComboFix.txt
2013-07-15 16:33 - 2013-07-15 16:02 - 00000000 ____D C:\Qoobox
2013-07-15 16:31 - 2013-07-15 16:01 - 00000000 ____D C:\WINDOWS\erdnt
2013-07-15 16:29 - 2004-08-04 12:00 - 00000227 _____ C:\WINDOWS\system.ini
2013-07-15 16:06 - 2013-07-15 16:06 - 00000000 _RSHD C:\cmdcons
2013-07-15 16:06 - 2013-01-01 16:29 - 00000355 __RSH C:\boot.ini
2013-07-15 16:02 - 2013-07-15 16:02 - 00000000 ___RD C:\Dokumente und Einstellungen\XX XXX\Startmenü\Programme\Verwaltung
2013-07-15 16:02 - 2013-01-01 15:50 - 00000000 ___RD C:\Dokumente und Einstellungen\XX XXX\Startmenü\Programme
2013-07-15 15:34 - 2013-07-15 15:34 - 00000000 ____D C:\WINDOWS\system32\Drivers\NST
2013-07-15 15:34 - 2013-07-15 15:34 - 00000000 ____D C:\Programme\Norton Identity Safe
2013-07-15 14:55 - 2013-07-15 14:55 - 00000000 ____D C:\FRST
2013-07-15 14:31 - 2013-07-15 14:31 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-15 14:31 - 2013-07-15 14:31 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Malwarebytes
2013-07-15 14:31 - 2013-07-15 14:30 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-07-15 14:31 - 2013-01-01 15:31 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Desktop
2013-07-15 13:48 - 2013-01-01 15:50 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX
2013-07-15 13:18 - 2013-07-15 12:58 - 00002506 _____ C:\WINDOWS\system32\ASOROSet.bin
2013-07-15 13:18 - 2013-01-01 16:29 - 21495808 _____ C:\WINDOWS\system32\config\software.bak
2013-07-15 13:18 - 2013-01-01 16:29 - 05505024 _____ C:\WINDOWS\system32\config\system.bak
2013-07-15 13:18 - 2013-01-01 15:49 - 00000000 __SHD C:\Dokumente und Einstellungen\LocalService
2013-07-15 13:18 - 2013-01-01 15:30 - 00262144 _____ C:\WINDOWS\system32\config\SECURITY.bak
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\system.sav.LOG
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\software.sav.LOG
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\SECURITY.sav.LOG
2013-07-15 13:17 - 2013-07-15 13:17 - 00000000 ____H C:\WINDOWS\system32\config\SAM.sav.LOG
2013-07-15 13:17 - 2013-01-01 15:48 - 00000000 __SHD C:\Dokumente und Einstellungen\NetworkService
2013-07-15 12:58 - 2013-07-15 12:57 - 00000000 ____D C:\WINDOWS\system32\config\RCCBakup
2013-07-15 12:43 - 2013-01-01 15:30 - 00262144 _____ C:\WINDOWS\system32\config\SAM.bak
2013-07-15 09:28 - 2013-01-01 15:58 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups
2013-07-15 09:28 - 2013-01-01 15:31 - 00000000 ___RD C:\Dokumente und Einstellungen\All Users\Startmenü
2013-07-15 09:21 - 2013-01-01 16:18 - 00000476 _____ C:\WINDOWS\system32\results.txt
2013-07-15 09:20 - 2013-01-01 16:39 - 00021361 _____ (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\AegisP.sys
2013-07-15 09:20 - 2013-01-01 16:39 - 00021361 _____ (Cisco Systems, Inc.) C:\WINDOWS\AegisP.sys
2013-07-15 09:20 - 2013-01-01 16:39 - 00010640 _____ C:\WINDOWS\AegisP.cat
2013-07-15 09:08 - 2013-07-15 09:08 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\ATI
2013-07-15 08:57 - 2013-01-01 16:07 - 00000000 ____D C:\Programme\ATI Technologies
2013-07-14 20:34 - 2013-07-14 00:36 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-07-14 17:22 - 2013-07-14 17:22 - 00001910 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\Entfernen des Avira DE-Cleaners.lnk
2013-07-14 17:22 - 2013-07-14 17:22 - 00001839 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\Avira DE-Cleaner.lnk
2013-07-14 17:04 - 2013-01-01 19:40 - 00000355 _____ C:\WINDOWS\WININIT.INI
2013-07-14 15:20 - 2013-01-01 15:31 - 01208170 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-14 13:36 - 2013-07-14 13:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB961118$
2013-07-14 11:17 - 2013-07-14 00:49 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2013-07-14 10:44 - 2013-07-14 08:38 - 00000000 ____D C:\Programme\HealthMonitor
2013-07-14 10:33 - 2013-07-14 09:25 - 00000000 ____D C:\Programme\My Dell
2013-07-14 09:31 - 2013-07-14 09:18 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\PCDr
2013-07-14 09:28 - 2013-07-14 09:28 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\Dell
2013-07-14 09:27 - 2013-07-14 09:27 - 00000000 ____D C:\Programme\Dell Support Center
2013-07-14 09:05 - 2013-07-14 09:05 - 00000747 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\EVEREST Home Edition.lnk
2013-07-14 09:05 - 2013-07-14 09:05 - 00000000 ____D C:\Programme\Lavalys
2013-07-14 08:11 - 2013-07-14 03:30 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Startmenü\Programme\Dell
2013-07-14 07:47 - 2013-01-01 15:30 - 00122136 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-14 04:16 - 2013-01-01 18:17 - 00000000 ____D C:\WINDOWS\system32\de-de
2013-07-14 03:39 - 2013-07-14 03:39 - 00000000 ____D C:\Programme\Microsoft.NET
2013-07-14 01:03 - 2013-07-14 01:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallXPSEPSCLP$
2013-07-14 00:55 - 2013-01-01 16:22 - 00000000 ____D C:\WINDOWS\system32\mui
2013-07-14 00:49 - 2013-07-14 00:49 - 00000000 ____D C:\Programme\MSBuild
2013-07-14 00:48 - 2013-07-14 00:48 - 00000000 ____D C:\Programme\Reference Assemblies
2013-07-14 00:47 - 2013-07-14 00:43 - 00000000 ____D C:\d8739e3979e09f9b20
2013-07-14 00:46 - 2013-01-01 16:22 - 00000000 ____D C:\WINDOWS\system32\spool
2013-07-14 00:37 - 2013-01-01 15:31 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Microsoft Shared
2013-07-14 00:36 - 2013-01-01 16:22 - 00000000 ____D C:\WINDOWS\pchealth
2013-07-13 21:38 - 2013-01-01 19:52 - 00692104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-07-13 21:38 - 2013-01-01 19:52 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-07-13 20:03 - 2013-07-13 20:03 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys.sum
2013-07-13 20:03 - 2013-07-13 20:03 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswSP.sys.sum
2013-07-13 20:03 - 2013-07-13 20:03 - 00000175 _____ C:\WINDOWS\system32\Drivers\aswSnx.sys.sum
2013-07-13 20:02 - 2013-01-01 15:44 - 00002951 _____ C:\WINDOWS\system32\CONFIG.NT
2013-07-13 19:53 - 2013-07-13 19:53 - 00000000 ____D C:\Programme\AVAST Software
2013-07-13 19:18 - 2013-07-13 19:18 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Eigene Dateien\ProcAlyzer Dumps
2013-07-13 19:16 - 2013-07-15 16:06 - 00000245 _____ C:\Boot.bak
2013-07-13 14:43 - 2004-08-04 12:00 - 00000477 _____ C:\WINDOWS\win.ini
2013-07-13 14:42 - 2013-01-01 20:56 - 00000000 ____D C:\Programme\Google
2013-07-13 14:27 - 2013-01-01 21:00 - 00002403 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\Google Chrome.lnk
2013-07-13 14:24 - 2013-07-13 13:58 - 00000000 ____D C:\Programme\stinger
2013-07-13 13:58 - 2013-07-13 13:58 - 00000000 ____D C:\Stinger_Quarantine
2013-07-13 10:24 - 2013-03-05 09:19 - 00000720 _____ C:\Dokumente und Einstellungen\XX XXX\Desktop\Eusing Free Registry Cleaner.lnk
2013-07-13 08:37 - 2013-07-13 08:37 - 00000000 ____D C:\WINDOWS\pss
2013-07-13 07:22 - 2013-01-01 15:41 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-07-12 15:28 - 2013-01-01 19:58 - 00000000 ____D C:\Dokumente und Einstellungen\XX XXX\Anwendungsdaten\vlc
2013-07-10 20:33 - 2013-01-01 20:58 - 00000731 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Picasa 3.lnk
2013-07-10 20:04 - 2013-07-10 20:04 - 00000691 _____ C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-10 19:48 - 2013-07-10 19:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2803821_WM9$
2013-07-10 19:46 - 2013-01-01 19:05 - 75699896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-07-10 19:45 - 2013-01-01 19:09 - 00000000 ____D C:\WINDOWS\ie8updates
2013-07-09 07:03 - 2013-01-01 19:24 - 00000000 ____D C:\Programme\Mozilla Maintenance Service
2013-07-07 13:25 - 2013-07-07 10:40 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-06-30 12:32 - 2013-06-30 12:32 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2013-06-23 22:35 - 2013-06-23 22:36 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-06-23 22:35 - 2013-06-23 22:36 - 00144896 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2013-06-23 22:35 - 2013-06-23 22:35 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-06-23 22:35 - 2013-06-23 22:35 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-06-23 22:35 - 2013-06-23 22:35 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-06-23 22:35 - 2013-01-15 00:42 - 00867240 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll
2013-06-23 22:35 - 2013-01-15 00:42 - 00789416 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-08-04 12:00] - [2008-04-14 08:52] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2004-08-04 12:00] - [2008-04-14 08:53] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2004-08-04 12:00] - [2008-04-14 08:53] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2004-08-04 12:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2004-08-04 12:00] - [2008-04-14 08:52] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2004-08-04 12:00] - [2008-04-14 08:53] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2004-08-04 12:00] - [2008-04-14 08:22] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================
--- --- ---
--- --- ---