jb_o_123 | 27.07.2013 12:56 | Code:
# AdwCleaner v2.306 - Datei am 27/07/2013 um 13:35:23 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzer : Christian Ohle - CHRISTIANOHLE
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Christian Ohle\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Windows\Tasks\LyricsWoofer Update.job
Ordner Gelöscht : C:\Program Files\LyricsWoofer
Ordner Gelöscht : C:\Users\Christian Ohle\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Christian Ohle\AppData\Roaming\Mozilla\Firefox\Profiles\45m6xicr.default\extensions\staged
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsWoofer
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16635
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v22.0 (de)
Datei : C:\Users\Christian Ohle\AppData\Roaming\Mozilla\Firefox\Profiles\45m6xicr.default\prefs.js
C:\Users\Christian Ohle\AppData\Roaming\Mozilla\Firefox\Profiles\45m6xicr.default\user.js ... Gelöscht !
[OK] Die Datei ist sauber.
-\\ Google Chrome v28.0.1500.72
Datei : C:\Users\Christian Ohle\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[R1].txt - [2191 octets] - [26/07/2013 11:39:40]
AdwCleaner[S1].txt - [2230 octets] - [27/07/2013 13:35:23]
########## EOF - C:\AdwCleaner[S1].txt - [2290 octets] ##########
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2013
Ran by Christian Ohle (administrator) on 27-07-2013 13:51:48
Running from C:\Users\Christian Ohle\Downloads
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2013-02-15] (Kaspersky Lab ZAO)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1672616 2013-07-10] (Valve Corporation)
HKU\Default\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\Sidebar.exe [ 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\Sidebar.exe [ 2010-11-20] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe"
SearchScopes: HKLM - DefaultScope value is missing.
BHO: LyricsWoofer - {544F52A2-4D6D-428B-A2DF-FB1EE3F0A263} - C:\Program Files\LyricsWoofer\125.dll No File
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: GameStar-Sparberater - {66F80CF1-E0B6-4525-9990-42F639E2943D} - C:\Program Files\gamestar\Internet Explorer\gamestar.dll ()
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Christian Ohle\AppData\Roaming\Mozilla\Firefox\Profiles\45m6xicr.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\Christian Ohle\AppData\Roaming\Mozilla\Firefox\Profiles\45m6xicr.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF HKCU\...\Firefox\Extensions: [lwoofer@lyricswoofer.co] C:\Program Files\LyricsWoofer\125.xpi
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Christian Ohle\AppData\Local\Google\Chrome\User Data\PepperFlash\11.6.602.167\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Christian Ohle\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\plugin/npUrlAdvisor.dll (Kaspersky Lab ZAO)
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Christian Ohle\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0\plugin/online_banking_npapi.dll (Kaspersky Lab ZAO)
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Christian Ohle\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\plugin/content_blocker_npapi.dll (Kaspersky Lab ZAO)
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Christian Ohle\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4190_0\plugin/npVKPlugin.dll No File
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Christian Ohle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\plugin/npABPlugin.dll (Kaspersky Lab ZAO)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Extension: (Google Docs) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0
CHR Extension: (AdBlock) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.3_0
CHR Extension: (GameStar-Sparberater) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gknbeajffddndejbibgfdboimocfncek\1.4.9_0
CHR Extension: (Safe Money) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0
CHR Extension: (Content Blocker) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0
CHR Extension: (Virtual Keyboard) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4292_0
CHR Extension: (YouTube Unblocker) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl\0.4.4_0
CHR Extension: (Gmail) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR Extension: (Anti-Banner) - C:\Users\CHRIST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx
CHR HKLM\...\Chrome\Extension: [gknbeajffddndejbibgfdboimocfncek] - C:\Program Files\gamestar\Chrome\gamestar-1.4.9.crx
CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx
CHR HKLM\...\Chrome\Extension: [jnikkfemnfogahcandhlchoengjbeaij] - C:\Program Files\LyricsWoofer\125.crx
CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx
========================== Services (Whitelisted) =================
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2013-02-15] (Kaspersky Lab ZAO)
==================== Drivers (Whitelisted) ====================
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [136024 2012-06-19] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [594528 2013-04-22] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [24408 2012-08-02] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25944 2012-10-25] (Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25944 2012-10-25] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [44000 2013-06-18] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145040 2013-04-22] (Kaspersky Lab ZAO)
S3 catchme; \??\C:\Users\CHRIST~1\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-27 13:48 - 2013-07-27 13:48 - 00000877 _____ C:\Users\Christian Ohle\Desktop\JRT.txt
2013-07-27 13:39 - 2013-07-27 13:39 - 00000000 ____D C:\Windows\ERUNT
2013-07-27 13:35 - 2013-07-27 13:35 - 00002359 _____ C:\AdwCleaner[S1].txt
2013-07-27 13:32 - 2013-07-27 13:32 - 00561198 _____ (Oleg N. Scherbakov) C:\Users\Christian Ohle\Desktop\JRT.exe
2013-07-27 13:04 - 2013-07-27 13:36 - 00000112 _____ C:\Windows\setupact.log
2013-07-27 13:04 - 2013-07-27 13:04 - 00000546 _____ C:\Windows\PFRO.log
2013-07-27 13:04 - 2013-07-27 13:04 - 00000000 _____ C:\Windows\setuperr.log
2013-07-26 15:16 - 2013-07-26 15:16 - 00010624 _____ C:\ComboFix.txt
2013-07-26 15:07 - 2013-07-26 15:07 - 00013581 _____ C:\Users\Christian Ohle\Desktop\combofix - Verknüpfung.lnk
2013-07-26 15:06 - 2013-07-26 15:16 - 00000000 ____D C:\Qoobox
2013-07-26 15:06 - 2013-07-26 15:15 - 00000000 ____D C:\Windows\erdnt
2013-07-26 15:06 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-26 15:06 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-26 15:06 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-26 15:06 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-26 15:06 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-26 15:06 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-26 15:06 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-26 15:06 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-26 15:04 - 2013-07-26 15:05 - 05093969 ____R (Swearware) C:\Users\Christian Ohle\Downloads\ComboFix.exe
2013-07-26 11:39 - 2013-07-26 11:39 - 00002191 _____ C:\AdwCleaner[R1].txt
2013-07-26 11:38 - 2013-07-26 11:38 - 00666633 _____ C:\Users\Christian Ohle\Desktop\adwcleaner.exe
2013-07-26 11:31 - 2013-07-26 11:31 - 00003112 _____ C:\Users\Christian Ohle\Documents\cc_20130726_113103.reg
2013-07-26 11:19 - 2013-07-26 11:19 - 00026932 _____ C:\Users\Christian Ohle\Documents\FRST.txt
2013-07-26 11:14 - 2013-07-26 11:26 - 00016147 _____ C:\Users\Christian Ohle\Downloads\Addition.txt
2013-07-26 11:07 - 2013-07-26 11:07 - 00000000 ____D C:\FRST
2013-07-26 11:04 - 2013-07-26 11:04 - 01220112 _____ (Farbar) C:\Users\Christian Ohle\Downloads\FRST.exe
2013-07-26 00:57 - 2013-07-26 00:57 - 01363456 _____ (Björn Bastian) C:\Users\Christian Ohle\Downloads\USB-Fehlerbehebung_2.2.exe
2013-07-26 00:53 - 2013-07-26 00:52 - 02477327 _____ (USB Wächter ) C:\Users\Christian Ohle\Downloads\usbwaechter.exe
2013-07-26 00:52 - 2013-07-26 00:52 - 01330752 _____ C:\Users\Christian Ohle\Downloads\usbwaechter-Downloader.exe
2013-07-25 23:32 - 2013-07-25 23:32 - 00000000 ____D C:\Users\Public\Documents\Logishrd
2013-07-25 23:32 - 2013-07-25 23:32 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\Leadertech
2013-07-25 23:31 - 2013-07-25 23:33 - 00000000 ____D C:\ProgramData\Logishrd
2013-07-25 23:31 - 2013-07-25 23:31 - 00000000 ____D C:\ProgramData\Logitech
2013-07-25 23:31 - 2013-07-25 23:31 - 00000000 ____D C:\Program Files\Logitech
2013-07-25 23:29 - 2013-07-26 00:10 - 00000000 ____D C:\Program Files\Common Files\Logishrd
2013-07-25 23:28 - 2013-07-25 23:32 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\Logitech
2013-07-25 23:28 - 2013-07-25 23:28 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\Logishrd
2013-07-20 02:32 - 2013-07-20 02:34 - 00000000 ____D C:\Windows\system32\MRT
2013-07-16 01:29 - 2013-07-16 01:29 - 00173186 _____ C:\Users\Christian Ohle\Downloads\gateway_settings (1).gws
2013-07-15 16:23 - 2013-07-15 16:24 - 00074274 __RSH C:\ProgramData\ntuser.pol
2013-07-11 14:53 - 2013-07-26 12:44 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-07-11 03:08 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 03:08 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 03:08 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 03:08 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 03:08 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 03:08 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 03:08 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-11 03:08 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 03:08 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 03:08 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 03:08 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 03:08 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-11 03:08 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-11 03:08 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-11 03:08 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-11 03:08 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 00:16 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 00:16 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 00:16 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 00:16 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-07 12:00 - 2013-07-07 12:00 - 00000000 ____D C:\Users\CHRIST~1\AppData\Local\Macromedia
2013-07-03 16:02 - 2013-07-27 13:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-03 16:02 - 2013-07-17 12:52 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-03 16:02 - 2013-07-17 12:52 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-03 16:02 - 2013-07-03 16:02 - 00000000 ____D C:\Windows\system32\Macromed
2013-07-03 15:57 - 2013-07-03 15:57 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-03 15:57 - 2013-07-03 15:57 - 00000000 ____D C:\Users\CHRIST~1\AppData\Local\Mozilla
2013-07-03 15:56 - 2013-07-03 15:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-03 15:55 - 2013-07-03 15:55 - 21703480 _____ (Mozilla) C:\Users\Christian Ohle\Downloads\Firefox Setup 22.0.exe
2013-06-27 17:24 - 2013-06-27 17:24 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\WinRAR
2013-06-27 17:23 - 2013-06-27 17:23 - 01609145 _____ C:\Users\Christian Ohle\Downloads\wrar420d.exe
2013-06-27 17:23 - 2013-06-27 17:23 - 00000000 ____D C:\Program Files\WinRAR
2013-06-27 17:17 - 2013-06-27 17:17 - 02510003 _____ C:\Users\Christian Ohle\Downloads\DIR-635_fw_revb_235eub01_ALL_multi_20130618 (2).zip
==================== One Month Modified Files and Folders =======
2013-07-27 13:48 - 2013-07-27 13:48 - 00000877 _____ C:\Users\Christian Ohle\Desktop\JRT.txt
2013-07-27 13:48 - 2013-02-13 05:39 - 00000000 ___RD C:\Users\Christian Ohle\Desktop
2013-07-27 13:44 - 2009-07-14 06:34 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-27 13:44 - 2009-07-14 06:34 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-27 13:39 - 2013-07-27 13:39 - 00000000 ____D C:\Windows\ERUNT
2013-07-27 13:37 - 2013-02-16 22:15 - 00000000 ____D C:\Program Files\Steam
2013-07-27 13:37 - 2013-02-15 15:05 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-07-27 13:36 - 2013-07-27 13:04 - 00000112 _____ C:\Windows\setupact.log
2013-07-27 13:36 - 2013-07-03 16:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-27 13:36 - 2013-02-15 15:13 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-27 13:36 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-27 13:35 - 2013-07-27 13:35 - 00002359 _____ C:\AdwCleaner[S1].txt
2013-07-27 13:35 - 2013-02-13 05:00 - 01193504 _____ C:\Windows\WindowsUpdate.log
2013-07-27 13:32 - 2013-07-27 13:32 - 00561198 _____ (Oleg N. Scherbakov) C:\Users\Christian Ohle\Desktop\JRT.exe
2013-07-27 13:31 - 2013-02-15 15:13 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-27 13:04 - 2013-07-27 13:04 - 00000546 _____ C:\Windows\PFRO.log
2013-07-27 13:04 - 2013-07-27 13:04 - 00000000 _____ C:\Windows\setuperr.log
2013-07-26 15:16 - 2013-07-26 15:16 - 00010624 _____ C:\ComboFix.txt
2013-07-26 15:16 - 2013-07-26 15:06 - 00000000 ____D C:\Qoobox
2013-07-26 15:16 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2013-07-26 15:16 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-07-26 15:15 - 2013-07-26 15:06 - 00000000 ____D C:\Windows\erdnt
2013-07-26 15:15 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-07-26 15:07 - 2013-07-26 15:07 - 00013581 _____ C:\Users\Christian Ohle\Desktop\combofix - Verknüpfung.lnk
2013-07-26 15:05 - 2013-07-26 15:04 - 05093969 ____R (Swearware) C:\Users\Christian Ohle\Downloads\ComboFix.exe
2013-07-26 12:44 - 2013-07-11 14:53 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-07-26 11:39 - 2013-07-26 11:39 - 00002191 _____ C:\AdwCleaner[R1].txt
2013-07-26 11:38 - 2013-07-26 11:38 - 00666633 _____ C:\Users\Christian Ohle\Desktop\adwcleaner.exe
2013-07-26 11:33 - 2013-02-13 04:54 - 00000000 ____D C:\Windows\Panther
2013-07-26 11:31 - 2013-07-26 11:31 - 00003112 _____ C:\Users\Christian Ohle\Documents\cc_20130726_113103.reg
2013-07-26 11:26 - 2013-07-26 11:14 - 00016147 _____ C:\Users\Christian Ohle\Downloads\Addition.txt
2013-07-26 11:19 - 2013-07-26 11:19 - 00026932 _____ C:\Users\Christian Ohle\Documents\FRST.txt
2013-07-26 11:07 - 2013-07-26 11:07 - 00000000 ____D C:\FRST
2013-07-26 11:04 - 2013-07-26 11:04 - 01220112 _____ (Farbar) C:\Users\Christian Ohle\Downloads\FRST.exe
2013-07-26 00:57 - 2013-07-26 00:57 - 01363456 _____ (Björn Bastian) C:\Users\Christian Ohle\Downloads\USB-Fehlerbehebung_2.2.exe
2013-07-26 00:52 - 2013-07-26 00:53 - 02477327 _____ (USB Wächter ) C:\Users\Christian Ohle\Downloads\usbwaechter.exe
2013-07-26 00:52 - 2013-07-26 00:52 - 01330752 _____ C:\Users\Christian Ohle\Downloads\usbwaechter-Downloader.exe
2013-07-26 00:12 - 2013-02-13 05:39 - 00000000 ____D C:\Users\Christian Ohle
2013-07-26 00:12 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp
2013-07-26 00:10 - 2013-07-25 23:29 - 00000000 ____D C:\Program Files\Common Files\Logishrd
2013-07-26 00:10 - 2013-02-15 18:13 - 00000000 ____D C:\Users\CHRIST~1\AppData\Local\Thunderbird
2013-07-26 00:10 - 2013-02-15 18:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-07-26 00:10 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\DriverStore
2013-07-26 00:10 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration
2013-07-26 00:10 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat
2013-07-25 23:33 - 2013-07-25 23:31 - 00000000 ____D C:\ProgramData\Logishrd
2013-07-25 23:32 - 2013-07-25 23:32 - 00000000 ____D C:\Users\Public\Documents\Logishrd
2013-07-25 23:32 - 2013-07-25 23:32 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\Leadertech
2013-07-25 23:32 - 2013-07-25 23:28 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\Logitech
2013-07-25 23:31 - 2013-07-25 23:31 - 00000000 ____D C:\ProgramData\Logitech
2013-07-25 23:31 - 2013-07-25 23:31 - 00000000 ____D C:\Program Files\Logitech
2013-07-25 23:28 - 2013-07-25 23:28 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\Logishrd
2013-07-20 02:34 - 2013-07-20 02:32 - 00000000 ____D C:\Windows\system32\MRT
2013-07-18 12:05 - 2013-02-16 22:15 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-07-17 12:52 - 2013-07-03 16:02 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-17 12:52 - 2013-07-03 16:02 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-17 12:52 - 2013-06-22 18:40 - 00000000 ____D C:\Users\CHRIST~1\AppData\Local\Adobe
2013-07-16 22:28 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-07-16 01:29 - 2013-07-16 01:29 - 00173186 _____ C:\Users\Christian Ohle\Downloads\gateway_settings (1).gws
2013-07-15 16:24 - 2013-07-15 16:23 - 00074274 __RSH C:\ProgramData\ntuser.pol
2013-07-15 16:22 - 2009-07-14 04:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-07-14 16:35 - 2013-02-15 15:15 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-11 13:22 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-11 13:04 - 2009-07-14 06:33 - 00343496 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 03:15 - 2011-04-12 03:39 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 03:15 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-11 03:10 - 2010-11-20 23:01 - 01519874 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-07 12:00 - 2013-07-07 12:00 - 00000000 ____D C:\Users\CHRIST~1\AppData\Local\Macromedia
2013-07-03 16:02 - 2013-07-03 16:02 - 00000000 ____D C:\Windows\system32\Macromed
2013-07-03 15:57 - 2013-07-03 15:57 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-03 15:57 - 2013-07-03 15:57 - 00000000 ____D C:\Users\CHRIST~1\AppData\Local\Mozilla
2013-07-03 15:57 - 2013-02-15 18:13 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\Mozilla
2013-07-03 15:57 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Desktop
2013-07-03 15:56 - 2013-07-03 15:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-03 15:55 - 2013-07-03 15:55 - 21703480 _____ (Mozilla) C:\Users\Christian Ohle\Downloads\Firefox Setup 22.0.exe
2013-06-27 17:24 - 2013-06-27 17:24 - 00000000 ____D C:\Users\Christian Ohle\AppData\Roaming\WinRAR
2013-06-27 17:23 - 2013-06-27 17:23 - 01609145 _____ C:\Users\Christian Ohle\Downloads\wrar420d.exe
2013-06-27 17:23 - 2013-06-27 17:23 - 00000000 ____D C:\Program Files\WinRAR
2013-06-27 17:17 - 2013-06-27 17:17 - 02510003 _____ C:\Users\Christian Ohle\Downloads\DIR-635_fw_revb_235eub01_ALL_multi_20130618 (2).zip
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-24 12:16
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.5 (07.26.2013:2)
OS: Windows 7 Professional x86
Ran by Christian Ohle on 27.07.2013 at 13:40:38,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\install.res.1031.dll
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Christian Ohle\AppData\Roaming\mozilla\firefox\profiles\45m6xicr.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.07.2013 at 13:48:00,69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Und gute besserung :abklatsch: |