Chrissi1111 | 29.08.2013 23:38 | Das kam dabei raus: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.29.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Chrissi :: CHRISSI-PC [Administrator]
Schutz: Aktiviert
29.08.2013 19:48:54
mbam-log-2013-08-29 (19-48-54).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 220955
Laufzeit: 4 Minute(n), 1 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 7
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 5
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Chrissi\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Chrissi\AppData\Roaming\OpenCandy\A6631361ADD542439503FD921EFFED63 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 8
C:\Users\Chrissi\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Chrissi\AppData\Roaming\OpenCandy\A6631361ADD542439503FD921EFFED63\driverscannerROE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Code:
# AdwCleaner v3.001 - Report created 30/08/2013 at 00:09:59
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Chrissi - CHRISSI-PC
# Running from : C:\Users\Chrissi\Downloads\adwcleaner(1).exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : Yontoo Desktop Updater
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\search protection
Folder Deleted : C:\ProgramData\Uniblue\DriverScanner
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue\DriverScanner
Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
Folder Deleted : C:\Program Files (x86)\Uniblue\DriverScanner
Folder Deleted : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Folder Deleted : C:\Windows\SysWOW64\ARFC
Folder Deleted : C:\Windows\SysWOW64\jmdp
Folder Deleted : C:\Windows\SysWOW64\WNLT
Folder Deleted : C:\Windows\System32\ARFC
Folder Deleted : C:\Users\Chrissi\AppData\Local\Ilivid
Folder Deleted : C:\Users\Chrissi\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Chrissi\AppData\LocalLow\adawaretb
Folder Deleted : C:\Users\Chrissi\AppData\LocalLow\incredibar.com
Folder Deleted : C:\Users\Chrissi\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Chrissi\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\Chrissi\AppData\Roaming\Uniblue\DriverScanner
Folder Deleted : C:\Users\Chrissi\AppData\Roaming\Mozilla\Firefox\Profiles\n3pp6cdz.default\adawaretb
Folder Deleted : C:\Users\Chrissi\AppData\Roaming\Mozilla\Firefox\Profiles\n3pp6cdz.default\jetpack
File Deleted : C:\Windows\System32\dmwu.exe
File Deleted : C:\Windows\System32\ImhxxpComm.dll
File Deleted : C:\Users\Chrissi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
File Deleted : C:\Users\Chrissi\AppData\Roaming\Mozilla\Firefox\Profiles\n3pp6cdz.default\searchplugins\MyStart Search.xml
File Deleted : C:\Users\Chrissi\AppData\Roaming\Mozilla\Firefox\Profiles\n3pp6cdz.default\user.js
File Deleted : C:\Windows\Tasks\driverscanner.job
File Deleted : C:\Windows\System32\Tasks\driverscanner
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}]
Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_perfect365_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_perfect365_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_colour-master-touch_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_colour-master-touch_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_freez-flv-to-mp3-converter_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_freez-flv-to-mp3-converter_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_koyote-free-video-converter_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_koyote-free-video-converter_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_super_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_super_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_tagscanner_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_tagscanner_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\WNLT
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\IB Updater
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\Uniblue\DriverScanner
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutocompletePro3_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WNLT
Key Deleted : [x64] HKLM\SOFTWARE\IB Updater
Key Deleted : [x64] HKLM\SOFTWARE\WNLT
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\Chrissi\AppData\Roaming\Mozilla\Firefox\Profiles\n3pp6cdz.default\prefs.js ]
Line Deleted : user_pref("extensions.incredibar.actvtyRptTime", "1359500295952");
Line Deleted : user_pref("extensions.incredibar.admin", false);
Line Deleted : user_pref("extensions.incredibar.aflt", "orgnl");
Line Deleted : user_pref("extensions.incredibar.afterInstallRpt", "sent");
Line Deleted : user_pref("extensions.incredibar.cntry", "DE");
Line Deleted : user_pref("extensions.incredibar.dfltLng", "EN");
Line Deleted : user_pref("extensions.incredibar.dfltSrch", false);
Line Deleted : user_pref("extensions.incredibar.dfltlng", "en");
Line Deleted : user_pref("extensions.incredibar.dfltsrch", "false");
Line Deleted : user_pref("extensions.incredibar.did", "10643");
Line Deleted : user_pref("extensions.incredibar.envrmnt", "production");
Line Deleted : user_pref("extensions.incredibar.excTlbr", false);
Line Deleted : user_pref("extensions.incredibar.hdrMd5", "4B9270BD374F4BF2CE0F5D4705BF4CF2");
Line Deleted : user_pref("extensions.incredibar.hmpg", false);
Line Deleted : user_pref("extensions.incredibar.hrdid", "8aa8e93600000000000006234e404b15");
Line Deleted : user_pref("extensions.incredibar.id", "8aa8e93600000000000006234e404b15");
Line Deleted : user_pref("extensions.incredibar.installerproductid", "26");
Line Deleted : user_pref("extensions.incredibar.instlDay", "15734");
Line Deleted : user_pref("extensions.incredibar.instlRef", "");
Line Deleted : user_pref("extensions.incredibar.instlday", "15734");
Line Deleted : user_pref("extensions.incredibar.instlref", "");
Line Deleted : user_pref("extensions.incredibar.isDcmntCmplt", false);
Line Deleted : user_pref("extensions.incredibar.isdcmntcmplt", "false");
Line Deleted : user_pref("extensions.incredibar.keywordurl", "");
Line Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1423:58:05");
Line Deleted : user_pref("extensions.incredibar.mntrvrsn", "1.2.0");
Line Deleted : user_pref("extensions.incredibar.newTab", false);
Line Deleted : user_pref("extensions.incredibar.newtab", "false");
Line Deleted : user_pref("extensions.incredibar.newtaburl", "");
Line Deleted : user_pref("extensions.incredibar.noFFXTlbr", false);
Line Deleted : user_pref("extensions.incredibar.ppd", "6666660837");
Line Deleted : user_pref("extensions.incredibar.prdct", "incredibar");
Line Deleted : user_pref("extensions.incredibar.productid", "26");
Line Deleted : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Line Deleted : user_pref("extensions.incredibar.prtnrid", "Incredibar");
Line Deleted : user_pref("extensions.incredibar.sg", "none");
Line Deleted : user_pref("extensions.incredibar.smplGrp", "none");
Line Deleted : user_pref("extensions.incredibar.smplgrp", "none");
Line Deleted : user_pref("extensions.incredibar.srch", "");
Line Deleted : user_pref("extensions.incredibar.srchprvdr", "");
Line Deleted : user_pref("extensions.incredibar.tlbrId", "base");
Line Deleted : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8SQbflTy&loc=IB_TB&i=26&search=");
Line Deleted : user_pref("extensions.incredibar.tlbrid", "base");
Line Deleted : user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6R8SQbflTy&loc=IB_TB&i=26&search=");
Line Deleted : user_pref("extensions.incredibar.upn2", "6R8SQbflTy");
Line Deleted : user_pref("extensions.incredibar.upn2n", "92825832808258048");
Line Deleted : user_pref("extensions.incredibar.vrsn", "1.5.11.14");
Line Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1423:58:05");
Line Deleted : user_pref("extensions.incredibar.vrsni", "1.5.11.14");
Line Deleted : user_pref("extensions.incredibar.vrsnts", "1.5.11.1423:58:05");
Line Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");
Line Deleted : user_pref("extensions.incredibar_i.dfltLng", "");
Line Deleted : user_pref("extensions.incredibar_i.did", "10643");
Line Deleted : user_pref("extensions.incredibar_i.excTlbr", false);
Line Deleted : user_pref("extensions.incredibar_i.id", "8aa8e93600000000000006234e404b15");
Line Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");
Line Deleted : user_pref("extensions.incredibar_i.instlDay", "15734");
Line Deleted : user_pref("extensions.incredibar_i.instlRef", "");
Line Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");
Line Deleted : user_pref("extensions.incredibar_i.newTab", false);
Line Deleted : user_pref("extensions.incredibar_i.ppd", "6666660837");
Line Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");
Line Deleted : user_pref("extensions.incredibar_i.productid", "26");
Line Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Line Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");
Line Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8SQbflTy&loc=IB_TB&i=26&search=");
Line Deleted : user_pref("extensions.incredibar_i.upn2", "6R8SQbflTy");
Line Deleted : user_pref("extensions.incredibar_i.upn2n", "92825832808258048");
Line Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Line Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1423:58:05");
Line Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
*************************
AdwCleaner[R0].txt - [14819 octets] - [30/08/2013 00:08:51]
AdwCleaner[S0].txt - [14189 octets] - [30/08/2013 00:09:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14250 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Windows 7 Home Premium x64
Ran by Chrissi on 30.08.2013 at 0:19:09,39
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\driverscanner
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-751161945-1929235623-774014638-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\adawarebp_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\adawarebp_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\pricegong_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\pricegong_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\uniblue
~~~ Files
Successfully deleted: [File] "C:\Users\Chrissi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\driverscanner.lnk"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\big fish games"
Successfully deleted: [Folder] "C:\Users\Chrissi\AppData\Roaming\big fish games"
Successfully deleted: [Folder] "C:\Users\Chrissi\appdata\local\adawarebp"
Successfully deleted: [Folder] "C:\Program Files (x86)\free video converter"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{01D31D39-9438-4179-8C4E-9DB8B9B2247A}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{04426254-2200-47EC-A18F-48A63F115C1A}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{07CA3EEC-435C-43D7-954D-CA456268B7C7}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{0E0B093B-161A-4E93-9E79-7C4D5C32F27B}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{0F96EF2D-10FE-4316-B45A-0E5E9D8437FE}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{10754297-C7C5-4897-AEB9-9901CA1C7282}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{154970DF-9CE0-487C-8BC7-1E462540058C}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{1726BC4D-0554-432E-94BC-CC0E9C255C60}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{18569A99-664A-4CFA-BA4E-31F5570EA924}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{1AA414FC-0D07-4842-9A9C-0CDA6A8472A0}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{1F48F895-CD32-4BC6-9CE7-472A2776B317}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{20AE1232-AE98-4F0A-9659-F4CC9EF1B877}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{224F1DC7-4736-494F-9BA1-2A51EB31140C}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{23815DEC-3ED9-474E-BBBB-28FD60709DB0}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{24332F78-A56D-4B44-A37F-B97ACA72ACCF}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{2796B60F-6489-464C-9AB6-913E806B04DF}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{29301FDF-FB51-4DEE-B54D-860264D2B5BD}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{2EEB023F-A84C-434D-B06F-1CB5CBB16536}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{31D1AC56-250C-416F-A31C-348280B576D3}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{353AF88E-F4D1-41A7-A291-1B0A19A8A826}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{36AE4F7B-5153-4564-B63F-1027EEFC972C}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{36B7DB16-87A6-4BA2-84CF-BFAA26DB3D0A}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{387FF840-068F-4F93-9EBB-62B4F34AC969}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{3A911DFE-3C7F-4D7B-81FB-18FC6F5B4FA5}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{3B3D531C-8FFC-4A99-BDBF-791182DD8EE3}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{3DEC162B-F685-421B-ABB9-A0F57BC79EB8}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{44278ABC-BA28-48A8-963B-60D3EB404B49}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{487C68AC-8861-41D2-BC93-8047153983C4}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{4B879399-C8B9-4C99-9E0E-B8404E36DBA4}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{4C445EA3-65A2-45E3-84AE-40490C00D297}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{4EA9C416-C5A6-4194-8866-1550CF2E1C6B}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{500D7DCE-A715-471C-B730-CCC5BBC0FDFE}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{50543CF6-4459-4310-920E-CD773F5A609D}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{51139659-8667-488A-9310-6924424EF7FD}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{51650ED0-880C-4BD4-8580-BBD83905A628}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{5295CA00-0C19-471A-B5B1-F931C923B28F}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{57C67E52-F0CA-4E91-8B14-CFA10BCB4CDE}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{5880C6F4-AD08-49A0-88A3-89269AC5C529}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{599FE8B9-ECE2-4AAF-B6CA-9187E03E58B6}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{5C0A2BFE-962C-4166-8C4F-C9C67DBA4486}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{5C7637D0-BF3A-4BD5-A89F-605294C29457}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{5F2580FB-97AC-48D9-97F8-3CCE613D5B9F}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{5FB8E1F5-E718-4B26-8EB1-9E634AE10985}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6153CC58-2599-48BB-B418-69CF6B71F0E2}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{61AC2F6A-5FE2-412E-8E4B-521B3BD26DC2}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{636211AB-FE72-4FAC-80E0-6C8EB0BFEE6A}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{677A6539-5CB1-44A2-93AB-FF3976DE76D5}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{686BDCD2-3BB9-442E-98B6-A1523EF5D7BE}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6BA5D747-A8D5-450F-91EE-B6C24E724551}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6C44EBB6-7E53-4FE7-B87E-5D71283B207C}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6C6E7456-2B83-451D-ABAE-C60901AD1650}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6C94C0FE-B683-4FF3-A1C9-F9E075B36499}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6D2D5ACA-489C-4C86-96B8-6E195EFD3C94}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6D4116BC-4EEC-43BE-8493-D065184B3C44}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{6EAD4D7A-1991-4F4A-B717-B6A5C25A2E3E}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{744142B2-B5DB-4126-BC0A-4EB5E9EDE7B3}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{74E1E708-D4A3-4C53-9597-C855420A96D9}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{78AD6D1E-C66E-428C-A180-EAF75C86AC56}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{79AF7B88-FF0E-47B1-8B3C-57CF860DC1FE}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{80F8934B-DEE3-471D-8DC5-6BEC99CA67B8}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{8460AF9A-6BA2-43C7-8E93-56D304DD965F}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{854290CA-E63E-41C9-85F9-31CB82C2B49A}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{980CFC4A-192E-4525-A3E2-737BD209BBE1}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{9A4DE791-AD50-4259-9B46-F0867E81DC80}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{9AE45D94-54AB-461A-9638-296910118A94}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A1FFDE1E-0BA6-4F15-9117-8018DE18E53B}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A6DC2CF7-791D-4C24-A5D6-5F5CD848F947}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A7506E46-739D-40E7-AC43-A9622BE62CD7}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A847ECC6-B592-4AEA-88BA-7C5FCDDC877D}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A8BA3655-784E-4661-8D4F-D4C9EBE19939}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A93A82FF-9686-4CD4-8C25-DF905620F847}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A93E53E4-F30E-4929-A66D-BE86943006FD}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{A9A7FD77-3F4D-4429-B98F-C880D562A828}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{AB08CB6E-9191-438F-A51D-870193645F6B}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{ADF50777-079B-4369-BF0F-470C9F3FC187}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{AF51DAB6-54D7-4945-BA41-E9167424DD72}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{AF89D185-281A-4A26-9BE9-2621AF1AF5F4}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{B3F4B363-4F34-4529-B6BC-946722E066A8}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{B4259ACE-D80C-4D4F-8F86-53957D81BF25}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{B92FA015-F4C3-4469-BB65-1AB5DC30210C}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{BF1C9B6A-3AE4-407A-858B-2FF331F8B8BF}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{C58813A2-27A4-4697-A2B0-D3BAF2C871FA}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{C6BE9C9F-4246-4F20-9AE4-E34A7C192A8F}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{CC7D559F-177B-4CBA-83D8-E578262B5954}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{D0A1B98E-198E-4A9D-9BAB-C51BD580DA09}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{D2619C55-0DAF-474E-81CA-2707A908D10E}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{D345B396-7AE4-4494-8358-A8DE1B702712}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{D657E461-6A93-4757-8277-B56E42065CBF}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{D7F8EE5C-6495-4F6F-8A3A-58446F68CB5D}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{D8D427F8-798B-4418-9482-BFEC381A7018}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{DAB7E7FE-3555-423B-A9B7-427446E04866}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{DED42EFB-6412-49EB-B919-04F5DA9F45AF}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E127B45A-1B89-49D0-8C26-1BD85C63CE7A}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E1996002-A9D5-489C-81C2-320FAB6F74D6}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E1C62D2E-4F91-4029-A228-D0362CF931B2}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E2DDB73E-B0AA-4412-8E64-85E75B5FD274}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E3F25A46-D4E0-4C50-84A5-60FAAD60D96C}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E42C7348-F63C-4D8C-8743-33A31FB5AB33}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E6D3ABAF-D7D9-463D-8E11-F02334050695}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{E7F220F2-058E-4F13-B375-AADEA1451B08}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{EA5F471C-67B1-43F1-AF21-678B99BF705A}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{EF0BC6F2-AF93-4ABC-B617-BB355BA2DE00}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{F2FDE86E-2C2D-455B-BBD2-3711BE7742BA}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{F4A3F5E0-85F3-473B-A6D6-FC280C4E635B}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{FA0E0B22-4FCC-418D-B08E-D809C4590E87}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{FAE17749-57D9-4140-A02F-0957699B4AA1}
Successfully deleted: [Empty Folder] C:\Users\Chrissi\appdata\local\{FC78A2FE-1EDD-41A9-81D9-4526BFC6256F}
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [Folder] C:\Users\Chrissi\AppData\Roaming\mozilla\firefox\profiles\n3pp6cdz.default\extensions\{87934C42-161D-45BC-8CEF-EF18ABE2A30C}
Successfully deleted the following from C:\Users\Chrissi\AppData\Roaming\mozilla\firefox\profiles\n3pp6cdz.default\prefs.js
user_pref("browser.startup.homepage", "hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=751E51B9856869C31BCE5C521F8E63DA");
user_pref("keyword.URL", "hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_4&hsimp=yhs-lavasoft&ent=bs&q=");
Emptied folder: C:\Users\Chrissi\AppData\Roaming\mozilla\firefox\profiles\n3pp6cdz.default\minidumps [96 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.08.2013 at 0:28:14,13
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Chrissi (administrator) on 30-08-2013 00:32:17
Running from C:\Users\Chrissi\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [651264 2012-04-17] ()
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft)
HKLM-x32\...\Run: [Search Protection] - C:\ProgramData\Search Protection\SearchProtection.exe [x]
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run [x]
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Chrissi\AppData\Roaming\Mozilla\Firefox\Profiles\n3pp6cdz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=15.0.2.72 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.2.72 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.2.72 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.2.72 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=15.0.2.72 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Chrissi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\acpro.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Chrissi\AppData\Roaming\Mozilla\Firefox\Profiles\n3pp6cdz.default\Extensions\{35379F86-8CCB-4724-AE33-4278DE266C70}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [gamescenter@gamescenter.com] C:\Program Files (x86)\GamesCenter\GamesCenter.xpi
FF Extension: No Name - C:\Program Files (x86)\GamesCenter\GamesCenter.xpi
==================== Services (Whitelisted) =================
R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43112 2012-02-16] (ArcSoft Inc.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] ()
S2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2028864 2011-12-08] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [38096 2012-12-17] (GFI Software)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-08-29] (GFI Software)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2011-07-07] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-30 00:19 - 2013-08-30 00:19 - 00000000 ____D C:\Windows\ERUNT
2013-08-30 00:08 - 2013-08-30 00:10 - 00000000 ____D C:\AdwCleaner
2013-08-29 20:11 - 2013-08-30 00:13 - 00001868 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2013-08-29 20:10 - 2013-08-29 20:10 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-08-29 20:10 - 2013-08-29 20:10 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection
2013-08-29 20:09 - 2013-08-29 20:09 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2013-08-29 20:04 - 2013-08-29 20:04 - 00047496 _____ (GFI Software) C:\Windows\system32\sbbd.exe
2013-08-29 19:56 - 2013-08-29 19:56 - 00004128 _____ C:\Windows\PFRO.log
2013-08-29 19:43 - 2013-08-29 19:43 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 19:43 - 2013-08-29 19:43 - 00000000 ____D C:\Users\Chrissi\AppData\Roaming\Malwarebytes
2013-08-29 19:43 - 2013-08-29 19:43 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 19:43 - 2013-08-29 19:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-29 19:43 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-29 19:41 - 2013-08-29 19:42 - 00994642 _____ C:\Users\Chrissi\Downloads\adwcleaner.exe
2013-08-29 19:41 - 2013-08-29 19:41 - 01023533 _____ (Thisisu) C:\Users\Chrissi\Desktop\JRT.exe
2013-08-29 19:39 - 2013-08-29 19:41 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Chrissi\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 17:27 - 2013-08-29 17:27 - 00012732 _____ C:\ComboFix.txt
2013-08-29 17:00 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-29 17:00 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-29 17:00 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-29 17:00 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-29 17:00 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-29 17:00 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-29 17:00 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-29 17:00 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-29 11:33 - 2013-08-29 17:28 - 00000000 ____D C:\Qoobox
2013-08-29 11:32 - 2013-08-29 17:24 - 00000000 ____D C:\Windows\erdnt
2013-08-29 11:27 - 2013-08-29 11:29 - 05115711 ____R (Swearware) C:\Users\Chrissi\Desktop\ComboFix.exe
2013-08-29 09:59 - 2013-08-29 09:59 - 00003304 ____N C:\bootsqm.dat
2013-08-29 02:00 - 2013-08-29 02:00 - 354462448 _____ C:\Windows\MEMORY.DMP
2013-08-29 02:00 - 2013-08-29 02:00 - 00521008 _____ C:\Windows\Minidump\082913-14757-01.dmp
2013-08-29 01:19 - 2013-08-30 00:30 - 00000000 ____D C:\Users\Chrissi\Desktop\pc
2013-08-29 01:10 - 2013-08-29 01:10 - 00377856 _____ C:\Users\Chrissi\Downloads\gmer_2.1.19163.exe
2013-08-29 01:04 - 2013-08-29 01:04 - 00000000 ____D C:\FRST
2013-08-29 01:01 - 2013-08-29 01:02 - 01579080 _____ (Farbar) C:\Users\Chrissi\Downloads\FRST64.exe
2013-08-29 01:01 - 2013-08-29 01:02 - 00000476 _____ C:\Users\Chrissi\Downloads\defogger_disable.log
2013-08-29 01:01 - 2013-08-29 01:01 - 00050477 _____ C:\Users\Chrissi\Downloads\Defogger.exe
2013-08-29 01:01 - 2013-08-29 01:01 - 00000000 _____ C:\Users\Chrissi\defogger_reenable
2013-08-29 00:51 - 2013-08-30 00:11 - 00000448 _____ C:\Windows\setupact.log
2013-08-29 00:51 - 2013-08-29 00:51 - 00000000 _____ C:\Windows\setuperr.log
2013-08-29 00:02 - 2013-08-29 00:02 - 00002982 _____ C:\Windows\System32\Tasks\{F94307F9-E964-4C11-93B3-9779DDD76456}
2013-08-29 00:02 - 2013-08-29 00:02 - 00002982 _____ C:\Windows\System32\Tasks\{B5C0825F-D13C-4A5F-9739-B33444950E86}
2013-08-27 23:17 - 2013-08-30 00:21 - 00000318 _____ C:\Windows\Tasks\PELDTPPZ.job
2013-08-27 23:17 - 2013-08-27 23:17 - 00458752 __RSH C:\Windows\SysWOW64\iassam1.dll
2013-08-27 23:17 - 2013-08-27 23:17 - 00002598 _____ C:\Windows\System32\Tasks\PELDTPPZ
2013-08-22 10:02 - 2013-08-22 10:02 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-08-19 13:09 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-19 13:09 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-19 13:09 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-19 13:09 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-19 13:09 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-19 13:09 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-19 13:09 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-19 13:09 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-19 13:09 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-19 13:09 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-19 13:09 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-19 13:09 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-19 13:09 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-19 13:09 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-19 12:47 - 2013-08-19 12:50 - 00000000 ____D C:\Windows\system32\MRT
2013-08-17 19:10 - 2013-08-17 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-14 13:22 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 13:21 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 13:21 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 13:19 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 13:19 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 13:19 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 13:19 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 13:19 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 13:19 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 13:19 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 13:19 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 13:18 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 13:18 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 13:18 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 13:18 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 13:18 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 13:18 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 13:18 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 13:18 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 13:18 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 13:18 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 13:18 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 13:18 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 13:18 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 13:18 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 13:18 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 13:17 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
==================== One Month Modified Files and Folders =======
2013-08-30 00:30 - 2013-08-29 01:19 - 00000000 ____D C:\Users\Chrissi\Desktop\pc
2013-08-30 00:29 - 2012-03-03 17:47 - 01753720 _____ C:\Windows\WindowsUpdate.log
2013-08-30 00:28 - 2013-08-30 00:28 - 00015098 _____ C:\Users\Chrissi\Desktop\JRT.txt
2013-08-30 00:21 - 2013-08-27 23:17 - 00000318 _____ C:\Windows\Tasks\PELDTPPZ.job
2013-08-30 00:19 - 2013-08-30 00:19 - 00000000 ____D C:\Windows\ERUNT
2013-08-30 00:19 - 2009-07-14 06:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-30 00:19 - 2009-07-14 06:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-30 00:13 - 2013-08-29 20:11 - 00001868 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2013-08-30 00:13 - 2012-09-11 01:40 - 00000000 ____D C:\Users\Chrissi\AppData\Local\Htc
2013-08-30 00:12 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-30 00:11 - 2013-08-29 00:51 - 00000448 _____ C:\Windows\setupact.log
2013-08-30 00:10 - 2013-08-30 00:08 - 00000000 ____D C:\AdwCleaner
2013-08-29 23:59 - 2012-11-10 13:30 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-29 20:33 - 2013-01-06 02:55 - 00000000 ____D C:\Users\Chrissi\AppData\Roaming\LavasoftStatistics
2013-08-29 20:33 - 2013-01-06 02:45 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus
2013-08-29 20:10 - 2013-08-29 20:10 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-08-29 20:10 - 2013-08-29 20:10 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection
2013-08-29 20:09 - 2013-08-29 20:09 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2013-08-29 20:04 - 2013-08-29 20:04 - 00047496 _____ (GFI Software) C:\Windows\system32\sbbd.exe
2013-08-29 20:04 - 2013-01-06 02:45 - 00014456 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys
2013-08-29 19:56 - 2013-08-29 19:56 - 00004128 _____ C:\Windows\PFRO.log
2013-08-29 19:43 - 2013-08-29 19:43 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 19:43 - 2013-08-29 19:43 - 00000000 ____D C:\Users\Chrissi\AppData\Roaming\Malwarebytes
2013-08-29 19:43 - 2013-08-29 19:43 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 19:43 - 2013-08-29 19:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-29 19:42 - 2013-08-29 19:41 - 00994642 _____ C:\Users\Chrissi\Downloads\adwcleaner.exe
2013-08-29 19:41 - 2013-08-29 19:41 - 01023533 _____ (Thisisu) C:\Users\Chrissi\Desktop\JRT.exe
2013-08-29 19:41 - 2013-08-29 19:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Chrissi\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 17:28 - 2013-08-29 11:33 - 00000000 ____D C:\Qoobox
2013-08-29 17:27 - 2013-08-29 17:27 - 00012732 _____ C:\ComboFix.txt
2013-08-29 17:27 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-29 17:24 - 2013-08-29 11:32 - 00000000 ____D C:\Windows\erdnt
2013-08-29 17:15 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-29 11:29 - 2013-08-29 11:27 - 05115711 ____R (Swearware) C:\Users\Chrissi\Desktop\ComboFix.exe
2013-08-29 09:59 - 2013-08-29 09:59 - 00003304 ____N C:\bootsqm.dat
2013-08-29 02:00 - 2013-08-29 02:00 - 354462448 _____ C:\Windows\MEMORY.DMP
2013-08-29 02:00 - 2013-08-29 02:00 - 00521008 _____ C:\Windows\Minidump\082913-14757-01.dmp
2013-08-29 02:00 - 2013-03-08 16:42 - 00000000 ____D C:\Windows\Minidump
2013-08-29 01:10 - 2013-08-29 01:10 - 00377856 _____ C:\Users\Chrissi\Downloads\gmer_2.1.19163.exe
2013-08-29 01:04 - 2013-08-29 01:04 - 00000000 ____D C:\FRST
2013-08-29 01:02 - 2013-08-29 01:01 - 01579080 _____ (Farbar) C:\Users\Chrissi\Downloads\FRST64.exe
2013-08-29 01:02 - 2013-08-29 01:01 - 00000476 _____ C:\Users\Chrissi\Downloads\defogger_disable.log
2013-08-29 01:01 - 2013-08-29 01:01 - 00050477 _____ C:\Users\Chrissi\Downloads\Defogger.exe
2013-08-29 01:01 - 2013-08-29 01:01 - 00000000 _____ C:\Users\Chrissi\defogger_reenable
2013-08-29 01:01 - 2012-03-03 17:57 - 00000000 ____D C:\Users\Chrissi
2013-08-29 00:51 - 2013-08-29 00:51 - 00000000 _____ C:\Windows\setuperr.log
2013-08-29 00:02 - 2013-08-29 00:02 - 00002982 _____ C:\Windows\System32\Tasks\{F94307F9-E964-4C11-93B3-9779DDD76456}
2013-08-29 00:02 - 2013-08-29 00:02 - 00002982 _____ C:\Windows\System32\Tasks\{B5C0825F-D13C-4A5F-9739-B33444950E86}
2013-08-29 00:01 - 2012-03-03 17:59 - 00003946 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{7F99FFB5-B081-4B1E-A27A-96C6AA5B16C0}
2013-08-27 23:17 - 2013-08-27 23:17 - 00458752 __RSH C:\Windows\SysWOW64\iassam1.dll
2013-08-27 23:17 - 2013-08-27 23:17 - 00002598 _____ C:\Windows\System32\Tasks\PELDTPPZ
2013-08-27 12:34 - 2012-03-05 04:01 - 00003072 ____H C:\Users\Chrissi\Desktop\photothumb.db
2013-08-24 11:38 - 2013-06-10 21:46 - 00000000 ____D C:\Users\Chrissi\Desktop\noch anschauen ob okay
2013-08-23 18:36 - 2013-06-11 13:42 - 00000000 ____D C:\Users\Chrissi\Desktop\brennen
2013-08-23 00:41 - 2013-06-18 13:26 - 00000000 ____D C:\Users\Chrissi\Desktop\konvertieren
2013-08-23 00:01 - 2012-03-04 01:51 - 00000000 ____D C:\Users\Chrissi\AppData\Roaming\Orbit
2013-08-22 23:15 - 2012-03-03 17:44 - 00000000 ____D C:\Windows\Panther
2013-08-22 10:11 - 2012-11-10 13:30 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-22 10:11 - 2012-11-10 13:30 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-22 10:11 - 2012-03-03 18:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-22 10:02 - 2013-08-22 10:02 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-08-20 10:19 - 2012-10-15 14:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-19 12:57 - 2009-07-14 19:58 - 00654400 _____ C:\Windows\system32\perfh007.dat
2013-08-19 12:57 - 2009-07-14 19:58 - 00130240 _____ C:\Windows\system32\perfc007.dat
2013-08-19 12:57 - 2009-07-14 07:13 - 01520734 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-19 12:50 - 2013-08-19 12:47 - 00000000 ____D C:\Windows\system32\MRT
2013-08-19 12:47 - 2013-01-08 16:12 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-17 19:11 - 2013-08-17 19:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 00:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-05 23:42 - 2012-03-05 04:14 - 00000000 ____D C:\Users\Chrissi\AppData\Roaming\vlc
2013-07-31 22:11 - 2012-03-03 17:57 - 00000000 ____D C:\Users\Chrissi\AppData\Local\VirtualStore
Files to move or delete:
====================
C:\Users\Chrissi\AppData\Local\Temp\5dce5bbf-e477-4d7b-8db1-979ce6c19d95.exe
C:\Users\Chrissi\AppData\Local\Temp\af8964fa-f763-47e2-a9aa-00fd05224349.exe
C:\Users\Chrissi\AppData\Local\Temp\db8f4fbf-2009-46bf-ad53-b4de7f0059cf.exe
C:\Users\Chrissi\AppData\Local\Temp\Quarantine.exe
C:\Users\Chrissi\AppData\Local\Temp\{EF629AEC-F597-4278-A993-7F220D4D165C}\ISBEW64.exe
C:\Users\Chrissi\AppData\Local\Temp\{CB1785BF-805E-4F2C-A593-B42E712CA6E4}\ISBEW64.exe
C:\Users\Chrissi\AppData\Local\Temp\{73D3C2D9-2F95-45E4-A4C6-674AE2AC865A}\ISBEW64.exe
C:\Users\Chrissi\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Chrissi\AppData\Local\Temp\b249740f-5c71-4e7d-ba13-76e2bde44a27\Statistics.dll
C:\Users\Chrissi\AppData\Local\Temp\53a5f003-8fb7-4071-8ddc-7cd879f6f809\CartSdk.dll
C:\Users\Chrissi\AppData\Local\Temp\53a5f003-8fb7-4071-8ddc-7cd879f6f809\CartSdk64.exe
C:\Users\Chrissi\AppData\Local\Temp\53a5f003-8fb7-4071-8ddc-7cd879f6f809\sbrc.exe
C:\Users\Chrissi\AppData\Local\Temp\53a5f003-8fb7-4071-8ddc-7cd879f6f809\i386\sbbd.exe
C:\Users\Chrissi\AppData\Local\Temp\53a5f003-8fb7-4071-8ddc-7cd879f6f809\amd64\sbbd.exe
C:\Users\Chrissi\AppData\Local\Temp\0464013f-93c7-42c0-9968-22f340a6da56\Statistics.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-02-05 02:14
==================== End Of Log ============================ --- --- --- |