Hallo Schrauber,
so jetzt habe ich alles gemacht.
Beim FRS-Scan gab es AUffälligkeiten, siehe unten.
viele Grüße, ponch
Malwarebytes, nichts gefunden....den hatte ich aber auch schon am Wochenende laufen lassen, bevor ich das Trojaner-board aufgesucht habe: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.03.06
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
AdminFP :: FP-PC [Administrator]
Schutz: Aktiviert
03.09.2013 21:41:21
mbam-log-2013-09-03 (21-41-21).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 260435
Laufzeit: 7 Minute(n), 5 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) AdwCleaner(jüngstes Logfile; lief auch schon mal vor meiner Anwendung bei Trojaner Board) Code:
# AdwCleaner v3.002 - Bericht erstellt am 03/09/2013 um 21:59:18
# Updated 01/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium (64 bits)
# Benutzername : AdminFP - FP-PC
# Gestartet von : C:\Users\Surfer1\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\AdminFP\AppData\Roaming\Mozilla\Firefox\Profiles\pvyhv2ns.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7600.17267
-\\ Mozilla Firefox v8.0.1 (de)
[ Datei : C:\Users\AdminFP\AppData\Roaming\Mozilla\Firefox\Profiles\pvyhv2ns.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.backgroundjs", "\n\n/*****************************************************************************[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.js", "\n\n /************************************************************************************\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_104.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_13.name", "CrossriderAppUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_14.name", "CrossriderUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==true)&&(typeof _[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.a[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_con[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_78.name", "CrossriderInfo");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_87.code", "var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform==\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_91.code", "(function(h){var p=(function(){var R=0;var Z=\"\";function Q(ac){return [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "140e05da9bf8eec570e76aa73f3dcf25");
[ Datei : C:\Users\Surfer1\AppData\Roaming\Mozilla\Firefox\Profiles\54v7oxpa.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.backgroundjs", "\n\n/*****************************************************************************[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.js", "\n\n /************************************************************************************\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_104.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_13.name", "CrossriderAppUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_14.name", "CrossriderUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==true)&&(typeof _[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.a[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_con[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_78.name", "CrossriderInfo");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_87.code", "var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform==\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_91.code", "(function(h){var p=(function(){var R=0;var Z=\"\";function Q(ac){return [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "140dadc33df07af773b5afc33b96987d");
*************************
AdwCleaner[R0].txt - [61754 octets] - [01/09/2013 17:04:51]
AdwCleaner[R1].txt - [1631 octets] - [01/09/2013 17:13:28]
AdwCleaner[R2].txt - [1631 octets] - [01/09/2013 17:13:46]
AdwCleaner[R3].txt - [11152 octets] - [03/09/2013 21:57:30]
AdwCleaner[S0].txt - [61615 octets] - [01/09/2013 17:07:11]
AdwCleaner[S1].txt - [11074 octets] - [03/09/2013 21:59:18]
########## EOF - \AdwCleaner\AdwCleaner[S1].txt - [11135 octets] ##########
JRT LOG: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.7 (09.01.2013:1)
OS: Windows 7 Home Premium x64
Ran by AdminFP on 03.09.2013 at 22:11:05,78
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.09.2013 at 22:11:05,98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST: ACHTUNG!!
vor dem Scan bekam ich einen Haufen Fehlermeldungen: Code:
Error Saving File
c:\FRST\HIVES\BCD !
Continue with next file?
[RegCreateKeyEx: 5 - Zugriff verweigert]
Error Saving File
c:\FRST\HIVES\SOFTWARE !
Continue with next file?
[RegCreateKeyEx: 5 - Zugriff verweigert]
Error Saving File
c:\FRST\HIVES\SYSTEM !
Continue with next file?
[RegCreateKeyEx: 5 - Zugriff verweigert]
und 6 weitere... Danach habe ich den Scan durchgeführt.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2013 03
Ran by Surfer1 (ATTENTION: The logged in user is not administrator) on FP-PC on 03-09-2013 22:19:29
Running from C:\Users\Surfer1\Desktop
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Sonix Technology Co., Ltd.) C:\Windows\PLFSetL.exe
() C:\Windows\snuvcdsm.exe
(Spotify Ltd) C:\Users\Surfer1\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(CyberLink Corp.) C:\Program Files (x86)\Cyberlink\PCM4Everio\EverioService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(OpenOffice.org) C:\Program Files (x86)\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\program\soffice.bin
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\NOTEPAD.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Ocs_SM] - C:\Users\AdminFP\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [x]
HKLM\...\Run: [CDAServer] - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] ()
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13626072 2013-06-25] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1311304 2013-06-05] (Realtek Semiconductor)
HKLM\...\Run: [PLFSetL] - C:\Windows\PLFSetL.exe [99712 2011-01-13] (Sonix Technology Co., Ltd.)
HKLM\...\Run: [SNUVCDSM] - C:\Windows\snuvcdsm.exe [30080 2011-01-13] ()
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Surfer1\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-08-15] (Spotify Ltd)
HKCU\...\Run: [NTRedirect] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\AdminFP\AppData\Roaming\BabSolution\Shared\enhancedNT.dll",Run [x]
MountPoints2: {20c9ac43-9c73-11df-8d08-00262daaf8e3} - E:\OnSpcLCK.exe
MountPoints2: {66aadd89-8dac-11e0-a0ad-78e4006009dc} - E:\Password.exe
MountPoints2: {809c401a-f285-11df-8475-78e4006009dc} - E:\INSTALL.EXE
MountPoints2: {f8e95474-d784-11e2-a6c6-00262daaf8e3} - E:\Startme.exe
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-05] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [EverioService] - C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe [151552 2007-11-01] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
Startup: C:\Users\Surfer1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={04F22AD8-1048-4E9B-8965-BD8347881C6B}&mid=e9ba9d6e578a4aff834298f1213ff962-63409944151192cbd3a210f548ed6b6fcc1be1e6&lang=de&ds=wa011&pr=&d=2012-10-05 20:25:12&v=12.2.5.34&sap=hp
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_3820&r=27360710h216l0468z1k5t5691k130
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_3820&r=27360710h216l0468z1k5t5691k130
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_3820&r=27360710h216l0468z1k5t5691k130
URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File
URLSearchHook: (No Name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
URLSearchHook: (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {947192C9-00C7-41DB-A76B-7B12FA6C7DA8} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
SearchScopes: HKCU - {05E2E7B2-91D8-4461-96C5-7594F13036D9} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&mode=bounce&k=0
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=520C78E4006009DC&affID=121564&tsp=4985
SearchScopes: HKCU - {0F1CFC72-B293-4462-B01E-D9145B86066C} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&mode=bounce&k=0
SearchScopes: HKCU - {1A5ABBBB-9A59-4145-8E98-523D5EA6C086} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&mode=bounce&k=0
SearchScopes: HKCU - {2024A9A5-B3B7-452A-ACF2-DB8D22375CA4} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&mode=bounce&k=0
SearchScopes: HKCU - {471CBEBF-9894-402E-B703-729F8559EC08} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&mode=bounce&k=0
SearchScopes: HKCU - {4C8AF76E-34BE-4761-BE35-82EA17561BBB} URL = hxxp://de.search.yahoo.com.anonymize-me.de/?anonymto=687474703A2F2F64652E7365617263682E7961686F6F2E636F6D2F7365617263683F66723D6368722D677265656E747265655F69652665693D7574662D3826696C633D313226747970653D33303233393826703D7B7365617263685465726D737D&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&k=0
SearchScopes: HKCU - {4F1D61BE-91E4-4FA3-952A-81CF207F80BB} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&mode=bounce&k=0
SearchScopes: HKCU - {947192C9-00C7-41DB-A76B-7B12FA6C7DA8} URL = hxxp://search.conduit.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E636F6E647569742E636F6D2F526573756C74734578742E617370783F713D7B7365617263685465726D737D26536561726368536F757263653D3426637469643D435432323639303530&st={searchTerms}&clid=53012174-460a-4945-8c31-a36e732a4cec&pid=winsoftware&k=0
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://isearch.avg.com/search?cid={04F22AD8-1048-4E9B-8965-BD8347881C6B}&mid=e9ba9d6e578a4aff834298f1213ff962-63409944151192cbd3a210f548ed6b6fcc1be1e6&lang=de&ds=wa011&pr=&d=2012-10-05 20:25:12&v=12.2.5.34&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1561552
SearchScopes: HKCU - {D0C416F9-AF56-49F4-9A63-69972C4BDC5E} URL = hxxp://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000026&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000
SearchScopes: HKCU - {D1C184D3-26A3-4B9F-8458-F1B00DAD0ADF} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms}
SearchScopes: HKCU - {E8171FF0-0CBF-45F1-BE4A-BD73E9041190} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=76D46D67-E773-40C6-A2DB-BD9DCAA1E12E&apn_sauid=7769E7B5-7495-4117-9B39-DDD6B71CA241
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10001&barid={75BB13D6-0CC2-11E2-81D7-00262DAAF8E3}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files (x86)\Web Check\WebCheck.dll (Web Check)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File
Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
Toolbar: HKCU - No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Surfer1\AppData\Roaming\Mozilla\Firefox\Profiles\54v7oxpa.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Surfer1\AppData\Roaming\Mozilla\Firefox\Profiles\54v7oxpa.default\Extensions\c17236e8-fd66-44bc-aeef-1e00981cbb64@0a4ee0fe-5356-4fd3-b37c-5cd5671a315c.com
FF Extension: amznUWL2 - C:\Users\Surfer1\AppData\Roaming\Mozilla\Firefox\Profiles\54v7oxpa.default\Extensions\amznUWL2@amazon.com.xpi
FF Extension: No Name - C:\Users\Surfer1\AppData\Roaming\Mozilla\Firefox\Profiles\54v7oxpa.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF Extension: No Name - C:\Users\Surfer1\AppData\Roaming\Mozilla\Firefox\Profiles\54v7oxpa.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Surfer1\AppData\Roaming\Mozilla\Firefox\Profiles\54v7oxpa.default\Extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{52b0f3db-f988-4788-b9dc-861d016f4487}] C:\Program Files (x86)\Web Check\WebCheck.xpi
FF Extension: No Name - C:\Program Files (x86)\Web Check\WebCheck.xpi
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (YouTube) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Adblock Plus) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.4_0
CHR Extension: (Google Search) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Klicken, um Gutscheine f\u00FCr die aktuelle Seite anzuzeigen) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjacnemeogppppmlcoafbiacilcpngh\1.1.0.0_0
CHR Extension: (Web Check) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dacechnliklhcacondhhkkfobapdopee\0.1_0
CHR Extension: (ProxMate - Improve your Internet!) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\2.4.3_0
CHR Extension: (vshare plugin) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0
CHR Extension: (Plus-HD-3.8) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjgnhihlklpobkaloamkankaaoclfjh\1.23.19_0
CHR Extension: (Lyrics-Monkey) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofnnlhbgdcabppjmlijllkhekcglbjlg\1.131_0
CHR Extension: (Gmail) - C:\Users\Surfer1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Users\AdminFP\AppData\Local\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.11.0.crx
CHR HKLM-x32\...\Chrome\Extension: [cpjacnemeogppppmlcoafbiacilcpngh] - C:\Program Files (x86)\shopping-preise.de\shopping-preise-hrome.crx
CHR HKLM-x32\...\Chrome\Extension: [dacechnliklhcacondhhkkfobapdopee] - C:\Program Files (x86)\Web Check\WebCheck.crx
CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\vShare.tv plugin\vshareplg.crx
CHR HKLM-x32\...\Chrome\Extension: [ofnnlhbgdcabppjmlijllkhekcglbjlg] - C:\Program Files (x86)\Lyrics_Monkey\131.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-05] (Avira Operations GmbH & Co. KG)
R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [820768 2010-02-02] (Acer Incorporated)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [227232 2010-01-15] (McAfee, Inc.)
S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-04] ()
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-30] (Avira Operations GmbH & Co. KG)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [42248 2012-11-01] (AnchorFree Inc.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1806592 2011-01-13] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [40712 2012-11-01] (Anchorfree Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-03 22:09 - 2013-09-03 22:09 - 01028757 _____ (Thisisu) C:\Users\Surfer1\Desktop\JRT.exe
2013-09-03 21:55 - 2013-09-03 21:55 - 01037222 _____ C:\Users\Surfer1\Desktop\adwcleaner.exe
2013-09-03 21:36 - 2013-09-03 21:36 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-03 21:36 - 2013-09-03 21:36 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-03 21:36 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-03 21:35 - 2013-09-03 21:36 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Surfer1\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-03 21:33 - 2013-09-03 21:33 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\Malwarebytes
2013-09-03 21:08 - 2013-09-03 21:08 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{52A80CFD-A23C-4E07-A1C7-D12E725703FF}
2013-09-02 22:27 - 2013-09-02 22:27 - 00021947 _____ C:\ComboFix.txt
2013-09-02 22:12 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-02 22:12 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-02 22:12 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-02 22:12 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-02 22:12 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-02 22:12 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-02 22:12 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-02 22:12 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-02 22:09 - 2013-09-02 22:27 - 00000000 ____D C:\Qoobox
2013-09-02 22:08 - 2013-09-02 22:26 - 00000000 ____D C:\Windows\erdnt
2013-09-02 21:43 - 2013-09-02 21:43 - 05119472 ____R (Swearware) C:\Users\Surfer1\Desktop\ComboFix.exe
2013-09-02 21:26 - 2013-09-02 21:33 - 00005368 _____ C:\Users\Surfer1\Desktop\gmer.txt
2013-09-02 21:18 - 2013-09-02 21:18 - 00000871 _____ C:\Users\Surfer1\Desktop\troja.txt
2013-09-02 21:17 - 2013-09-02 21:17 - 00377856 _____ C:\Users\Surfer1\Desktop\q4olppq8.exe
2013-09-02 20:55 - 2013-09-02 20:55 - 00050610 _____ C:\Users\Surfer1\Desktop\FRST1.txt
2013-09-02 20:55 - 2013-09-02 20:55 - 00036734 _____ C:\Users\Surfer1\Desktop\Addition.txt
2013-09-02 20:52 - 2013-09-02 20:52 - 00000000 ____D C:\FRST
2013-09-02 20:46 - 2013-09-02 20:46 - 00000476 _____ C:\Users\Surfer1\Desktop\defogger_disable.log
2013-09-02 20:45 - 2013-09-02 20:45 - 00000000 _____ C:\Users\AdminFP\defogger_reenable
2013-09-02 20:43 - 2013-09-02 20:43 - 00050477 _____ C:\Users\Surfer1\Desktop\Defogger.exe
2013-09-01 21:38 - 2013-09-01 21:38 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{531C5CC6-9105-41B6-912D-98C9BBF73145}
2013-09-01 17:19 - 2013-09-01 17:19 - 00000000 ____D C:\Users\AdminFP\AppData\Roaming\Malwarebytes
2013-09-01 17:19 - 2013-09-01 17:19 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 17:17 - 2013-09-01 17:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Surfer1\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-01 17:04 - 2013-09-03 21:59 - 00000000 ____D C:\AdwCleaner
2013-09-01 17:04 - 2013-09-01 17:04 - 00994642 _____ C:\Users\Surfer1\Downloads\adwcleaner3001.exe
2013-08-31 21:34 - 2011-08-11 16:55 - 00001332 _____ C:\Windows\system32\Drivers\DTSU2P.DAT
2013-08-31 21:33 - 2013-06-25 18:42 - 03462616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2013-08-31 21:33 - 2013-06-25 16:25 - 00602901 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2013-08-31 21:33 - 2013-06-25 11:40 - 27937792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2013-08-31 21:33 - 2013-06-25 10:48 - 00146648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2013-08-31 21:33 - 2013-06-18 19:52 - 01004248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2013-08-31 21:33 - 2013-06-18 17:44 - 02736160 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2013-08-31 21:33 - 2013-06-18 15:40 - 03760856 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2013-08-31 21:33 - 2013-06-18 13:53 - 02795224 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2013-08-31 21:33 - 2013-06-05 21:42 - 00208072 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2013-08-31 21:33 - 2013-05-02 12:01 - 02103040 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2013-08-31 21:33 - 2013-05-02 12:01 - 02032896 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2013-08-31 21:33 - 2013-05-02 12:00 - 00920320 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2013-08-31 21:33 - 2013-04-24 17:16 - 01662024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2013-08-31 21:33 - 2013-04-18 13:49 - 14035712 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2013-08-31 21:33 - 2013-04-03 22:02 - 00613448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2013-08-31 21:33 - 2013-02-20 18:55 - 01284680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2013-08-31 21:33 - 2012-12-12 11:17 - 00395208 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2013-08-31 21:33 - 2012-07-15 21:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2013-08-31 21:33 - 2012-06-20 17:26 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2013-08-31 21:33 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2013-08-31 21:33 - 2012-01-30 11:43 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2013-08-31 21:33 - 2012-01-10 10:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2013-08-31 21:33 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2013-08-31 21:33 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2013-08-31 21:33 - 2011-03-17 12:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2013-08-31 21:33 - 2011-03-07 17:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2013-08-31 21:33 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2013-08-31 21:33 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2013-08-31 21:33 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2013-08-31 21:33 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2013-08-31 21:33 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2013-08-31 21:33 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2013-08-31 21:33 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2013-08-31 21:33 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2013-08-31 21:29 - 2013-08-31 21:29 - 00000000 ____D C:\Program Files\ATI Technologies
2013-08-31 20:57 - 2013-09-03 22:01 - 00001832 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job
2013-08-31 20:57 - 2013-09-03 22:01 - 00001294 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job
2013-08-31 20:57 - 2013-09-03 22:01 - 00001200 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job
2013-08-31 20:57 - 2013-09-03 22:01 - 00001098 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job
2013-08-31 20:57 - 2013-08-31 20:58 - 00000000 ____D C:\ProgramData\FreeDriverScout
2013-08-31 20:56 - 2013-09-03 22:01 - 00001908 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job
2013-08-31 20:56 - 2013-08-31 20:57 - 00000000 ____D C:\Program Files (x86)\Plus-HD-3.8
2013-08-31 20:56 - 2013-08-31 20:56 - 00002543 _____ C:\Users\Public\Desktop\Free Driver Scout.lnk
2013-08-31 20:56 - 2013-08-31 20:56 - 00000000 ____D C:\Program Files (x86)\Web Check
2013-08-31 20:55 - 2013-08-31 20:56 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-31 20:43 - 2013-08-31 20:43 - 00000000 ____D C:\Intel
2013-08-31 20:18 - 2013-08-31 20:18 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acer
2013-08-31 20:17 - 2013-08-31 20:17 - 00398848 _____ C:\Users\Surfer1\Downloads\SystemInformationSetup.msi
2013-08-31 19:50 - 2013-08-31 19:50 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-31 19:50 - 2013-08-31 19:50 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-31 19:50 - 2013-08-31 19:50 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-31 19:50 - 2013-08-31 19:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-31 19:47 - 2013-08-31 19:47 - 00903080 _____ (Oracle Corporation) C:\Users\Surfer1\Downloads\chromeinstall-7u25.exe
2013-08-26 22:21 - 2013-08-26 22:21 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\WinZip
2013-08-26 21:55 - 2013-08-26 21:55 - 00000000 ____D C:\Users\AdminFP\AppData\Roaming\Easeware
2013-08-26 21:54 - 2013-08-26 21:54 - 03025608 _____ (Easeware ) C:\Users\Surfer1\Downloads\DriverEasy_453Setup.exe
2013-08-26 21:17 - 2013-08-26 21:21 - 85415856 _____ C:\Users\Surfer1\Downloads\shotcut-win32-130823.exe
2013-08-26 21:11 - 2013-08-26 21:11 - 00000000 ____D C:\Program Files (x86)\Shotcut
2013-08-26 19:36 - 2013-08-26 19:37 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{25143AD7-53D4-4704-8BC6-33B54C6446E8}
2013-08-25 21:36 - 2013-08-25 21:41 - 85415153 _____ C:\Users\Surfer1\Downloads\shotcut-win32-130822.exe
2013-08-25 21:05 - 2013-08-25 21:05 - 00000000 ____D C:\Users\Surfer1\AppData\Local\avgchrome
2013-08-25 20:17 - 2013-08-31 23:32 - 00000000 ____D C:\FFOutput
2013-08-25 20:16 - 2013-08-25 20:16 - 00000000 ____D C:\Program Files (x86)\FreeTime
2013-08-25 19:49 - 2013-08-25 19:52 - 52657859 _____ C:\Users\Surfer1\Downloads\FFSetup3.1.1 (1).exe
2013-08-25 18:33 - 2013-08-25 18:33 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\TuneUp Software
2013-08-25 16:15 - 2013-08-25 16:15 - 00001370 _____ C:\Users\Public\Desktop\Free Video Dub.lnk
2013-08-25 16:14 - 2013-08-25 16:15 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-08-25 16:13 - 2013-08-26 22:17 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-08-25 16:13 - 2013-08-25 16:13 - 00000000 ____D C:\Users\AdminFP\AppData\Roaming\TuneUp Software
2013-08-25 16:13 - 2013-08-25 16:13 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-08-25 16:07 - 2013-08-25 16:07 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{FF086F32-24AC-4C00-AEA5-D20C80F7490A}
2013-08-25 13:34 - 2013-08-31 23:15 - 00000000 ____D C:\Users\Surfer1\Documents\MakeDiscVideo
2013-08-25 13:34 - 2013-08-26 19:34 - 00000000 ____D C:\Users\Surfer1\AppData\Local\PCM4Everio
2013-08-25 13:34 - 2013-08-25 16:01 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\CyberLink
2013-08-25 13:28 - 2013-08-25 13:28 - 00002083 _____ C:\Users\Public\Desktop\PowerCinema NE for Everio.lnk
2013-08-25 13:13 - 2013-08-25 13:15 - 09640162 _____ C:\Users\Surfer1\Downloads\JVC_Patch.v1718_EverioSD_Patch_PCM070507-01_R8.zip
2013-08-25 13:13 - 2013-08-25 13:14 - 04356968 _____ (Informer Technologies, Inc. ) C:\Users\Surfer1\Downloads\siinst.exe
2013-08-25 12:59 - 2013-08-25 13:00 - 00000000 ____D C:\Users\Surfer1\Documents\JVC
2013-08-25 12:58 - 2013-08-25 12:58 - 00002057 _____ C:\Users\Public\Desktop\Digital Photo Navigator 1.5.lnk
2013-08-25 12:58 - 2013-08-25 12:58 - 00000000 ____D C:\Program Files (x86)\Digital Photo Navigator 1.5
2013-08-21 22:18 - 2013-08-21 22:19 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{8506EFBB-6794-4B0A-BB8C-8BADDD3368E3}
2013-08-16 10:26 - 2013-08-16 10:26 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{117D2D01-842D-4B65-991F-687AC8A0D125}
2013-08-15 20:27 - 2013-08-15 20:30 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 16:18 - 2013-08-14 16:19 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{191AD794-DE5C-45F6-8125-66FA1EAD4ED4}
2013-08-11 11:52 - 2013-08-11 11:53 - 05698098 _____ C:\Users\Surfer1\Downloads\bremer_stadtmusikanten1.zip
2013-08-07 21:24 - 2013-08-07 21:24 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{673DC58A-5559-41AC-8BE4-31B68C5ED3A9}
2013-08-07 21:11 - 2013-08-07 22:00 - 00009110 _____ C:\Users\Surfer1\Documents\urlaubslliste.ods
2013-08-06 22:20 - 2013-08-06 22:20 - 00002216 _____ C:\Users\Public\Desktop\Google Earth.lnk
==================== One Month Modified Files and Folders =======
2013-09-03 22:17 - 2010-07-30 21:40 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-03 22:15 - 2013-09-03 22:15 - 01950416 _____ (Farbar) C:\Users\Surfer1\Desktop\FRST64.exe
2013-09-03 22:12 - 2009-07-14 06:51 - 00170819 _____ C:\Windows\setupact.log
2013-09-03 22:09 - 2013-09-03 22:09 - 01028757 _____ (Thisisu) C:\Users\Surfer1\Desktop\JRT.exe
2013-09-03 22:09 - 2009-07-14 06:45 - 00017376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-03 22:09 - 2009-07-14 06:45 - 00017376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-03 22:01 - 2013-08-31 20:57 - 00001832 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job
2013-09-03 22:01 - 2013-08-31 20:57 - 00001294 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job
2013-09-03 22:01 - 2013-08-31 20:57 - 00001200 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job
2013-09-03 22:01 - 2013-08-31 20:57 - 00001098 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job
2013-09-03 22:01 - 2013-08-31 20:56 - 00001908 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job
2013-09-03 22:01 - 2010-07-30 21:40 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-03 22:01 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-03 21:59 - 2013-09-01 17:04 - 00000000 ____D C:\AdwCleaner
2013-09-03 21:59 - 2010-05-28 18:55 - 01305729 _____ C:\Windows\WindowsUpdate.log
2013-09-03 21:55 - 2013-09-03 21:55 - 01037222 _____ C:\Users\Surfer1\Desktop\adwcleaner.exe
2013-09-03 21:55 - 2012-04-24 21:26 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-03 21:36 - 2013-09-03 21:36 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-03 21:36 - 2013-09-03 21:36 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-03 21:36 - 2013-09-03 21:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Surfer1\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-03 21:33 - 2013-09-03 21:33 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\Malwarebytes
2013-09-03 21:08 - 2013-09-03 21:08 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{52A80CFD-A23C-4E07-A1C7-D12E725703FF}
2013-09-03 21:08 - 2010-11-16 22:15 - 00000000 ____D C:\Users\Surfer1\AppData\Local\Windows Live
2013-09-03 20:22 - 2010-05-29 04:42 - 00664868 _____ C:\Windows\system32\perfh007.dat
2013-09-03 20:22 - 2010-05-29 04:42 - 00135004 _____ C:\Windows\system32\perfc007.dat
2013-09-03 20:22 - 2009-07-14 07:13 - 01527550 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-03 20:12 - 2012-12-17 11:04 - 00000072 _____ C:\Users\Public\LMDebug.log
2013-09-02 22:38 - 2010-03-24 21:55 - 00132102 _____ C:\Windows\PFRO.log
2013-09-02 22:29 - 2010-07-30 21:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-02 22:27 - 2013-09-02 22:27 - 00021947 _____ C:\ComboFix.txt
2013-09-02 22:27 - 2013-09-02 22:09 - 00000000 ____D C:\Qoobox
2013-09-02 22:26 - 2013-09-02 22:08 - 00000000 ____D C:\Windows\erdnt
2013-09-02 22:26 - 2010-07-30 21:26 - 00000000 ___RD C:\Users\Surfer1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-02 22:24 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-09-02 21:43 - 2013-09-02 21:43 - 05119472 ____R (Swearware) C:\Users\Surfer1\Desktop\ComboFix.exe
2013-09-02 21:33 - 2013-09-02 21:26 - 00005368 _____ C:\Users\Surfer1\Desktop\gmer.txt
2013-09-02 21:18 - 2013-09-02 21:18 - 00000871 _____ C:\Users\Surfer1\Desktop\troja.txt
2013-09-02 21:17 - 2013-09-02 21:17 - 00377856 _____ C:\Users\Surfer1\Desktop\q4olppq8.exe
2013-09-02 20:55 - 2013-09-02 20:55 - 00050610 _____ C:\Users\Surfer1\Desktop\FRST1.txt
2013-09-02 20:55 - 2013-09-02 20:55 - 00036734 _____ C:\Users\Surfer1\Desktop\Addition.txt
2013-09-02 20:52 - 2013-09-02 20:52 - 00000000 ____D C:\FRST
2013-09-02 20:46 - 2013-09-02 20:46 - 00000476 _____ C:\Users\Surfer1\Desktop\defogger_disable.log
2013-09-02 20:45 - 2013-09-02 20:45 - 00000000 _____ C:\Users\AdminFP\defogger_reenable
2013-09-02 20:45 - 2010-07-30 21:08 - 00000000 ____D C:\Users\AdminFP
2013-09-02 20:43 - 2013-09-02 20:43 - 00050477 _____ C:\Users\Surfer1\Desktop\Defogger.exe
2013-09-01 21:38 - 2013-09-01 21:38 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{531C5CC6-9105-41B6-912D-98C9BBF73145}
2013-09-01 20:49 - 2010-03-24 21:45 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-01 17:19 - 2013-09-01 17:19 - 00000000 ____D C:\Users\AdminFP\AppData\Roaming\Malwarebytes
2013-09-01 17:19 - 2013-09-01 17:19 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 17:18 - 2013-09-01 17:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Surfer1\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-01 17:04 - 2013-09-01 17:04 - 00994642 _____ C:\Users\Surfer1\Downloads\adwcleaner3001.exe
2013-08-31 23:32 - 2013-08-25 20:17 - 00000000 ____D C:\FFOutput
2013-08-31 23:15 - 2013-08-25 13:34 - 00000000 ____D C:\Users\Surfer1\Documents\MakeDiscVideo
2013-08-31 21:52 - 2010-05-28 19:02 - 00000000 ____D C:\Program Files (x86)\Cyberlink
2013-08-31 21:51 - 2010-03-24 21:40 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-31 21:34 - 2010-05-28 18:56 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2013-08-31 21:29 - 2013-08-31 21:29 - 00000000 ____D C:\Program Files\ATI Technologies
2013-08-31 20:58 - 2013-08-31 20:57 - 00000000 ____D C:\ProgramData\FreeDriverScout
2013-08-31 20:57 - 2013-08-31 20:56 - 00000000 ____D C:\Program Files (x86)\Plus-HD-3.8
2013-08-31 20:56 - 2013-08-31 20:56 - 00002543 _____ C:\Users\Public\Desktop\Free Driver Scout.lnk
2013-08-31 20:56 - 2013-08-31 20:56 - 00000000 ____D C:\Program Files (x86)\Web Check
2013-08-31 20:56 - 2013-08-31 20:55 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-31 20:43 - 2013-08-31 20:43 - 00000000 ____D C:\Intel
2013-08-31 20:18 - 2013-08-31 20:18 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acer
2013-08-31 20:18 - 2010-03-24 21:45 - 00000000 ____D C:\Program Files (x86)\Acer
2013-08-31 20:17 - 2013-08-31 20:17 - 00398848 _____ C:\Users\Surfer1\Downloads\SystemInformationSetup.msi
2013-08-31 19:50 - 2013-08-31 19:50 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-31 19:50 - 2013-08-31 19:50 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-31 19:50 - 2013-08-31 19:50 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-31 19:50 - 2013-08-31 19:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-31 19:50 - 2012-10-02 20:58 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2013-08-31 19:50 - 2010-10-05 21:16 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-31 19:47 - 2013-08-31 19:47 - 00903080 _____ (Oracle Corporation) C:\Users\Surfer1\Downloads\chromeinstall-7u25.exe
2013-08-29 18:58 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-26 22:59 - 2010-05-28 19:12 - 00000000 ____D C:\Program Files (x86)\Windows Live
2013-08-26 22:21 - 2013-08-26 22:21 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\WinZip
2013-08-26 22:17 - 2013-08-25 16:13 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-08-26 22:17 - 2010-07-31 22:50 - 00000000 ____D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2013-08-26 21:55 - 2013-08-26 21:55 - 00000000 ____D C:\Users\AdminFP\AppData\Roaming\Easeware
2013-08-26 21:54 - 2013-08-26 21:54 - 03025608 _____ (Easeware ) C:\Users\Surfer1\Downloads\DriverEasy_453Setup.exe
2013-08-26 21:21 - 2013-08-26 21:17 - 85415856 _____ C:\Users\Surfer1\Downloads\shotcut-win32-130823.exe
2013-08-26 21:11 - 2013-08-26 21:11 - 00000000 ____D C:\Program Files (x86)\Shotcut
2013-08-26 19:37 - 2013-08-26 19:36 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{25143AD7-53D4-4704-8BC6-33B54C6446E8}
2013-08-26 19:34 - 2013-08-25 13:34 - 00000000 ____D C:\Users\Surfer1\AppData\Local\PCM4Everio
2013-08-26 19:33 - 2009-07-14 06:45 - 00364256 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-25 21:41 - 2013-08-25 21:36 - 85415153 _____ C:\Users\Surfer1\Downloads\shotcut-win32-130822.exe
2013-08-25 21:05 - 2013-08-25 21:05 - 00000000 ____D C:\Users\Surfer1\AppData\Local\avgchrome
2013-08-25 20:16 - 2013-08-25 20:16 - 00000000 ____D C:\Program Files (x86)\FreeTime
2013-08-25 20:01 - 2010-07-30 21:26 - 00000000 ____D C:\Users\Surfer1\AppData\Local\VirtualStore
2013-08-25 19:52 - 2013-08-25 19:49 - 52657859 _____ C:\Users\Surfer1\Downloads\FFSetup3.1.1 (1).exe
2013-08-25 18:33 - 2013-08-25 18:33 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\TuneUp Software
2013-08-25 16:15 - 2013-08-25 16:15 - 00001370 _____ C:\Users\Public\Desktop\Free Video Dub.lnk
2013-08-25 16:15 - 2013-08-25 16:14 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-08-25 16:15 - 2013-05-20 22:18 - 00001247 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-08-25 16:15 - 2011-07-21 21:45 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\DVDVideoSoft
2013-08-25 16:15 - 2010-09-25 23:12 - 00000000 ____D C:\Users\Surfer1\Documents\DVDVideoSoft
2013-08-25 16:14 - 2011-07-21 21:44 - 00000000 ____D C:\Users\AdminFP\AppData\Roaming\DVDVideoSoft
2013-08-25 16:13 - 2013-08-25 16:13 - 00000000 ____D C:\Users\AdminFP\AppData\Roaming\TuneUp Software
2013-08-25 16:13 - 2013-08-25 16:13 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-08-25 16:07 - 2013-08-25 16:07 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{FF086F32-24AC-4C00-AEA5-D20C80F7490A}
2013-08-25 16:01 - 2013-08-25 13:34 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\CyberLink
2013-08-25 16:01 - 2010-05-28 19:01 - 00000000 ____D C:\ProgramData\CyberLink
2013-08-25 14:25 - 2010-11-27 22:00 - 00000000 ____D C:\deme
2013-08-25 13:34 - 2010-07-30 21:27 - 00086792 _____ C:\Users\Surfer1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-25 13:28 - 2013-08-25 13:28 - 00002083 _____ C:\Users\Public\Desktop\PowerCinema NE for Everio.lnk
2013-08-25 13:15 - 2013-08-25 13:13 - 09640162 _____ C:\Users\Surfer1\Downloads\JVC_Patch.v1718_EverioSD_Patch_PCM070507-01_R8.zip
2013-08-25 13:14 - 2013-08-25 13:13 - 04356968 _____ (Informer Technologies, Inc. ) C:\Users\Surfer1\Downloads\siinst.exe
2013-08-25 13:00 - 2013-08-25 12:59 - 00000000 ____D C:\Users\Surfer1\Documents\JVC
2013-08-25 12:58 - 2013-08-25 12:58 - 00002057 _____ C:\Users\Public\Desktop\Digital Photo Navigator 1.5.lnk
2013-08-25 12:58 - 2013-08-25 12:58 - 00000000 ____D C:\Program Files (x86)\Digital Photo Navigator 1.5
2013-08-21 22:19 - 2013-08-21 22:18 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{8506EFBB-6794-4B0A-BB8C-8BADDD3368E3}
2013-08-21 21:56 - 2012-04-24 21:26 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-21 21:56 - 2011-06-02 20:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-16 16:07 - 2012-04-04 22:45 - 00000000 ____D C:\Users\Surfer1\AppData\Roaming\Spotify
2013-08-16 10:26 - 2013-08-16 10:26 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{117D2D01-842D-4B65-991F-687AC8A0D125}
2013-08-15 21:54 - 2012-04-04 22:47 - 00000000 ____D C:\Users\Surfer1\AppData\Local\Spotify
2013-08-15 20:30 - 2013-08-15 20:27 - 00000000 ____D C:\Windows\system32\MRT
2013-08-15 20:30 - 2010-03-24 21:47 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-15 20:26 - 2011-07-07 21:47 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 16:19 - 2013-08-14 16:18 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{191AD794-DE5C-45F6-8125-66FA1EAD4ED4}
2013-08-11 11:53 - 2013-08-11 11:52 - 05698098 _____ C:\Users\Surfer1\Downloads\bremer_stadtmusikanten1.zip
2013-08-07 22:00 - 2013-08-07 21:11 - 00009110 _____ C:\Users\Surfer1\Documents\urlaubslliste.ods
2013-08-07 21:24 - 2013-08-07 21:24 - 00000000 ____D C:\Users\Surfer1\AppData\Local\{673DC58A-5559-41AC-8BE4-31B68C5ED3A9}
2013-08-06 22:20 - 2013-08-06 22:20 - 00002216 _____ C:\Users\Public\Desktop\Google Earth.lnk
Files to move or delete:
====================
C:\Users\AdminFP\pb-setup-5.4.0201.exe
C:\Users\Surfer1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ --- --- --- |