hallo Schrauber,
hier schon mal log von Eset:
Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=1a3a215dedbb674faccb3f97c1e49b8c
# engine=15046
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-09-08 08:20:19
# local_time=2013-09-08 10:20:19 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1286 16777213 100 98 16976 33394741 0 0
# compatibility_mode=5892 16776574 100 100 100971 216161147 0 0
# scanned=158959
# found=1
# cleaned=0
# scan_time=6116
sh=67971BFDA4A85D27945D4F77AEFFDD17350C693F ft=1 fh=26404b2de5881d6f vn="Win32/Adware.PCFixCleaner application" ac=I fn="D:\pcfix-v205-de.exe"
die anderen beiden logs kommen anschließend, bg
das Fenster mit SoftwareUpdater.Ui.exe erscheint nicht mehr
nun haperts aber woanders:
-wenn ich meine e-mails abgerufen habe, und outlook wieder schließen will, kommt:
word kann den Speichervorgang aufgrund eines Berechtigungsfehlers nicht zu ende führen.
(C:\Users\Uschi\AppData\...\Normal.dot)
-beim Hochfahren des PC`s kommt ein Fenster mit:
die Leistung Ihres PC`s ist schwach
Beheben sie dies
-als ich für den ESET Online Scanner Firewall und Kaspersky Internet Security deaktiviert habe, hieß es: 34 Externverbindungen geöffnet
......wird in 5 sec geschlossen
sind sie damit einverstanden?
Ja oder nein, hab ich nein geklickt
ich hoffe, das war richtig
-------------------------------------------
SecurityCheck kann ich nicht downloaden, es öffnet sich ein kleines Fenster:
C:\Users\Uschi\AppData\Local\Temp konnte nicht gespeichert werden, weil sie die Inhalte dieses Ordners nicht ändern können.
Ändern sie die Ordnereigenschaften und versuchen Sie es nochmals oder versuchen Sie , an einem anderen Ort zu speichern.
Wie soll ich nun vorgehen?
hab nun eine ältere Version von SecurityCheck genommen, den Link dazu hab ich hier aus dem Forum
ich hoffe, das war in Ordnung
Code:
Results of screen317's Security Check version 0.99.72
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Kaspersky Internet Security
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java(TM) 6 Update 33
Java 7 Update 25
Adobe Flash Player 11.8.800.94
Adobe Reader 10.1.7 Adobe Reader out of Date!
Mozilla Firefox (23.0.1)
Google Chrome 29.0.1547.62
Google Chrome 29.0.1547.66
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
Kaspersky Lab Kaspersky Internet Security 2013 avp.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
-------------------
jetzt kann ich FRST nicht mehr downloaden
als ich den Scan machen wollte, hieß es die Version sei veraltet
ich hab mich verdrückt und anschließend war FRST gelöscht
wenn ich FRST nun downloaden will steht da das gleiche wie vorher bei SecurityCheck:
C:\Users\Uschi\AppData\Local\Temp konnte nicht gespeichert werden, weil sie die Inhalte dieses Ordners nicht ändern können.
Ändern sie die Ordnereigenschaften und versuchen Sie es nochmals oder versuchen Sie , an einem anderen Ort zu speichern.
Ich habe es auch mit der alten Version versucht, die noch angezeigt wird, aber da steht dann das Gleiche.
--------------------------------
hallo, nun hab ich es mit einem USB-Stick auf einem sauberen PC geschafft
hier nun FRST-log
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-09-2013
Ran by Uschi (administrator) on USCHI-PC on 08-09-2013 15:56:15
Running from G:\
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Micro-Star International Co., Ltd.) C:\Program Files\System Control Manager\MSIService.exe
() C:\Program Files\CDBurnerXP\NMSAccessU.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6265376 2008-08-21] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1833504 2008-08-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2012-12-08] (Kaspersky Lab ZAO)
HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [162856 2013-02-19] (Geek Software GmbH)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Policies\Explorer: [NoDrives] 0
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search
SearchScopes: HKCU - {208FCEF1-F711-441F-ACAB-ABF883A63EE3} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=si_de-21&index=blended&linkCode=ur2&camp=1638&creative=6742
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - No Name - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU -No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1
FireFox:
========
FF ProfilePath: C:\Users\Uschi\AppData\Roaming\Mozilla\Firefox\Profiles\ivk4uh7y.default
FF Homepage: about:home
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=13 - C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll No File
FF Plugin: @tools.google.com/Google Update;version=8 - C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Uschi\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Uschi\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Uschi\AppData\Roaming\Mozilla\Firefox\Profiles\ivk4uh7y.default\Extensions\ad80235d-5e5a-4a1d-a891-51b66a3e70f8@8f877d80-6977-415f-ac14-b52043838c19.com
FF Extension: No Name - C:\Users\Uschi\AppData\Roaming\Mozilla\Firefox\Profiles\ivk4uh7y.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM\...\Firefox\Extensions: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.de/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Uschi\AppData\Local\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Uschi\AppData\Local\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Uschi\AppData\Local\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\plugin/npUrlAdvisor.dll (Kaspersky Lab ZAO)
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0\plugin/online_banking_npapi.dll (Kaspersky Lab ZAO)
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\plugin/content_blocker_npapi.dll (Kaspersky Lab ZAO)
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4190_0\plugin/npVKPlugin.dll No File
CHR Plugin: (Skype Click to Call) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\plugin/npABPlugin.dll (Kaspersky Lab ZAO)
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Google Update) - C:\Users\Uschi\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File
CHR Extension: (YouTube) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0
CHR Extension: (Safe Money) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0
CHR Extension: (Content Blocker) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0
CHR Extension: (Plus-HD-2.4) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.24.48_0
CHR Extension: (Virtual Keyboard) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4292_0
CHR Extension: (Skype Click to Call) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Gmail) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR Extension: (Anti-Banner) - C:\Users\Uschi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx
CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx
========================== Services (Whitelisted) =================
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2012-12-08] (Kaspersky Lab ZAO)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.)
R2 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2009-11-12] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [x]
S2 gusvc; "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" [x]
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [165376 2010-10-08] ()
R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [136024 2012-06-19] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [594528 2013-04-23] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [24408 2012-08-02] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25944 2012-12-08] (Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25944 2012-12-08] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [44000 2013-06-18] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145040 2013-04-23] (Kaspersky Lab ZAO)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2010-10-08] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MonitorFunction; C:\Windows\System32\DRIVERS\TVMonitor.sys [13304 2011-12-16] (TeamViewer GmbH)
S3 RTL8187Se; C:\Windows\System32\DRIVERS\RTL8187Se.sys [333824 2008-08-23] (Realtek Semiconductor Corporation )
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1748352 2008-06-10] ()
S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Uschi\AppData\Local\Temp\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2013-04-23] (Kaspersky Lab ZAO)
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-08 14:17 - 2013-09-08 14:18 - 00891115 _____ C:\Users\Uschi\Downloads\SecurityCheck.exe
2013-09-08 08:17 - 2013-09-08 08:18 - 02347384 _____ (ESET) C:\Users\Uschi\Downloads\esetsmartinstaller_enu.exe
2013-09-07 15:21 - 2013-09-07 15:21 - 00035946 _____ C:\Users\Uschi\Desktop\FRST.txt
2013-09-07 15:14 - 2013-09-07 15:14 - 00000608 _____ C:\Users\Uschi\Desktop\AdwCleaner[S0] - Verknüpfung.lnk
2013-09-07 15:07 - 2013-09-07 15:07 - 00003528 _____ C:\Users\Uschi\Desktop\JRT.txt
2013-09-07 15:01 - 2013-09-07 15:01 - 00000000 ____D C:\Windows\ERUNT
2013-09-07 15:00 - 2013-09-07 15:00 - 01028823 _____ (Thisisu) C:\Users\Uschi\Desktop\JRT.exe
2013-09-07 14:51 - 2013-09-07 14:53 - 00000000 ____D C:\AdwCleaner
2013-09-07 14:50 - 2013-09-07 14:50 - 01037308 _____ C:\Users\Uschi\Desktop\adwcleaner.exe
2013-09-07 14:23 - 2013-09-07 14:23 - 00000912 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-07 14:23 - 2013-09-07 14:23 - 00000000 ____D C:\Users\Uschi\AppData\Roaming\Malwarebytes
2013-09-07 14:23 - 2013-09-07 14:23 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-07 14:23 - 2013-09-07 14:23 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-07 14:23 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-07 14:13 - 2013-09-07 14:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Uschi\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-06 23:31 - 2013-09-06 23:31 - 00000606 _____ C:\Users\Uschi\Desktop\ComboFix log - Verknüpfung.lnk
2013-09-06 22:54 - 2013-09-06 22:54 - 00011834 _____ C:\ComboFix.txt
2013-09-06 21:14 - 2013-09-06 22:54 - 00000000 ____D C:\Qoobox
2013-09-06 21:14 - 2013-09-06 22:54 - 00000000 ____D C:\ComboFix
2013-09-06 21:14 - 2013-09-06 21:27 - 00000000 ____D C:\Windows\erdnt
2013-09-06 21:14 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-06 21:14 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-06 21:14 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-06 21:14 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-06 21:14 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-06 21:14 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-06 21:14 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-06 21:14 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-06 21:13 - 2013-09-06 21:13 - 00000586 _____ C:\Users\Uschi\Desktop\ComboFix - Verknüpfung.lnk
2013-09-06 21:11 - 2013-09-06 21:11 - 00445803 _____ (Swearware) C:\Users\Uschi\Downloads\ComboFix(1).exe.part
2013-09-06 20:59 - 2013-09-06 21:01 - 05120615 ____R (Swearware) C:\Users\Uschi\Downloads\ComboFix.exe
2013-09-06 19:16 - 2013-09-06 19:16 - 00000626 _____ C:\Users\Uschi\Desktop\Additionlogdatei - Verknüpfung.lnk
2013-09-06 19:15 - 2013-09-06 19:15 - 00000626 _____ C:\Users\Uschi\Desktop\defogger_disable - Verknüpfung.lnk
2013-09-06 19:15 - 2013-09-06 19:15 - 00000606 _____ C:\Users\Uschi\Desktop\FRSTlogdatei - Verknüpfung.lnk
2013-09-06 18:35 - 2013-09-06 18:35 - 00377856 _____ C:\Users\Uschi\Downloads\gmer_2.1.19163.exe
2013-09-06 08:24 - 2013-09-06 08:24 - 00034476 _____ C:\Users\Uschi\Downloads\FRST.txt
2013-09-06 08:23 - 2013-09-06 08:27 - 00029120 _____ C:\Users\Uschi\Downloads\Addition.txt
2013-09-06 08:20 - 2013-09-06 08:20 - 00000000 ____D C:\FRST
2013-09-06 08:17 - 2013-09-06 08:17 - 00000887 _____ C:\Users\Uschi\Desktop\Defogger - Verknüpfung.lnk
2013-09-06 08:12 - 2013-09-06 08:19 - 00000472 _____ C:\Users\Uschi\Downloads\defogger_disable.log
2013-09-06 08:12 - 2013-09-06 08:12 - 00000000 _____ C:\Users\Uschi\defogger_reenable
2013-09-06 08:09 - 2013-09-06 08:09 - 00050477 _____ C:\Users\Uschi\Downloads\Defogger.exe
2013-09-01 11:24 - 2013-09-01 11:36 - 00000000 ____D C:\Users\Uschi\AppData\Local\Freemium
2013-09-01 11:19 - 2013-09-01 12:12 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-09-01 11:12 - 2013-09-01 11:13 - 00000000 ____D C:\Program Files\Plus-HD-2.4
2013-09-01 11:11 - 2013-09-01 13:01 - 00002535 _____ C:\Users\Public\Desktop\Free System Utilities.lnk
2013-09-01 11:11 - 2013-09-01 11:11 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-09-01 11:11 - 2013-09-01 11:11 - 00000000 ____D C:\Program Files\Covus Freemium
2013-09-01 11:10 - 2013-09-01 11:11 - 00000000 ____D C:\ProgramData\Package Cache
2013-09-01 10:58 - 2013-09-01 10:59 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_de-DE.exe
2013-09-01 10:55 - 2013-09-01 10:55 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_en-US (2).exe
2013-09-01 10:49 - 2013-09-01 10:49 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_en-US (1).exe
2013-09-01 10:47 - 2013-09-01 10:47 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_en-US.exe
2013-09-01 10:30 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe
2013-09-01 10:25 - 2013-09-01 10:25 - 00720496 _____ C:\Users\Uschi\Downloads\free-clever-privacy_1.0_de-DE.exe
2013-09-01 10:25 - 2013-09-01 10:25 - 00720496 _____ C:\Users\Uschi\Downloads\free-clever-privacy_1.0_de-DE (1).exe
2013-09-01 09:55 - 2013-09-01 09:55 - 00000000 ____D C:\Program Files\Common Files\Skype
2013-08-28 20:06 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-22 21:06 - 2013-08-22 21:06 - 00015872 _____ C:\Users\Uschi\Documents\Kostenauflistung Alfred Batzhuber.xls
2013-08-17 20:16 - 2013-09-01 10:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-16 07:51 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-16 07:51 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-16 07:51 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-16 07:51 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-16 07:51 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-16 07:51 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-16 07:51 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-16 07:51 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-16 07:51 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-16 07:51 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-16 07:51 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-16 07:51 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-16 07:51 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-16 07:51 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-16 07:51 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-16 07:51 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-14 05:26 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 05:26 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 05:26 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 05:26 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-14 05:26 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 05:26 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 05:26 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 05:26 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 05:26 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 05:26 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 05:26 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-08-14 05:26 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-09-08 15:55 - 2013-09-08 15:55 - 00000277 _____ C:\Users\Uschi\Desktop\FRST - Verknüpfung.lnk
2013-09-08 15:55 - 2012-08-27 07:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-08 15:55 - 2008-10-07 10:51 - 01441486 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-08 15:53 - 2012-05-08 19:42 - 00002882 _____ C:\Windows\setupact.log
2013-09-08 15:46 - 2012-09-26 10:32 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4228028503-2934421193-2793015311-1000UA.job
2013-09-08 15:39 - 2012-12-08 09:50 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-09-08 15:08 - 2008-11-22 15:45 - 01251571 _____ C:\Windows\WindowsUpdate.log
2013-09-08 15:06 - 2008-10-07 13:32 - 00056959 _____ C:\ProgramData\nvModes.001
2013-09-08 15:03 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-08 15:03 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-08 15:03 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-08 15:02 - 2006-11-02 15:01 - 00032510 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-08 14:18 - 2013-09-08 14:17 - 00891115 _____ C:\Users\Uschi\Downloads\SecurityCheck.exe
2013-09-08 08:18 - 2013-09-08 08:17 - 02347384 _____ (ESET) C:\Users\Uschi\Downloads\esetsmartinstaller_enu.exe
2013-09-08 06:46 - 2012-09-26 10:32 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4228028503-2934421193-2793015311-1000Core.job
2013-09-07 21:57 - 2008-11-22 15:55 - 00000000 ____D C:\Users\Uschi
2013-09-07 19:54 - 2010-11-01 19:26 - 00000000 ____D C:\Users\Uschi\AppData\Local\CrashDumps
2013-09-07 15:21 - 2013-09-07 15:21 - 00035946 _____ C:\Users\Uschi\Desktop\FRST.txt
2013-09-07 15:14 - 2013-09-07 15:14 - 00000608 _____ C:\Users\Uschi\Desktop\AdwCleaner[S0] - Verknüpfung.lnk
2013-09-07 15:07 - 2013-09-07 15:07 - 00003528 _____ C:\Users\Uschi\Desktop\JRT.txt
2013-09-07 15:01 - 2013-09-07 15:01 - 00000000 ____D C:\Windows\ERUNT
2013-09-07 15:00 - 2013-09-07 15:00 - 01028823 _____ (Thisisu) C:\Users\Uschi\Desktop\JRT.exe
2013-09-07 14:53 - 2013-09-07 14:51 - 00000000 ____D C:\AdwCleaner
2013-09-07 14:50 - 2013-09-07 14:50 - 01037308 _____ C:\Users\Uschi\Desktop\adwcleaner.exe
2013-09-07 14:23 - 2013-09-07 14:23 - 00000912 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-07 14:23 - 2013-09-07 14:23 - 00000000 ____D C:\Users\Uschi\AppData\Roaming\Malwarebytes
2013-09-07 14:23 - 2013-09-07 14:23 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-07 14:23 - 2013-09-07 14:23 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-07 14:16 - 2013-09-07 14:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Uschi\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-07 07:13 - 2012-09-26 18:03 - 00000000 ____D C:\Users\Uschi\AppData\Roaming\Skype
2013-09-07 05:42 - 2008-01-21 04:47 - 00763590 _____ C:\Windows\PFRO.log
2013-09-06 23:31 - 2013-09-06 23:31 - 00000606 _____ C:\Users\Uschi\Desktop\ComboFix log - Verknüpfung.lnk
2013-09-06 22:54 - 2013-09-06 22:54 - 00011834 _____ C:\ComboFix.txt
2013-09-06 22:54 - 2013-09-06 21:14 - 00000000 ____D C:\Qoobox
2013-09-06 22:54 - 2013-09-06 21:14 - 00000000 ____D C:\ComboFix
2013-09-06 22:54 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2013-09-06 22:54 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-09-06 21:27 - 2013-09-06 21:14 - 00000000 ____D C:\Windows\erdnt
2013-09-06 21:27 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2013-09-06 21:13 - 2013-09-06 21:13 - 00000586 _____ C:\Users\Uschi\Desktop\ComboFix - Verknüpfung.lnk
2013-09-06 21:11 - 2013-09-06 21:11 - 00445803 _____ (Swearware) C:\Users\Uschi\Downloads\ComboFix(1).exe.part
2013-09-06 21:01 - 2013-09-06 20:59 - 05120615 ____R (Swearware) C:\Users\Uschi\Downloads\ComboFix.exe
2013-09-06 19:16 - 2013-09-06 19:16 - 00000626 _____ C:\Users\Uschi\Desktop\Additionlogdatei - Verknüpfung.lnk
2013-09-06 19:15 - 2013-09-06 19:15 - 00000626 _____ C:\Users\Uschi\Desktop\defogger_disable - Verknüpfung.lnk
2013-09-06 19:15 - 2013-09-06 19:15 - 00000606 _____ C:\Users\Uschi\Desktop\FRSTlogdatei - Verknüpfung.lnk
2013-09-06 18:35 - 2013-09-06 18:35 - 00377856 _____ C:\Users\Uschi\Downloads\gmer_2.1.19163.exe
2013-09-06 08:27 - 2013-09-06 08:23 - 00029120 _____ C:\Users\Uschi\Downloads\Addition.txt
2013-09-06 08:24 - 2013-09-06 08:24 - 00034476 _____ C:\Users\Uschi\Downloads\FRST.txt
2013-09-06 08:20 - 2013-09-06 08:20 - 00000000 ____D C:\FRST
2013-09-06 08:19 - 2013-09-06 08:12 - 00000472 _____ C:\Users\Uschi\Downloads\defogger_disable.log
2013-09-06 08:17 - 2013-09-06 08:17 - 00000887 _____ C:\Users\Uschi\Desktop\Defogger - Verknüpfung.lnk
2013-09-06 08:12 - 2013-09-06 08:12 - 00000000 _____ C:\Users\Uschi\defogger_reenable
2013-09-06 08:09 - 2013-09-06 08:09 - 00050477 _____ C:\Users\Uschi\Downloads\Defogger.exe
2013-09-06 05:59 - 2012-09-26 10:45 - 00002088 _____ C:\Users\Uschi\Desktop\Google Chrome.lnk
2013-09-01 13:01 - 2013-09-01 11:11 - 00002535 _____ C:\Users\Public\Desktop\Free System Utilities.lnk
2013-09-01 12:12 - 2013-09-01 11:19 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-09-01 11:36 - 2013-09-01 11:24 - 00000000 ____D C:\Users\Uschi\AppData\Local\Freemium
2013-09-01 11:32 - 2012-09-27 07:53 - 00000000 ____D C:\Users\Uschi\Desktop\Spiele
2013-09-01 11:13 - 2013-09-01 11:12 - 00000000 ____D C:\Program Files\Plus-HD-2.4
2013-09-01 11:11 - 2013-09-01 11:11 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-09-01 11:11 - 2013-09-01 11:11 - 00000000 ____D C:\Program Files\Covus Freemium
2013-09-01 11:11 - 2013-09-01 11:10 - 00000000 ____D C:\ProgramData\Package Cache
2013-09-01 10:59 - 2013-09-01 10:58 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_de-DE.exe
2013-09-01 10:55 - 2013-09-01 10:55 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_en-US (2).exe
2013-09-01 10:49 - 2013-09-01 10:49 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_en-US (1).exe
2013-09-01 10:47 - 2013-09-01 10:47 - 00720496 _____ C:\Users\Uschi\Downloads\free-system-utilities_1.0_en-US.exe
2013-09-01 10:30 - 2013-08-17 20:16 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-01 10:25 - 2013-09-01 10:25 - 00720496 _____ C:\Users\Uschi\Downloads\free-clever-privacy_1.0_de-DE.exe
2013-09-01 10:25 - 2013-09-01 10:25 - 00720496 _____ C:\Users\Uschi\Downloads\free-clever-privacy_1.0_de-DE (1).exe
2013-09-01 09:55 - 2013-09-01 09:55 - 00000000 ____D C:\Program Files\Common Files\Skype
2013-09-01 09:55 - 2012-09-26 18:03 - 00001880 _____ C:\Users\Public\Desktop\Skype.lnk
2013-09-01 09:55 - 2012-09-26 18:03 - 00000000 ___RD C:\Program Files\Skype
2013-09-01 09:55 - 2012-09-26 18:03 - 00000000 ____D C:\ProgramData\Skype
2013-08-22 21:06 - 2013-08-22 21:06 - 00015872 _____ C:\Users\Uschi\Documents\Kostenauflistung Alfred Batzhuber.xls
2013-08-22 20:41 - 2008-11-22 16:13 - 00002665 _____ C:\Users\Uschi\Desktop\Microsoft Office Excel 2003.lnk
2013-08-22 17:32 - 2010-05-03 21:03 - 00000000 ____D C:\Users\Uschi\Documents\Rezepte
2013-08-21 19:01 - 2012-04-26 21:35 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-08-21 19:01 - 2011-11-01 17:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-08-19 04:46 - 2012-04-25 05:36 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-18 07:55 - 2013-06-27 20:49 - 00000000 ____D C:\Program Files\Mozilla Firefox.bak
2013-08-14 06:05 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-08-14 05:45 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-14 05:37 - 2013-07-18 06:35 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 05:35 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-08-14 05:32 - 2006-11-02 12:23 - 00000240 _____ C:\Windows\win.ini
2013-08-13 08:38 - 2013-09-01 10:30 - 00032328 _____ C:\Windows\Launcher.exe
Files to move or delete:
====================
C:\Users\Uschi\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-08 15:11
==================== End Of Log ============================
--- --- ---
--- --- ---
gruss und einen schönen Sonntag Nachmittag