emilienne | 21.09.2013 22:41 | Hey, Punkt 1 macht mir zu schaffen. Ich kann die fixlog.txt nicht erstellen. Wenn ich auf Fix drücke, kommt immer fixlist.txt konnte nicht gefunden werden (obwohl auf meinem Desktop gespeichert!). Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.21.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16686
Katharina :: KATHARINA-PC [Administrator]
Schutz: Aktiviert
21.09.2013 23:21:39
mbam-log-2013-09-21 (23-21-39).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 188054
Laufzeit: 5 Minute(n), 15 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 2
HKLM\SOFTWARE\Plus-HD-3.8 (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-3.8 (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 1
C:\Program Files\Plus-HD-3.8 (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
Infizierte Dateien: 18
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\39030.crx (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\39030.xpi (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\background.html (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Installer.log (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-bg.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-buttonutil.dll (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-buttonutil.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-buttonutil64.dll (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-buttonutil64.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-helper.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-updater.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Plus-HD-3.8.ico (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\Uninstall.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
C:\Program Files\Plus-HD-3.8\utils.exe (PUP.Optional.PlusHD.A) -> Keine Aktion durchgeführt.
(Ende) Code:
# AdwCleaner v3.004 - Bericht erstellt am 21/09/2013 um 23:05:58
# Updated 15/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Katharina - KATHARINA-PC
# Gestartet von : C:\Users\Katharina\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\blekko toolbars
Ordner Gelöscht : C:\Users\Katharina\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Katharina\AppData\LocalLow\HomeTab
Ordner Gelöscht : C:\Users\Katharina\AppData\LocalLow\SimplyTech
Ordner Gelöscht : C:\Users\Katharina\AppData\Roaming\blekko
Ordner Gelöscht : C:\Users\Katharina\AppData\Roaming\HomeTab
Ordner Gelöscht : C:\Users\Katharina\AppData\Roaming\SimplyTech
Ordner Gelöscht : C:\Users\Katharina\AppData\Roaming\Windows Net Data
Datei Gelöscht : C:\Users\Katharina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
Datei Gelöscht : C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_466150\searchplugins\Web Search.xml
Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\Web Search.xml
Datei Gelöscht : C:\Windows\System32\Tasks\Browser Updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\HomeTab.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKCU\Software\HomeTab
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16686
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultengine", "Web Search");
Zeile gelöscht : user_pref("browser.search.order.1", "Web Search");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.backgroundjs", "\n\n/*****************************************************************************[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/2a71b3b28494cf1854d333288ccc18ba_DE.value", "%22var%20cat_2a71b3b28494cf1854d3332[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/3518e1eac042730aa1274618984462b3_DE.value", "%22var%20cat_3518e1eac042730aa127461[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9.value", "%22function%20tcmMarkWindow%28a%29%7Bva[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/d5baae4ef839769f8eb7e9f9d82d8a40_DE.value", "%22var%20cat_d5baae4ef839769f8eb7e9f[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.js", "\n\n /************************************************************************************\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_104.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_13.name", "CrossriderAppUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_14.name", "CrossriderUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==true)&&(typeof _[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.a[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_con[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a};}()var [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_78.name", "CrossriderInfo");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_87.code", "var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform==\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_9.code", "appAPI.hooks.addHook(\"searchEngine\",(function(a){return function(){var [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_91.code", "(function(h){var p=(function(){var R=0;var Z=\"\";function Q(ac){return [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "14136fb2dd8a571fb51af963d24995aa");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.4&ts=1379541600000.000009&tguid=66920-6787-1379606188873-35BB8D1CC92B7A23A46E07720937A4FD&st=chrome&q=");
[ Datei : C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_466150\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultengine", "Web Search");
Zeile gelöscht : user_pref("browser.search.order.1", "Web Search");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.backgroundjs", "\n\n/*****************************************************************************[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/2a71b3b28494cf1854d333288ccc18ba_DE.value", "%22var%20cat_2a71b3b28494cf1854d3332[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/3518e1eac042730aa1274618984462b3_DE.value", "%22var%20cat_3518e1eac042730aa127461[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9.value", "%22function%20tcmMarkWindow%28a%29%7Bva[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/d5baae4ef839769f8eb7e9f9d82d8a40_DE.value", "%22var%20cat_d5baae4ef839769f8eb7e9f[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.js", "\n\n /************************************************************************************\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_104.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_13.name", "CrossriderAppUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_14.name", "CrossriderUtils");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==true)&&(typeof _[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.a[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_con[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a};}()var [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_78.name", "CrossriderInfo");
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_87.code", "var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform==\[...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_9.code", "appAPI.hooks.addHook(\"searchEngine\",(function(a){return function(){var [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_91.code", "(function(h){var p=(function(){var R=0;var Z=\"\";function Q(ac){return [...]
Zeile gelöscht : user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "14136fb2dd8a571fb51af963d24995aa");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.4&ts=1379541600000.000009&tguid=66920-6787-1379606188873-35BB8D1CC92B7A23A46E07720937A4FD&st=chrome&q=");
*************************
AdwCleaner[R0].txt - [17948 octets] - [21/09/2013 22:57:31]
AdwCleaner[S0].txt - [16822 octets] - [21/09/2013 23:05:58]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16883 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.1 (09.15.2013:1)
OS: Windows 7 Home Premium x86
Ran by Katharina on 21.09.2013 at 23:13:28,44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322902230}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366906630}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366906630}
~~~ Files
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-3.8-chromeinstaller
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-3.8-codedownloader
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-3.8-enabler
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-3.8-firefoxinstaller
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-3.8-updater
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-3.8-enabler.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-3.8-updater.job
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Katharina\appdata\locallow\simplytech"
~~~ FireFox
Successfully deleted the following from C:\Users\Katharina\AppData\Roaming\mozilla\firefox\profiles\840nz3m7.default\prefs.js
user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/530e52021dc20843b1aa62957edeb9f8.value", "%22var%20adsDe
user_pref("extensions.ac17236e8fd6644bcaeef1e00981cbb640a4ee0fe53564fd3b37c5cd5671a315ccom39030.39030.internaldb.cache/833447eaff04548ccb80787286a7cad9_DE.value", "%22var%20ca
Emptied folder: C:\Users\Katharina\AppData\Roaming\mozilla\firefox\profiles\840nz3m7.default\minidumps [19 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.09.2013 at 23:18:23,81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-09-2013
Ran by Katharina (administrator) on KATHARINA-PC on 21-09-2013 23:32:33
Running from C:\Users\Katharina\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe
(AMD) C:\Windows\system32\atieclxx.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [PSUAMain] - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe [32736 2013-07-08] (Panda Security, S.L.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll ()
Toolbar: HKLM - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files\Freemium\Free PDF Perfect\ieagent32.dll (soft Xpansion)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default
FF NewTab: about:home
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @soft-xpansion/npsxpdf - C:\Program Files\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin: @videolan.org/vlc,version=2.0.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default\Extensions\c17236e8-fd66-44bc-aeef-1e00981cbb64@0a4ee0fe-5356-4fd3-b37c-5cd5671a315c.com
FF Extension: pricealarm - C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
FF Extension: HomeTab - C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947}
FF Extension: No Name - C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default\Extensions\WTB_GLOBAL.sqlite
FF Extension: No Name - C:\Users\Katharina\AppData\Roaming\Mozilla\Firefox\Profiles\840nz3m7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF HKLM\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
========================== Services (Whitelisted) =================
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2012-08-13] (LSI Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NanoServiceMain; C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [140768 2013-07-17] (Panda Security, S.L.)
R2 PSUAService; C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe [37344 2013-07-08] (Panda Security, S.L.)
S3 SXDS10; C:\Program Files\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-19] (soft Xpansion)
==================== Drivers (Whitelisted) ====================
R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [36856 2012-12-25] (IVT Corporation.)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R0 iaStorA; C:\Windows\System32\DRIVERS\iaStorA.sys [527344 2013-02-04] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [26096 2013-02-04] (Intel Corporation)
R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [16440 2012-12-04] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7530736 2013-02-27] (Intel Corporation)
R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [84200 2013-05-29] (Panda Security, S.L.)
R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [126184 2013-05-29] (Panda Security, S.L.)
R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [107752 2013-05-29] (Panda Security, S.L.)
R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [124648 2013-05-29] (Panda Security, S.L.)
R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95464 2013-05-29] (Panda Security, S.L.)
S4 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [61672 2013-05-29] (Panda Security, S.L.)
R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [106344 2013-05-29] (Panda Security, S.L.)
R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [287336 2013-05-29] (Panda Security, S.L.)
R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [161384 2013-05-29] (Panda Security, S.L.)
R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [108904 2013-05-29] (Panda Security, S.L.)
R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [230376 2013-05-29] (Panda Security, S.L.)
R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [93928 2013-05-29] (Panda Security, S.L.)
R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [145128 2013-05-28] (Panda Security, S.L.)
R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [105704 2013-07-17] (Panda Security, S.L.)
R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [175848 2013-05-28] (Panda Security, S.L.)
R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [114920 2013-05-28] (Panda Security, S.L.)
R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [127720 2013-05-29] (Panda Security, S.L.)
S3 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [97512 2013-05-28] (Panda Security, S.L.)
U3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1805872 2009-07-01] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-21 23:18 - 2013-09-21 23:18 - 00002447 _____ C:\Users\Katharina\Desktop\JRT.txt
2013-09-21 23:13 - 2013-09-21 23:13 - 00000000 ____D C:\Windows\ERUNT
2013-09-21 23:12 - 2013-09-21 23:13 - 01029675 _____ (Thisisu) C:\Users\Katharina\Downloads\JRT6.1.exe
2013-09-21 23:08 - 2013-04-29 09:17 - 00047632 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys
2013-09-21 22:56 - 2013-09-21 23:06 - 00000000 ____D C:\AdwCleaner
2013-09-21 22:56 - 2013-09-21 22:56 - 01039554 _____ C:\Users\Katharina\Downloads\adwcleaner.exe
2013-09-21 22:55 - 2013-09-21 22:55 - 01089757 _____ (Farbar) C:\Users\Katharina\Downloads\FRST(1).exe
2013-09-21 22:47 - 2013-09-21 22:47 - 00000000 ____D C:\Users\Katharina\Desktop\FRST
2013-09-21 22:38 - 2013-09-21 22:38 - 00000252 _____ C:\Users\Katharina\Desktop\fixlist.txt
2013-09-21 18:42 - 2013-09-21 18:42 - 00000356 _____ C:\Users\Katharina\Downloads\keine_Links_in_Outlook.reg
2013-09-21 15:58 - 2013-09-21 23:27 - 00000000 ____D C:\Users\Katharina\Desktop\Trojanerboard
2013-09-21 15:46 - 2013-09-21 15:47 - 00018865 _____ C:\Users\Katharina\Downloads\Addition.txt
2013-09-21 15:45 - 2013-09-21 22:43 - 00000000 ____D C:\FRST
2013-09-21 15:44 - 2013-09-21 15:44 - 01089757 _____ (Farbar) C:\Users\Katharina\Downloads\FRST.exe
2013-09-21 00:25 - 2013-09-21 12:56 - 00005856 _____ C:\ProgramData\NanoRepository.bin
2013-09-21 00:25 - 2013-09-21 00:25 - 00005856 _____ C:\ProgramData\NanoRepository.bin.bak
2013-09-20 20:39 - 2013-09-20 20:39 - 00050477 _____ C:\Users\Katharina\Downloads\Defogger(1).exe
2013-09-20 20:13 - 2013-09-20 20:13 - 00377856 _____ C:\Users\Katharina\Downloads\gmer_2.1.19163(1).exe
2013-09-20 20:09 - 2013-09-20 20:09 - 430908101 _____ C:\Windows\MEMORY.DMP
2013-09-20 20:09 - 2013-09-20 20:09 - 00143240 _____ C:\Windows\Minidump\092013-16411-01.dmp
2013-09-20 20:09 - 2013-09-20 20:09 - 00000000 ____D C:\Windows\Minidump
2013-09-20 19:43 - 2013-09-20 19:43 - 00377856 _____ C:\Users\Katharina\Downloads\gmer_2.1.19163.exe
2013-09-20 19:40 - 2013-09-21 23:08 - 00000280 _____ C:\Windows\setupact.log
2013-09-20 19:40 - 2013-09-20 19:40 - 00000000 _____ C:\Windows\setuperr.log
2013-09-20 19:30 - 2013-09-20 19:30 - 01950622 _____ (Farbar) C:\Users\Katharina\Downloads\FRST64.exe
2013-09-20 19:20 - 2013-09-20 19:25 - 00000480 _____ C:\Users\Katharina\Downloads\defogger_disable.log
2013-09-20 19:20 - 2013-09-20 19:20 - 00000000 _____ C:\Users\Katharina\defogger_reenable
2013-09-20 19:19 - 2013-09-20 19:19 - 00050477 _____ C:\Users\Katharina\Downloads\Defogger.exe
2013-09-20 18:39 - 2013-09-20 18:51 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-20 18:38 - 2013-09-20 18:51 - 00000000 ____D C:\Users\Katharina\Desktop\mbar
2013-09-20 18:37 - 2013-09-20 18:38 - 12907592 _____ (Malwarebytes Corp.) C:\Users\Katharina\Downloads\mbar-1.07.0.1005(1).exe
2013-09-20 18:37 - 2013-09-20 18:37 - 12907592 _____ (Malwarebytes Corp.) C:\Users\Katharina\Downloads\mbar-1.07.0.1005.exe
2013-09-20 17:34 - 2013-09-20 17:34 - 00001073 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-20 17:34 - 2013-09-20 17:34 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Malwarebytes
2013-09-20 17:34 - 2013-09-20 17:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-20 17:34 - 2013-09-20 17:34 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-20 17:34 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-20 17:33 - 2013-09-20 17:33 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Katharina\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-20 15:28 - 2013-09-21 16:38 - 00000000 ____D C:\Users\Katharina\Desktop\Kleiderkreisel
2013-09-19 18:09 - 2013-09-21 23:11 - 00000000 ____D C:\SoloApp
2013-09-19 18:00 - 2013-09-19 18:00 - 00010464 _____ C:\Windows\system32\sx_p2d.tlb
2013-09-19 18:00 - 2013-09-19 18:00 - 00002114 _____ C:\Users\Katharina\Desktop\Free PDF Perfect.lnk
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\ProgramData\Freemium
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\Program Files\Freemium
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\Program Files\Common Files\soft Xpansion
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\Program Files\Common Files\Freemium
2013-09-19 17:58 - 2013-09-19 17:58 - 00000000 ____D C:\Users\Katharina\Downloads\freepdf
2013-09-19 17:58 - 2013-09-19 17:58 - 00000000 ____D C:\ProgramData\Package Cache
2013-09-19 17:58 - 2013-09-19 17:58 - 00000000 ____D C:\Program Files\Covus Freemium
2013-09-19 17:57 - 2013-09-19 17:58 - 00000000 ____D C:\Program Files\Plus-HD-3.8
2013-09-19 17:57 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe
2013-09-19 17:54 - 2013-09-19 17:54 - 00444400 _____ C:\Users\Katharina\Downloads\DLG_free-pdf-perfect_chip_de-DE10.exe
2013-09-19 17:51 - 2013-09-19 17:51 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2013-09-19 17:49 - 2013-09-19 17:49 - 02469824 _____ C:\Users\Katharina\Downloads\AdobeDownloadAssistant.exe
2013-09-19 11:30 - 2013-09-19 17:45 - 00000000 ____D C:\Users\Katharina\Desktop\Bewerbung Schwabing
2013-09-19 11:26 - 2013-09-19 18:25 - 00000000 ____D C:\Users\Katharina\Desktop\Bewerbung LMU
2013-09-18 00:32 - 2013-09-18 00:32 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-09-18 00:32 - 2013-09-18 00:32 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-09-17 22:51 - 2013-09-17 22:51 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-09-17 22:48 - 2013-09-17 22:48 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-09-17 22:47 - 2013-09-18 00:39 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-17 22:47 - 2013-09-17 22:50 - 00000000 ____D C:\Program Files\Microsoft Office
2013-09-17 22:47 - 2013-09-17 22:47 - 00000000 __RHD C:\MSOCache
2013-09-17 22:47 - 2013-09-17 22:47 - 00000000 ____D C:\Users\Katharina\AppData\Local\Microsoft Help
2013-09-17 19:23 - 2013-09-17 22:40 - 1025493776 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X17-75062.exe
2013-09-17 14:35 - 2013-09-17 14:49 - 1169711680 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X17-75168.exe
2013-09-17 14:08 - 2013-09-17 14:16 - 813301744 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X17-22389.exe
2013-09-17 13:51 - 2013-09-17 14:00 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Download Manager
2013-09-17 13:50 - 2013-09-17 13:50 - 00000000 ____D C:\Windows\Sun
2013-09-17 10:22 - 2013-09-20 17:26 - 00000000 ____D C:\Users\Katharina\AppData\Local\Google
2013-09-17 10:22 - 2013-09-20 17:26 - 00000000 ____D C:\Program Files\Google
2013-09-17 10:22 - 2013-09-17 10:22 - 00001854 _____ C:\Users\Katharina\Desktop\IrfanView Thumbnails.lnk
2013-09-17 10:22 - 2013-09-17 10:22 - 00000978 _____ C:\Users\Katharina\Desktop\IrfanView.lnk
2013-09-17 10:22 - 2013-09-17 10:22 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-09-17 10:22 - 2013-09-17 10:22 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\IrfanView
2013-09-17 10:22 - 2013-09-17 10:22 - 00000000 ____D C:\Program Files\IrfanView
2013-09-17 10:19 - 2013-09-17 10:19 - 02145888 _____ (Irfan Skiljan) C:\Users\Katharina\Downloads\iview436g_setup.exe
2013-09-17 09:44 - 2013-09-17 09:45 - 28404551 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X16-33163(1).exe.part
2013-09-17 09:25 - 2013-09-17 09:31 - 329930248 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X16-33163.exe
2013-09-17 09:13 - 2013-09-19 11:32 - 00000000 ____D C:\Users\Katharina\Desktop\Bewerbung Leipzig
2013-09-13 21:19 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 21:19 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 21:19 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-13 21:19 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 21:19 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-13 21:19 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 21:19 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-13 11:12 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-13 11:12 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-13 11:12 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-13 11:12 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-13 11:11 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-13 11:11 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-13 11:11 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-13 11:11 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-13 11:11 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-03 12:57 - 2013-09-03 13:02 - 00000142 _____ C:\Users\Katharina\Desktop\Kurzdarmsyndrom.txt
==================== One Month Modified Files and Folders =======
2013-09-21 23:27 - 2013-09-21 15:58 - 00000000 ____D C:\Users\Katharina\Desktop\Trojanerboard
2013-09-21 23:18 - 2013-09-21 23:18 - 00002447 _____ C:\Users\Katharina\Desktop\JRT.txt
2013-09-21 23:16 - 2013-08-09 12:13 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-21 23:15 - 2009-07-14 06:34 - 00028128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-21 23:15 - 2009-07-14 06:34 - 00028128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-21 23:13 - 2013-09-21 23:13 - 00000000 ____D C:\Windows\ERUNT
2013-09-21 23:13 - 2013-09-21 23:12 - 01029675 _____ (Thisisu) C:\Users\Katharina\Downloads\JRT6.1.exe
2013-09-21 23:12 - 2010-11-20 23:01 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-21 23:11 - 2013-09-19 18:09 - 00000000 ____D C:\SoloApp
2013-09-21 23:11 - 2013-08-09 11:16 - 01568794 _____ C:\Windows\WindowsUpdate.log
2013-09-21 23:08 - 2013-09-20 19:40 - 00000280 _____ C:\Windows\setupact.log
2013-09-21 23:08 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-21 23:06 - 2013-09-21 22:56 - 00000000 ____D C:\AdwCleaner
2013-09-21 22:56 - 2013-09-21 22:56 - 01039554 _____ C:\Users\Katharina\Downloads\adwcleaner.exe
2013-09-21 22:55 - 2013-09-21 22:55 - 01089757 _____ (Farbar) C:\Users\Katharina\Downloads\FRST(1).exe
2013-09-21 22:47 - 2013-09-21 22:47 - 00000000 ____D C:\Users\Katharina\Desktop\FRST
2013-09-21 22:47 - 2013-08-11 13:46 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Skype
2013-09-21 22:43 - 2013-09-21 15:45 - 00000000 ____D C:\FRST
2013-09-21 22:38 - 2013-09-21 22:38 - 00000252 _____ C:\Users\Katharina\Desktop\fixlist.txt
2013-09-21 18:42 - 2013-09-21 18:42 - 00000356 _____ C:\Users\Katharina\Downloads\keine_Links_in_Outlook.reg
2013-09-21 16:38 - 2013-09-20 15:28 - 00000000 ____D C:\Users\Katharina\Desktop\Kleiderkreisel
2013-09-21 15:47 - 2013-09-21 15:46 - 00018865 _____ C:\Users\Katharina\Downloads\Addition.txt
2013-09-21 15:44 - 2013-09-21 15:44 - 01089757 _____ (Farbar) C:\Users\Katharina\Downloads\FRST.exe
2013-09-21 12:56 - 2013-09-21 00:25 - 00005856 _____ C:\ProgramData\NanoRepository.bin
2013-09-21 11:36 - 2013-08-09 12:28 - 00000000 ____D C:\Users\Katharina\AppData\Local\Windows Live
2013-09-21 00:25 - 2013-09-21 00:25 - 00005856 _____ C:\ProgramData\NanoRepository.bin.bak
2013-09-20 20:39 - 2013-09-20 20:39 - 00050477 _____ C:\Users\Katharina\Downloads\Defogger(1).exe
2013-09-20 20:13 - 2013-09-20 20:13 - 00377856 _____ C:\Users\Katharina\Downloads\gmer_2.1.19163(1).exe
2013-09-20 20:09 - 2013-09-20 20:09 - 430908101 _____ C:\Windows\MEMORY.DMP
2013-09-20 20:09 - 2013-09-20 20:09 - 00143240 _____ C:\Windows\Minidump\092013-16411-01.dmp
2013-09-20 20:09 - 2013-09-20 20:09 - 00000000 ____D C:\Windows\Minidump
2013-09-20 19:43 - 2013-09-20 19:43 - 00377856 _____ C:\Users\Katharina\Downloads\gmer_2.1.19163.exe
2013-09-20 19:40 - 2013-09-20 19:40 - 00000000 _____ C:\Windows\setuperr.log
2013-09-20 19:30 - 2013-09-20 19:30 - 01950622 _____ (Farbar) C:\Users\Katharina\Downloads\FRST64.exe
2013-09-20 19:25 - 2013-09-20 19:20 - 00000480 _____ C:\Users\Katharina\Downloads\defogger_disable.log
2013-09-20 19:20 - 2013-09-20 19:20 - 00000000 _____ C:\Users\Katharina\defogger_reenable
2013-09-20 19:20 - 2013-08-09 11:20 - 00000000 ____D C:\Users\Katharina
2013-09-20 19:19 - 2013-09-20 19:19 - 00050477 _____ C:\Users\Katharina\Downloads\Defogger.exe
2013-09-20 18:51 - 2013-09-20 18:39 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-20 18:51 - 2013-09-20 18:38 - 00000000 ____D C:\Users\Katharina\Desktop\mbar
2013-09-20 18:38 - 2013-09-20 18:37 - 12907592 _____ (Malwarebytes Corp.) C:\Users\Katharina\Downloads\mbar-1.07.0.1005(1).exe
2013-09-20 18:37 - 2013-09-20 18:37 - 12907592 _____ (Malwarebytes Corp.) C:\Users\Katharina\Downloads\mbar-1.07.0.1005.exe
2013-09-20 18:31 - 2013-08-09 12:12 - 00000000 ____D C:\Windows\Panther
2013-09-20 18:20 - 2009-07-14 06:33 - 00376328 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-20 17:57 - 2013-08-09 11:23 - 00086144 _____ C:\Users\Katharina\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-20 17:34 - 2013-09-20 17:34 - 00001073 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-20 17:34 - 2013-09-20 17:34 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Malwarebytes
2013-09-20 17:34 - 2013-09-20 17:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-20 17:34 - 2013-09-20 17:34 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-20 17:33 - 2013-09-20 17:33 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Katharina\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-20 17:28 - 2013-08-09 12:08 - 00000000 ____D C:\Program Files\OpenOffice.org 3
2013-09-20 17:26 - 2013-09-17 10:22 - 00000000 ____D C:\Users\Katharina\AppData\Local\Google
2013-09-20 17:26 - 2013-09-17 10:22 - 00000000 ____D C:\Program Files\Google
2013-09-19 18:25 - 2013-09-19 11:26 - 00000000 ____D C:\Users\Katharina\Desktop\Bewerbung LMU
2013-09-19 18:00 - 2013-09-19 18:00 - 00010464 _____ C:\Windows\system32\sx_p2d.tlb
2013-09-19 18:00 - 2013-09-19 18:00 - 00002114 _____ C:\Users\Katharina\Desktop\Free PDF Perfect.lnk
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\ProgramData\Freemium
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\Program Files\Freemium
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\Program Files\Common Files\soft Xpansion
2013-09-19 18:00 - 2013-09-19 18:00 - 00000000 ____D C:\Program Files\Common Files\Freemium
2013-09-19 17:58 - 2013-09-19 17:58 - 00000000 ____D C:\Users\Katharina\Downloads\freepdf
2013-09-19 17:58 - 2013-09-19 17:58 - 00000000 ____D C:\ProgramData\Package Cache
2013-09-19 17:58 - 2013-09-19 17:58 - 00000000 ____D C:\Program Files\Covus Freemium
2013-09-19 17:58 - 2013-09-19 17:57 - 00000000 ____D C:\Program Files\Plus-HD-3.8
2013-09-19 17:56 - 2013-08-19 08:36 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-19 17:54 - 2013-09-19 17:54 - 00444400 _____ C:\Users\Katharina\Downloads\DLG_free-pdf-perfect_chip_de-DE10.exe
2013-09-19 17:52 - 2013-08-09 11:38 - 00000000 ____D C:\Program Files\Adobe
2013-09-19 17:51 - 2013-09-19 17:51 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2013-09-19 17:51 - 2013-08-09 11:37 - 00000000 ____D C:\ProgramData\Adobe
2013-09-19 17:49 - 2013-09-19 17:49 - 02469824 _____ C:\Users\Katharina\Downloads\AdobeDownloadAssistant.exe
2013-09-19 17:49 - 2013-08-09 12:25 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Adobe
2013-09-19 17:49 - 2013-08-09 12:12 - 00000000 ____D C:\Users\Katharina\AppData\Local\Adobe
2013-09-19 17:45 - 2013-09-19 11:30 - 00000000 ____D C:\Users\Katharina\Desktop\Bewerbung Schwabing
2013-09-19 16:26 - 2013-08-09 11:34 - 00000000 ____D C:\ProgramData\Panda Security URL Filtering
2013-09-19 11:32 - 2013-09-17 09:13 - 00000000 ____D C:\Users\Katharina\Desktop\Bewerbung Leipzig
2013-09-18 00:39 - 2013-09-17 22:47 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-18 00:32 - 2013-09-18 00:32 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-09-18 00:32 - 2013-09-18 00:32 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-09-17 23:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-09-17 22:51 - 2013-09-17 22:51 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-09-17 22:51 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-09-17 22:50 - 2013-09-17 22:47 - 00000000 ____D C:\Program Files\Microsoft Office
2013-09-17 22:50 - 2013-08-09 12:32 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-09-17 22:48 - 2013-09-17 22:48 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-09-17 22:48 - 2011-04-12 03:39 - 00000000 ____D C:\Windows\ShellNew
2013-09-17 22:47 - 2013-09-17 22:47 - 00000000 __RHD C:\MSOCache
2013-09-17 22:47 - 2013-09-17 22:47 - 00000000 ____D C:\Users\Katharina\AppData\Local\Microsoft Help
2013-09-17 22:40 - 2013-09-17 19:23 - 1025493776 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X17-75062.exe
2013-09-17 14:49 - 2013-09-17 14:35 - 1169711680 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X17-75168.exe
2013-09-17 14:16 - 2013-09-17 14:08 - 813301744 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X17-22389.exe
2013-09-17 14:00 - 2013-09-17 13:51 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Download Manager
2013-09-17 13:50 - 2013-09-17 13:50 - 00000000 ____D C:\Windows\Sun
2013-09-17 11:34 - 2013-08-09 11:45 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\vlc
2013-09-17 11:16 - 2013-08-09 11:46 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\WinRAR
2013-09-17 10:22 - 2013-09-17 10:22 - 00001854 _____ C:\Users\Katharina\Desktop\IrfanView Thumbnails.lnk
2013-09-17 10:22 - 2013-09-17 10:22 - 00000978 _____ C:\Users\Katharina\Desktop\IrfanView.lnk
2013-09-17 10:22 - 2013-09-17 10:22 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-09-17 10:22 - 2013-09-17 10:22 - 00000000 ____D C:\Users\Katharina\AppData\Roaming\IrfanView
2013-09-17 10:22 - 2013-09-17 10:22 - 00000000 ____D C:\Program Files\IrfanView
2013-09-17 10:19 - 2013-09-17 10:19 - 02145888 _____ (Irfan Skiljan) C:\Users\Katharina\Downloads\iview436g_setup.exe
2013-09-17 09:45 - 2013-09-17 09:44 - 28404551 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X16-33163(1).exe.part
2013-09-17 09:31 - 2013-09-17 09:25 - 329930248 _____ (Microsoft Corporation) C:\Users\Katharina\Downloads\X16-33163.exe
2013-09-14 13:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-09-14 10:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-09-13 21:18 - 2013-08-20 15:27 - 00000000 ____D C:\Windows\system32\MRT
2013-09-13 21:16 - 2013-08-10 16:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-11 10:16 - 2013-08-09 12:13 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-11 10:16 - 2013-08-09 12:13 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-03 13:02 - 2013-09-03 12:57 - 00000142 _____ C:\Users\Katharina\Desktop\Kurzdarmsyndrom.txt
Some content of TEMP:
====================
C:\Users\Katharina\AppData\Local\Temp\apptorun.exe
C:\Users\Katharina\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-21 09:24
==================== End Of Log ============================ --- --- ---
vg, Emilienne |