Samsodong | 08.10.2013 19:55 | Hallo und Danke für deine Hilfe.
So, beide Programme ausgeführt und hier nun die Logs. Code:
ComboFix 13-10-08.01 - Sir Ingo 08.10.2013 20:03:34.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1033.18.12286.10648 [GMT 2:00]
ausgeführt von:: c:\users\Sir Ingo\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Disk Defrag
c:\programdata\Microsoft\Windows\Start Menu\Programs\Disk Defrag\ Check Your PC Performance.url
c:\programdata\Microsoft\Windows\Start Menu\Programs\Disk Defrag\Auslogics Disk Defrag on the Web.url
c:\programdata\Microsoft\Windows\Start Menu\Programs\Disk Defrag\Auslogics Disk Defrag.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Disk Defrag\Uninstall Auslogics Disk Defrag.lnk
c:\users\Sir Ingo\AppData\Local\Google\Desktop\Install
c:\users\Sir Ingo\AppData\Local\Google\Desktop\Install\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\???\???\???\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\@
c:\users\Sir Ingo\AppData\Local\Google\Desktop\Install\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\???\???\???\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\GoogleUpdate.exe
c:\users\Sir Ingo\AppData\Local\Google\Desktop\Install\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\C3C1~1\01C8~1\CFFE~1\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\@
c:\users\Sir Ingo\AppData\Local\Google\Desktop\Install\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\C3C1~1\01C8~1\CFFE~1\{18fefda9-c825-4cec-4a93-f2097a68dc1f}\GoogleUpdate.exe
c:\users\Sir Ingo\AppData\Roaming\skype.ini
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\IsUn0407.exe
c:\windows\PFRO.log
c:\windows\SysWow64\tmpCBBA.tmp
c:\windows\SysWow64\tmpCC86.tmp
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-09-08 bis 2013-10-08 ))))))))))))))))))))))))))))))
.
.
2013-10-08 18:18 . 2013-10-08 18:23 -------- d-----w- c:\users\postgres\AppData\Local\temp
2013-10-08 18:18 . 2013-10-08 18:18 -------- d-----w- c:\users\Internet\AppData\Local\temp
2013-10-08 18:18 . 2013-10-08 18:18 -------- d-----w- c:\users\Ingo\AppData\Local\temp
2013-10-08 18:18 . 2013-10-08 18:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-08 18:18 . 2013-10-08 18:18 -------- d-----w- c:\users\aefaea\AppData\Local\temp
2013-10-08 18:18 . 2013-10-08 18:18 -------- d-----w- c:\users\AAA\AppData\Local\temp
2013-10-07 19:50 . 2013-10-07 19:50 -------- d-----w- C:\FRST
2013-10-06 20:34 . 2013-10-06 20:34 -------- d-----w- c:\users\Sir Ingo\AppData\Roaming\SUPERAntiSpyware.com
2013-10-06 20:34 . 2013-10-06 20:34 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2013-10-06 20:32 . 2013-10-06 20:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-10-02 22:40 . 2013-10-02 22:40 -------- d-----w- c:\users\aefaea\AppData\Local\Adobe_Systems_Incorporate
2013-10-02 18:46 . 2013-10-02 18:46 -------- d-----w- c:\program files (x86)\Plus-HD-2.2
2013-10-02 18:46 . 2013-10-02 18:46 -------- d-----w- c:\users\Sir Ingo\AppData\Local\Cool_Mirage
2013-09-29 12:12 . 2013-09-29 12:12 -------- d-----w- c:\users\Sir Ingo\AppData\Roaming\IrfanView
2013-09-28 21:05 . 2013-09-28 21:05 -------- d-----w- c:\users\Sir Ingo\AppData\Roaming\JAM Software
2013-09-20 17:45 . 2013-07-31 13:23 887808 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2013-09-13 14:00 . 2013-10-06 14:00 -------- d-----w- c:\program files (x86)\Google
2013-09-13 14:00 . 2013-10-06 14:00 -------- d-----w- c:\users\Sir Ingo\AppData\Local\Google
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-01 09:37 . 2013-06-26 18:29 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-10-01 09:37 . 2013-06-26 18:29 132600 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-10-01 09:37 . 2013-06-26 18:29 105856 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-23 17:49 . 2012-06-23 17:36 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-23 17:49 . 2012-06-23 17:36 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-20 17:46 . 2006-11-02 12:35 79143768 ----a-w- c:\windows\system32\mrt.exe
2013-07-17 20:01 . 2013-08-20 20:47 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-17 19:41 . 2013-08-20 20:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1555968]
"MagicKey"="c:\progra~1\TASTAT~1\MagicKey.exe" [2007-01-10 516608]
"SoftAuto.exe"="c:\program files (x86)\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
"SUPERAntiSpyware"="c:\program files (x86)\Festplatte\Superantispyware\SUPERAntiSpyware.exe" [2013-10-02 6588144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]
"ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2013-03-27 73832]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-10-01 681032]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
S2 !SASCORE;SAS Core Service;c:\program files (x86)\Festplatte\Superantispyware\SASCORE64.EXE;c:\program files (x86)\Festplatte\Superantispyware\SASCORE64.EXE [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Inhalt des "geplante Tasks" Ordners
.
2013-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-13 14:00]
.
2013-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-13 14:00]
.
2013-10-08 c:\windows\Tasks\Plus-HD-2.2-codedownloader.job
- c:\program files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe [2013-10-02 18:46]
.
2013-10-08 c:\windows\Tasks\Plus-HD-2.2-firefoxinstaller.job
- c:\program files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe [2013-10-02 18:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-18 8067616]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2012-11-22 1127592]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Download by Orbit - c:\program files (x86)\Internet\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files (x86)\Internet\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files (x86)\Internet\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files (x86)\Internet\Orbitdownloader\orbitmxt.dll/202
IE: Free YouTube Download - c:\users\Sir Ingo\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\postgresql-8.4]
"ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"D:/Hand\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\postgresql-8.4]
"ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"D:/Hand\" -w"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3987018002-2970003512-1192746098-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:a8,0c,1c,fc,f7,c1,0d,c6,9f,9e,dc,ef,fe,f4,94,8b,53,d2,2b,e4,39,d2,fe,
94,aa,b1,a0,5b,ea,1e,5d,93,9c,a7,2b,6f,ea,e0,96,c8,fc,15,8a,e5,ce,13,e3,99,\
"??"=hex:41,e0,42,8c,cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b
.
[HKEY_USERS\S-1-5-21-3987018002-2970003512-1192746098-1000\Software\SecuROM\License information*]
"datasecu"=hex:f6,db,0c,ac,6e,2c,c7,c2,d5,b3,d8,b7,17,de,fc,59,7b,29,74,75,b3,
ab,da,06,51,14,ce,81,3f,c0,62,cf,e1,cd,b1,74,4c,92,42,b0,2a,ab,85,e5,54,8f,\
"rkeysecu"=hex:09,5c,d2,4f,ab,c9,cc,df,c3,6c,63,d3,fa,d7,37,60
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Denied: (A 2) (Everyone)
@="FlashProp Class"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@="d:\\Spiele\\Abenteuer\\Tod auf dem Nil\\flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="d:\\Spiele\\Abenteuer\\Tod auf dem Nil\\flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="d:\\Spiele\\Abenteuer\\Tod auf dem Nil\\flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="d:\\Spiele\\Abenteuer\\Tod auf dem Nil\\flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="d:\\Spiele\\Abenteuer\\Tod auf dem Nil\\flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Avira\AntiVir Desktop\sched.exe
c:\program files (x86)\Creative\Shared Files\CTDevSrv.exe
c:\program files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-10-08 20:28:20 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-10-08 18:28
.
Vor Suchlauf: 2.383.097.856 bytes free
Nach Suchlauf: 2.940.280.832 bytes free
.
- - End Of File - - 8A5CAD2760E99FF99362C372D59ADCA6
5C616939100B85E558DA92B899A0FC36
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Sir Ingo (administrator) on SIRINGO-PC on 08-10-2013 20:34:44
Running from C:\Users\Sir Ingo\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files (x86)\Festplatte\Superantispyware\SASCORE64.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Program Files\Tastatur Media Key\MagicKey.exe
(SUPERAntiSpyware) C:\Program Files (x86)\Festplatte\Superantispyware\SUPERAntiSpyware.exe
(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8067616 2009-08-18] (Realtek Semiconductor)
HKLM\...\Run: [ISW] - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [1127592 2012-11-22] (Check Point Software Technologies)
HKCU\...\Run: [MagicKey] - C:\Program Files\Tastatur Media Key\MagicKey.exe [516608 2007-01-10] ()
HKCU\...\Run: [SoftAuto.exe] - C:\Program Files (x86)\Creative\Software Update 3\SoftAuto.exe [405504 2008-08-13] (Creative Technology Ltd)
HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [221184 2005-02-17] (InstallShield Software Corporation)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files (x86)\Festplatte\Superantispyware\SUPERAntiSpyware.exe [6588144 2013-10-02] (SUPERAntiSpyware)
HKLM-x32\...\Run: [ATICustomerCare] - C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [311296 2010-03-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe [40048 2007-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ZoneAlarm] - C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-03-27] (Check Point Software Technologies LTD)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-17] (InstallShield Software Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9DD14FF97447CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=272
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=272
BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO-x32: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Internet\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKCU - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [304128] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @checkpoint.com/FFApi - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: ftd - C:\Users\Sir Ingo\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi
FF HKLM\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\TrustChecker
FF Extension: No Name - C:\Program Files\CheckPoint\ZAForceField\TrustChecker
FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF Extension: ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files (x86)\Festplatte\Superantispyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-07-04] (Advanced Micro Devices, Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 CTDevice_Srv; C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe [61440 2007-04-02] (Creative Technology Ltd)
S3 CTUPnPSv; C:\Program Files (x86)\Creative\Creative Centrale\CTUPnPSv.exe [64000 2008-05-21] (Creative Technology Ltd)
R2 IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [828072 2012-11-22] (Check Point Software Technologies)
S4 RemoteAccess; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2447888 2013-03-27] (Check Point Software Technologies LTD)
R2 postgresql-8.4; C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "D:/Hand" -w [x]
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-03-20] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 gdrv; C:\Windows\gdrv.sys [25640 2010-09-19] (Windows (R) Server 2003 DDK provider)
S3 gdrv; C:\Windows\gdrv.sys [25640 2010-09-19] (Windows (R) Server 2003 DDK provider)
R2 ISWKL; C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [33712 2012-11-22] (Check Point Software Technologies)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-03-20] ()
S1 prodrv06; C:\Windows\SysWow64\drivers\prodrv06.sys [77184 2004-03-09] (Protection Technology)
S0 prohlp02; C:\Windows\SysWow64\drivers\prohlp02.sys [65504 2004-03-09] (Protection Technology)
S0 prosync1; C:\Windows\SysWow64\drivers\prosync1.sys [6944 2003-09-06] (Protection Technology)
R1 SASDIFSV; C:\Program Files (x86)\Festplatte\Superantispyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files (x86)\Festplatte\Superantispyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files (x86)\Festplatte\Superantispyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files (x86)\Festplatte\Superantispyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S0 sfhlp01; C:\Windows\SysWow64\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology)
S2 tandpl; C:\Windows\SysWow64\drivers\tandpl.sys [4736 2003-04-19] ()
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [443992 2012-12-13] (Check Point Software Technologies LTD)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S1 prodrv06; \SystemRoot\System32\drivers\prodrv06.sys [x]
S0 prohlp02; System32\drivers\prohlp02.sys [x]
S0 prosync1; System32\drivers\prosync1.sys [x]
S0 sfhlp01; System32\drivers\sfhlp01.sys [x]
S2 tandpl; System32\drivers\tandpl.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-08 20:34 - 2013-10-08 20:34 - 00014789 _____ C:\Users\Sir Ingo\Desktop\combofix.txt
2013-10-08 20:28 - 2013-10-08 20:28 - 00014789 _____ C:\ComboFix.txt
2013-10-08 19:50 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-08 19:50 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-08 19:50 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-08 19:50 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-08 19:50 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-08 19:50 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-08 19:50 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-08 19:50 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-08 19:48 - 2013-10-08 20:28 - 00000000 ____D C:\Qoobox
2013-10-08 19:47 - 2013-10-08 20:27 - 00000000 ____D C:\Windows\erdnt
2013-10-08 19:45 - 2013-10-08 19:33 - 05132072 ____R (Swearware) C:\Users\Sir Ingo\Desktop\ComboFix.exe
2013-10-08 17:06 - 2013-10-08 17:04 - 00038400 _____ C:\Users\Sir Ingo\Desktop\AVSCAN-20131008-120305-F170CF22.LOG
2013-10-07 23:01 - 2013-10-07 23:01 - 00000000 ____D C:\Users\Sir Ingo\Desktop\New Folder (2)
2013-10-07 22:58 - 2013-10-07 22:58 - 00000000 ____D C:\Users\Sir Ingo\Desktop\Malwarebytes' Anti-Malware
2013-10-07 22:16 - 2013-10-07 22:21 - 00002033 _____ C:\Users\Sir Ingo\Desktop\gmer text.txt
2013-10-07 21:51 - 2013-10-07 21:52 - 00022890 _____ C:\Users\Sir Ingo\Desktop\Addition.txt
2013-10-07 21:50 - 2013-10-07 21:50 - 00000000 ____D C:\FRST
2013-10-07 21:49 - 2013-10-07 21:49 - 00000478 _____ C:\Users\Sir Ingo\Desktop\defogger_disable.log
2013-10-07 21:49 - 2013-10-07 21:49 - 00000000 _____ C:\Users\Sir Ingo\defogger_reenable
2013-10-07 21:48 - 2013-10-07 21:48 - 00000000 ____D C:\Users\Sir Ingo\Desktop\New Folder
2013-10-07 21:48 - 2013-10-07 21:44 - 01954124 _____ (Farbar) C:\Users\Sir Ingo\Desktop\FRST64.exe
2013-10-07 21:48 - 2013-10-07 21:43 - 00050477 _____ C:\Users\Sir Ingo\Desktop\Defogger.exe
2013-10-07 21:48 - 2013-10-07 20:08 - 00377856 _____ C:\Users\Sir Ingo\Desktop\gmer_2.1.19163.exe
2013-10-06 22:34 - 2013-10-06 22:34 - 00002017 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-10-06 22:34 - 2013-10-06 22:34 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\SUPERAntiSpyware.com
2013-10-06 22:34 - 2013-10-06 22:34 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-10-06 22:32 - 2013-10-06 22:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-06 21:00 - 2013-10-06 21:00 - 00005572 _____ C:\Users\aefaea\Documents\cc_20131006_210016.reg
2013-10-06 20:51 - 2013-10-06 20:55 - 00000732 _____ C:\Users\aefaea\AppData\Local\d3d9caps64.dat
2013-10-03 00:40 - 2013-10-03 00:40 - 00000000 ____D C:\Users\aefaea\Documents\My Digital Editions
2013-10-03 00:40 - 2013-10-03 00:40 - 00000000 ____D C:\Users\aefaea\AppData\Local\Adobe_Systems_Incorporate
2013-10-02 20:46 - 2013-10-08 20:23 - 00001836 _____ C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job
2013-10-02 20:46 - 2013-10-08 20:23 - 00001204 _____ C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job
2013-10-02 20:46 - 2013-10-02 20:46 - 00004234 _____ C:\Windows\System32\Tasks\Plus-HD-2.2-codedownloader
2013-10-02 20:46 - 2013-10-02 20:46 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com
2013-10-02 20:46 - 2013-10-02 20:46 - 00000000 ____D C:\Users\Sir Ingo\AppData\Local\Cool_Mirage
2013-10-02 20:46 - 2013-10-02 20:46 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.2
2013-09-30 20:46 - 2013-09-30 20:46 - 00002013 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
2013-09-30 19:59 - 2013-09-30 19:59 - 00001042 _____ C:\Users\Sir Ingo\Desktop\TREESIZE.lnk
2013-09-29 14:12 - 2013-09-29 14:12 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\IrfanView
2013-09-29 13:34 - 2013-09-29 13:34 - 00003044 _____ C:\Windows\System32\Tasks\{A4C3FB77-A51E-4046-970C-99C06E7FB587}
2013-09-28 23:05 - 2013-09-28 23:05 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\JAM Software
2013-09-20 19:46 - 2013-07-31 15:29 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-20 19:46 - 2013-07-31 15:20 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-20 19:46 - 2013-07-31 15:19 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-20 19:46 - 2013-07-31 15:18 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-20 19:46 - 2013-07-31 15:17 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-20 19:46 - 2013-07-31 15:16 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-20 19:46 - 2013-07-31 15:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-20 19:46 - 2013-07-31 15:13 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-20 19:46 - 2013-07-31 15:13 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-20 19:46 - 2013-07-31 15:11 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-20 19:46 - 2013-07-31 15:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-20 19:46 - 2013-07-31 15:08 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-20 19:46 - 2013-07-31 15:05 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-20 19:46 - 2013-07-31 12:00 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-20 19:46 - 2013-07-31 11:53 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-20 19:46 - 2013-07-31 11:52 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-20 19:46 - 2013-07-31 11:52 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-20 19:46 - 2013-07-31 11:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-20 19:46 - 2013-07-31 11:49 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-20 19:46 - 2013-07-31 11:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-20 19:46 - 2013-07-31 11:48 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-20 19:46 - 2013-07-31 11:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-20 19:46 - 2013-07-31 11:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-20 19:46 - 2013-07-31 11:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-20 19:46 - 2013-07-31 11:45 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-20 19:46 - 2013-07-31 11:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-20 19:45 - 2013-08-08 04:03 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-20 19:45 - 2013-08-02 16:06 - 01706496 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-09-20 19:45 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-09-20 19:45 - 2013-07-31 16:17 - 17833472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-20 19:45 - 2013-07-31 15:42 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-20 19:45 - 2013-07-31 15:11 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-20 19:45 - 2013-07-31 12:30 - 12335104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-20 19:45 - 2013-07-31 12:05 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-20 19:45 - 2013-07-31 11:46 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-20 19:45 - 2013-07-16 11:25 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2013-09-20 19:45 - 2013-07-16 06:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2013-09-13 16:02 - 2013-09-13 16:02 - 00002115 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-09-13 16:00 - 2013-10-08 20:23 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-13 16:00 - 2013-10-08 20:05 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-13 16:00 - 2013-10-06 16:00 - 00000000 ____D C:\Users\Sir Ingo\AppData\Local\Google
2013-09-13 16:00 - 2013-10-06 16:00 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-13 16:00 - 2013-09-13 16:00 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-09-13 16:00 - 2013-09-13 16:00 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
==================== One Month Modified Files and Folders =======
2013-10-08 20:34 - 2013-10-08 20:34 - 00014789 _____ C:\Users\Sir Ingo\Desktop\combofix.txt
2013-10-08 20:28 - 2013-10-08 20:28 - 00014789 _____ C:\ComboFix.txt
2013-10-08 20:28 - 2013-10-08 19:48 - 00000000 ____D C:\Qoobox
2013-10-08 20:28 - 2006-11-02 15:33 - 00000000 __RHD C:\Users\Default
2013-10-08 20:28 - 2006-11-02 14:46 - 00769000 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-08 20:27 - 2013-10-08 19:47 - 00000000 ____D C:\Windows\erdnt
2013-10-08 20:23 - 2013-10-02 20:46 - 00001836 _____ C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job
2013-10-08 20:23 - 2013-10-02 20:46 - 00001204 _____ C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job
2013-10-08 20:23 - 2013-09-13 16:00 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-08 20:23 - 2006-11-02 14:34 - 00000215 _____ C:\Windows\system.ini
2013-10-08 20:22 - 2006-11-02 17:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-08 20:22 - 2006-11-02 17:22 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-08 20:22 - 2006-11-02 17:22 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-08 20:21 - 2008-01-21 03:53 - 01910035 _____ C:\Windows\WindowsUpdate.log
2013-10-08 20:21 - 2006-11-02 17:42 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-08 20:05 - 2013-09-13 16:00 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-08 19:33 - 2013-10-08 19:45 - 05132072 ____R (Swearware) C:\Users\Sir Ingo\Desktop\ComboFix.exe
2013-10-08 17:04 - 2013-10-08 17:06 - 00038400 _____ C:\Users\Sir Ingo\Desktop\AVSCAN-20131008-120305-F170CF22.LOG
2013-10-07 23:01 - 2013-10-07 23:01 - 00000000 ____D C:\Users\Sir Ingo\Desktop\New Folder (2)
2013-10-07 22:58 - 2013-10-07 22:58 - 00000000 ____D C:\Users\Sir Ingo\Desktop\Malwarebytes' Anti-Malware
2013-10-07 22:21 - 2013-10-07 22:16 - 00002033 _____ C:\Users\Sir Ingo\Desktop\gmer text.txt
2013-10-07 21:52 - 2013-10-07 21:51 - 00022890 _____ C:\Users\Sir Ingo\Desktop\Addition.txt
2013-10-07 21:50 - 2013-10-07 21:50 - 00000000 ____D C:\FRST
2013-10-07 21:49 - 2013-10-07 21:49 - 00000478 _____ C:\Users\Sir Ingo\Desktop\defogger_disable.log
2013-10-07 21:49 - 2013-10-07 21:49 - 00000000 _____ C:\Users\Sir Ingo\defogger_reenable
2013-10-07 21:49 - 2010-08-04 19:32 - 00000000 ____D C:\Users\Sir Ingo
2013-10-07 21:48 - 2013-10-07 21:48 - 00000000 ____D C:\Users\Sir Ingo\Desktop\New Folder
2013-10-07 21:44 - 2013-10-07 21:48 - 01954124 _____ (Farbar) C:\Users\Sir Ingo\Desktop\FRST64.exe
2013-10-07 21:43 - 2013-10-07 21:48 - 00050477 _____ C:\Users\Sir Ingo\Desktop\Defogger.exe
2013-10-07 20:08 - 2013-10-07 21:48 - 00377856 _____ C:\Users\Sir Ingo\Desktop\gmer_2.1.19163.exe
2013-10-06 22:34 - 2013-10-06 22:34 - 00002017 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-10-06 22:34 - 2013-10-06 22:34 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\SUPERAntiSpyware.com
2013-10-06 22:34 - 2013-10-06 22:34 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-10-06 22:34 - 2012-06-25 23:19 - 00000000 ____D C:\Program Files (x86)\Festplatte
2013-10-06 22:32 - 2013-10-06 22:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-06 22:31 - 2013-06-27 00:30 - 00003975 _____ C:\Windows\setupact.log
2013-10-06 21:34 - 2006-11-02 17:21 - 00232056 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-06 21:00 - 2013-10-06 21:00 - 00005572 _____ C:\Users\aefaea\Documents\cc_20131006_210016.reg
2013-10-06 20:55 - 2013-10-06 20:51 - 00000732 _____ C:\Users\aefaea\AppData\Local\d3d9caps64.dat
2013-10-06 20:17 - 2013-01-30 20:34 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\HoldemManager
2013-10-06 20:06 - 2012-06-22 23:08 - 00003706 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{48F17EDA-5149-4FF2-BA05-5AE15C050392}
2013-10-06 19:33 - 2010-08-04 19:32 - 00001460 _____ C:\Users\Sir Ingo\AppData\Local\d3d9caps64.dat
2013-10-06 16:00 - 2013-09-13 16:00 - 00000000 ____D C:\Users\Sir Ingo\AppData\Local\Google
2013-10-06 16:00 - 2013-09-13 16:00 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-03 17:59 - 2012-06-02 18:40 - 00000000 ____D C:\Users\Public\Documents\STALKER-SHOC
2013-10-03 14:45 - 2012-07-14 12:00 - 00000000 ____D C:\Users\Sir Ingo\.umplayer
2013-10-03 00:40 - 2013-10-03 00:40 - 00000000 ____D C:\Users\aefaea\Documents\My Digital Editions
2013-10-03 00:40 - 2013-10-03 00:40 - 00000000 ____D C:\Users\aefaea\AppData\Local\Adobe_Systems_Incorporate
2013-10-02 20:46 - 2013-10-02 20:46 - 00004234 _____ C:\Windows\System32\Tasks\Plus-HD-2.2-codedownloader
2013-10-02 20:46 - 2013-10-02 20:46 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com
2013-10-02 20:46 - 2013-10-02 20:46 - 00000000 ____D C:\Users\Sir Ingo\AppData\Local\Cool_Mirage
2013-10-02 20:46 - 2013-10-02 20:46 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.2
2013-10-02 20:46 - 2013-03-13 15:33 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\Mozilla
2013-10-01 11:37 - 2013-06-26 20:29 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-01 11:37 - 2013-06-26 20:29 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-01 11:37 - 2013-06-26 20:29 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-30 20:46 - 2013-09-30 20:46 - 00002013 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
2013-09-30 19:59 - 2013-09-30 19:59 - 00001042 _____ C:\Users\Sir Ingo\Desktop\TREESIZE.lnk
2013-09-29 14:12 - 2013-09-29 14:12 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\IrfanView
2013-09-29 13:43 - 2010-08-05 19:01 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-29 13:34 - 2013-09-29 13:34 - 00003044 _____ C:\Windows\System32\Tasks\{A4C3FB77-A51E-4046-970C-99C06E7FB587}
2013-09-28 23:05 - 2013-09-28 23:05 - 00000000 ____D C:\Users\Sir Ingo\AppData\Roaming\JAM Software
2013-09-27 20:01 - 2013-01-06 16:13 - 00000000 ____D C:\Users\Sir Ingo\Desktop\Filme Musik Massage
2013-09-23 19:49 - 2012-06-23 19:36 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-23 19:49 - 2012-06-23 19:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-23 19:49 - 2011-04-14 23:06 - 00000000 ____D C:\Users\Sir Ingo\AppData\Local\Adobe
2013-09-20 19:49 - 2013-07-23 13:23 - 00000000 ____D C:\Windows\system32\MRT
2013-09-20 19:46 - 2006-11-02 14:35 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-09-13 16:02 - 2013-09-13 16:02 - 00002115 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-09-13 16:00 - 2013-09-13 16:00 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-09-13 16:00 - 2013-09-13 16:00 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
Files to move or delete:
====================
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install
C:\ProgramData\0tbpw.pad
Some content of TEMP:
====================
C:\Users\Sir Ingo\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-08 20:28
==================== End Of Log ============================ --- --- ---
--- --- --- |