Baumwolle | 29.10.2013 14:18 | Hallo Schrauber,
habe alles ausgeführt - einzig beim Adw-Cleaner bin ich mir nicht sicher, ob der Scan 100 % geklappt hat (war so ähnlich wie bei Combofix), Scan/Balken hat sich ewig nicht bewegt.. irgendwann nach 3 Stunden hab ich abgebrochen und dann aber trotzdem ein Logfile erhalten.
Hier die Ergebnisse - Danke noch einmal für Deine Hilfe!
Malwarebites: Code:
29.10.2013 00:12:34
mbam-log-2013-10-29 (00-12-34).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 221451
Laufzeit: 50 Minute(n), 1 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 3
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} (PUP.Optional.EasyLife.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} (PUP.Optional.EasyLife.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 2
C:\ProgramData\Browse2save (PUP.Optional.BrowseToSave.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Browse2save\data (PUP.Optional.BrowseToSave.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 3
C:\ProgramData\Browse2save\511161e54d634.tlb (PUP.Optional.BrowseToSave.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Browse2save\settings.ini (PUP.Optional.BrowseToSave.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Browse2save\data\Browse2save.dat (PUP.Optional.BrowseToSave.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
Adw-Cleaner: Code:
# Gestartet von : C:\Users\Sabrina\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\ParetoLogic
Ordner Gelöscht : C:\ProgramData\RightClick
Ordner Gelöscht : C:\Users\Sabrina\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Sabrina\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\Sabrina\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Users\Sabrina\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Sabrina\AppData\Roaming\SendSpace
Ordner Gelöscht : C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\StumbleUpon
Ordner Gelöscht : C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\vshare@toolbar
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5EB0259D-AB79-4AE6-A6E6-24FFE21C3DA4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\Software\ParetoLogic
Schlüssel Gelöscht : HKLM\Software\SP Global
Schlüssel Gelöscht : HKLM\Software\Vittalia
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16514
-\\ Mozilla Firefox v14.0.1 (de)
[ Datei : C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\prefs.js ]
Zeile gelöscht : user_pref("aol_toolbar.default.homepage.check", false);
Zeile gelöscht : user_pref("aol_toolbar.default.search.check", false);
Zeile gelöscht : user_pref("browser.search.defaultenginename", "EasyLife");
Zeile gelöscht : user_pref("browser.search.defaultenginename,S", "EasyLife");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.easylifeapp.com/?pid=34&r=2013/02/05&hid=2354436646&lg=EN&cc=DE&l=1&q=");
Zeile gelöscht : user_pref("browser.search.order.1", "EasyLife");
Zeile gelöscht : user_pref("browser.search.order.1,S", "EasyLife");
Zeile gelöscht : user_pref("browser.search.selectedEngine,S", "EasyLife");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.easylifeapp.com/?pid=34&r=2013/02/05&hid=2354436646&lg=EN&cc=DE");
Zeile gelöscht : user_pref("extensions.511161e54d54f.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[...]
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Zeile gelöscht : user_pref("extensions.enabledItems", "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3,{E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1,6,2,48,exif_viewer@mozilla.doslash.org:1.81,{d37dc5d0-431d-44e5-8c91-4941937[...]
Zeile gelöscht : user_pref("extensions.vshare@toolbar.install-event-fired", true);
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.easylifeapp.com/?pid=34&r=2013/02/05&hid=2354436646&lg=EN&cc=DE&l=1&q=");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "EasyLife");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "EasyLife");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://search.easylifeapp.com/?pid=34&r=2013/02/05&hid=2354436646&lg=EN&cc=DE");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://search.easylifeapp.com/?pid=34&r=2013/02/05&hid=2354436646&lg=EN&cc=DE&l=1&q=");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.enable", "");
Zeile gelöscht : user_pref("vshare.install.date", "1284163200000");
Zeile gelöscht : user_pref("vshare.install.finished", "1.0.0");
Zeile gelöscht : user_pref("vshare.install.guid", "{11e45ce9-e567-411d-b051-fe09f44a8ec9}");
Zeile gelöscht : user_pref("vshare.install.isHidden", true);
Zeile gelöscht : user_pref("vshare.install.laststatreq", "1340064000000");
Zeile gelöscht : user_pref("vshare.install.newtab", false);
-\\ Google Chrome v
[ Datei : C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : homepage
Gelöscht : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [7225 octets] - [29/10/2013 11:12:29]
AdwCleaner[S0].txt - [7162 octets] - [29/10/2013 13:08:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7222 octets] ##########
JRT: Code:
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Sabrina\AppData\Roaming\mozilla\firefox\profiles\nm8a3p9r.default\minidumps [42 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.10.2013 at 13:39:13,02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
und das frische FRST: Code:
Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(UPEK Inc.) C:\Program Files\Protector Suite QL\upeksvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
(Garmin Ltd or its subsidiaries) C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Sony Corporation) C:\Program Files\Sony\ISB Utility\ISBMgr.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(UPEK Inc.) C:\Program Files\Protector Suite QL\psqltray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.)
HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\Sony\ISB Utility\ISBMgr.exe [317560 2007-06-11] (Sony Corporation)
HKLM\...\Run: [PSQLLauncher] - C:\Program Files\Protector Suite QL\launcher.exe [49168 2007-06-05] (UPEK Inc.)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8522272 2010-02-22] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-10] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\psfus: C:\Windows\System32\psqlpwd.dll (UPEK Inc.)
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Lsa: [Notification Packages] scecli psqlpwd
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {EDC625A9-4063-417F-B2DA-4D6B7F807CDD} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default
FF SelectedSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Move Media Player - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\moveplayer@movenetworks.com
FF Extension: TinEye Reverse Image Search - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\tineye@ideeinc.com
FF Extension: Garmin Communicator - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: GetVideo - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{a51dd9d0-56c3-11db-b0de-0800200c9a66}
FF Extension: ReminderFox - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
FF Extension: DownloadHelper - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: FoxClocks - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
FF Extension: Pixlr Grabber - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
FF Extension: Adobe DLM (powered by getPlus(R)) - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF Extension: exif_viewer - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\exif_viewer@mozilla.doslash.org.xpi
FF Extension: sessionmanager - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
FF Extension: No Name - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}.xpi
FF Extension: No Name - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF Extension: defaults - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi
FF Extension: Adblock Plus - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\nm8a3p9r.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\congstar\Internet-Manager\Bin\addon
FF Extension: Bytemobile Optimization Client - C:\Program Files\congstar\Internet-Manager\Bin\addon
FF HKLM\...\Firefox\Extensions: [{33044118-6597-4D2F-ABEA-7974BB185379}] - C:\Users\Sabrina\AppData\Roaming\14001.052
FF Extension: Java Link Helper - C:\Users\Sabrina\AppData\Roaming\14001.052
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF HKCU\...\Firefox\Extensions: [{33044118-6597-4D2F-ABEA-7974BB185379}] - C:\Users\Sabrina\AppData\Roaming\14001.052
FF Extension: Java Link Helper - C:\Users\Sabrina\AppData\Roaming\14001.052
Chrome:
=======
CHR Extension: (Browse2save) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbfnfnpacmcbaecknnmonlchagbcnlha\1
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 ClipInc001; C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe [1344512 2008-03-03] ()
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528624 2009-11-17] (Cisco Systems, Inc.)
R2 Garmin Core Update Service; C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250200 2013-09-19] (Garmin Ltd or its subsidiaries)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S4 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2008-06-15] ()
S3 OpenVPNService; C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpnserv.exe [422512 2007-10-05] ()
S4 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
S4 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2007-06-28] (Sony Corporation)
R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [182392 2007-07-24] (Sony Corporation)
S3 VAIOMediaPlatform-IntegratedServer-AppServer; C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe [2523136 2007-06-20] (Sony Corporation)
S3 VAIOMediaPlatform-IntegratedServer-UPnP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [1089536 2007-06-20] (Sony Corporation)
S3 VAIOMediaPlatform-UCLS-AppServer; C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [745472 2007-01-10] (Sony Corporation)
S3 VAIOMediaPlatform-UCLS-UPnP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [1089536 2007-06-20] (Sony Corporation)
S3 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [292152 2007-07-05] (Sony Corporation)
R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [274432 2007-06-28] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2007-08-28] (Sony Corporation)
R2 VzFw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [131072 2007-08-28] (Sony Corporation)
S3 Adobe LM Service; "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" [x]
S2 CLTNetCnService; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [x]
S4 Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [x]
S4 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [x]
S4 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [x]
S3 VAIOMediaPlatform-IntegratedServer-HTTP; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP" [x]
S3 VAIOMediaPlatform-Mobile-Gateway; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server" [x]
S3 VAIOMediaPlatform-UCLS-HTTP; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" [x]
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [45696 2008-01-19] (Microsoft Corporation)
R1 Aspi32; C:\Windows\System32\Drivers\Aspi32.sys [25244 2001-02-01] (Adaptec)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [278728 2009-03-09] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-10] (Avira Operations GmbH & Co. KG)
S3 catchme; C:\Users\Sabrina\AppData\Local\Temp\catchme.sys [31744 2013-10-27] ()
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2009-11-17] (Cisco Systems, Inc.)
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
S3 HSPADataCardusbmdm; C:\Windows\System32\DRIVERS\HSPADataCardusbmdm.sys [106880 2011-08-19] (HSPADataCard Incorporated)
S3 HSPADataCardusbnmea; C:\Windows\System32\DRIVERS\HSPADataCardusbnmea.sys [106880 2011-08-19] (HSPADataCard Incorporated)
S3 HSPADataCardusbser; C:\Windows\System32\DRIVERS\HSPADataCardusbser.sys [106880 2011-08-19] (HSPADataCard Incorporated)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2009-03-04] ()
S3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [14604 2003-08-11] (Padus, Inc.)
S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 Secdrv; C:\Windows\system32\drivers\SECDRV.SYS [11616 2001-08-25] ()
R2 Sentinel; C:\Windows\System32\Drivers\SENTINEL.SYS [73728 2001-06-22] (Rainbow Technologies, Inc.)
S3 Serial; C:\Windows\System32\DRIVERS\AvidXPSerial.sys [54272 2002-06-12] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-10-10] (Avira GmbH)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [25600 2007-10-05] (The OpenVPN Project)
R3 ti21sony; C:\Windows\System32\drivers\ti21sony.sys [812544 2007-06-06] (Texas Instruments)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S1 PCLEPCI; \??\C:\Windows\system32\drivers\pclepci.sys [x]
U4 Rasd9cost; No ImagePath
S3 tosporte; system32\DRIVERS\tosporte.sys [x]
S3 tosrfbd; system32\DRIVERS\tosrfbd.sys [x]
S3 tosrfbnp; System32\Drivers\tosrfbnp.sys [x]
S3 Tosrfcom; System32\Drivers\tosrfcom.sys [x]
S3 Tosrfhid; system32\DRIVERS\Tosrfhid.sys [x]
S3 tosrfnds; system32\DRIVERS\tosrfnds.sys [x]
S3 tosrfusb; system32\DRIVERS\tosrfusb.sys [x]
S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-29 13:39 - 2013-10-29 13:39 - 00000766 _____ C:\Users\Sabrina\Desktop\JRT.txt
2013-10-29 13:30 - 2013-10-29 13:30 - 00000000 ____D C:\Windows\ERUNT
2013-10-29 11:11 - 2013-10-29 13:08 - 00000000 ____D C:\AdwCleaner
2013-10-29 00:17 - 2013-10-29 00:17 - 01033335 _____ (Thisisu) C:\Users\Sabrina\Desktop\JRT.exe
2013-10-29 00:15 - 2013-10-29 00:15 - 01060070 _____ C:\Users\Sabrina\Desktop\adwcleaner.exe
2013-10-27 20:04 - 2013-10-27 20:05 - 01089097 _____ (Farbar) C:\Users\Sabrina\Desktop\FRST.exe
2013-10-27 13:53 - 2013-10-27 13:56 - 00000000 ___SD C:\ComboFix
2013-10-27 13:52 - 2013-10-27 13:53 - 00000000 ___SD C:\32788R22FWJFW
2013-10-26 23:49 - 2013-10-26 23:49 - 05136694 ____R (Swearware) C:\Users\Sabrina\Desktop\ComboFix.exe
2013-10-25 21:09 - 2013-10-25 21:09 - 269314744 _____ C:\Windows\MEMORY.DMP
2013-10-25 21:09 - 2013-10-25 21:09 - 00142776 _____ C:\Windows\Minidump\Mini102513-01.dmp
2013-10-25 20:33 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-25 20:33 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-25 20:33 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-25 20:33 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-25 20:33 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-25 20:33 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-25 20:33 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-25 20:33 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-25 20:32 - 2013-10-25 20:32 - 00000000 ____D C:\Qoobox
2013-10-25 20:31 - 2013-10-25 20:31 - 00000000 ____D C:\Windows\erdnt
2013-10-24 13:26 - 2013-10-24 13:26 - 00052810 _____ C:\Users\Sabrina\Desktop\FRST__1.txt
2013-10-24 13:25 - 2013-10-24 13:26 - 00026159 _____ C:\Users\Sabrina\Desktop\Addition__.txt
2013-10-24 13:22 - 2013-10-24 13:22 - 00000000 ____D C:\FRST
2013-10-24 13:06 - 2013-10-24 13:19 - 00000000 ____D C:\Windows\system32\MRT
2013-10-24 12:54 - 2013-10-24 12:54 - 00010703 _____ C:\Users\Sabrina\Desktop\Gmer.txt
2013-10-24 11:53 - 2013-10-24 11:53 - 00377856 _____ C:\Users\Sabrina\Downloads\gmer_2.1.19163.exe
2013-10-24 11:48 - 2013-10-24 11:49 - 00000476 _____ C:\Users\Sabrina\Downloads\defogger_disable.log
2013-10-24 11:46 - 2013-10-24 11:47 - 00000476 _____ C:\Users\Sabrina\Desktop\defogger_disable.log
2013-10-24 11:46 - 2013-10-24 11:46 - 00000000 _____ C:\Users\Sabrina\defogger_reenable
2013-10-24 11:45 - 2013-10-24 11:45 - 00050477 _____ C:\Users\Sabrina\Downloads\Defogger.exe
2013-10-24 09:58 - 2013-10-24 09:58 - 00040576 _____ C:\Users\Sabrina\Desktop\AVSCAN-20131024-000321-277FEAF1.LOG
2013-10-23 23:10 - 2013-10-23 23:10 - 00001482 _____ C:\Users\Sabrina\Desktop\Schutz vor Burn-out - Seelische Gesu - Verknüpfung.lnk
2013-10-23 20:13 - 2013-10-23 20:13 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Avira
2013-10-23 20:04 - 2013-10-23 20:05 - 00000000 ____D C:\ProgramData\Avira
2013-10-23 20:04 - 2013-10-10 18:14 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-23 20:04 - 2013-10-10 18:14 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-23 20:04 - 2013-10-10 18:14 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-23 19:53 - 2013-10-23 19:55 - 123853152 _____ C:\Users\Sabrina\Downloads\avira_free_antivirus_de_14b411.exe
2013-10-23 18:22 - 2013-10-23 18:25 - 00000019 _____ C:\Windows\install.log
2013-10-23 14:21 - 2013-10-23 14:21 - 00013271 _____ C:\Users\Sabrina\Desktop\hijackthis.log
2013-10-23 12:24 - 2013-10-23 12:24 - 00025742 _____ C:\Users\Sabrina\Desktop\AVSCAN-20131023-103123-484A54E2.LOG
2013-10-22 22:30 - 2013-10-27 19:53 - 00105366 _____ C:\Windows\PFRO.log
2013-10-22 14:21 - 2013-10-22 14:21 - 00000000 ____D C:\Users\Sabrina\Documents\Garmin
2013-10-22 12:47 - 2013-10-22 12:47 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Garmin
2013-10-22 12:44 - 2013-10-22 12:45 - 00000000 ____D C:\ProgramData\Garmin
2013-10-22 12:44 - 2013-10-22 12:44 - 00001770 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2013-10-22 12:43 - 2013-10-22 12:43 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-22 12:42 - 2013-10-22 12:42 - 12142192 _____ (Garmin Ltd or its subsidiaries) C:\Users\Sabrina\Downloads\GarminExpress.exe
2013-10-22 12:16 - 2013-10-23 19:30 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-10-14 09:09 - 2013-09-22 11:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-14 09:09 - 2013-09-22 11:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-14 09:09 - 2013-09-22 11:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-14 09:09 - 2013-09-22 11:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-10-14 09:09 - 2013-09-22 11:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-14 09:09 - 2013-09-22 11:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-14 09:09 - 2013-09-22 11:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-14 09:09 - 2013-09-22 11:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-14 09:09 - 2013-09-22 11:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-10-14 09:09 - 2013-09-22 11:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-14 09:09 - 2013-09-22 11:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-10-14 09:09 - 2013-09-22 11:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-14 09:09 - 2013-09-22 11:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-14 09:09 - 2013-09-22 11:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-14 09:09 - 2013-09-22 11:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-14 09:09 - 2013-09-22 10:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 10:41 - 2013-08-27 03:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-10-10 10:41 - 2013-08-27 03:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-10-10 10:41 - 2013-08-27 03:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-10-10 10:41 - 2013-08-27 03:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-10-10 10:41 - 2013-08-27 02:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-10-10 10:41 - 2013-08-27 02:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-10-10 10:41 - 2013-08-27 02:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-10-10 10:41 - 2013-08-27 02:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-10-10 10:41 - 2013-08-27 02:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-10-10 10:41 - 2013-08-01 04:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 10:41 - 2013-08-01 03:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-10-10 10:41 - 2013-07-20 11:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 10:41 - 2013-06-27 00:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 10:40 - 2013-08-29 08:36 - 02050048 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 10:40 - 2013-07-12 10:04 - 00134272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 10:40 - 2013-07-12 10:04 - 00073344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2013-10-10 10:40 - 2013-06-29 03:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-10 10:40 - 2013-06-29 03:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-10 10:40 - 2013-06-29 03:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-10 10:40 - 2013-06-29 03:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-10 10:40 - 2011-05-05 14:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-10 10:40 - 2011-05-05 14:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-10 10:39 - 2013-07-04 05:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 10:39 - 2013-07-03 03:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 10:39 - 2013-07-03 03:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 10:39 - 2013-06-04 05:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 10:39 - 2013-06-04 02:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 09:44 - 2013-10-09 09:44 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Fotobuchexpress24
2013-10-09 09:37 - 2013-10-09 15:37 - 17750408 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2013-10-05 13:10 - 2013-10-05 12:58 - 300363112 _____ C:\Users\Sabrina\Desktop\Filmfinal_klein.mpg
2013-10-05 13:09 - 2013-10-05 11:53 - 886304946 _____ C:\Users\Sabrina\Desktop\FILMFinal.mpg
2013-10-02 23:16 - 2013-10-02 23:16 - 00000000 ____D C:\Users\Sabrina\AppData\Local\MPlayer
2013-10-02 23:12 - 2013-10-02 23:24 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\FreeSmith
2013-10-02 23:12 - 2013-10-02 23:12 - 00000000 ____D C:\Program Files\FreeSmith
2013-10-02 23:11 - 2013-10-02 23:11 - 08965317 _____ (Anvsoft ) C:\Users\Sabrina\Downloads\freesmith-video-player.exe
2013-10-01 09:43 - 2013-10-05 10:46 - 00000000 ____D C:\Users\Sabrina\Documents\Pinnacle
2013-10-01 09:03 - 2013-10-15 16:18 - 00000000 ____D C:\Users\Sabrina\Desktop\Weinfurtner Wiesn
==================== One Month Modified Files and Folders =======
2013-10-29 13:39 - 2013-10-29 13:39 - 00000766 _____ C:\Users\Sabrina\Desktop\JRT.txt
2013-10-29 13:37 - 2012-04-14 15:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-29 13:30 - 2013-10-29 13:30 - 00000000 ____D C:\Windows\ERUNT
2013-10-29 13:21 - 2008-01-23 14:38 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\OpenOffice.org2
2013-10-29 13:11 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-29 13:11 - 2006-11-02 13:47 - 00003680 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-29 13:11 - 2006-11-02 13:47 - 00003680 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-29 13:10 - 2006-11-02 14:01 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-29 13:09 - 2009-04-19 13:29 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-10-29 13:09 - 2008-01-17 12:11 - 01657008 _____ C:\Windows\WindowsUpdate.log
2013-10-29 13:08 - 2013-10-29 11:11 - 00000000 ____D C:\AdwCleaner
2013-10-29 00:17 - 2013-10-29 00:17 - 01033335 _____ (Thisisu) C:\Users\Sabrina\Desktop\JRT.exe
2013-10-29 00:15 - 2013-10-29 00:15 - 01060070 _____ C:\Users\Sabrina\Desktop\adwcleaner.exe
2013-10-27 20:05 - 2013-10-27 20:04 - 01089097 _____ (Farbar) C:\Users\Sabrina\Desktop\FRST.exe
2013-10-27 19:53 - 2013-10-22 22:30 - 00105366 _____ C:\Windows\PFRO.log
2013-10-27 13:56 - 2013-10-27 13:53 - 00000000 ___SD C:\ComboFix
2013-10-27 13:53 - 2013-10-27 13:52 - 00000000 ___SD C:\32788R22FWJFW
2013-10-26 23:49 - 2013-10-26 23:49 - 05136694 ____R (Swearware) C:\Users\Sabrina\Desktop\ComboFix.exe
2013-10-25 21:09 - 2013-10-25 21:09 - 269314744 _____ C:\Windows\MEMORY.DMP
2013-10-25 21:09 - 2013-10-25 21:09 - 00142776 _____ C:\Windows\Minidump\Mini102513-01.dmp
2013-10-25 21:09 - 2008-10-05 12:39 - 00000000 ____D C:\Windows\Minidump
2013-10-25 20:32 - 2013-10-25 20:32 - 00000000 ____D C:\Qoobox
2013-10-25 20:31 - 2013-10-25 20:31 - 00000000 ____D C:\Windows\erdnt
2013-10-24 21:42 - 2012-12-19 00:42 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-24 13:26 - 2013-10-24 13:26 - 00052810 _____ C:\Users\Sabrina\Desktop\FRST__1.txt
2013-10-24 13:26 - 2013-10-24 13:25 - 00026159 _____ C:\Users\Sabrina\Desktop\Addition__.txt
2013-10-24 13:22 - 2013-10-24 13:22 - 00000000 ____D C:\FRST
2013-10-24 13:19 - 2013-10-24 13:06 - 00000000 ____D C:\Windows\system32\MRT
2013-10-24 12:54 - 2013-10-24 12:54 - 00010703 _____ C:\Users\Sabrina\Desktop\Gmer.txt
2013-10-24 11:53 - 2013-10-24 11:53 - 00377856 _____ C:\Users\Sabrina\Downloads\gmer_2.1.19163.exe
2013-10-24 11:49 - 2013-10-24 11:48 - 00000476 _____ C:\Users\Sabrina\Downloads\defogger_disable.log
2013-10-24 11:47 - 2013-10-24 11:46 - 00000476 _____ C:\Users\Sabrina\Desktop\defogger_disable.log
2013-10-24 11:46 - 2013-10-24 11:46 - 00000000 _____ C:\Users\Sabrina\defogger_reenable
2013-10-24 11:46 - 2008-01-17 13:23 - 00000000 ____D C:\Users\Sabrina
2013-10-24 11:45 - 2013-10-24 11:45 - 00050477 _____ C:\Users\Sabrina\Downloads\Defogger.exe
2013-10-24 10:29 - 2008-01-17 13:23 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Adobe
2013-10-24 09:58 - 2013-10-24 09:58 - 00040576 _____ C:\Users\Sabrina\Desktop\AVSCAN-20131024-000321-277FEAF1.LOG
2013-10-23 23:10 - 2013-10-23 23:10 - 00001482 _____ C:\Users\Sabrina\Desktop\Schutz vor Burn-out - Seelische Gesu - Verknüpfung.lnk
2013-10-23 20:29 - 2012-04-14 21:46 - 00211920 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-10-23 20:29 - 2006-11-02 13:47 - 04195640 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-23 20:26 - 2012-06-19 23:19 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-23 20:26 - 2012-01-10 00:12 - 00000000 ____D C:\Program Files\7-Zip
2013-10-23 20:26 - 2008-01-18 16:58 - 00000000 ____D C:\Program Files\Avira
2013-10-23 20:13 - 2013-10-23 20:13 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Avira
2013-10-23 20:05 - 2013-10-23 20:04 - 00000000 ____D C:\ProgramData\Avira
2013-10-23 19:55 - 2013-10-23 19:53 - 123853152 _____ C:\Users\Sabrina\Downloads\avira_free_antivirus_de_14b411.exe
2013-10-23 19:30 - 2013-10-22 12:16 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-10-23 18:43 - 2008-07-23 10:48 - 00000000 ____D C:\Program Files\Common Files\Real
2013-10-23 18:29 - 2008-01-17 13:23 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Google
2013-10-23 18:25 - 2013-10-23 18:22 - 00000019 _____ C:\Windows\install.log
2013-10-23 18:25 - 2007-08-13 13:09 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-10-23 18:21 - 2012-08-07 16:33 - 00001349 _____ C:\ProgramData\hpzinstall.log
2013-10-23 17:57 - 2008-03-30 16:46 - 00000000 ____D C:\Program Files\Pinnacle
2013-10-23 17:50 - 2008-03-30 16:46 - 00000000 ____D C:\ProgramData\Pinnacle
2013-10-23 16:30 - 2006-11-02 12:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-10-23 16:29 - 2012-08-07 00:05 - 00000000 ____D C:\ProgramData\Corel
2013-10-23 15:21 - 2008-10-27 16:16 - 00000000 ____D C:\Program Files\HijackThis
2013-10-23 14:50 - 2013-09-20 18:21 - 00000000 ____D C:\Program Files\PDF Architect
2013-10-23 14:21 - 2013-10-23 14:21 - 00013271 _____ C:\Users\Sabrina\Desktop\hijackthis.log
2013-10-23 12:24 - 2013-10-23 12:24 - 00025742 _____ C:\Users\Sabrina\Desktop\AVSCAN-20131023-103123-484A54E2.LOG
2013-10-22 22:24 - 2008-10-27 16:07 - 00001538 _____ C:\Windows\wininit.ini
2013-10-22 22:13 - 2013-02-05 20:21 - 00000000 ____D C:\ProgramData\InstallMate
2013-10-22 18:32 - 2008-10-27 15:30 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2013-10-22 18:27 - 2008-10-07 09:14 - 00000000 ____D C:\Users\Sabrina\Downloads\CCleaner
2013-10-22 17:10 - 2011-01-09 16:42 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\GARMIN
2013-10-22 14:21 - 2013-10-22 14:21 - 00000000 ____D C:\Users\Sabrina\Documents\Garmin
2013-10-22 12:47 - 2013-10-22 12:47 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Garmin
2013-10-22 12:47 - 2011-01-09 18:21 - 00000000 ____D C:\Program Files\Garmin
2013-10-22 12:45 - 2013-10-22 12:44 - 00000000 ____D C:\ProgramData\Garmin
2013-10-22 12:44 - 2013-10-22 12:44 - 00001770 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2013-10-22 12:43 - 2013-10-22 12:43 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-22 12:42 - 2013-10-22 12:42 - 12142192 _____ (Garmin Ltd or its subsidiaries) C:\Users\Sabrina\Downloads\GarminExpress.exe
2013-10-16 14:43 - 2013-09-28 12:05 - 00000000 ____D C:\Users\Sabrina\AppData\Local\PMB Files
2013-10-15 22:31 - 2013-09-28 13:42 - 00001078 _____ C:\Users\Sabrina\AppData\Roaming\__AvidCloudManager.log
2013-10-15 16:18 - 2013-10-01 09:03 - 00000000 ____D C:\Users\Sabrina\Desktop\Weinfurtner Wiesn
2013-10-15 15:43 - 2008-12-18 18:40 - 00000000 ___HD C:\Users\Sabrina\AppData\Local\Pinnacle
2013-10-15 14:32 - 2013-09-28 13:42 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Avid
2013-10-15 14:31 - 2008-03-30 16:48 - 00000349 _____ C:\Users\Public\Documents\PCLECHAL.INI
2013-10-15 13:18 - 2008-03-30 17:29 - 00000069 _____ C:\Windows\NeroDigital.ini
2013-10-15 07:17 - 2013-09-28 13:41 - 00001441 _____ C:\Users\Sabrina\AppData\Roaming\SABRINA-PC.MTBF.txt
2013-10-14 20:41 - 2008-02-11 18:33 - 00000000 ____D C:\Users\Sabrina\Desktop\Bewerbung
2013-10-14 10:11 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-10-10 18:14 - 2013-10-23 20:04 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-10 18:14 - 2013-10-23 20:04 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-10 18:14 - 2013-10-23 20:04 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-10 18:14 - 2008-01-18 16:58 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2013-10-09 15:37 - 2013-10-09 09:37 - 17750408 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2013-10-09 09:44 - 2013-10-09 09:44 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Fotobuchexpress24
2013-10-09 09:43 - 2012-04-13 20:06 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2013-10-09 08:37 - 2012-04-14 15:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-09 08:37 - 2011-07-15 21:13 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-07 14:49 - 2013-09-28 13:42 - 00001128 _____ C:\Users\Sabrina\AppData\Roaming\__AvidCloudManagerPrevious.log
2013-10-05 12:58 - 2013-10-05 13:10 - 300363112 _____ C:\Users\Sabrina\Desktop\Filmfinal_klein.mpg
2013-10-05 11:53 - 2013-10-05 13:09 - 886304946 _____ C:\Users\Sabrina\Desktop\FILMFinal.mpg
2013-10-05 10:46 - 2013-10-01 09:43 - 00000000 ____D C:\Users\Sabrina\Documents\Pinnacle
2013-10-04 13:38 - 2008-01-17 13:23 - 00006324 _____ C:\Users\Sabrina\AppData\Local\d3d9caps.dat
2013-10-02 23:24 - 2013-10-02 23:12 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\FreeSmith
2013-10-02 23:16 - 2013-10-02 23:16 - 00000000 ____D C:\Users\Sabrina\AppData\Local\MPlayer
2013-10-02 23:12 - 2013-10-02 23:12 - 00000000 ____D C:\Program Files\FreeSmith
2013-10-02 23:11 - 2013-10-02 23:11 - 08965317 _____ (Anvsoft ) C:\Users\Sabrina\Downloads\freesmith-video-player.exe
2013-10-02 15:52 - 2008-01-17 13:23 - 00056832 _____ C:\Users\Sabrina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Files to move or delete:
====================
C:\ProgramData\PKP_DLdu.DAT
C:\ProgramData\PKP_DLdw.DAT
Some content of TEMP:
====================
C:\Users\Sabrina\AppData\Local\Temp\avgnt.exe
C:\Users\Sabrina\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-29 13:25
==================== End Of Log ============================ ein paar Fieslinge (Browse2Save und so) sind schon weg, oder?
Danke und schönen Gruß
Baumwolle |