ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=891feb85d68ed443a059a48f00482181
# engine=16048
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-11-27 10:25:25
# local_time=2013-11-27 11:25:25 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 89890 137220975 0 0
# scanned=156513
# found=19
# cleaned=0
# scan_time=10312
sh=836D94364F1CFC07116133EF521AA88C316A8252 ft=0 fh=0000000000000000 vn="HTML/Ransom.B trojan" ac=I fn="C:\ProgramData\hlyyrmrrvlmpjrk\main.html"
sh=836D94364F1CFC07116133EF521AA88C316A8252 ft=0 fh=0000000000000000 vn="HTML/Ransom.B trojan" ac=I fn="C:\Users\All Users\hlyyrmrrvlmpjrk\main.html"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="VBS/Kryptik.Y trojan" ac=I fn="C:\Users\sanderle\AppData\Local\Temp\iTunesHelper.vbe"
sh=CD665FDD62D8C0A42C05F004EA6C0E0164CE5463 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\sanderle\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\29f1cce7-5c5cce8f"
sh=05D02240EE6DE3A289CB848382D83B65882BD8A6 ft=0 fh=0000000000000000 vn="VBS/Kryptik.Y trojan" ac=I fn="C:\Users\sanderle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe"
sh=FDF3B19B700F434CCD91AEAE3C271F8AF3C0E63C ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\LAZAR\MA_COURS_PARIS\Argotologie\Ref\18414-Formation des mots.lnk"
sh=99E30867C2222B8DC74800FA580ADC52B03E2652 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\LAZAR\MA_COURS_PARIS\Argotologie\Ref\censimento_volume_completo.lnk"
sh=DCD98C722357AA198CB4AECC7CFD267F0E255C19 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\LAZAR\MA_COURS_PARIS\Argotologie\Ref\Language_distribution_in_South_Tyrol_and_Trentino.lnk"
sh=02A013F562E0D5A387732953E095CC4513F18254 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\LAZAR\MA_COURS_PARIS\Argotologie\Ref\logo-parisdescartes.lnk"
sh=F6235E85BCF2CC55A6F81F490B6AA6381602B6CD ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\LAZAR\MA_COURS_PARIS\Argotologie\Ref\Logo_Sorbonne_Paris_Cite.lnk"
sh=A103C770F06776708713FB81C4683BB9579076D1 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\LAZAR\MA_COURS_PARIS\Argotologie\Ref\wappen_bundesland_tirol.lnk"
sh=4639274B3DDBBD4D2FA362238AAFC58293FB651F ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\LAZAR\MA_COURS_PARIS\Argotologie\Ref\zPharaoh.lnk"
sh=FDF3B19B700F434CCD91AEAE3C271F8AF3C0E63C ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\Neuer Ordner\Argotologie\Ref\18414-Formation des mots.lnk"
sh=99E30867C2222B8DC74800FA580ADC52B03E2652 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\Neuer Ordner\Argotologie\Ref\censimento_volume_completo.lnk"
sh=DCD98C722357AA198CB4AECC7CFD267F0E255C19 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\Neuer Ordner\Argotologie\Ref\Language_distribution_in_South_Tyrol_and_Trentino.lnk"
sh=02A013F562E0D5A387732953E095CC4513F18254 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\Neuer Ordner\Argotologie\Ref\logo-parisdescartes.lnk"
sh=F6235E85BCF2CC55A6F81F490B6AA6381602B6CD ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\Neuer Ordner\Argotologie\Ref\Logo_Sorbonne_Paris_Cite.lnk"
sh=A103C770F06776708713FB81C4683BB9579076D1 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\Neuer Ordner\Argotologie\Ref\wappen_bundesland_tirol.lnk"
sh=4639274B3DDBBD4D2FA362238AAFC58293FB651F ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\sanderle\Desktop\Neuer Ordner\Argotologie\Ref\zPharaoh.lnk"
Results of screen317's Security Check version 0.99.76
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Trend Micro Titanium Internet Security
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware Version 1.75.0.1300
Java(TM) 7 Update 1
Java version out of Date!
Adobe Reader XI
Google Chrome 30.0.1599.101
Google Chrome 31.0.1650.57
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Spybot Teatimer.exe is disabled!
Malwarebytes' Anti-Malware mbamscheduler.exe
Trend Micro Titanium TiMiniService.exe
Trend Micro Titanium TiResumeSrv.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-11-2013 01
Ran by sanderle (administrator) on SANDERLE-PC on 27-11-2013 23:54:29
Running from C:\Users\sanderle\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\CxUtilSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
( ) C:\Windows\System32\lxeacoms.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\TiMiniService.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
() C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [iTunesHelper] - C:\Users\sanderle\AppData\Local\Temp\iTunesHelper.vbe [69558261 2013-10-15] () <===== ATTENTION
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKU\Sanni\...\Policies\system: [LogonHoursAction] 2
HKU\Sanni\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\sanderle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe ()
Startup: C:\Users\sanderle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL =
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1077\TmIEPlg.dll (Trend Micro Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1077\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1077\TmIEPlg.dll (Trend Micro Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1077\TmIEPlg32.dll (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 89.2.0.1 89.2.0.2
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/", "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.10.8) - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U1) - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (TelevisionFanatic Installer Plugin Stub) - C:\Program Files (x86)\TelevisionFanaticEI\Installr\1.bin\NP64EISB.dll No File
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\sanderle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\sanderle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\sanderle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\sanderle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
==================== Services (Whitelisted) =================
R2 CxUtilSvc; C:\Program Files\Conexant\SA3\CxUtilSvc.exe [109184 2011-10-12] (Conexant Systems, Inc.)
R2 lxea_device; C:\windows\system32\lxeacoms.exe [1052328 2010-04-14] ( )
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-07-28] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 TiMiniService; C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [244440 2011-05-21] (Trend Micro Inc.)
R2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-04-20] (Vodafone)
S3 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [x]
==================== Drivers (Whitelisted) ====================
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90896 2011-05-21] (Trend Micro Inc.)
R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144656 2011-05-21] (Trend Micro Inc.)
R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [69392 2011-05-21] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2011-05-21] (Trend Micro Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-27 23:54 - 2013-11-27 23:54 - 01958850 _____ (Farbar) C:\Users\sanderle\Downloads\FRST64.exe
2013-11-27 23:54 - 2013-11-27 23:54 - 00013572 _____ C:\Users\sanderle\Downloads\FRST.txt
2013-11-27 20:26 - 2013-11-27 20:26 - 02347384 _____ (ESET) C:\Users\sanderle\Downloads\esetsmartinstaller_enu (1).exe
2013-11-27 20:26 - 2013-11-27 20:26 - 00000000 ____D C:\Program Files (x86)\ESET
2013-11-26 23:19 - 2013-11-26 23:19 - 00891184 _____ C:\Users\sanderle\Downloads\SecurityCheck.exe
2013-11-26 22:27 - 2013-11-26 22:27 - 02347384 _____ (ESET) C:\Users\sanderle\Downloads\esetsmartinstaller_enu.exe
2013-11-26 16:16 - 2013-11-26 16:16 - 00001430 _____ C:\Users\sanderle\AppData\Local\RecConfig.xml
2013-11-26 16:13 - 2013-11-26 16:13 - 02497825 _____ (No23) C:\Users\sanderle\Downloads\No23Recorder2103.exe
2013-11-25 11:29 - 2013-11-25 11:29 - 00762814 _____ C:\Users\sanderle\Downloads\ei_enseignement_superieur _recherche_cm (1)
2013-11-25 11:29 - 2013-11-25 11:29 - 00762814 _____ C:\Users\sanderle\Downloads\ei_enseignement_superieur _recherche_cm
2013-11-25 10:01 - 2013-11-25 10:01 - 00001203 _____ C:\Users\sanderle\Desktop\JRT.txt
2013-11-25 09:53 - 2013-11-25 09:53 - 01034531 _____ (Thisisu) C:\Users\sanderle\Downloads\JRT.exe
2013-11-25 09:47 - 2013-11-25 09:47 - 01091882 _____ C:\Users\sanderle\Downloads\adwcleaner.exe
2013-11-25 09:26 - 2013-11-25 09:26 - 00001127 _____ C:\Users\sanderle\Desktop\Continue AnyProtect Installation.lnk
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\wangzhisong
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\Documents\Mobogenie
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\AppData\Roaming\0C1I1L1R1J0M1P0I1G
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\AppData\Local\Mobogenie
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\AppData\Local\cache
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 _____ C:\Users\sanderle\daemonprocess.txt
2013-11-25 09:25 - 2013-11-25 09:28 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-11-25 09:24 - 2013-11-25 09:24 - 00602144 _____ C:\Users\sanderle\Downloads\Setup.exe
2013-11-22 13:05 - 2013-11-22 13:05 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-11-22 11:08 - 2013-11-26 23:22 - 00000000 ____D C:\Users\sanderle\Desktop\Viren
2013-11-22 11:02 - 2013-11-22 11:02 - 00030742 _____ C:\ComboFix.txt
2013-11-22 10:52 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe
2013-11-22 10:52 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe
2013-11-22 10:52 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2013-11-22 10:52 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2013-11-22 10:52 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2013-11-22 10:52 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe
2013-11-22 10:52 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe
2013-11-22 10:52 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe
2013-11-22 10:51 - 2013-11-22 11:02 - 00000000 ____D C:\Qoobox
2013-11-22 10:51 - 2013-11-22 11:01 - 00000000 ____D C:\windows\erdnt
2013-11-22 10:51 - 2013-11-22 10:51 - 05147802 ____R (Swearware) C:\Users\sanderle\Downloads\ComboFix.exe
2013-11-22 10:45 - 2013-11-22 10:45 - 00000000 ____D C:\Users\sanderle\Desktop\ListeDienste
2013-11-19 19:26 - 2013-11-19 19:26 - 06186980 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856 (3).odp
2013-11-19 19:24 - 2013-11-19 19:24 - 00965500 _____ C:\Users\sanderle\Downloads\Pr__sentationTRAVAILseminaire_Argotologie.zip
2013-11-19 19:20 - 2013-11-19 19:20 - 06184926 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856 (2).odp
2013-11-19 19:19 - 2013-11-19 19:19 - 06184926 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856 (1).odp
2013-11-19 19:17 - 2013-11-19 19:18 - 06187007 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856.odp
2013-11-19 17:00 - 2013-11-19 17:00 - 00074703 _____ C:\windows\SysWOW64\mfc45.dat
2013-11-19 16:32 - 2013-11-19 16:32 - 00000000 ____D C:\FRST
2013-11-19 14:47 - 2013-11-19 14:47 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-19 14:46 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-11-18 22:22 - 2013-11-18 22:23 - 00000000 ____D C:\Users\sanderle\Desktop\Neuer Ordner
2013-11-18 17:29 - 2013-11-18 17:29 - 00000000 ____D C:\windows\ERUNT
2013-11-18 16:54 - 2013-11-18 16:54 - 00000375 _____ C:\Users\sanderle\Desktop\Lexar (D) - Verknüpfung.lnk
2013-11-18 16:42 - 2013-11-18 17:01 - 00000000 ____D C:\Users\sanderle\AppData\Roaming\Mipony
2013-11-14 13:09 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-11-14 13:09 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-11-14 13:09 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-11-14 13:09 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-11-14 13:09 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-11-14 13:09 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-11-14 13:09 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-11-14 13:09 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-11-14 13:09 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-11-14 13:09 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-11-14 13:09 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-11-14 13:09 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-14 11:00 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2013-11-14 11:00 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2013-11-14 11:00 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2013-11-14 11:00 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2013-11-14 11:00 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2013-11-14 11:00 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-11-14 11:00 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-11-14 11:00 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2013-11-14 11:00 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2013-11-14 11:00 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-11-14 11:00 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 11:00 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2013-11-14 11:00 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\credui.dll
2013-11-14 11:00 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2013-11-14 11:00 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2013-11-14 11:00 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2013-11-14 11:00 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2013-11-14 11:00 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2013-11-14 11:00 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2013-11-14 11:00 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2013-11-14 11:00 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2013-11-14 11:00 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2013-11-14 11:00 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2013-11-14 11:00 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2013-11-14 11:00 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2013-11-14 11:00 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2013-11-14 11:00 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2013-11-14 11:00 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2013-11-14 11:00 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2013-11-14 11:00 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2013-11-09 20:12 - 2013-11-09 20:12 - 00000000 ____D C:\Users\sanderle\Desktop\B_Sociolinguistiquecritique
2013-11-08 10:44 - 2013-09-04 02:37 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2013-11-08 10:44 - 2013-09-04 02:37 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2013-11-08 10:44 - 2013-09-04 02:37 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2013-11-08 10:44 - 2013-09-04 02:37 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2013-11-08 10:44 - 2013-09-04 02:37 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2013-11-08 10:44 - 2013-09-04 02:37 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2013-11-08 10:44 - 2013-09-04 02:37 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2013-11-07 19:28 - 2013-11-27 09:37 - 00000000 ____D C:\Users\sanderle\Desktop\LAZAR
2013-11-04 22:33 - 2013-11-25 09:49 - 00000000 ____D C:\AdwCleaner
2013-11-04 21:03 - 2013-11-04 21:03 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-04 21:03 - 2013-11-04 21:03 - 00000000 _____ C:\autoexec.bat
2013-11-04 21:02 - 2013-11-04 22:14 - 00000000 ____D C:\windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-11-03 12:50 - 2013-11-03 12:50 - 00000093 _____ C:\Users\sanderle\AppData\Roaming\WB.CFG
2013-11-03 12:50 - 2013-11-03 12:50 - 00000006 _____ C:\Users\sanderle\AppData\Roaming\WBPU-TTL.DAT
2013-11-03 12:03 - 2013-11-03 12:03 - 00001132 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
2013-11-03 12:02 - 2013-11-03 12:02 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
==================== One Month Modified Files and Folders =======
2013-11-27 23:55 - 2013-11-27 23:54 - 00013572 _____ C:\Users\sanderle\Downloads\FRST.txt
2013-11-27 23:54 - 2013-11-27 23:54 - 01958850 _____ (Farbar) C:\Users\sanderle\Downloads\FRST64.exe
2013-11-27 23:33 - 2013-02-12 18:45 - 00001114 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-27 23:07 - 2012-01-22 08:16 - 00708842 _____ C:\windows\system32\perfh007.dat
2013-11-27 23:07 - 2012-01-22 08:16 - 00152188 _____ C:\windows\system32\perfc007.dat
2013-11-27 23:07 - 2009-07-14 06:13 - 01645504 _____ C:\windows\system32\PerfStringBackup.INI
2013-11-27 20:26 - 2013-11-27 20:26 - 02347384 _____ (ESET) C:\Users\sanderle\Downloads\esetsmartinstaller_enu (1).exe
2013-11-27 20:26 - 2013-11-27 20:26 - 00000000 ____D C:\Program Files (x86)\ESET
2013-11-27 20:20 - 2013-05-22 13:54 - 00003440 _____ C:\windows\System32\Tasks\PCDEventLauncherTask
2013-11-27 19:59 - 2012-01-22 06:25 - 01320229 _____ C:\windows\WindowsUpdate.log
2013-11-27 17:29 - 2009-07-14 05:45 - 00020928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-27 17:29 - 2009-07-14 05:45 - 00020928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-27 17:22 - 2013-02-12 18:45 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-27 17:22 - 2012-01-22 07:04 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2013-11-27 17:22 - 2012-01-22 07:04 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2013-11-27 17:22 - 2012-01-22 06:55 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-11-27 17:22 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-11-27 17:22 - 2009-07-14 05:51 - 00115331 _____ C:\windows\setupact.log
2013-11-27 12:48 - 2012-01-31 17:10 - 00000000 ____D C:\Users\sanderle\AppData\Roaming\SoftGrid Client
2013-11-27 09:37 - 2013-11-07 19:28 - 00000000 ____D C:\Users\sanderle\Desktop\LAZAR
2013-11-26 23:22 - 2013-11-22 11:08 - 00000000 ____D C:\Users\sanderle\Desktop\Viren
2013-11-26 23:19 - 2013-11-26 23:19 - 00891184 _____ C:\Users\sanderle\Downloads\SecurityCheck.exe
2013-11-26 23:04 - 2012-03-06 21:05 - 00000000 ____D C:\Users\sanderle\AppData\Roaming\Skype
2013-11-26 22:27 - 2013-11-26 22:27 - 02347384 _____ (ESET) C:\Users\sanderle\Downloads\esetsmartinstaller_enu.exe
2013-11-26 22:24 - 2012-01-31 16:51 - 00064024 _____ C:\Users\sanderle\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-26 16:16 - 2013-11-26 16:16 - 00001430 _____ C:\Users\sanderle\AppData\Local\RecConfig.xml
2013-11-26 16:13 - 2013-11-26 16:13 - 02497825 _____ (No23) C:\Users\sanderle\Downloads\No23Recorder2103.exe
2013-11-25 11:29 - 2013-11-25 11:29 - 00762814 _____ C:\Users\sanderle\Downloads\ei_enseignement_superieur _recherche_cm (1)
2013-11-25 11:29 - 2013-11-25 11:29 - 00762814 _____ C:\Users\sanderle\Downloads\ei_enseignement_superieur _recherche_cm
2013-11-25 10:01 - 2013-11-25 10:01 - 00001203 _____ C:\Users\sanderle\Desktop\JRT.txt
2013-11-25 09:53 - 2013-11-25 09:53 - 01034531 _____ (Thisisu) C:\Users\sanderle\Downloads\JRT.exe
2013-11-25 09:49 - 2013-11-04 22:33 - 00000000 ____D C:\AdwCleaner
2013-11-25 09:47 - 2013-11-25 09:47 - 01091882 _____ C:\Users\sanderle\Downloads\adwcleaner.exe
2013-11-25 09:44 - 2010-11-21 04:47 - 00129974 _____ C:\windows\PFRO.log
2013-11-25 09:28 - 2013-11-25 09:25 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-11-25 09:27 - 2012-01-31 16:54 - 00000000 ___RD C:\Users\sanderle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-25 09:26 - 2013-11-25 09:26 - 00001127 _____ C:\Users\sanderle\Desktop\Continue AnyProtect Installation.lnk
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\wangzhisong
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\Documents\Mobogenie
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\AppData\Roaming\0C1I1L1R1J0M1P0I1G
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\AppData\Local\Mobogenie
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 ____D C:\Users\sanderle\AppData\Local\cache
2013-11-25 09:26 - 2013-11-25 09:26 - 00000000 _____ C:\Users\sanderle\daemonprocess.txt
2013-11-25 09:26 - 2012-01-31 16:51 - 00000000 ____D C:\Users\sanderle
2013-11-25 09:24 - 2013-11-25 09:24 - 00602144 _____ C:\Users\sanderle\Downloads\Setup.exe
2013-11-22 13:05 - 2013-11-22 13:05 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-11-22 11:02 - 2013-11-22 11:02 - 00030742 _____ C:\ComboFix.txt
2013-11-22 11:02 - 2013-11-22 10:51 - 00000000 ____D C:\Qoobox
2013-11-22 11:01 - 2013-11-22 10:51 - 00000000 ____D C:\windows\erdnt
2013-11-22 11:00 - 2009-07-14 03:34 - 00000215 _____ C:\windows\system.ini
2013-11-22 10:51 - 2013-11-22 10:51 - 05147802 ____R (Swearware) C:\Users\sanderle\Downloads\ComboFix.exe
2013-11-22 10:45 - 2013-11-22 10:45 - 00000000 ____D C:\Users\sanderle\Desktop\ListeDienste
2013-11-22 10:31 - 2013-02-12 17:55 - 00000000 ____D C:\ProgramData\iolo
2013-11-19 19:26 - 2013-11-19 19:26 - 06186980 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856 (3).odp
2013-11-19 19:24 - 2013-11-19 19:24 - 00965500 _____ C:\Users\sanderle\Downloads\Pr__sentationTRAVAILseminaire_Argotologie.zip
2013-11-19 19:20 - 2013-11-19 19:20 - 06184926 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856 (2).odp
2013-11-19 19:19 - 2013-11-19 19:19 - 06184926 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856 (1).odp
2013-11-19 19:18 - 2013-11-19 19:17 - 06187007 _____ C:\Users\sanderle\Downloads\Sandra_Hanni_1137856.odp
2013-11-19 17:00 - 2013-11-19 17:00 - 00074703 _____ C:\windows\SysWOW64\mfc45.dat
2013-11-19 16:32 - 2013-11-19 16:32 - 00000000 ____D C:\FRST
2013-11-19 14:47 - 2013-11-19 14:47 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-19 14:47 - 2012-10-25 16:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-18 22:23 - 2013-11-18 22:22 - 00000000 ____D C:\Users\sanderle\Desktop\Neuer Ordner
2013-11-18 17:29 - 2013-11-18 17:29 - 00000000 ____D C:\windows\ERUNT
2013-11-18 17:01 - 2013-11-18 16:42 - 00000000 ____D C:\Users\sanderle\AppData\Roaming\Mipony
2013-11-18 16:54 - 2013-11-18 16:54 - 00000375 _____ C:\Users\sanderle\Desktop\Lexar (D) - Verknüpfung.lnk
2013-11-17 00:56 - 2013-02-12 18:46 - 00002177 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-16 13:52 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2013-11-15 15:22 - 2013-05-22 13:53 - 00000000 ____D C:\Program Files\My Dell
2013-11-15 15:22 - 2012-02-21 16:00 - 00000000 ____D C:\ProgramData\PCDr
2013-11-11 05:50 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2013-11-09 20:12 - 2013-11-09 20:12 - 00000000 ____D C:\Users\sanderle\Desktop\B_Sociolinguistiquecritique
2013-11-04 22:34 - 2012-01-31 16:54 - 00001003 _____ C:\Users\sanderle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-04 22:14 - 2013-11-04 21:02 - 00000000 ____D C:\windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-11-04 21:03 - 2013-11-04 21:03 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-04 21:03 - 2013-11-04 21:03 - 00000000 _____ C:\autoexec.bat
2013-11-04 20:42 - 2009-07-14 06:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-11-03 15:06 - 2009-07-14 05:45 - 00294168 _____ C:\windows\system32\FNTCACHE.DAT
2013-11-03 12:50 - 2013-11-03 12:50 - 00000093 _____ C:\Users\sanderle\AppData\Roaming\WB.CFG
2013-11-03 12:50 - 2013-11-03 12:50 - 00000006 _____ C:\Users\sanderle\AppData\Roaming\WBPU-TTL.DAT
2013-11-03 12:04 - 2013-02-12 18:45 - 00000000 ____D C:\Users\sanderle\AppData\Local\Google
2013-11-03 12:03 - 2013-11-03 12:03 - 00001132 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
2013-11-03 12:02 - 2013-11-03 12:02 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-11-03 12:01 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
Files to move or delete:
====================
C:\Users\sanderle\AppData\Local\Temp\iTunesHelper.vbe
Some content of TEMP:
====================
C:\Users\sanderle\AppData\Local\Temp\BackupSetup.exe
C:\Users\sanderle\AppData\Local\Temp\ICReinstall_nse1A79.tmp.exe
C:\Users\sanderle\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-26 19:54
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
soweit keine neuen Schwierigkeiten.
Lieben Dank :-)