Hallo Schrauber!
Deine Anweisungen habe ich alle ausgeführt, anbei die Logs.
Die svchost.exe von Netzwerkdienst ist immer noch unbeeindruckt bei ihren 50% CPU.
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 08.06.2014
Scan Time: 12:04:46
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.08.01
Rootkit Database: v2014.06.02.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: AdminS
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 385635
Time Elapsed: 14 min, 44 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 11
PUP.Optional.YTDToolbar, HKU\S-1-5-21-2904712871-953101035-2089307719-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{F3FEE66E-E034-436A-86E4-9690573BEE8A}, Quarantined, [1fe296e0611ac274bf16db5f5ea405fb],
PUP.Optional.YTDToolbar, HKU\S-1-5-21-2904712871-953101035-2089307719-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{F3FEE66E-E034-436A-86E4-9690573BEE8A}, Quarantined, [1fe296e0611ac274bf16db5f5ea405fb],
PUP.Optional.YTDToolbar, HKU\S-1-5-21-2904712871-953101035-2089307719-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{F3FEE66E-E034-436A-86E4-9690573BEE8A}, Quarantined, [1fe296e0611ac274bf16db5f5ea405fb],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-5.0, Quarantined, [956ce690b4c72f07e0b703a915ed9c64],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\mysearchdial, Quarantined, [6d9443337902a49293fa30a09e65fc04],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [05fc3e383a4137ff6c97489c33d0867a],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-5.0, Quarantined, [56aba7cff68572c4c8cf9e0edb27629e],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [cf32c6b029528babe09de0d9f0127b85],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\mysearchdial, Quarantined, [fe03d0a652293df9291debe918eb817f],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [45bc3640bdbe55e1612827a87291c43c],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [50b163137b00ed4930f15f49e81a639d],
Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2904712871-953101035-2089307719-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0A2O0R1R1H2Z1S1G0H1F, Quarantined, [45bc3640bdbe55e1612827a87291c43c]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 6
PUP.Optional.Spigot.A, C:\ProgramData\YouTube Downloader\ytd_installer.exe, Quarantined, [c63bbcba4932989e3053a185c937837d],
PUP.Optional.Bandoo.A, C:\Users\micha\Downloads\jZipSetup-r113-n-bf.exe, Quarantined, [17eae690cbb068cee7faf034847ca35d],
PUP.OfferBundler.ST, C:\Users\micha\Downloads\SoftonicDownloader_fuer_nvu.exe, Quarantined, [10f16c0af68531052dd2216b6b952cd4],
PUP.OfferBundler.ST, C:\Users\micha\Downloads\SoftonicDownloader_fuer_totaledit(portabel).exe, Quarantined, [f110e98dcab158de7b848309ba4656aa],
PUP.OfferBundler.ST, C:\Users\micha\Downloads\SoftonicDownloader_fuer_totaledit.exe, Quarantined, [fb066c0a483382b4877855378e72a759],
PUP.Optional.Spigot.A, C:\Windows\Installer\50dd4.msi, Quarantined, [50b190e64f2c4fe7a35b9ae9e021b947],
Physical Sectors: 0
(No malicious items detected)
(end) AdwCleaner[S1].txt: Code:
# AdwCleaner v3.212 - Bericht erstellt am 08/06/2014 um 12:51:28
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : AdminS - SABINPC
# Gestartet von : C:\Users\AdminS\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\AdminS\AppData\Roaming\Mozilla\Firefox\Profiles\6uejegd8.default-1397162983529\prefs.js ]
Zeile gelöscht : user_pref("extensions.irmysearch.aflt", "dsites05_14_18_ff");
Zeile gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtD0F0FyByC0EtDtD0B0A0AtAtB0AzztN0D0Tzu0SzzyDtDtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StByCzz0BtC0FyB0FtG0FtC0E0At[...]
Zeile gelöscht : user_pref("extensions.irmysearch.cr", "1358254258");
Zeile gelöscht : user_pref("extensions.irmysearch.instlRef", "140305_b");
[ Datei : C:\Users\maya\AppData\Roaming\Mozilla\Firefox\Profiles\t9ua2v3f.default\prefs.js ]
[ Datei : C:\Users\micha\AppData\Roaming\Mozilla\Firefox\Profiles\bntu9o8t.default\prefs.js ]
[ Datei : C:\Users\micha\AppData\Roaming\Mozilla\Firefox\Profiles\m4ux8q19.micha\prefs.js ]
Zeile gelöscht : user_pref("extensions.irmysearch.aflt", "dsites05_14_18_ff");
Zeile gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtD0F0FyByC0EtDtD0B0A0AtAtB0AzztN0D0Tzu0SzzyDtDtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StByCzz0BtC0FyB0FtG0FtC0E0At[...]
Zeile gelöscht : user_pref("extensions.irmysearch.cr", "1358254258");
Zeile gelöscht : user_pref("extensions.irmysearch.instlRef", "140305_b");
[ Datei : C:\Users\sabin\AppData\Roaming\Mozilla\Firefox\Profiles\x9of3h2j.default\prefs.js ]
[ Datei : C:\Users\Sofie\AppData\Roaming\Mozilla\Firefox\Profiles\7ttul5ln.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [15791 octets] - [11/05/2014 16:28:48]
AdwCleaner[R1].txt - [2573 octets] - [08/06/2014 12:49:31]
AdwCleaner[S0].txt - [15125 octets] - [11/05/2014 16:30:37]
AdwCleaner[S1].txt - [2498 octets] - [08/06/2014 12:51:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2558 octets] ########## JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by AdminS on 08.06.2014 at 13:32:19,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.06.2014 at 13:35:09,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST.txt:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-06-2014 01
Ran by AdminS (administrator) on SABINPC on 08-06-2014 13:58:00
Running from C:\Users\AdminS\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\wmi32.exe
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
==================== Registry (Whitelisted) ==================
HKU\S-1-5-21-2904712871-953101035-2089307719-1000\...\Run: [LaunchList] => C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe [145496 2007-03-21] (Pinnacle Systems)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {90300B97-ECFD-407D-8D44-14B273A45DCF} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\AdminS\AppData\Roaming\Mozilla\Firefox\Profiles\6uejegd8.default-1397162983529
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]
FF Extension: Chặn quảng cáo - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-02]
FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-02]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-02]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-02]
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Chặn quảng cáo - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-02]
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-02]
========================== Services (Whitelisted) =================
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2011-05-18] (Flexera Software, Inc.)
S2 HOSTS Anti-PUPs; C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2014-05-11] ()
S2 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH)
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [46976 2009-07-14] (Microsoft Corporation)
R3 acpials; C:\Windows\System32\DRIVERS\acpials.sys [7680 2009-07-14] (Microsoft Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-06-04] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-06-04] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-06-04] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-06-04] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-06-04] (Kaspersky Lab ZAO)
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2007-01-04] (Pinnacle Systems GmbH)
S3 MODRC; C:\Windows\System32\DRIVERS\modrc.sys [20032 2009-11-16] (DiBcom S.A.)
S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1311232 2009-07-14] (NXP Semiconductors)
S2 SE4BLPT; C:\Windows\system32\SE4BLPT.SYS [54488 2004-04-26] (Sharp Corporation)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26112 2010-11-08] (The OpenVPN Project)
S3 TTUSB2BDA; C:\Windows\System32\DRIVERS\ttusb2bda.sys [581888 2013-12-24] (TechnoTrend Goerler GmbH)
S3 USB28xxBGA; C:\Windows\System32\DRIVERS\emBDA.sys [217088 2006-02-06] (eMPIA Technology, Inc.)
S3 USB28xxOEM; C:\Windows\System32\DRIVERS\emOEM.sys [17792 2006-02-06] (eMPIA Technology, Inc.)
S3 Afc; system32\drivers\Afc.sys [X]
S3 catchme; \??\C:\Users\AdminS\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-08 13:35 - 2014-06-08 13:35 - 00000874 _____ () C:\Users\AdminS\Desktop\JRT.txt
2014-06-08 13:32 - 2014-06-08 13:32 - 00000000 ____D () C:\Windows\ERUNT
2014-06-08 12:57 - 2014-06-08 12:20 - 01016261 _____ (Thisisu) C:\Users\AdminS\Desktop\JRT.exe
2014-06-08 12:55 - 2014-06-08 12:55 - 00002638 _____ () C:\Users\AdminS\Desktop\AdwCleaner[S1].txt
2014-06-08 12:48 - 2014-06-08 12:18 - 01333465 _____ () C:\Users\AdminS\Desktop\adwcleaner_3.212.exe
2014-06-08 12:46 - 2014-06-08 12:46 - 00004316 _____ () C:\Users\AdminS\Desktop\mbam.txt
2014-06-08 12:44 - 2014-06-08 12:44 - 00000000 __SHD () C:\Users\AdminS\AppData\Local\EmieUserList
2014-06-08 12:44 - 2014-06-08 12:44 - 00000000 __SHD () C:\Users\AdminS\AppData\Local\EmieSiteList
2014-06-08 11:54 - 2014-06-08 12:42 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-08 11:54 - 2014-06-08 11:54 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-08 11:54 - 2014-06-08 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-08 11:54 - 2014-06-08 11:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-08 11:54 - 2014-06-08 11:54 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-08 11:54 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-08 11:54 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-08 11:54 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Sofie\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\sabin\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\micha\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\maya\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-05 21:49 - 2014-06-05 21:49 - 00009287 _____ () C:\ComboFix.txt
2014-06-05 21:34 - 2014-06-05 21:50 - 00000000 ____D () C:\Qoobox
2014-06-05 21:34 - 2014-06-05 21:44 - 00000000 ____D () C:\Windows\erdnt
2014-06-05 21:34 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-05 21:34 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-05 21:34 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-05 21:34 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-05 21:34 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-05 21:34 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-05 21:34 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-05 21:34 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-04 19:58 - 2014-06-04 19:58 - 00001224 _____ () C:\Users\AdminS\Desktop\Revo Uninstaller.lnk
2014-06-04 19:58 - 2014-06-04 19:58 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-04 19:55 - 2014-06-04 19:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\AdminS\Desktop\revosetup95.exe
2014-06-02 21:04 - 2014-06-04 20:57 - 00002278 _____ () C:\Users\AdminS\Desktop\Sicherer Zahlungsverkehr.lnk
2014-06-02 21:04 - 2014-06-02 21:04 - 00001096 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2014-06-02 21:04 - 2014-06-02 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-06-02 21:03 - 2014-06-04 20:38 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-02 21:03 - 2014-06-04 20:38 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-02 21:03 - 2014-06-02 21:03 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-06-02 21:03 - 2014-06-02 21:03 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-02 20:15 - 2014-06-08 13:58 - 00010671 _____ () C:\Users\AdminS\Desktop\FRST.txt
2014-06-02 20:15 - 2014-06-02 20:15 - 00024362 _____ () C:\Users\AdminS\Desktop\Addition.txt
2014-06-02 20:14 - 2014-06-08 13:58 - 00000000 ____D () C:\FRST
2014-06-02 19:24 - 2014-06-02 19:22 - 01058304 _____ (Farbar) C:\Users\AdminS\Desktop\FRST.exe
2014-05-30 10:51 - 2014-05-30 10:56 - 00033280 ___SH () C:\Users\Public\Thumbs.db
2014-05-29 23:15 - 2014-05-29 23:15 - 00000000 ____D () C:\aaavirus
2014-05-25 17:43 - 2014-05-25 17:44 - 00000000 ____D () C:\Users\micha\Downloads\KAZ
2014-05-18 21:05 - 2014-05-18 21:05 - 00008704 _____ () C:\Users\micha\Desktop\AG-Zuschuss.xls
2014-05-15 20:47 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 20:47 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 20:47 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 20:10 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 20:10 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 20:10 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 20:10 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 20:10 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 20:10 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 20:10 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 20:10 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 20:10 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 20:10 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-05-15 20:10 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 20:10 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 20:10 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 20:10 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 20:09 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-11 20:13 - 2014-05-11 20:13 - 00005871 _____ () C:\Users\micha\.recently-used.xbel
2014-05-11 20:07 - 2014-05-11 20:07 - 00000042 _____ () C:\Users\micha\.gtk-bookmarks
2014-05-11 18:19 - 2014-05-11 18:19 - 00000000 __SHD () C:\Users\micha\AppData\Local\EmieUserList
2014-05-11 18:19 - 2014-05-11 18:19 - 00000000 __SHD () C:\Users\micha\AppData\Local\EmieSiteList
2014-05-11 16:38 - 2014-05-11 16:38 - 00001141 _____ () C:\Users\AdminS\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2014-05-11 16:38 - 2014-05-11 16:38 - 00000000 ____D () C:\Program Files\Hosts_Anti_Adwares_PUPs
2014-05-11 16:28 - 2014-06-08 12:51 - 00000000 ____D () C:\AdwCleaner
2014-05-09 21:01 - 2014-05-11 16:01 - 00000063 _____ () C:\Users\AdminS\AppData\Roaming\WB.CFG
==================== One Month Modified Files and Folders =======
2014-06-08 13:58 - 2014-06-02 20:15 - 00010671 _____ () C:\Users\AdminS\Desktop\FRST.txt
2014-06-08 13:58 - 2014-06-02 20:14 - 00000000 ____D () C:\FRST
2014-06-08 13:58 - 2010-12-27 17:00 - 00000000 ____D () C:\Users\AdminS\AppData\Local\Temp
2014-06-08 13:50 - 2011-03-13 14:50 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-08 13:50 - 2010-12-27 17:16 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-08 13:50 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-08 13:50 - 2009-07-14 06:39 - 00080146 _____ () C:\Windows\setupact.log
2014-06-08 13:37 - 2010-12-27 16:47 - 01793984 _____ () C:\Windows\WindowsUpdate.log
2014-06-08 13:35 - 2014-06-08 13:35 - 00000874 _____ () C:\Users\AdminS\Desktop\JRT.txt
2014-06-08 13:32 - 2014-06-08 13:32 - 00000000 ____D () C:\Windows\ERUNT
2014-06-08 13:23 - 2009-07-14 06:34 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-08 13:23 - 2009-07-14 06:34 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-08 13:16 - 2011-03-13 14:50 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-08 12:55 - 2014-06-08 12:55 - 00002638 _____ () C:\Users\AdminS\Desktop\AdwCleaner[S1].txt
2014-06-08 12:53 - 2011-01-09 15:24 - 00255084 _____ () C:\Windows\PFRO.log
2014-06-08 12:51 - 2014-05-11 16:28 - 00000000 ____D () C:\AdwCleaner
2014-06-08 12:46 - 2014-06-08 12:46 - 00004316 _____ () C:\Users\AdminS\Desktop\mbam.txt
2014-06-08 12:44 - 2014-06-08 12:44 - 00000000 __SHD () C:\Users\AdminS\AppData\Local\EmieUserList
2014-06-08 12:44 - 2014-06-08 12:44 - 00000000 __SHD () C:\Users\AdminS\AppData\Local\EmieSiteList
2014-06-08 12:42 - 2014-06-08 11:54 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-08 12:20 - 2014-06-08 12:57 - 01016261 _____ (Thisisu) C:\Users\AdminS\Desktop\JRT.exe
2014-06-08 12:20 - 2012-01-21 15:33 - 00000000 ____D () C:\ProgramData\YouTube Downloader
2014-06-08 12:18 - 2014-06-08 12:48 - 01333465 _____ () C:\Users\AdminS\Desktop\adwcleaner_3.212.exe
2014-06-08 11:54 - 2014-06-08 11:54 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-08 11:54 - 2014-06-08 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-08 11:54 - 2014-06-08 11:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-08 11:54 - 2014-06-08 11:54 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Sofie\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\sabin\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\micha\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\maya\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:50 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-05 21:50 - 2014-06-05 21:34 - 00000000 ____D () C:\Qoobox
2014-06-05 21:50 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-06-05 21:50 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-06-05 21:49 - 2014-06-05 21:49 - 00009287 _____ () C:\ComboFix.txt
2014-06-05 21:44 - 2014-06-05 21:34 - 00000000 ____D () C:\Windows\erdnt
2014-06-05 21:43 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-06-04 20:57 - 2014-06-02 21:04 - 00002278 _____ () C:\Users\AdminS\Desktop\Sicherer Zahlungsverkehr.lnk
2014-06-04 20:46 - 2012-05-30 06:04 - 00000008 __RSH () C:\Users\micha\ntuser.pol
2014-06-04 20:46 - 2010-12-27 17:59 - 00000000 ____D () C:\Users\micha
2014-06-04 20:38 - 2014-06-02 21:03 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-04 20:38 - 2014-06-02 21:03 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-04 20:38 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2014-06-04 20:38 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2014-06-04 20:38 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2014-06-04 20:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-06-04 19:58 - 2014-06-04 19:58 - 00001224 _____ () C:\Users\AdminS\Desktop\Revo Uninstaller.lnk
2014-06-04 19:58 - 2014-06-04 19:58 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-04 19:53 - 2012-05-30 05:57 - 00000008 __RSH () C:\Users\AdminS\ntuser.pol
2014-06-04 19:53 - 2010-12-27 17:00 - 00000000 ____D () C:\Users\AdminS
2014-06-04 19:49 - 2009-07-14 04:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-04 19:48 - 2014-06-04 19:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\AdminS\Desktop\revosetup95.exe
2014-06-02 21:04 - 2014-06-02 21:04 - 00001096 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2014-06-02 21:04 - 2014-06-02 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-06-02 21:03 - 2014-06-02 21:03 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-06-02 21:03 - 2014-06-02 21:03 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-02 20:15 - 2014-06-02 20:15 - 00024362 _____ () C:\Users\AdminS\Desktop\Addition.txt
2014-06-02 19:22 - 2014-06-02 19:24 - 01058304 _____ (Farbar) C:\Users\AdminS\Desktop\FRST.exe
2014-05-30 11:10 - 2010-05-11 20:42 - 00000000 ____D () C:\Elster
2014-05-30 10:56 - 2014-05-30 10:51 - 00033280 ___SH () C:\Users\Public\Thumbs.db
2014-05-30 10:50 - 2011-05-26 21:22 - 00000000 ____D () C:\temp
2014-05-29 23:15 - 2014-05-29 23:15 - 00000000 ____D () C:\aaavirus
2014-05-29 15:39 - 2010-12-27 17:03 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-29 13:13 - 2013-11-02 19:09 - 00000000 ____D () C:\Users\micha\AppData\Roaming\TV-Browser
2014-05-27 18:39 - 2012-04-10 10:18 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-05-27 18:39 - 2011-09-07 09:40 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-05-25 17:44 - 2014-05-25 17:43 - 00000000 ____D () C:\Users\micha\Downloads\KAZ
2014-05-25 12:48 - 2012-10-25 19:20 - 00000680 __RSH () C:\Users\sabin\ntuser.pol
2014-05-25 12:48 - 2010-12-27 17:08 - 00000000 ____D () C:\Users\sabin
2014-05-22 15:06 - 2012-12-02 13:00 - 00000680 __RSH () C:\Users\Sofie\ntuser.pol
2014-05-22 15:06 - 2012-12-02 13:00 - 00000000 ____D () C:\Users\Sofie
2014-05-18 21:05 - 2014-05-18 21:05 - 00008704 _____ () C:\Users\micha\Desktop\AG-Zuschuss.xls
2014-05-16 20:40 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-05-16 20:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-16 19:46 - 2014-05-06 20:40 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 19:45 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-05-15 20:52 - 2013-10-06 17:16 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 20:49 - 2011-01-30 11:30 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-12 07:26 - 2014-06-08 11:54 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-08 11:54 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:25 - 2014-06-08 11:54 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 20:30 - 2011-02-13 10:22 - 00000000 ____D () C:\Users\micha\Documents\mibosoft
2014-05-11 20:14 - 2011-01-09 14:05 - 00000000 ____D () C:\Users\micha\.gimp-2.6
2014-05-11 20:13 - 2014-05-11 20:13 - 00005871 _____ () C:\Users\micha\.recently-used.xbel
2014-05-11 20:13 - 2011-01-17 20:07 - 00000000 ____D () C:\Users\micha\AppData\Roaming\gtk-2.0
2014-05-11 20:07 - 2014-05-11 20:07 - 00000042 _____ () C:\Users\micha\.gtk-bookmarks
2014-05-11 18:19 - 2014-05-11 18:19 - 00000000 __SHD () C:\Users\micha\AppData\Local\EmieUserList
2014-05-11 18:19 - 2014-05-11 18:19 - 00000000 __SHD () C:\Users\micha\AppData\Local\EmieSiteList
2014-05-11 16:55 - 2012-02-19 18:41 - 00000085 _____ () C:\Users\micha\Documents\adac.txt
2014-05-11 16:38 - 2014-05-11 16:38 - 00001141 _____ () C:\Users\AdminS\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2014-05-11 16:38 - 2014-05-11 16:38 - 00000000 ____D () C:\Program Files\Hosts_Anti_Adwares_PUPs
2014-05-11 16:01 - 2014-05-09 21:01 - 00000063 _____ () C:\Users\AdminS\AppData\Roaming\WB.CFG
2014-05-09 20:34 - 2013-12-30 17:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-05-09 09:06 - 2014-05-15 20:10 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 09:04 - 2014-05-15 20:10 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
Some content of TEMP:
====================
C:\Users\AdminS\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-06-02 20:55
==================== End Of Log ============================ --- --- ---
--- --- ---
Was meinst Du?
Grüße,
Mibo's |