Sorry....
Avira Code:
Avira Free Antivirus
Report file date: Samstag, 21. Juni 2014 11:48
The program is running as an unrestricted full version.
Online services are available.
Licensee : Avira Antivirus Free
Serial number : 0000149996-AVHOE-0000001
Platform : Windows 7 Home Premium
Windows version : (Service Pack 1) [6.1.7601]
Boot mode : Normally booted
Username : SYSTEM
Computer name : KATJA-PC
Version information:
BUILD.DAT : 14.0.4.672 91560 Bytes 27.05.2014 17:13:00
AVSCAN.EXE : 14.0.4.632 1030736 Bytes 27.05.2014 15:13:01
AVSCANRC.DLL : 14.0.4.620 52304 Bytes 27.05.2014 15:13:01
LUKE.DLL : 14.0.4.620 57936 Bytes 27.05.2014 15:13:04
AVSCPLR.DLL : 14.0.4.620 89680 Bytes 27.05.2014 15:13:01
AVREG.DLL : 14.0.4.632 261200 Bytes 27.05.2014 15:13:01
avlode.dll : 14.0.4.638 583760 Bytes 27.05.2014 15:13:01
avlode.rdf : 14.0.4.22 64276 Bytes 27.05.2014 15:13:01
XBV00008.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00009.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00010.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00011.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00012.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00013.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00014.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00015.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00016.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00017.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00018.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:17
XBV00019.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00020.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00021.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00022.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00023.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00024.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00025.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00026.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00027.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00028.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00029.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00030.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00031.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00032.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00033.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00034.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00035.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00036.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00037.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00038.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00039.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00040.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00041.VDF : 8.11.153.142 2048 Bytes 06.06.2014 08:47:18
XBV00096.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00097.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00098.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00099.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00100.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00101.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00102.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00103.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:26
XBV00104.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00105.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00106.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00107.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00108.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00109.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00110.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00111.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00112.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00113.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:27
XBV00114.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00115.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00116.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00117.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00118.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00119.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00120.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00121.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00122.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00123.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00124.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00125.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00126.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00127.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00128.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00129.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00130.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00131.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00132.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00133.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00134.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:28
XBV00135.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00136.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00137.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00138.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00139.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00140.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00141.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00142.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00143.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00144.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00145.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00146.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00147.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00148.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00149.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00150.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00151.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00152.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00153.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00154.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00155.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00156.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00157.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00158.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00159.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00160.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00161.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00162.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00163.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00164.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00165.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00166.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:29
XBV00167.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00168.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00169.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00170.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00171.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00172.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00173.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00174.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00175.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00176.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00177.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00178.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00179.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00180.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00181.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00182.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00183.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00184.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00185.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00186.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00187.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00188.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00189.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00190.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00191.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00192.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00193.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00194.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00195.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00196.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00197.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00198.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00199.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00200.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00201.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00202.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00203.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00204.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:30
XBV00205.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00206.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00207.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00208.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00209.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00210.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00211.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00212.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00213.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00214.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00215.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00216.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00217.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00218.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00219.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00220.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00221.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00222.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00223.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00224.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00225.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00226.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00227.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00228.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00229.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00230.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00231.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:31
XBV00232.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00233.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00234.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00235.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00236.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00237.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00238.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00239.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00240.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00241.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00242.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00243.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00244.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00245.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00246.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00247.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00248.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00249.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00250.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00251.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00252.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00253.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00254.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00255.VDF : 8.11.155.44 2048 Bytes 16.06.2014 08:47:32
XBV00000.VDF : 7.11.70.0 66736640 Bytes 04.04.2013 15:13:12
XBV00001.VDF : 7.11.74.226 2201600 Bytes 30.04.2013 15:13:12
XBV00002.VDF : 7.11.80.60 2751488 Bytes 28.05.2013 15:13:12
XBV00003.VDF : 7.11.85.214 2162688 Bytes 21.06.2013 15:13:12
XBV00004.VDF : 7.11.91.176 3903488 Bytes 23.07.2013 15:13:12
XBV00005.VDF : 7.11.98.186 6822912 Bytes 29.08.2013 15:13:12
XBV00006.VDF : 7.11.139.38 15708672 Bytes 27.03.2014 08:47:11
XBV00007.VDF : 7.11.152.100 4193792 Bytes 02.06.2014 08:47:17
XBV00042.VDF : 8.11.153.142 710656 Bytes 06.06.2014 08:47:19
XBV00043.VDF : 8.11.155.44 1013760 Bytes 16.06.2014 08:47:21
XBV00044.VDF : 8.11.155.46 3072 Bytes 16.06.2014 08:47:21
XBV00045.VDF : 8.11.155.52 38912 Bytes 16.06.2014 08:47:21
XBV00046.VDF : 8.11.155.54 29696 Bytes 16.06.2014 08:47:22
XBV00047.VDF : 8.11.155.58 13824 Bytes 16.06.2014 08:47:22
XBV00048.VDF : 8.11.155.62 20480 Bytes 17.06.2014 08:47:22
XBV00049.VDF : 8.11.155.64 5632 Bytes 17.06.2014 08:47:22
XBV00050.VDF : 8.11.155.66 139264 Bytes 17.06.2014 08:47:22
XBV00051.VDF : 8.11.155.68 2048 Bytes 17.06.2014 08:47:22
XBV00052.VDF : 8.11.155.70 6144 Bytes 17.06.2014 08:47:22
XBV00053.VDF : 8.11.155.74 180224 Bytes 17.06.2014 08:47:23
XBV00054.VDF : 8.11.155.78 18432 Bytes 17.06.2014 08:47:23
XBV00055.VDF : 8.11.155.80 6144 Bytes 17.06.2014 08:47:23
XBV00056.VDF : 8.11.155.82 4608 Bytes 18.06.2014 08:47:23
XBV00057.VDF : 8.11.155.86 17408 Bytes 18.06.2014 08:47:23
XBV00058.VDF : 8.11.155.100 144896 Bytes 18.06.2014 08:47:23
XBV00059.VDF : 8.11.155.114 25088 Bytes 18.06.2014 08:47:23
XBV00060.VDF : 8.11.155.128 2048 Bytes 18.06.2014 08:47:23
XBV00061.VDF : 8.11.155.146 27648 Bytes 18.06.2014 08:47:23
XBV00062.VDF : 8.11.155.148 2048 Bytes 18.06.2014 08:47:23
XBV00063.VDF : 8.11.155.150 148992 Bytes 18.06.2014 08:47:24
XBV00064.VDF : 8.11.155.152 5120 Bytes 18.06.2014 08:47:24
XBV00065.VDF : 8.11.155.156 12800 Bytes 18.06.2014 08:47:24
XBV00066.VDF : 8.11.155.158 2048 Bytes 18.06.2014 08:47:24
XBV00067.VDF : 8.11.155.160 2048 Bytes 18.06.2014 08:47:24
XBV00068.VDF : 8.11.155.164 7680 Bytes 18.06.2014 08:47:24
XBV00069.VDF : 8.11.155.168 18432 Bytes 19.06.2014 08:47:24
XBV00070.VDF : 8.11.155.172 2048 Bytes 19.06.2014 08:47:24
XBV00071.VDF : 8.11.155.174 7680 Bytes 19.06.2014 08:47:24
XBV00072.VDF : 8.11.155.176 2048 Bytes 19.06.2014 08:47:24
XBV00073.VDF : 8.11.155.178 7680 Bytes 19.06.2014 08:47:24
XBV00074.VDF : 8.11.155.180 5120 Bytes 19.06.2014 08:47:24
XBV00075.VDF : 8.11.155.182 4608 Bytes 19.06.2014 08:47:24
XBV00076.VDF : 8.11.155.184 6144 Bytes 19.06.2014 08:47:24
XBV00077.VDF : 8.11.155.186 4608 Bytes 19.06.2014 08:47:24
XBV00078.VDF : 8.11.155.188 5632 Bytes 19.06.2014 08:47:25
XBV00079.VDF : 8.11.155.190 5120 Bytes 19.06.2014 08:47:25
XBV00080.VDF : 8.11.155.192 2048 Bytes 19.06.2014 08:47:25
XBV00081.VDF : 8.11.155.196 17408 Bytes 19.06.2014 08:47:25
XBV00082.VDF : 8.11.155.200 2048 Bytes 19.06.2014 08:47:25
XBV00083.VDF : 8.11.155.202 5632 Bytes 20.06.2014 08:47:25
XBV00084.VDF : 8.11.155.204 14848 Bytes 20.06.2014 08:47:25
XBV00085.VDF : 8.11.155.206 3072 Bytes 20.06.2014 08:47:25
XBV00086.VDF : 8.11.155.208 2048 Bytes 20.06.2014 08:47:25
XBV00087.VDF : 8.11.155.210 11264 Bytes 20.06.2014 08:47:26
XBV00088.VDF : 8.11.155.214 4608 Bytes 20.06.2014 08:47:26
XBV00089.VDF : 8.11.155.218 8704 Bytes 20.06.2014 08:47:26
XBV00090.VDF : 8.11.155.222 2048 Bytes 20.06.2014 08:47:26
XBV00091.VDF : 8.11.155.224 2048 Bytes 20.06.2014 08:47:26
XBV00092.VDF : 8.11.155.228 151552 Bytes 20.06.2014 08:47:26
XBV00093.VDF : 8.11.155.242 13312 Bytes 21.06.2014 08:47:26
XBV00094.VDF : 8.11.156.2 12800 Bytes 21.06.2014 08:47:26
XBV00095.VDF : 8.11.156.4 58368 Bytes 21.06.2014 08:47:26
LOCAL000.VDF : 8.11.156.4 106779136 Bytes 21.06.2014 08:48:53
Engine version : 8.3.20.10
AEVDF.DLL : 8.3.0.4 118976 Bytes 27.05.2014 15:13:00
AESCRIPT.DLL : 8.1.4.212 528584 Bytes 21.06.2014 08:46:39
AESCN.DLL : 8.3.1.2 135360 Bytes 21.06.2014 08:46:39
AESBX.DLL : 8.2.20.24 1409224 Bytes 27.05.2014 15:13:00
AERDL.DLL : 8.2.0.138 704888 Bytes 27.05.2014 15:13:00
AEPACK.DLL : 8.4.0.24 778440 Bytes 27.05.2014 15:13:00
AEOFFICE.DLL : 8.3.0.4 205000 Bytes 27.05.2014 15:13:00
AEHEUR.DLL : 8.1.4.1112 6738120 Bytes 21.06.2014 08:46:38
AEHELP.DLL : 8.3.1.0 278728 Bytes 21.06.2014 08:46:32
AEGEN.DLL : 8.1.7.28 450752 Bytes 21.06.2014 08:46:32
AEEXP.DLL : 8.4.2.2 237760 Bytes 21.06.2014 08:46:39
AEEMU.DLL : 8.1.3.2 393587 Bytes 27.05.2014 15:13:00
AEDROID.DLL : 8.4.2.24 442568 Bytes 21.06.2014 08:46:40
AECORE.DLL : 8.3.1.4 241864 Bytes 21.06.2014 08:46:32
AEBB.DLL : 8.1.1.4 53619 Bytes 27.05.2014 15:13:00
AVWINLL.DLL : 14.0.4.620 24144 Bytes 27.05.2014 15:13:01
AVPREF.DLL : 14.0.4.632 50256 Bytes 27.05.2014 15:13:01
AVREP.DLL : 14.0.4.620 219216 Bytes 27.05.2014 15:13:01
AVARKT.DLL : 14.0.4.632 225872 Bytes 27.05.2014 15:13:00
AVEVTLOG.DLL : 14.0.4.620 182352 Bytes 27.05.2014 15:13:00
SQLITE3.DLL : 14.0.4.620 452176 Bytes 27.05.2014 15:13:10
AVSMTP.DLL : 14.0.4.620 76368 Bytes 27.05.2014 15:13:01
NETNT.DLL : 14.0.4.620 13392 Bytes 27.05.2014 15:13:04
RCIMAGE.DLL : 14.0.4.620 4980816 Bytes 27.05.2014 15:13:05
RCTEXT.DLL : 14.0.4.620 73296 Bytes 27.05.2014 15:13:07
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Program Files (x86)\Avira\AntiVir Desktop\sysscan.avp
Reporting...........................: default
Primary action......................: Interactive
Secondary action....................: Ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, E:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Limit recursion depth...............: 20
Smart extensions....................: on
Macrovirus heuristic................: on
File heuristic......................: extended
Start of the scan: Samstag, 21. Juni 2014 11:48
Start scanning boot sectors:
Boot sector 'HDD0(C:, E:)'
[INFO] No virus was found!
Boot sector 'HDD1(D:)'
[INFO] No virus was found!
Starting search for hidden objects.
The scan of running processes will be started:
Scan process 'svchost.exe' - '53' Module(s) have been scanned
Scan process 'nvvsvc.exe' - '36' Module(s) have been scanned
Scan process 'svchost.exe' - '37' Module(s) have been scanned
Scan process 'MsMpEng.exe' - '83' Module(s) have been scanned
Scan process 'svchost.exe' - '90' Module(s) have been scanned
Scan process 'svchost.exe' - '116' Module(s) have been scanned
Scan process 'svchost.exe' - '85' Module(s) have been scanned
Scan process 'svchost.exe' - '154' Module(s) have been scanned
Scan process 'WTabletServiceCon.exe' - '30' Module(s) have been scanned
Scan process 'svchost.exe' - '76' Module(s) have been scanned
Scan process 'NvXDSync.exe' - '46' Module(s) have been scanned
Scan process 'nvvsvc.exe' - '68' Module(s) have been scanned
Scan process 'WLANExt.exe' - '35' Module(s) have been scanned
Scan process 'conhost.exe' - '17' Module(s) have been scanned
Scan process 'spoolsv.exe' - '86' Module(s) have been scanned
Scan process 'taskeng.exe' - '29' Module(s) have been scanned
Scan process 'sched.exe' - '60' Module(s) have been scanned
Scan process 'svchost.exe' - '63' Module(s) have been scanned
Scan process 'armsvc.exe' - '29' Module(s) have been scanned
Scan process 'avguard.exe' - '107' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '70' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '36' Module(s) have been scanned
Scan process 'taskeng.exe' - '32' Module(s) have been scanned
Scan process 'btwdins.exe' - '51' Module(s) have been scanned
Scan process 'Dwm.exe' - '37' Module(s) have been scanned
Scan process 'FABS.exe' - '33' Module(s) have been scanned
Scan process 'taskhost.exe' - '56' Module(s) have been scanned
Scan process 'svchost.exe' - '61' Module(s) have been scanned
Scan process 'NBService.exe' - '43' Module(s) have been scanned
Scan process 'ccSvcHst.exe' - '154' Module(s) have been scanned
Scan process 'ccSvcHst.exe' - '92' Module(s) have been scanned
Scan process 'Explorer.EXE' - '161' Module(s) have been scanned
Scan process 'NOBuAgent.exe' - '31' Module(s) have been scanned
Scan process 'rndlresolversvc.exe' - '26' Module(s) have been scanned
Scan process 'RichVideo.exe' - '29' Module(s) have been scanned
Scan process 'SDFSSvc.exe' - '112' Module(s) have been scanned
Scan process 'taskeng.exe' - '31' Module(s) have been scanned
Scan process 'YCMMirage.exe' - '42' Module(s) have been scanned
Scan process 'dmhkcore.exe' - '60' Module(s) have been scanned
Scan process 'WifiManager.exe' - '48' Module(s) have been scanned
Scan process 'avshadow.exe' - '35' Module(s) have been scanned
Scan process 'SDUpdSvc.exe' - '74' Module(s) have been scanned
Scan process 'Avira.OE.ServiceHost.exe' - '141' Module(s) have been scanned
Scan process 'SDWSCSvc.exe' - '62' Module(s) have been scanned
Scan process 'NisSrv.exe' - '35' Module(s) have been scanned
Scan process 'svchost.exe' - '36' Module(s) have been scanned
Scan process 'svchost.exe' - '38' Module(s) have been scanned
Scan process 'rundll32.exe' - '29' Module(s) have been scanned
Scan process 'WUDFHost.exe' - '35' Module(s) have been scanned
Scan process 'RAVCpl64.exe' - '47' Module(s) have been scanned
Scan process 'WCScheduler.exe' - '63' Module(s) have been scanned
Scan process 'ETDCtrl.exe' - '58' Module(s) have been scanned
Scan process 'Pen_TabletUser.exe' - '26' Module(s) have been scanned
Scan process 'WacomHost.exe' - '39' Module(s) have been scanned
Scan process 'BJMYPRT.EXE' - '26' Module(s) have been scanned
Scan process 'msseces.exe' - '54' Module(s) have been scanned
Scan process 'Pen_Tablet.exe' - '57' Module(s) have been scanned
Scan process 'Pen_TouchUser.exe' - '37' Module(s) have been scanned
Scan process 'NMBgMonitor.exe' - '61' Module(s) have been scanned
Scan process 'SmartRestarter.exe' - '36' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '55' Module(s) have been scanned
Scan process 'AmazonMP3DownloaderHelper.exe' - '48' Module(s) have been scanned
Scan process 'BTTray.exe' - '64' Module(s) have been scanned
Scan process 'CNSEMAIN.EXE' - '64' Module(s) have been scanned
Scan process 'NMIndexingService.exe' - '49' Module(s) have been scanned
Scan process 'NMIndexStoreSvr.exe' - '64' Module(s) have been scanned
Scan process 'ETDCtrlHelper.exe' - '29' Module(s) have been scanned
Scan process 'AdobeARM.exe' - '73' Module(s) have been scanned
Scan process 'realsched.exe' - '41' Module(s) have been scanned
Scan process 'BambooCore.exe' - '52' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '79' Module(s) have been scanned
Scan process 'SDTray.exe' - '117' Module(s) have been scanned
Scan process 'Avira.OE.Systray.exe' - '140' Module(s) have been scanned
Scan process 'svchost.exe' - '55' Module(s) have been scanned
Scan process 'RunDll32.exe' - '38' Module(s) have been scanned
Scan process 'avgnt.exe' - '101' Module(s) have been scanned
Scan process 'BtStackServer.exe' - '70' Module(s) have been scanned
Scan process 'iPodService.exe' - '34' Module(s) have been scanned
Scan process 'BluetoothHeadsetProxy.exe' - '24' Module(s) have been scanned
Scan process 'MovieColorEnhancer.exe' - '48' Module(s) have been scanned
Scan process 'splwow64.exe' - '36' Module(s) have been scanned
Scan process 'SSCKbdHk.exe' - '34' Module(s) have been scanned
Scan process 'igfxext.exe' - '26' Module(s) have been scanned
Scan process 'igfxsrvc.exe' - '30' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '124' Module(s) have been scanned
Scan process 'LMS.exe' - '34' Module(s) have been scanned
Scan process 'daemonu.exe' - '47' Module(s) have been scanned
Scan process 'SUPBackground.exe' - '65' Module(s) have been scanned
Scan process 'svchost.exe' - '51' Module(s) have been scanned
Scan process 'brs.exe' - '27' Module(s) have been scanned
Scan process 'CLMLSvc.exe' - '41' Module(s) have been scanned
Scan process 'PDVD10Serv.exe' - '32' Module(s) have been scanned
Scan process 'SeaPort.EXE' - '60' Module(s) have been scanned
Scan process 'WLIDSVC.EXE' - '77' Module(s) have been scanned
Scan process 'hkcmd.exe' - '55' Module(s) have been scanned
Scan process 'igfxtray.exe' - '30' Module(s) have been scanned
Scan process 'igfxpers.exe' - '50' Module(s) have been scanned
Scan process 'WLIDSvcM.exe' - '18' Module(s) have been scanned
Scan process 'EasySpeedUpManager.exe' - '39' Module(s) have been scanned
Scan process 'UNS.exe' - '46' Module(s) have been scanned
Scan process 'avcenter.exe' - '130' Module(s) have been scanned
Scan process 'avscan.exe' - '130' Module(s) have been scanned
Scan process 'vssvc.exe' - '48' Module(s) have been scanned
Scan process 'svchost.exe' - '29' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '39' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Scan process 'csrss.exe' - '18' Module(s) have been scanned
Scan process 'wininit.exe' - '27' Module(s) have been scanned
Scan process 'csrss.exe' - '18' Module(s) have been scanned
Scan process 'services.exe' - '34' Module(s) have been scanned
Scan process 'lsass.exe' - '67' Module(s) have been scanned
Scan process 'lsm.exe' - '16' Module(s) have been scanned
Scan process 'winlogon.exe' - '32' Module(s) have been scanned
Starting to scan executable files (registry):
The registry was scanned ( '4568' files ).
Starting the file scan:
Begin scan in 'C:\'
Begin scan in 'D:\' <2ndHDD>
Begin scan in 'E:\'
End of the scan: Samstag, 21. Juni 2014 15:50
Used time: 4:02:38 Hour(s)
The scan has been done completely.
46061 Scanned directories
1045901 Files were scanned
0 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 Files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
1045901 Files not concerned
15350 Archives were scanned
0 Warnings
0 Notes
1084843 Objects were scanned with rootkit scan
0 Hidden objects were found Avira Stinger Code:
McAfee® Labs Stinger™ Version 12.1.0.959 built on Jun 20 2014 at 12:31:00
Copyright© 2014, McAfee, Inc. All Rights Reserved.
AV Engine version v5700.7147 for Windows.
Virus data file v1000.0 created on Jun 20, 2014
Ready to scan for 6349 viruses, trojans and variants.
Custom scan initiated on Samstag, Juni 21, 2014 15:59:22
Rootkit scan result : Clean.
Summary Report on C:
D:
File(s)
TotalFiles:............ 1756858
Clean:................. 308742
Not Scanned:........... 1448116
Possibly Infected:..... 0
Time: 03:14:13
Scan completed on Samstag, Juni 21, 2014 19:13:35 SpyBot Code:
Search results from Spybot - Search & Destroy
6/21/2014 9:34:34 AM
Scan took 00:22:21.
208 items found.
Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Katja\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ATT8PLL2\4-seasons.tv\com.jeroenwijering.sol
Properties.size=53
Properties.md5=496E14B262EB0664AF09BB24355AADF6
Properties.filedate=1402858156
Properties.filedatetext=2014-06-15 20:49:16
Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Katja\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ATT8PLL2\a.vimeocdn.com\com.conviva.livePass.sol
Properties.size=225
Properties.md5=28FD5D25C61BEC2F5E90B42BE47AE4DA
Properties.filedate=1381778448
Properties.filedatetext=2013-10-14 21:20:47
Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Katja\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ATT8PLL2\admin.brightcove.com\analytics.sol
Properties.size=419
Properties.md5=9BE70FD0DC07F4C5840538F2CC7E03FC
Properties.filedate=1391634150
Properties.filedatetext=2014-02-05 23:02:30
Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Katja\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ATT8PLL2\aka-cdn-ns.adtech.de\movad.sol
Properties.size=67
Properties.md5=F9DA390D7634AEF67A5EC567FDD80313
Properties.filedate=1397502019
Properties.filedatetext=2014-04-14 21:00:19
Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Katja\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ATT8PLL2\art.aim4media.com\analytics.sol
Properties.size=257
Properties.md5=0F1B64EFA77F0AEDACA8FB38FFC97194
Properties.filedate=1392495357
Properties.filedatetext=2014-02-15 22:15:57 Malwarebytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.06.2014
Suchlauf-Zeit: 12:20:29
Logdatei: Malwarebytes 22.06.14.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.22.01
Rootkit Datenbank: v2014.06.20.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Katja
Suchlauf-Art: Benutzerdefinierter Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 618131
Verstrichene Zeit: 2 Std, 43 Min, 12 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 2
PUP.Optional.OpenCandy, C:\Users\Katja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHNOB02V\stubinst_pkg_de[1].cab, In Quarantäne, [0772542795e60f27ec2c198d1aea10f0],
PUP.Optional.OpenCandy, C:\Users\Katja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VAWDSA3A\stubinst_pkg_de[1].cab, In Quarantäne, [0772116ad9a25adcf22605a17b89e818],
Physische Sektoren: 0
(No malicious items detected)
(end) Gmer Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-22 11:59:04
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.2AR1 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Katja\AppData\Local\Temp\ugloqpow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80003204000 33 bytes [00, 00, 20, 00, 53, 4E, 44, ...]
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 562 fffff80003204022 89 bytes [01, 07, 80, FA, FF, FF, E8, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2152] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2152] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2644] C:\windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2644] C:\windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5580] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5580] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[4088] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[4088] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Users\Katja\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe[4560] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Users\Katja\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe[4560] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE[7100] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE[7100] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[6228] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[6228] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Program Files (x86)\Bamboo Dock\BambooCore.exe[3496] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\Bamboo Dock\BambooCore.exe[3496] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[732] C:\windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[732] C:\windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
.text C:\windows\SysWOW64\RunDll32.exe[5564] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75]
.text C:\windows\SysWOW64\RunDll32.exe[5564] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\windows\SysWOW64\ntdll.dll [2412:2416] 000000000041009c
Thread C:\windows\SysWOW64\ntdll.dll [2412:5972] 00000000608ae21c
Thread C:\windows\SysWOW64\ntdll.dll [2412:5896] 000000006be03a2a
Thread C:\windows\SysWOW64\ntdll.dll [2412:3176] 000000006e7c8f59
Thread C:\windows\SysWOW64\ntdll.dll [2412:6204] 000000006e1d2238
Thread C:\windows\SysWOW64\ntdll.dll [2412:6208] 000000006e1d2238
Thread C:\windows\SysWOW64\ntdll.dll [2412:6212] 000000006e1d2238
Thread C:\windows\SysWOW64\ntdll.dll [2412:6216] 000000006e744b0d
Thread C:\windows\SysWOW64\ntdll.dll [2412:4476] 0000000074c01854
Thread C:\windows\SysWOW64\ntdll.dll [2412:3568] 00000000608bd23d
Thread C:\windows\SysWOW64\ntdll.dll [2412:4500] 00000000608b6720
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00006b0289b0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001bb1f85207
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\90a4de9c9a4b
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00006b0289b0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001bb1f85207 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\90a4de9c9a4b (not active ControlSet)
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2014 01
Ran by Katja (administrator) on KATJA-PC on 22-06-2014 11:34:04
Running from C:\Users\Katja\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccsvchst.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe
() C:\Users\Katja\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
() C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccsvchst.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corp.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-25] (CANON INC.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Video_deluxe_17_Download-Version\Trayserver.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [619008 2010-05-25] (Nikon Corporation)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [295512 2013-09-06] (RealNetworks, Inc.)
HKLM-x32\...\Run: [BambooCore] => C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2774599765-3218687334-1828580283-1002\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-10-15] (Nero AG)
HKU\S-1-5-21-2774599765-3218687334-1828580283-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Katja\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-2774599765-3218687334-1828580283-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-10-15] (Nero AG)
HKU\S-1-5-21-2774599765-3218687334-1828580283-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Katja\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [226920 2011-01-17] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [192616 2011-01-17] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\wx6r2fgg.default
FF Homepage: https://www.facebook.com/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Katja\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Yahoo! Toolbar - C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\wx6r2fgg.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2014-06-12]
FF Extension: 4or6 - C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\wx6r2fgg.default\Extensions\4or6@hunen.net.xpi [2013-09-15]
FF Extension: Pin It button - C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\wx6r2fgg.default\Extensions\pinterest@robertnyman.com.xpi [2013-10-09]
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFF
FF Extension: Symantec Intrusion Prevention - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFF [2013-10-09]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 [2014-06-22]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-06]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-06]
Chrome:
=======
CHR HomePage: hxxp://samsung.msn.com/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL No File
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility) - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Extension: (Google Docs) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-20]
CHR Extension: (Google Drive) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-20]
CHR Extension: (YouTube) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-20]
CHR Extension: (Google Search) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-20]
CHR Extension: (RealDownloader) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-07-08]
CHR Extension: (Word CaptureX Extension) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjdepfkicdcciagbigfcmdhknnoaaegf [2013-05-20]
CHR Extension: (Google Wallet) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-12]
CHR Extension: (Gmail) - C:\Users\Katja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-20]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM-x32\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Deskperience\Word Capture\wcxChrome.crx [2010-07-23]
==================== Services (Whitelisted) =================
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-10-15] (Nero AG)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2011-09-01] () [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-11-14] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20140606.001\BHDrvx64.sys [1530160 2014-05-10] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-06-11] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142128 2014-06-11] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20140620.001\IDSvia64.sys [525016 2014-03-22] (Symantec Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-22] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20140621.001\ENG64.SYS [126040 2014-01-19] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20140621.001\EX64.SYS [2099288 2014-01-19] (Symantec Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1207020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1207020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1207020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1207020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2013-02-27] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [171128 2011-01-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-22 11:34 - 2014-06-22 11:34 - 00028137 _____ () C:\Users\Katja\Downloads\FRST.txt
2014-06-22 11:33 - 2014-06-22 11:34 - 00000000 ____D () C:\FRST
2014-06-22 11:33 - 2014-06-22 11:33 - 02083328 _____ (Farbar) C:\Users\Katja\Downloads\FRST64.exe
2014-06-22 09:43 - 2014-06-22 11:29 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-22 09:43 - 2014-06-22 09:43 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-22 09:43 - 2014-06-22 09:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-22 09:43 - 2014-06-22 09:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 09:43 - 2014-06-22 09:43 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-22 09:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-06-22 09:43 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-06-22 09:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-06-22 09:42 - 2014-06-22 09:42 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Katja\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-21 19:18 - 2014-06-21 19:18 - 00000114 ___RH () C:\Users\Katja\Downloads\Stinger.opt
2014-06-21 15:56 - 2014-06-21 15:56 - 00000000 ____D () C:\OETemp
2014-06-21 15:56 - 2014-06-21 15:56 - 00000000 _____ () C:\ProgramData\rebootpending.txt
2014-06-21 10:39 - 2014-06-21 15:56 - 00000000 ____D () C:\ProgramData\Avira
2014-06-21 10:39 - 2014-06-21 15:56 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-06-21 09:59 - 2014-06-21 09:59 - 00000000 ____D () C:\Users\Katja\AppData\Roaming\com.adobe.example.samsung-computer
2014-06-21 09:43 - 2014-06-21 09:43 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-06-21 09:43 - 2014-06-21 09:43 - 00001912 _____ () C:\windows\epplauncher.mif
2014-06-21 09:43 - 2014-06-21 09:43 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-06-21 09:43 - 2014-06-21 09:43 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-06-21 09:42 - 2014-06-21 09:42 - 00000000 ____D () C:\Users\Katja\Downloads\mse-install45
2014-06-21 09:41 - 2014-06-21 09:42 - 24625644 _____ () C:\Users\Katja\Downloads\mse-install45.zip
2014-06-21 09:07 - 2014-06-21 09:07 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking
2014-06-21 09:06 - 2014-06-21 09:12 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-21 09:06 - 2014-06-21 09:08 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-21 09:06 - 2014-06-21 09:06 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-21 09:06 - 2014-06-21 09:06 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-21 09:06 - 2014-06-21 09:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-21 09:06 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe
2014-06-21 09:05 - 2014-06-21 09:05 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Katja\Downloads\spybot-2.3.exe
2014-06-21 08:38 - 2014-06-21 08:38 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-21 05:33 - 2014-06-21 05:33 - 06010880 _____ () C:\Program Files (x86)\GUT29BB.tmp
2014-06-21 05:33 - 2014-06-21 05:33 - 00000000 ____D () C:\Program Files (x86)\GUM29BA.tmp
2014-06-20 19:12 - 2014-06-20 19:11 - 00177680 _____ (McAfee, Inc.) C:\windows\system32\mfevtps.exe.cb79.deleteme
2014-06-20 18:56 - 2014-06-21 19:18 - 00000000 ____D () C:\Program Files\stinger
2014-06-20 18:56 - 2014-06-20 18:56 - 00177680 _____ (McAfee, Inc.) C:\windows\system32\mfevtps.exe.9332.deleteme
2014-06-20 18:53 - 2014-06-20 18:53 - 00000000 __SHD () C:\Users\Katja\AppData\Local\EmieUserList
2014-06-20 18:53 - 2014-06-20 18:53 - 00000000 __SHD () C:\Users\Katja\AppData\Local\EmieSiteList
2014-06-20 18:44 - 2014-06-20 18:45 - 00000000 ____D () C:\NPE
2014-06-20 18:43 - 2014-06-20 18:54 - 00000000 ____D () C:\Users\Katja\AppData\Local\NPE
2014-06-12 18:52 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2014-06-12 18:52 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2014-06-12 18:52 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-12 18:52 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 18:52 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-12 18:52 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-12 18:52 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-12 18:52 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-12 18:52 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2014-06-12 18:52 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-12 18:52 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2014-06-12 18:52 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2014-06-12 18:51 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-12 18:51 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-12 18:51 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-12 18:51 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-12 18:51 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-12 18:51 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-12 18:51 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-12 18:51 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-12 18:51 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-12 18:51 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-12 18:51 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-12 18:51 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-12 18:51 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-12 18:51 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-12 18:51 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-12 18:51 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-12 18:51 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-12 18:51 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-12 18:51 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 18:51 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-12 18:51 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-12 18:51 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-06-12 18:51 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-12 18:51 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-12 18:51 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-12 18:51 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-12 18:51 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-12 18:51 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-12 18:51 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-12 18:51 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-06-12 18:51 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-12 18:51 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-06-12 18:51 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-06-12 18:51 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-12 18:51 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-12 18:51 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-12 18:51 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 18:51 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-12 18:51 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-12 18:51 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-12 18:51 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-12 18:51 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-12 18:51 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-12 18:51 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-12 18:51 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-12 18:51 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-12 18:51 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-12 18:51 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-12 18:51 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-12 18:51 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-12 18:51 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-12 18:51 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-06-12 18:48 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-12 18:48 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-11 19:30 - 2014-06-11 19:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-11 19:03 - 2014-06-11 19:03 - 07290267 _____ () C:\Users\Katja\Downloads\pss110-v1020-win-1.zip
==================== One Month Modified Files and Folders =======
2014-06-22 11:34 - 2014-06-22 11:34 - 00028137 _____ () C:\Users\Katja\Downloads\FRST.txt
2014-06-22 11:34 - 2014-06-22 11:33 - 00000000 ____D () C:\FRST
2014-06-22 11:33 - 2014-06-22 11:33 - 02083328 _____ (Farbar) C:\Users\Katja\Downloads\FRST64.exe
2014-06-22 11:32 - 2013-05-20 18:35 - 00001108 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-22 11:30 - 2013-05-20 18:35 - 00001104 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-22 11:29 - 2014-06-22 09:43 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-22 10:17 - 2011-07-21 03:10 - 02019227 _____ () C:\windows\WindowsUpdate.log
2014-06-22 10:11 - 2009-07-14 06:45 - 00020992 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-22 10:11 - 2009-07-14 06:45 - 00020992 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-22 10:02 - 2010-11-21 05:47 - 00246762 _____ () C:\windows\PFRO.log
2014-06-22 10:02 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-22 10:02 - 2009-07-14 06:51 - 00085885 _____ () C:\windows\setupact.log
2014-06-22 10:02 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\security
2014-06-22 09:43 - 2014-06-22 09:43 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-22 09:43 - 2014-06-22 09:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-22 09:43 - 2014-06-22 09:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 09:43 - 2014-06-22 09:43 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-22 09:42 - 2014-06-22 09:42 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Katja\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-21 22:55 - 2013-02-26 22:35 - 00000020 ____H () C:\ProgramData\PKP_DLbw.DAT
2014-06-21 22:55 - 2013-02-26 22:32 - 00000020 ____H () C:\ProgramData\PKP_DLbx.DAT
2014-06-21 22:55 - 2013-02-26 22:06 - 00000020 ____H () C:\ProgramData\PKP_DLbz.DAT
2014-06-21 19:18 - 2014-06-21 19:18 - 00000114 ___RH () C:\Users\Katja\Downloads\Stinger.opt
2014-06-21 19:18 - 2014-06-20 18:56 - 00000000 ____D () C:\Program Files\stinger
2014-06-21 15:56 - 2014-06-21 15:56 - 00000000 ____D () C:\OETemp
2014-06-21 15:56 - 2014-06-21 15:56 - 00000000 _____ () C:\ProgramData\rebootpending.txt
2014-06-21 15:56 - 2014-06-21 10:39 - 00000000 ____D () C:\ProgramData\Avira
2014-06-21 15:56 - 2014-06-21 10:39 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-06-21 09:59 - 2014-06-21 09:59 - 00000000 ____D () C:\Users\Katja\AppData\Roaming\com.adobe.example.samsung-computer
2014-06-21 09:58 - 2013-12-15 17:44 - 00000000 ____D () C:\Users\Katja\Downloads\Adobe
2014-06-21 09:43 - 2014-06-21 09:43 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-06-21 09:43 - 2014-06-21 09:43 - 00001912 _____ () C:\windows\epplauncher.mif
2014-06-21 09:43 - 2014-06-21 09:43 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-06-21 09:43 - 2014-06-21 09:43 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-06-21 09:42 - 2014-06-21 09:42 - 00000000 ____D () C:\Users\Katja\Downloads\mse-install45
2014-06-21 09:42 - 2014-06-21 09:41 - 24625644 _____ () C:\Users\Katja\Downloads\mse-install45.zip
2014-06-21 09:12 - 2014-06-21 09:06 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-21 09:08 - 2014-06-21 09:06 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-21 09:07 - 2014-06-21 09:07 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking
2014-06-21 09:06 - 2014-06-21 09:06 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-21 09:06 - 2014-06-21 09:06 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-21 09:06 - 2014-06-21 09:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-21 09:05 - 2014-06-21 09:05 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Katja\Downloads\spybot-2.3.exe
2014-06-21 08:38 - 2014-06-21 08:38 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-21 08:26 - 2013-05-20 18:35 - 00003852 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-21 05:33 - 2014-06-21 05:33 - 06010880 _____ () C:\Program Files (x86)\GUT29BB.tmp
2014-06-21 05:33 - 2014-06-21 05:33 - 00000000 ____D () C:\Program Files (x86)\GUM29BA.tmp
2014-06-20 19:11 - 2014-06-20 19:12 - 00177680 _____ (McAfee, Inc.) C:\windows\system32\mfevtps.exe.cb79.deleteme
2014-06-20 18:56 - 2014-06-20 18:56 - 00177680 _____ (McAfee, Inc.) C:\windows\system32\mfevtps.exe.9332.deleteme
2014-06-20 18:54 - 2014-06-20 18:43 - 00000000 ____D () C:\Users\Katja\AppData\Local\NPE
2014-06-20 18:53 - 2014-06-20 18:53 - 00000000 __SHD () C:\Users\Katja\AppData\Local\EmieUserList
2014-06-20 18:53 - 2014-06-20 18:53 - 00000000 __SHD () C:\Users\Katja\AppData\Local\EmieSiteList
2014-06-20 18:45 - 2014-06-20 18:44 - 00000000 ____D () C:\NPE
2014-06-20 18:43 - 2011-07-20 11:33 - 00000000 ____D () C:\ProgramData\Norton
2014-06-17 18:34 - 2013-02-28 22:49 - 00000000 ____D () C:\Users\Katja\Documents\Urlaub
2014-06-16 23:56 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache
2014-06-15 14:48 - 2014-04-12 14:48 - 00000000 ____D () C:\Users\Katja\Downloads\KTP Birds 2008
2014-06-15 11:33 - 2013-05-20 18:36 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-13 20:01 - 2013-07-07 17:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-12 22:20 - 2013-08-14 22:35 - 00000000 ____D () C:\windows\system32\MRT
2014-06-12 22:18 - 2013-04-22 21:13 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-12 22:17 - 2014-05-11 21:48 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-12 21:08 - 2013-03-10 20:17 - 00000000 ____D () C:\Users\Katja\AppData\Local\Canon Easy-PhotoPrint EX
2014-06-12 21:06 - 2009-07-14 07:32 - 00000000 ____D () C:\windows\system32\FxsTmp
2014-06-11 19:30 - 2014-06-11 19:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-11 19:03 - 2014-06-11 19:03 - 07290267 _____ () C:\Users\Katja\Downloads\pss110-v1020-win-1.zip
2014-06-09 12:50 - 2013-02-28 22:49 - 00000000 ____D () C:\Users\Katja\Documents\Rezepte
2014-06-08 11:13 - 2014-06-12 18:48 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 18:48 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-02 19:16 - 2013-02-26 22:17 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 19:16 - 2013-02-26 22:17 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-30 12:21 - 2014-06-12 18:51 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 18:51 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 18:51 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 18:51 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 18:51 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-12 18:51 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-12 18:51 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 18:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 18:51 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 18:51 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 18:51 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-12 18:51 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-12 18:51 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 18:51 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 18:51 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 18:51 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 18:51 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 18:51 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 18:51 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 18:51 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-12 18:51 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 18:51 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 18:51 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 18:51 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 18:51 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 18:51 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 18:51 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 18:51 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 18:51 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 18:51 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 18:51 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 18:51 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 18:51 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 18:51 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 18:51 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 18:51 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 18:51 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 18:51 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 18:51 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 18:51 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 18:51 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 18:51 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 18:51 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 18:51 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 18:51 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 18:51 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 18:51 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 18:51 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 18:51 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 18:51 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 18:51 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 18:51 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-05-25 10:09 - 2013-02-28 22:49 - 00000000 ____D () C:\Users\Katja\Documents\Bonn
Files to move or delete:
====================
C:\ProgramData\PKP_DLbw.DAT
C:\ProgramData\PKP_DLbx.DAT
C:\ProgramData\PKP_DLbz.DAT
Some content of TEMP:
====================
C:\Users\Katja\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-18 16:57
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- --- |