Hallo Schrauber,
erst mal die Logs: Mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 02.07.2014
Scan Time: 16:21:21
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.07.02.03
Rootkit Database: v2014.07.01.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: ***
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 257717
Time Elapsed: 1 hr, 8 min, 13 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
AdwareCleaner Code:
# AdwCleaner v3.214 - Bericht erstellt am 02/07/2014 um 19:05:16
# Aktualisiert 29/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : *** - TOSHIBA
# Gestartet von : C:\Users\***\Desktop\adwcleaner_3.214.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\2dg3ck1q.default\prefs.js ]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [24106 octets] - [22/11/2013 00:40:31]
AdwCleaner[R1].txt - [1181 octets] - [27/11/2013 00:18:43]
AdwCleaner[R2].txt - [1497 octets] - [09/12/2013 21:06:56]
AdwCleaner[R3].txt - [1938 octets] - [22/06/2014 09:00:44]
AdwCleaner[R4].txt - [1998 octets] - [22/06/2014 09:04:29]
AdwCleaner[R5].txt - [1263 octets] - [22/06/2014 09:15:31]
AdwCleaner[R6].txt - [1437 octets] - [02/07/2014 19:01:55]
AdwCleaner[S0].txt - [23228 octets] - [22/11/2013 00:43:15]
AdwCleaner[S1].txt - [2043 octets] - [22/06/2014 09:06:15]
AdwCleaner[S2].txt - [1358 octets] - [02/07/2014 19:05:16]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1418 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by *** on 02.07.2014 at 19:11:17,92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1019774711-1455369172-2651612590-1000\Software\sweetim
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Emptied folder: C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\2dg3ck1q.default\minidumps [4 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.07.2014 at 19:15:16,71
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:28-06-2014 02
Ran by *** (administrator) on TOSHIBA on 02-07-2014 19:33:45
Running from C:\Users\***\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynToshiba.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
() C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Dropbox, Inc.) C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1316136 2008-06-20] (Synaptics, Inc.)
HKLM\...\Run: [FreePDF Assistant] => C:\Program Files\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [BrMfcWnd] => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1163264 2012-09-25] ()
HKLM\...\Run: [ControlCenter3] => C:\Program Files\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-26] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.googl.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {687293DB-9727-4EEA-B56A-0314263A4611} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {A8999728-B95C-4439-8291-2007452BE524} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {D3F652E0-3103-4B8F-917E-3AF6FDB8DA19} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
SearchScopes: HKCU - {F70C5623-AD96-4662-9D73-8C009114F57C} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\2dg3ck1q.default
FF DefaultSearchEngine: LEO Eng-Deu
FF SelectedSearchEngine: LEO Eng-Deu
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin: @java.com/DTPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: WOT - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\2dg3ck1q.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-06-22]
FF Extension: Adblock Plus - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\2dg3ck1q.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-22]
========================== Services (Whitelisted) =================
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [811088 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-06-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1028688 2014-06-26] (Avira Operations GmbH & Co. KG)
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97648 2014-06-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-02-25] (Avira GmbH)
S3 catchme; \??\C:\Users\***\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-02 19:33 - 2014-07-02 19:35 - 00008566 _____ () C:\Users\***\Desktop\FRST.txt
2014-07-02 19:30 - 2014-07-02 19:30 - 00000425 _____ () C:\Users\***\Desktop\troja.txt
2014-07-02 19:15 - 2014-07-02 19:15 - 00001005 _____ () C:\Users\***\Desktop\JRT.txt
2014-07-02 19:11 - 2014-07-02 19:11 - 00000000 ____D () C:\Windows\ERUNT
2014-07-02 19:08 - 2014-07-02 19:07 - 01016261 _____ (Thisisu) C:\Users\***\Desktop\JRT.exe
2014-07-02 19:01 - 2014-07-02 18:51 - 01346519 _____ () C:\Users\***\Desktop\adwcleaner_3.214.exe
2014-07-02 18:59 - 2014-07-02 18:59 - 00131072 ____N () C:\Windows\Minidump\070214-23712-01.dmp
2014-07-02 18:46 - 2014-07-02 19:29 - 00001059 _____ () C:\Users\***\Desktop\mbam.txt
2014-07-02 18:34 - 2014-07-02 18:34 - 01346519 _____ () C:\Users\***\Downloads\adwcleaner_3.214.exe
2014-07-02 18:31 - 2014-07-02 18:31 - 00131072 ____N () C:\Windows\Minidump\070214-21387-01.dmp
2014-07-02 16:18 - 2014-07-02 16:18 - 00131072 ____N () C:\Windows\Minidump\070214-22510-01.dmp
2014-07-01 20:08 - 2014-07-01 20:21 - 00000000 ____D () C:\Qoobox
2014-07-01 20:08 - 2014-07-01 20:19 - 00000000 ____D () C:\Windows\erdnt
2014-07-01 20:08 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-01 20:08 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-01 20:08 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-01 20:08 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-01 20:08 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-01 20:08 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-01 20:08 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-01 20:08 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-01 19:38 - 2014-07-01 19:35 - 05212874 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe
2014-06-30 17:40 - 2014-06-30 17:54 - 00001226 _____ () C:\Users\***\Desktop\Revo Uninstaller.lnk
2014-06-30 17:40 - 2014-06-30 17:40 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-30 17:36 - 2014-06-30 17:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\***\Desktop\revosetup95.exe
2014-06-29 16:50 - 2014-06-29 16:50 - 00131072 ____N () C:\Windows\Minidump\062914-23415-01.dmp
2014-06-29 16:38 - 2014-06-29 16:38 - 00131072 ____N () C:\Windows\Minidump\062914-22386-01.dmp
2014-06-29 16:18 - 2014-06-29 16:18 - 00143384 _____ () C:\Windows\Minidump\062914-22869-01.dmp
2014-06-29 15:27 - 2014-06-29 15:27 - 00000000 _____ () C:\Users\***\defogger_reenable
2014-06-29 15:16 - 2014-06-29 15:18 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe
2014-06-29 15:09 - 2014-06-29 15:14 - 01073664 _____ (Farbar) C:\Users\***\Desktop\FRST.exe
2014-06-29 14:58 - 2014-06-29 14:59 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe
2014-06-29 13:42 - 2014-06-29 13:42 - 00131072 ____N () C:\Windows\Minidump\062914-23868-01.dmp
2014-06-28 15:40 - 2014-06-28 15:40 - 00131072 ____N () C:\Windows\Minidump\062814-22776-01.dmp
2014-06-25 13:49 - 2014-06-25 13:49 - 00131072 ____N () C:\Windows\Minidump\062514-24070-01.dmp
2014-06-23 16:40 - 2014-06-23 16:41 - 00000000 ____D () C:\Users\***\Desktop\Pc-check
2014-06-22 22:08 - 2014-06-22 22:08 - 00000000 ____D () C:\Users\***\AppData\Local\Adobe
2014-06-22 21:49 - 2014-07-02 16:44 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-22 21:49 - 2014-06-22 21:56 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-06-22 21:49 - 2014-06-22 21:56 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-06-22 21:36 - 2014-06-22 21:36 - 00000952 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-06-22 21:34 - 2014-06-22 21:56 - 00001245 _____ () C:\Windows\SecuniaPackage.log
2014-06-22 21:29 - 2014-06-22 21:29 - 00001031 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2014-06-22 21:29 - 2014-06-22 21:29 - 00000000 ____D () C:\Users\***\AppData\Local\Secunia PSI
2014-06-22 21:29 - 2014-06-22 21:29 - 00000000 ____D () C:\Program Files\Secunia
2014-06-22 21:22 - 2014-07-02 18:36 - 00000000 ____D () C:\ProgramData\TEMP
2014-06-22 21:22 - 2014-06-29 14:27 - 00000000 ____D () C:\Program Files\SpywareBlaster
2014-06-22 21:22 - 2014-06-22 21:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2014-06-22 21:22 - 2014-06-22 21:22 - 00000000 ____D () C:\ProgramData\Licenses
2014-06-22 21:21 - 2014-06-22 21:21 - 04095448 _____ (BrightFort LLC ) C:\Users\***\Downloads\spywareblastersetup50.exe
2014-06-22 17:18 - 2014-07-02 18:46 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-22 17:18 - 2014-06-22 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-22 17:18 - 2014-06-22 17:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 17:18 - 2014-06-22 17:18 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-22 17:18 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-22 17:18 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-22 17:18 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-22 17:16 - 2014-06-22 17:17 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-22 09:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-06-20 19:20 - 2014-07-02 19:34 - 00000000 ____D () C:\FRST
2014-06-18 15:24 - 2014-06-18 15:24 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-17 18:26 - 2014-06-17 18:26 - 00131072 ____N () C:\Windows\Minidump\061714-22495-01.dmp
2014-06-17 18:24 - 2014-06-17 18:24 - 00131072 ____N () C:\Windows\Minidump\061714-22011-01.dmp
2014-06-15 17:44 - 2014-06-15 17:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-15 17:44 - 2014-06-15 17:44 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-06-15 17:44 - 2014-05-07 15:02 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-06-15 17:44 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-06-15 17:44 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-06-15 17:44 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-06-15 17:43 - 2014-06-15 17:44 - 00004528 _____ () C:\Windows\system32\jupdate-1.7.0_60-b19.log
2014-06-15 16:09 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-06-15 16:05 - 2014-05-08 11:06 - 02742784 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-15 16:05 - 2014-05-08 11:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-15 15:55 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-06-15 15:55 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-06-15 15:55 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-06-15 15:55 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-06-15 15:55 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-06-15 15:55 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-06-15 15:55 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-06-15 15:55 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-06-15 15:55 - 2013-10-02 01:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-06-15 15:55 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-06-15 15:55 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-06-15 15:55 - 2012-08-23 16:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-15 15:55 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-06-15 15:55 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-06-15 15:53 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-06-13 17:00 - 2014-06-13 17:01 - 00011278 _____ () C:\Users\***\Desktop\putzplan.xlsx
2014-06-12 17:24 - 2014-06-13 17:39 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2014-06-12 17:10 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 17:10 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 17:10 - 2014-05-30 11:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 17:10 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 17:10 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 17:10 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 17:10 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 17:10 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 17:10 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 17:10 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 17:10 - 2014-05-30 10:28 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 17:10 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 17:10 - 2014-05-30 10:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 17:10 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 17:10 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 17:10 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 17:10 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 17:10 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 17:10 - 2014-05-30 09:57 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 17:10 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 17:10 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 17:10 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 17:10 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 17:10 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 17:10 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 17:10 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 17:10 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 17:10 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 17:10 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 17:10 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 17:09 - 2014-06-08 10:48 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 17:09 - 2014-06-08 10:43 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-12 17:09 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 17:09 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 17:09 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 17:09 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 17:08 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-03 18:30 - 2014-06-25 16:52 - 00039498 _____ () C:\Users\***\Documents\IntelliPlanArchive.zip
2014-06-03 18:27 - 2014-06-25 16:42 - 00004096 _____ () C:\Users\Public\Documents\0000181D.LCS
2014-06-03 18:27 - 2014-06-03 18:27 - 00000000 ____D () C:\Users\***\AppData\Roaming\ProtectDISC
==================== One Month Modified Files and Folders =======
2014-07-02 19:35 - 2014-07-02 19:33 - 00008566 _____ () C:\Users\***\Desktop\FRST.txt
2014-07-02 19:34 - 2014-06-20 19:20 - 00000000 ____D () C:\FRST
2014-07-02 19:32 - 2012-08-10 13:42 - 01051229 _____ () C:\Windows\WindowsUpdate.log
2014-07-02 19:30 - 2014-07-02 19:30 - 00000425 _____ () C:\Users\***\Desktop\troja.txt
2014-07-02 19:29 - 2014-07-02 18:46 - 00001059 _____ () C:\Users\***\Desktop\mbam.txt
2014-07-02 19:15 - 2014-07-02 19:15 - 00001005 _____ () C:\Users\***\Desktop\JRT.txt
2014-07-02 19:15 - 2009-07-14 06:34 - 00033904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-02 19:15 - 2009-07-14 06:34 - 00033904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-02 19:11 - 2014-07-02 19:11 - 00000000 ____D () C:\Windows\ERUNT
2014-07-02 19:09 - 2012-08-13 20:51 - 00000000 ____D () C:\Users\***\AppData\Roaming\Dropbox
2014-07-02 19:08 - 2014-05-02 23:18 - 00000000 ____D () C:\Users\***\AppData\Roaming\DropboxMaster
2014-07-02 19:08 - 2012-08-13 21:28 - 00000000 ___RD () C:\Users\***\Dropbox
2014-07-02 19:07 - 2014-07-02 19:08 - 01016261 _____ (Thisisu) C:\Users\***\Desktop\JRT.exe
2014-07-02 19:07 - 2010-11-20 23:48 - 00237750 _____ () C:\Windows\PFRO.log
2014-07-02 19:07 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-02 19:07 - 2009-07-14 06:39 - 00196199 _____ () C:\Windows\setupact.log
2014-07-02 19:05 - 2013-11-22 00:39 - 00000000 ____D () C:\AdwCleaner
2014-07-02 18:59 - 2014-07-02 18:59 - 00131072 ____N () C:\Windows\Minidump\070214-23712-01.dmp
2014-07-02 18:59 - 2012-08-11 10:29 - 00000000 ____D () C:\Windows\Minidump
2014-07-02 18:51 - 2014-07-02 19:01 - 01346519 _____ () C:\Users\***\Desktop\adwcleaner_3.214.exe
2014-07-02 18:46 - 2014-06-22 17:18 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-02 18:36 - 2014-06-22 21:22 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-02 18:34 - 2014-07-02 18:34 - 01346519 _____ () C:\Users\***\Downloads\adwcleaner_3.214.exe
2014-07-02 18:31 - 2014-07-02 18:31 - 00131072 ____N () C:\Windows\Minidump\070214-21387-01.dmp
2014-07-02 16:44 - 2014-06-22 21:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-02 16:18 - 2014-07-02 16:18 - 00131072 ____N () C:\Windows\Minidump\070214-22510-01.dmp
2014-07-01 20:21 - 2014-07-01 20:08 - 00000000 ____D () C:\Qoobox
2014-07-01 20:20 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-07-01 20:19 - 2014-07-01 20:08 - 00000000 ____D () C:\Windows\erdnt
2014-07-01 20:18 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-07-01 19:38 - 2010-11-20 23:01 - 01658652 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-01 19:35 - 2014-07-01 19:38 - 05212874 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe
2014-06-30 17:54 - 2014-06-30 17:40 - 00001226 _____ () C:\Users\***\Desktop\Revo Uninstaller.lnk
2014-06-30 17:40 - 2014-06-30 17:40 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-30 17:32 - 2014-06-30 17:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\***\Desktop\revosetup95.exe
2014-06-30 17:12 - 2012-12-11 00:20 - 00000000 ____D () C:\Program Files\Common Files\Blizzard Entertainment
2014-06-29 20:46 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-29 16:50 - 2014-06-29 16:50 - 00131072 ____N () C:\Windows\Minidump\062914-23415-01.dmp
2014-06-29 16:38 - 2014-06-29 16:38 - 00131072 ____N () C:\Windows\Minidump\062914-22386-01.dmp
2014-06-29 16:18 - 2014-06-29 16:18 - 00143384 _____ () C:\Windows\Minidump\062914-22869-01.dmp
2014-06-29 16:18 - 2012-11-24 22:11 - 237395221 _____ () C:\Windows\MEMORY.DMP
2014-06-29 15:27 - 2014-06-29 15:27 - 00000000 _____ () C:\Users\***\defogger_reenable
2014-06-29 15:27 - 2012-08-10 13:49 - 00000000 ____D () C:\Users\***
2014-06-29 15:18 - 2014-06-29 15:16 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe
2014-06-29 15:14 - 2014-06-29 15:09 - 01073664 _____ (Farbar) C:\Users\***\Desktop\FRST.exe
2014-06-29 14:59 - 2014-06-29 14:58 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe
2014-06-29 14:27 - 2014-06-22 21:22 - 00000000 ____D () C:\Program Files\SpywareBlaster
2014-06-29 13:42 - 2014-06-29 13:42 - 00131072 ____N () C:\Windows\Minidump\062914-23868-01.dmp
2014-06-28 15:40 - 2014-06-28 15:40 - 00131072 ____N () C:\Windows\Minidump\062814-22776-01.dmp
2014-06-26 13:37 - 2014-05-12 18:07 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-25 16:52 - 2014-06-03 18:30 - 00039498 _____ () C:\Users\***\Documents\IntelliPlanArchive.zip
2014-06-25 16:42 - 2014-06-03 18:27 - 00004096 _____ () C:\Users\Public\Documents\0000181D.LCS
2014-06-25 13:49 - 2014-06-25 13:49 - 00131072 ____N () C:\Windows\Minidump\062514-24070-01.dmp
2014-06-23 16:41 - 2014-06-23 16:40 - 00000000 ____D () C:\Users\***\Desktop\Pc-check
2014-06-23 10:14 - 2012-08-10 15:01 - 00000000 ____D () C:\Program Files\WinRAR
2014-06-22 22:08 - 2014-06-22 22:08 - 00000000 ____D () C:\Users\***\AppData\Local\Adobe
2014-06-22 21:56 - 2014-06-22 21:49 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-06-22 21:56 - 2014-06-22 21:49 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-06-22 21:56 - 2014-06-22 21:34 - 00001245 _____ () C:\Windows\SecuniaPackage.log
2014-06-22 21:36 - 2014-06-22 21:36 - 00000952 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-06-22 21:36 - 2012-08-10 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-06-22 21:29 - 2014-06-22 21:29 - 00001031 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2014-06-22 21:29 - 2014-06-22 21:29 - 00000000 ____D () C:\Users\***\AppData\Local\Secunia PSI
2014-06-22 21:29 - 2014-06-22 21:29 - 00000000 ____D () C:\Program Files\Secunia
2014-06-22 21:22 - 2014-06-22 21:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2014-06-22 21:22 - 2014-06-22 21:22 - 00000000 ____D () C:\ProgramData\Licenses
2014-06-22 21:21 - 2014-06-22 21:21 - 04095448 _____ (BrightFort LLC ) C:\Users\***\Downloads\spywareblastersetup50.exe
2014-06-22 17:18 - 2014-06-22 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-22 17:18 - 2014-06-22 17:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 17:18 - 2014-06-22 17:18 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-22 17:17 - 2014-06-22 17:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-19 19:13 - 2012-09-27 17:16 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-06-18 19:09 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-06-18 15:24 - 2014-06-18 15:24 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-17 18:26 - 2014-06-17 18:26 - 00131072 ____N () C:\Windows\Minidump\061714-22495-01.dmp
2014-06-17 18:24 - 2014-06-17 18:24 - 00131072 ____N () C:\Windows\Minidump\061714-22011-01.dmp
2014-06-15 17:44 - 2014-06-15 17:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-15 17:44 - 2014-06-15 17:44 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-06-15 17:44 - 2014-06-15 17:43 - 00004528 _____ () C:\Windows\system32\jupdate-1.7.0_60-b19.log
2014-06-15 17:44 - 2013-10-03 12:59 - 00000000 ____D () C:\ProgramData\Oracle
2014-06-15 17:44 - 2013-10-03 12:58 - 00000000 ____D () C:\Program Files\Java
2014-06-15 16:36 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-06-15 15:59 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-06-15 15:57 - 2012-08-10 23:36 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2014-06-15 14:30 - 2014-05-09 18:25 - 00000000 ____D () C:\Users\***\Desktop\Stick Pascal
2014-06-13 17:39 - 2014-06-12 17:24 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2014-06-13 17:01 - 2014-06-13 17:00 - 00011278 _____ () C:\Users\***\Desktop\putzplan.xlsx
2014-06-13 09:08 - 2014-05-06 15:39 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 20:08 - 2013-08-14 15:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 20:07 - 2012-08-10 16:26 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-08 10:48 - 2014-06-12 17:09 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 10:43 - 2014-06-12 17:09 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-06 20:51 - 2014-05-22 23:03 - 00040015 _____ () C:\Users\***\Desktop\20140308_Modul_17.2_Sexualdelikte_Karsten_Bettels.odt
2014-06-03 18:27 - 2014-06-03 18:27 - 00000000 ____D () C:\Users\***\AppData\Roaming\ProtectDISC
2014-06-02 18:07 - 2012-08-13 20:56 - 00000000 ____D () C:\Users\***\Desktop\PA
2014-06-02 17:20 - 2009-07-14 06:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Files to move or delete:
====================
C:\ProgramData\EBLib.dll
Some content of TEMP:
====================
C:\Users\***\AppData\Local\Temp\avgnt.exe
C:\Users\***\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxzqj7g.dll
C:\Users\***\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-18 19:01
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:28-06-2014 02
Ran by *** at 2014-07-02 19:40:52
Running from C:\Users\***\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
2007 Microsoft Office Suite Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Adobe Flash Player 14 ActiveX (HKLM\...\{1F5E5F2E-5E61-431D-B796-58CCC6B68E28}) (Version: 14.0.0.125 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.125 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Antivirus Pro (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.5.450 - Avira)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
Free YouTube Download version 3.2.9.725 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.9.725 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.12.827 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.12.827 - DVDVideoSoft Ltd.)
FreeLanguageTranslator2 (HKLM\...\{8AA462CC-7F29-4F51-9D7F-68ED38658E92}) (Version: 2.02 - Decebal Mihailescu)
FreePDF (Remove only) (HKLM\...\FreePDF_XP) (Version: - )
Google Update Helper (Version: 1.3.23.0 - BonanzaDeals) Hidden <==== ATTENTION
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.)
GUILD WARS (HKLM\...\Guild Wars) (Version: - )
Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (Version: 2.1.60.19 - Oracle, Inc.) Hidden
King's Quest I: Quest for the Crown (4.1c) (HKLM\...\{486CC64F-030A-4C9A-8716-87E26D28FKQ1}_is1) (Version: 4.1 - AGD Interactive, LLC)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Maniac Mansion Deluxe (HKLM\...\Maniac Mansion Deluxe) (Version: - )
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 30.0 (x86 de) (HKLM\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.6.0 (x86 de) (HKLM\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla)
No23 Recorder (HKLM\...\{22B0E143-2B0B-435B-9F56-136A3D16065F}) (Version: 2.1.0.3 - No23)
PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.213.1 - Tracker Software Products Ltd)
QTranslate 5.2.0 (HKLM\...\QTranslate) (Version: 5.2.0 - QuestSoft)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - )
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Secunia PSI (3.0.0.9016) (HKLM\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Skype™ 6.7 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.7.102 - Skype Technologies S.A.)
SpywareBlaster 5.0 (HKLM\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 11.1.18.0 - Synaptics)
TIPCI (Version: 1.23.0000 - Ihr Firmenname) Hidden
TIPCI (Version: 2.00.0001 - Ihr Firmenname) Hidden
Utility Common Driver (Version: 0.0.1.1C - TOSHIBA) Hidden
VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN)
==================== Restore Points =========================
15-06-2014 13:54:06 Windows Update
15-06-2014 14:07:04 Windows Update
15-06-2014 14:34:45 Windows Update
15-06-2014 15:38:43 Removed Java 7 Update 55
15-06-2014 15:40:13 Removed Java 7 Update 55
15-06-2014 15:43:05 Installed Java 7 Update 60
22-06-2014 16:15:56 Geplanter Prüfpunkt
22-06-2014 19:39:05 Removed Adobe Flash Player 14 ActiveX.
22-06-2014 19:39:38 Removed Adobe Flash Player 14 ActiveX.
22-06-2014 19:46:15 Removed Adobe Flash Player 14 ActiveX.
22-06-2014 19:46:31 Removed Adobe Flash Player 14 ActiveX.
01-07-2014 18:09:11 ComboFix created restore point
==================== Hosts content: ==========================
2009-07-14 04:04 - 2014-07-01 20:18 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {27D699C0-5EF7-4F3D-90AF-9A5B7CBF5EC3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-22] (Adobe Systems Incorporated)
Task: {EE3EE25C-47CE-4CBF-9FD5-2EECA82D0B3D} - System32\Tasks\{DD649DA7-0857-4615-8596-5F9C85D2013D} => C:\Users\***\Downloads\madtv\MTV.EXE
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2012-08-10 16:33 - 2010-06-17 21:56 - 00116224 _____ () C:\Windows\System32\redmonnt.dll
2013-02-21 22:57 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2013-02-21 22:57 - 2002-11-26 14:43 - 00106496 ____N () C:\Windows\system32\BrMuSNMP.dll
2013-02-21 22:57 - 2012-09-25 12:26 - 01163264 ____N () C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
2014-07-02 19:08 - 2014-07-02 19:08 - 00043008 _____ () c:\users\***\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxzqj7g.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\***\AppData\Roaming\Dropbox\bin\libcef.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
Error: (02/21/2013 10:59:27 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 537 seconds with 120 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 2046.05 MB
Available physical RAM: 1298.9 MB
Total Pagefile: 4092.09 MB
Available Pagefile: 3029.47 MB
Total Virtual: 2047.88 MB
Available Virtual: 1926.11 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:117.81 GB) (Free:71.37 GB) NTFS
Drive d: (Data) (Fixed) (Total:114.98 GB) (Free:110.13 GB) NTFS
Drive h: (USB DISK) (Removable) (Total:7.45 GB) (Free:7.19 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 444C4189)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=118 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=115 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18)
Partition 1: (Not Active) - (Size=7 GB) - (Type=0C)
==================== End Of Log ============================
Nachdem ich gestern Combofix laufen lies, hatte ich das Gefühl, dass der Pc besser lief.
Heut habe ich das Book angeschmissen und gleich Malwarebytes angeworfen und nicht weiter drauf geachtet, wie das Book sonst so läuft.
MBAM hatte ich schon auf dem Book und habe es nur aktualisiert.
MBAM hat nichts gefunden und nach dem es gelaufen ist, lief das Book wieder richtig schlecht. Ich konnte wieder kaum mit ihm Arbeiten
Alle anderen Programme musste ich auch auf ein anders Book herunterladen und mittels USB stick auf diesen verschieben, da der PC so lahm ist, dass es mit dem unmöglich ist.
Kann es sein, dass ich mir den Mist immer hin und her schiebe?
Das andere Book haben wir eigentlich vor 3-4 wochen gereinigt. es macht auch keine Probleme. Ich habe aber trotzdem auch mal MBAM & AdwC drüber laufen lassen. MBAM hat nix gefunden, jedoch adwc.
Ich habe da ja überhaupt keine Ahnung. Aber vllt. schiebe ich idiot mir die Dinger ja die ganze zeit hin und her. Im Abgesicherten Modus läuft das book allerdings recht gut.
Ansonsten keine Besserung auf diesen PC. :headbang:
Dabei war ich seit dem letzten Mal extra Vorsichtig, habe alle Sicherheitstipps beachtet usw.
ich verstehe es einfach nicht:confused:
Gruß |