Malware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.07.2014
Suchlauf-Zeit: 10:19:57
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.18.03
Rootkit Datenbank: v2014.07.17.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Sebastian
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 260084
Verstrichene Zeit: 25 Min, 0 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 4
Trojan.Reveton, C:\Users\Sebastian\AppData\Local\Temp\1405.dll, In Quarantäne, [de1d415f7407142270777c1ffd04768a],
PUP.Optional.DownloadSponsor, C:\Users\Sebastian\Downloads\setup_turbine_31.exe, In Quarantäne, [7388762aa9d24de91a85027038cc36ca],
PUP.Optional.Conduit.A, C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M7CF4B603-3FBA-4E48-9D96-960C12DAB4B6&SearchSource=55&CUI=&UM=5&UP=SP5A1627A4-284F-4B73-9B0F-F13F4A300033&SSPV=",), Ersetzt,[2fcc247c6318e15596afd50117ed07f9]
PUP.Optional.Conduit.A, C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M7CF4B603-3FBA-4E48-9D96-960C12DAB4B6&SearchSource=55&CUI=&UM=5&UP=SP5A1627A4-284F-4B73-9B0F-F13F4A300033&SSPV=" ],), Ersetzt,[5ba0653bbbc058de98df4f871de708f8]
Physische Sektoren: 0
(No malicious items detected)
(end) ADW Cleaner: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.07.2014
Suchlauf-Zeit: 10:19:57
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.18.03
Rootkit Datenbank: v2014.07.17.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Sebastian
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 260084
Verstrichene Zeit: 25 Min, 0 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 4
Trojan.Reveton, C:\Users\Sebastian\AppData\Local\Temp\1405.dll, In Quarantäne, [de1d415f7407142270777c1ffd04768a],
PUP.Optional.DownloadSponsor, C:\Users\Sebastian\Downloads\setup_turbine_31.exe, In Quarantäne, [7388762aa9d24de91a85027038cc36ca],
PUP.Optional.Conduit.A, C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M7CF4B603-3FBA-4E48-9D96-960C12DAB4B6&SearchSource=55&CUI=&UM=5&UP=SP5A1627A4-284F-4B73-9B0F-F13F4A300033&SSPV=",), Ersetzt,[2fcc247c6318e15596afd50117ed07f9]
PUP.Optional.Conduit.A, C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M7CF4B603-3FBA-4E48-9D96-960C12DAB4B6&SearchSource=55&CUI=&UM=5&UP=SP5A1627A4-284F-4B73-9B0F-F13F4A300033&SSPV=" ],), Ersetzt,[5ba0653bbbc058de98df4f871de708f8]
Physische Sektoren: 0
(No malicious items detected)
(end) JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Starter x86
Ran by Sebastian on 18.07.2014 at 11:12:37,53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Sebastian\AppData\Roaming\mozilla\firefox\profiles\jtkbnsoj.default\minidumps [378 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.07.2014 at 11:20:06,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by Sebastian (administrator) on SEBASTIAN-PC on 18-07-2014 11:33:39
Running from C:\Users\Sebastian\Downloads
Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(PGWARE LLC) C:\Program Files\PGWARE\SuperRam\SuperRamService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(PGWARE LLC) C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-03] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [UCam_Menu] => C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [SuperRam] => C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe [1956600 2013-07-07] (PGWARE LLC)
HKLM\...\Run: [SuperHybridEngine] => C:\Program Files\EeePC\SHE\SuperHybridEngine.exe [412600 2010-06-09] (ASUSTeK Computer Inc.)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [GraphicsSwitch] => AsusSender.exe C:\Program Files\Asus\GraphicsSwitch\GraphicsSwitch.exe /auto
HKLM\...\Run: [Eee Docking] => C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [414384 2010-06-10] ()
HKLM\...\Run: [CapsHook] => C:\Program Files\EeePC\CapsHook\CapsHook.exe [445344 2010-05-29] (ASUS)
HKLM\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [2018032 2010-08-09] (ASUSTek Computer Inc.)
HKU\S-1-5-21-3537988428-1571804110-173448233-1000\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-3537988428-1571804110-173448233-1000\...\MountPoints2: {12966e6a-6859-11e1-8029-20cf306bfd7e} - E:\Setup.exe
HKU\S-1-5-21-3537988428-1571804110-173448233-1000\...\MountPoints2: {dad4b290-c371-11e0-9927-20cf306bfd7e} - E:\Setup.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default
FF NetworkProxy: "ftp", "178.21.112.27"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "http", "178.21.112.27"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "178.21.112.27"
FF NetworkProxy: "socks_port", 3128
FF NetworkProxy: "ssl", "178.21.112.27"
FF NetworkProxy: "ssl_port", 3128
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 - C:\windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin: @videolan.org/vlc,version=2.0.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DownloadHelper - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-27]
FF Extension: Personas Plus - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\Extensions\personas@christopher.beard.xpi [2012-01-25]
FF Extension: Stealthy - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\Extensions\stealthyextension@gmail.com.xpi [2012-05-05]
FF Extension: Adblock Plus - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\jtkbnsoj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-05-15]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-06-19]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-06-19]
FF HKLM\...\Firefox\Extensions: [{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B}] - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B}
Chrome:
=======
CHR HomePage: hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M7CF4B603-3FBA-4E48-9D96-960C12DAB4B6&SearchSource=55&CUI=&UM=5&UP=SP5A1627A4-284F-4B73-9B0F-F13F4A300033&SSPV=
CHR StartupUrls: "hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M7CF4B603-3FBA-4E48-9D96-960C12DAB4B6&SearchSource=55&CUI=&UM=5&UP=SP5A1627A4-284F-4B73-9B0F-F13F4A300033&SSPV="
CHR Extension: (Google Docs) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-11]
CHR Extension: (Google Drive) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-11]
CHR Extension: (YouTube) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-11]
CHR Extension: (Adblock Plus) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-07]
CHR Extension: (Google-Suche) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-11]
CHR Extension: (AdBlock) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-19]
CHR Extension: (Google Wallet) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Google Mail) - C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-11]
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG)
S2 Net Driver HPZ12; C:\windows\system32\HPZinw12.dll [44032 2009-05-15] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\windows\system32\HPZipm12.dll [53760 2009-05-15] (Hewlett-Packard) [File not signed]
R2 SuperRam; C:\Program Files\PGWARE\SuperRam\SuperRamService.exe [1942264 2013-07-07] (PGWARE LLC)
==================== Drivers (Whitelisted) ====================
S3 1394ohci; C:\windows\system32\drivers\1394ohci.sys [163840 2010-04-03] (Microsoft Corporation) [File not signed]
R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11520 2010-03-31] ()
R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [97648 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2014-04-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG)
S3 btwampfl; C:\windows\System32\drivers\btwampfl.sys [293928 2010-05-21] (Broadcom Corporation.)
R3 ETD; C:\windows\System32\DRIVERS\ETD.sys [119592 2011-04-13] (ELAN Microelectronics Corp.)
S3 hwdatacard; C:\windows\System32\DRIVERS\ewusbmdm.sys [102784 2010-08-12] (Huawei Technologies Co., Ltd.) [File not signed]
S3 hwusbfake; C:\windows\System32\DRIVERS\ewusbfake.sys [103040 2010-08-12] (Huawei Technologies Co., Ltd.) [File not signed]
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
S3 sffp_sd; C:\windows\system32\drivers\sffp_sd.sys [12800 2009-10-10] (Microsoft Corporation) [File not signed]
R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2013-04-06] (Avira GmbH)
S3 LgBttPort; system32\DRIVERS\lgbtport.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbus.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-18 11:20 - 2014-07-18 11:20 - 00000761 _____ () C:\Users\Sebastian\Desktop\JRT.txt
2014-07-18 11:12 - 2014-07-18 11:12 - 00000000 ____D () C:\windows\ERUNT
2014-07-18 11:10 - 2014-07-18 11:11 - 01016261 _____ (Thisisu) C:\Users\Sebastian\Desktop\JRT.exe
2014-07-18 11:08 - 2014-07-18 11:08 - 00002356 _____ () C:\Users\Sebastian\Desktop\AdwCleaner[S1].txt
2014-07-18 11:00 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\system32\sqlite3.dll
2014-07-18 10:57 - 2014-07-18 10:58 - 01354223 _____ () C:\Users\Sebastian\Desktop\adwcleaner_3.216.exe
2014-07-18 10:52 - 2014-07-18 11:06 - 00001136 _____ () C:\windows\PFRO.log
2014-07-18 10:46 - 2014-07-18 10:46 - 00002137 _____ () C:\Users\Sebastian\Desktop\mbam.txt
2014-07-18 10:19 - 2014-07-18 10:55 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 10:14 - 2014-07-18 10:14 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 10:14 - 2014-07-18 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 10:14 - 2014-07-18 10:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 10:14 - 2014-07-18 10:14 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-18 10:14 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-07-18 10:14 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-07-18 10:14 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-07-18 10:11 - 2014-07-18 10:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-17 18:19 - 2014-07-17 18:21 - 00028689 _____ () C:\Users\Sebastian\Downloads\Addition.txt
2014-07-17 18:17 - 2014-07-18 11:33 - 00014180 _____ () C:\Users\Sebastian\Downloads\FRST.txt
2014-07-17 18:16 - 2014-07-17 18:17 - 01077248 _____ (Farbar) C:\Users\Sebastian\Downloads\FRST.exe
2014-07-17 16:59 - 2014-07-17 16:59 - 00000000 ____D () C:\windows\system32\x64
2014-07-17 16:56 - 2012-08-23 16:48 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-07-17 16:56 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2014-07-17 16:56 - 2012-08-23 15:52 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-07-17 16:56 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2014-07-17 16:56 - 2012-08-23 12:08 - 02739712 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-07-17 16:55 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-07-17 16:55 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-07-17 16:54 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-07-17 16:54 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-07-17 16:54 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-07-17 16:54 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-07-17 16:54 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-07-17 16:54 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-07-17 16:54 - 2013-10-02 01:00 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-07-17 16:54 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-07-17 16:54 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-07-17 16:54 - 2013-10-01 22:55 - 05698048 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-07-17 16:52 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2014-07-17 16:52 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2014-07-17 00:29 - 2014-07-18 11:33 - 00000000 ____D () C:\FRST
2014-07-16 13:43 - 2014-07-16 13:43 - 00000341 _____ () C:\ProgramData\RUNDLL32.EXE-3216-F.txt
2014-07-16 13:37 - 2014-07-16 13:37 - 00000339 _____ () C:\ProgramData\RUNDLL32.EXE-2760-F.txt
2014-07-16 12:15 - 2014-07-16 12:15 - 00000340 _____ () C:\ProgramData\RUNDLL32.EXE-2480-F.txt
2014-07-16 12:14 - 2014-07-18 11:06 - 00000672 _____ () C:\windows\setupact.log
2014-07-16 12:14 - 2014-07-16 12:14 - 00000000 _____ () C:\windows\setuperr.log
2014-07-16 12:13 - 2014-07-16 13:42 - 00000000 _____ () C:\windows\system32\ztUASvSloy
2014-07-16 12:09 - 2014-07-16 12:12 - 00008111 _____ () C:\ProgramData\RUNDLL32.EXE-3280-F.txt
2014-07-10 09:20 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-07-10 09:20 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-07-10 09:20 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-07-10 09:20 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-07-10 09:20 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-07-10 09:20 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-07-10 09:20 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-07-10 09:20 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-07-10 09:20 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-07-10 09:20 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-07-10 09:20 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-07-10 09:20 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-07-10 09:20 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-07-10 09:20 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-07-10 09:20 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-07-10 09:20 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-07-10 09:20 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-07-10 09:20 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 09:20 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-07-10 09:20 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-07-10 09:20 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-07-10 09:20 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-07-10 09:20 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-07-10 09:20 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-07-10 09:20 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-07-10 09:20 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-07-10 09:20 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-07-10 09:20 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-07-10 09:20 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-07-10 09:20 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-07-10 09:17 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2014-07-10 09:17 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-07-10 09:17 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-07-10 09:17 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-07-10 09:17 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-07-10 09:17 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-07-10 09:17 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-07-10 09:17 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-07-10 09:17 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-07-10 09:17 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-07-10 09:17 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2014-07-10 09:16 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-07-10 09:09 - 2014-07-10 09:09 - 00000909 _____ () C:\Users\Sebastian\Downloads\map.php
2014-07-10 09:09 - 2014-07-10 09:09 - 00000909 _____ () C:\Users\Sebastian\Downloads\map (1).php
2014-07-03 01:40 - 2014-07-03 01:40 - 00001077 _____ () C:\Users\Public\Desktop\Horland Scan2Pdf 3.lnk
2014-07-02 17:13 - 2014-07-02 17:13 - 00066946 _____ () C:\Users\Sebastian\Downloads\20140831_Timesheet_Den-Brok.xlsx
2014-06-25 10:56 - 2014-06-25 10:56 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ___RD () C:\Program Files\Skype
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\Skype
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-06-19 18:26 - 2014-06-19 18:26 - 00000000 ____D () C:\Users\Sebastian\Documents\Bildungskredit
2014-06-19 12:47 - 2014-06-19 12:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-07-18 11:35 - 2014-07-17 18:17 - 00014180 _____ () C:\Users\Sebastian\Downloads\FRST.txt
2014-07-18 11:33 - 2014-07-17 00:29 - 00000000 ____D () C:\FRST
2014-07-18 11:22 - 2012-02-03 16:21 - 01753137 _____ () C:\windows\WindowsUpdate.log
2014-07-18 11:21 - 2011-03-03 01:10 - 00001104 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-18 11:20 - 2014-07-18 11:20 - 00000761 _____ () C:\Users\Sebastian\Desktop\JRT.txt
2014-07-18 11:19 - 2013-06-08 02:29 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-07-18 11:14 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-18 11:14 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-18 11:12 - 2014-07-18 11:12 - 00000000 ____D () C:\windows\ERUNT
2014-07-18 11:11 - 2014-07-18 11:10 - 01016261 _____ (Thisisu) C:\Users\Sebastian\Desktop\JRT.exe
2014-07-18 11:08 - 2014-07-18 11:08 - 00002356 _____ () C:\Users\Sebastian\Desktop\AdwCleaner[S1].txt
2014-07-18 11:07 - 2011-03-03 01:10 - 00001100 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-18 11:06 - 2014-07-18 10:52 - 00001136 _____ () C:\windows\PFRO.log
2014-07-18 11:06 - 2014-07-16 12:14 - 00000672 _____ () C:\windows\setupact.log
2014-07-18 11:06 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-07-18 11:05 - 2014-04-19 00:50 - 00000000 ____D () C:\AdwCleaner
2014-07-18 10:58 - 2014-07-18 10:57 - 01354223 _____ () C:\Users\Sebastian\Desktop\adwcleaner_3.216.exe
2014-07-18 10:55 - 2014-07-18 10:19 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 10:46 - 2014-07-18 10:46 - 00002137 _____ () C:\Users\Sebastian\Desktop\mbam.txt
2014-07-18 10:14 - 2014-07-18 10:14 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 10:14 - 2014-07-18 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 10:14 - 2014-07-18 10:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 10:14 - 2014-07-18 10:14 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-18 10:13 - 2014-07-18 10:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-18 02:32 - 2013-07-11 21:02 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-17 18:21 - 2014-07-17 18:19 - 00028689 _____ () C:\Users\Sebastian\Downloads\Addition.txt
2014-07-17 18:17 - 2014-07-17 18:16 - 01077248 _____ (Farbar) C:\Users\Sebastian\Downloads\FRST.exe
2014-07-17 18:05 - 2011-12-28 01:24 - 00000000 ____D () C:\windows\pss
2014-07-17 18:05 - 2010-12-25 21:17 - 00000000 ____D () C:\Users\Sebastian\Documents\Youcam
2014-07-17 18:04 - 2009-07-14 06:53 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-07-17 17:07 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-17 17:03 - 2009-07-26 03:27 - 00000000 ____D () C:\windows\system32\Drivers\de-DE
2014-07-17 17:03 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE
2014-07-17 16:59 - 2014-07-17 16:59 - 00000000 ____D () C:\windows\system32\x64
2014-07-16 13:43 - 2014-07-16 13:43 - 00000341 _____ () C:\ProgramData\RUNDLL32.EXE-3216-F.txt
2014-07-16 13:42 - 2014-07-16 12:13 - 00000000 _____ () C:\windows\system32\ztUASvSloy
2014-07-16 13:37 - 2014-07-16 13:37 - 00000339 _____ () C:\ProgramData\RUNDLL32.EXE-2760-F.txt
2014-07-16 12:15 - 2014-07-16 12:15 - 00000340 _____ () C:\ProgramData\RUNDLL32.EXE-2480-F.txt
2014-07-16 12:14 - 2014-07-16 12:14 - 00000000 _____ () C:\windows\setuperr.log
2014-07-16 12:12 - 2014-07-16 12:09 - 00008111 _____ () C:\ProgramData\RUNDLL32.EXE-3280-F.txt
2014-07-16 03:21 - 2010-12-25 20:47 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\VirtualStore
2014-07-15 11:52 - 2013-05-11 16:27 - 00035848 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2014-07-11 20:07 - 2009-07-14 06:33 - 00438992 _____ () C:\windows\system32\FNTCACHE.DAT
2014-07-11 13:37 - 2013-08-15 03:16 - 00000000 ____D () C:\windows\system32\MRT
2014-07-11 13:30 - 2011-01-11 13:21 - 93585272 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-07-10 09:09 - 2014-07-10 09:09 - 00000909 _____ () C:\Users\Sebastian\Downloads\map.php
2014-07-10 09:09 - 2014-07-10 09:09 - 00000909 _____ () C:\Users\Sebastian\Downloads\map (1).php
2014-07-09 13:19 - 2012-11-11 16:25 - 00699056 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-07-09 13:19 - 2011-05-28 13:40 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-03 17:51 - 2013-04-06 19:27 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2014-07-03 01:41 - 2014-04-06 18:06 - 00000000 ____D () C:\Program Files\Horland Scan2Pdf 3.0
2014-07-03 01:40 - 2014-07-03 01:40 - 00001077 _____ () C:\Users\Public\Desktop\Horland Scan2Pdf 3.lnk
2014-07-03 01:40 - 2014-04-06 18:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Horland Scan2Pdf 3
2014-07-03 01:36 - 2009-07-25 09:50 - 01635912 _____ () C:\windows\system32\PerfStringBackup.INI
2014-07-02 17:13 - 2014-07-02 17:13 - 00066946 _____ () C:\Users\Sebastian\Downloads\20140831_Timesheet_Den-Brok.xlsx
2014-06-25 11:13 - 2011-08-12 19:25 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\Skype
2014-06-25 10:56 - 2014-06-25 10:56 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ___RD () C:\Program Files\Skype
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\Skype
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-25 10:56 - 2014-06-25 10:56 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-06-25 10:55 - 2011-08-12 19:24 - 00000000 ____D () C:\ProgramData\Skype
2014-06-20 21:39 - 2014-07-10 09:20 - 00240824 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-06-20 09:24 - 2012-04-27 15:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-06-19 22:42 - 2014-06-02 22:52 - 00016231 _____ () C:\Users\Sebastian\Desktop\Euro Stoxx Auditors.ods
2014-06-19 18:29 - 2013-12-08 18:59 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\banshee-1
2014-06-19 18:27 - 2012-10-23 20:48 - 00000000 ____D () C:\Users\Sebastian\Desktop\HS Rhein Waal
2014-06-19 18:26 - 2014-06-19 18:26 - 00000000 ____D () C:\Users\Sebastian\Documents\Bildungskredit
2014-06-19 12:47 - 2014-06-19 12:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-19 02:16 - 2014-07-10 09:20 - 17276416 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-19 01:56 - 2014-07-10 09:20 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-19 01:56 - 2014-07-10 09:20 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-19 01:38 - 2014-07-10 09:20 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-19 01:37 - 2014-07-10 09:20 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-19 01:36 - 2014-07-10 09:20 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-19 01:35 - 2014-07-10 09:20 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-06-19 01:32 - 2014-07-10 09:20 - 02179072 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-19 01:28 - 2014-07-10 09:20 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-19 01:28 - 2014-07-10 09:20 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-19 01:25 - 2014-07-10 09:20 - 00442368 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-19 01:23 - 2014-07-10 09:20 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-19 01:23 - 2014-07-10 09:20 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-19 01:22 - 2014-07-10 09:20 - 00592896 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-19 01:16 - 2014-07-10 09:20 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-19 01:12 - 2014-07-10 09:20 - 00367616 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-19 01:06 - 2014-07-10 09:20 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 01:01 - 2014-07-10 09:20 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-19 00:59 - 2014-07-10 09:20 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-19 00:58 - 2014-07-10 09:20 - 00239616 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-19 00:52 - 2014-07-10 09:20 - 04254720 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-19 00:52 - 2014-07-10 09:20 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-19 00:49 - 2014-07-10 09:20 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-19 00:46 - 2014-07-10 09:20 - 01068032 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-19 00:45 - 2014-07-10 09:20 - 01964544 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-19 00:35 - 2014-07-10 09:20 - 11742208 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-19 00:13 - 2014-07-10 09:20 - 01791488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-19 00:09 - 2014-07-10 09:20 - 01139200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-19 00:07 - 2014-07-10 09:20 - 00704512 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-18 03:51 - 2014-07-10 09:17 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2014-06-18 02:52 - 2014-07-10 09:17 - 02350080 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
Some content of TEMP:
====================
C:\Users\Sebastian\AppData\Local\Temp\avgnt.exe
C:\Users\Sebastian\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-02 18:29
==================== End Of Log ============================ --- --- --- |