Music.Junky | 22.08.2014 16:06 | Hallo schrauber,
hab alles wie gewünscht ausgeführt. Da kamen wirklich einige Dateien zusammen, die gelöscht wurden.. mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 21.08.2014
Suchlauf-Zeit: 19:15:30
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.21.06
Rootkit Datenbank: v2014.08.16.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: UliMx921
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 309525
Verstrichene Zeit: 7 Min, 32 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 8
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-351139012-3454371372-141882758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [25157c4d017acc6a159fbbb4c33f25db],
PUP.Optional.FastSearchings, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [73c71faa7ffcc4727a92dd6f2adad32d],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, In Quarantäne, [eb4f29a0e596bb7b7b1a807041c15da3],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [b288488199e2a78f8a9889a225dfae52],
PUP.Optional.ConduitSearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [0139e6e37b007fb7f34d44e31fe51ee2],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-351139012-3454371372-141882758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, In Quarantäne, [0436d1f87dfeb77fff8d70bbba4a6f91],
PUP.Optional.WebSearchInfo, HKU\S-1-5-21-351139012-3454371372-141882758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [4bef2a9f7a0179bd3634b38555afb34d],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-351139012-3454371372-141882758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [5dddd5f4c1ba41f566bb7cafa064b64a],
Registrierungswerte: 3
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, In Quarantäne, [eb4f29a0e596bb7b7b1a807041c15da3]
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 11111111, In Quarantäne, [b288488199e2a78f8a9889a225dfae52]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-351139012-3454371372-141882758-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 11111111, In Quarantäne, [5dddd5f4c1ba41f566bb7cafa064b64a]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 13
PUP.Optional.OpenCandy, C:\Users\UliMx921\AppData\Roaming\OpenCandy, In Quarantäne, [e159eadf077454e24e00ceee986ad32d],
PUP.Optional.OpenCandy, C:\Users\UliMx921\AppData\Roaming\OpenCandy\5C837033B4E14D378F95E6F0785EF55D, In Quarantäne, [e159eadf077454e24e00ceee986ad32d],
PUP.Optional.OpenCandy, C:\Users\UliMx921\AppData\Roaming\OpenCandy\B5EF948F675F4B90B097E914F6035DEA, In Quarantäne, [e159eadf077454e24e00ceee986ad32d],
PUP.Optional.OpenCandy, C:\Users\UliMx921\AppData\Roaming\OpenCandy\CD6CD61CE82A4FCEA9BA2A3E82BC4EDD, In Quarantäne, [e159eadf077454e24e00ceee986ad32d],
PUP.Optional.Vaudix.A, C:\Users\UliMx921\AppData\LocalLow\Vaudix, In Quarantäne, [50ea4f7af289ae88ad6730a0db27d22e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\Logs, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\SearchProtect\Logs, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\UI, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
Dateien: 8
PUP.Optional.OpenCandy, C:\Users\UliMx921\AppData\Roaming\OpenCandy\5C837033B4E14D378F95E6F0785EF55D\zafwSetupWeb_131_211_000.exe, In Quarantäne, [e159eadf077454e24e00ceee986ad32d],
PUP.Optional.OpenCandy, C:\Users\UliMx921\AppData\Roaming\OpenCandy\B5EF948F675F4B90B097E914F6035DEA\TuneUpUtilities2013-2200217_de-DE.exe, In Quarantäne, [e159eadf077454e24e00ceee986ad32d],
PUP.Optional.OpenCandy, C:\Users\UliMx921\AppData\Roaming\OpenCandy\CD6CD61CE82A4FCEA9BA2A3E82BC4EDD\speedupmypcROE.exe, In Quarantäne, [e159eadf077454e24e00ceee986ad32d],
PUP.Optional.Vaudix.A, C:\Users\UliMx921\AppData\LocalLow\Vaudix\Vaudix.dat, In Quarantäne, [50ea4f7af289ae88ad6730a0db27d22e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\SearchProtect\rep\Cvc.dat, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
PUP.Optional.SearchProtect.A, C:\Users\UliMx921\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [e3573c8d5f1c89adfe19e7eb4db5827e],
Physische Sektoren: 0
(No malicious items detected)
(end) ADW-Cleaner: Code:
# AdwCleaner v3.308 - Bericht erstellt am 21/08/2014 um 19:40:22
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : UliMx921 - ULIMX921-HP
# Gestartet von : C:\Users\UliMx921\Desktop\adwcleaner_3.308.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\SearchProtect
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\Vaudix
Ordner Gelöscht : C:\Program Files (x86)\DVDvideoSoft_2.0
Ordner Gelöscht : C:\Windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Users\UliMx921\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\UliMx921\AppData\Local\PutLockerDownloader
Ordner Gelöscht : C:\Users\UliMx921\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\UliMx921\AppData\LocalLow\DVDvideoSoft_2.0
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
Datei Gelöscht : C:\Users\UliMx921\AppData\Roaming\Mozilla\Firefox\Profiles\wbnsoi44.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\UliMx921\AppData\Roaming\Mozilla\Firefox\Profiles\wbnsoi44.default\user.js
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Movie2KDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3279453
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{04A8DD1A-4754-48FE-A703-99846646EF04}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{17667902-A1A2-4DC4-8C42-CB1B60BF2202}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04A8DD1A-4754-48FE-A703-99846646EF04}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{04A8DD1A-4754-48FE-A703-99846646EF04}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17667902-A1A2-4DC4-8C42-CB1B60BF2202}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD4F85E5-E226-47F5-AF76-6A1DEA5AAB8E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C01F9B66-75B5-4F0D-A49A-932D2FEC6858}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{04A8DD1A-4754-48FE-A703-99846646EF04}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{04A8DD1A-4754-48FE-A703-99846646EF04}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{04A8DD1A-4754-48FE-A703-99846646EF04}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDvideoSoft_2.0
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG SafeGuard toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\SP Global
Schlüssel Gelöscht : HKLM\SOFTWARE\SProtector
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\DVDvideoSoft_2.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDvideoSoft_2.0 Toolbar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v0.0.0.0
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\UliMx921\AppData\Roaming\Mozilla\Firefox\Profiles\wbnsoi44.default\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\UliMx921\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : blaofbhgbmeikidhlkmjhbkbfohpgekf
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : niapdbllcanepiiimjjndipklodoedlc
*************************
AdwCleaner[R0].txt - [10098 octets] - [21/08/2014 19:39:16]
AdwCleaner[S0].txt - [9426 octets] - [21/08/2014 19:40:22]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9486 octets] ########## JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by UliMx921 on 21.08.2014 at 19:45:58,17
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{ED6242A3-5D15-4557-BD56-B1C486765F61}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{ED6242A3-5D15-4557-BD56-B1C486765F61}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\cloud software ltd"
Successfully deleted: [Folder] "C:\Program Files (x86)\justbrowse"
Successfully deleted: [Empty Folder] C:\Users\UliMx921\appdata\local\{FD70A85E-50E0-4D51-A710-F439535471A2}
~~~ FireFox
Emptied folder: C:\Users\UliMx921\AppData\Roaming\mozilla\firefox\profiles\wbnsoi44.default\minidumps [6 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.08.2014 at 19:53:27,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und das neue FRST.txt:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2014 01
Ran by UliMx921 (administrator) on ULIMX921-HP on 21-08-2014 19:54:05
Running from C:\Users\UliMx921\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
() C:\Windows\vsnpstd3.exe
(Badoo) C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe
(Spotify Ltd) C:\Users\UliMx921\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
() C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [827392 2006-09-19] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-05-06] (PDF Complete Inc)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-08-11] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-08-05] (Hewlett-Packard)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
HKU\S-1-5-21-351139012-3454371372-141882758-1000\...\Run: [Badoo Desktop] => C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [1067232 2012-12-24] (Badoo)
HKU\S-1-5-21-351139012-3454371372-141882758-1000\...\Run: [Spotify Web Helper] => C:\Users\UliMx921\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104280 2013-03-29] (Spotify Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA1100 Setup-Assistent.lnk
ShortcutTarget: NETGEAR WNA1100 Setup-Assistent.lnk -> C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://badoo.com/startpage/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK/4
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM - {ED6242A3-5D15-4557-BD56-B1C486765F61} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\UliMx921\AppData\Roaming\Mozilla\Firefox\Profiles\wbnsoi44.default
FF Homepage: hxxp://www.ebay.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\UliMx921\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\UliMx921\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\UliMx921\AppData\Roaming\Mozilla\Firefox\Profiles\wbnsoi44.default\searchplugins\badoo.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DownloadHelper - C:\Users\UliMx921\AppData\Roaming\Mozilla\Firefox\Profiles\wbnsoi44.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-08-15]
Chrome:
=======
CHR HomePage: hxxp://google.de/
CHR StartupUrls: "hxxp://google.de/"
CHR Plugin: (Shockwave Flash) - C:\Users\UliMx921\AppData\Local\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\UliMx921\AppData\Local\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\UliMx921\AppData\Local\Google\Chrome\Application\36.0.1985.143\pdf.dll ()
CHR Plugin: (Norton Confidential) - C:\Users\UliMx921\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\6.0.2_0\npcoplgn.dll No File
CHR Plugin: (Windows Live? Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\UliMx921\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File
CHR Extension: (Google Drive) - C:\Users\UliMx921\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-16]
CHR Extension: (YouTube) - C:\Users\UliMx921\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-16]
CHR Extension: (Google-Suche) - C:\Users\UliMx921\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-16]
CHR Extension: (Google Wallet) - C:\Users\UliMx921\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-08]
CHR Extension: (Google Mail) - C:\Users\UliMx921\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-16]
CHR HKCU\...\Chrome\Extension: [oolkekjjhnaeaahibbnfebmogackofpf] - C:\Users\UliMx921\AppData\Local\CRE\oolkekjjhnaeaahibbnfebmogackofpf.crx [2013-03-27]
CHR HKLM-x32\...\Chrome\Extension: [oolkekjjhnaeaahibbnfebmogackofpf] - C:\Users\UliMx921\AppData\Local\CRE\oolkekjjhnaeaahibbnfebmogackofpf.crx [2013-03-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-08-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-11] (AVG Technologies CZ, s.r.o.)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2185528 2014-04-15] (AVG)
R2 WSWNA1100; C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe [266240 2010-08-04] () [File not signed]
S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2012-03-26] (Apple Inc.) [File not signed]
S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10550272 2007-03-27] (Sonix Co. Ltd.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-03-26] (TuneUp Software)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [53760 2012-09-28] (Apple, Inc.) [File not signed]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-21 19:53 - 2014-08-21 19:53 - 00001436 _____ () C:\Users\UliMx921\Desktop\JRT.txt
2014-08-21 19:45 - 2014-08-21 19:45 - 00009594 _____ () C:\Users\UliMx921\Desktop\AdwCleaner[S0].txt
2014-08-21 19:45 - 2014-08-21 19:45 - 00000000 ____D () C:\Windows\ERUNT
2014-08-21 19:39 - 2014-08-21 19:40 - 00000000 ____D () C:\AdwCleaner
2014-08-21 19:39 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-21 19:35 - 2014-08-21 19:35 - 01016261 _____ (Thisisu) C:\Users\UliMx921\Desktop\JRT.exe
2014-08-21 19:32 - 2014-08-21 19:32 - 01364531 _____ () C:\Users\UliMx921\Desktop\adwcleaner_3.308.exe
2014-08-21 19:32 - 2014-08-21 19:32 - 00006153 _____ () C:\Users\UliMx921\Desktop\mbam.txt
2014-08-21 19:30 - 2014-08-21 19:30 - 00029224 _____ () C:\Users\UliMx921\Desktop\combofix.txt
2014-08-21 19:14 - 2014-08-21 19:44 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-21 19:13 - 2014-08-21 19:13 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:13 - 2014-08-21 19:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-21 19:13 - 2014-08-21 19:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:13 - 2014-08-21 19:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-21 19:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-21 19:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-21 19:10 - 2014-08-21 19:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\UliMx921\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-21 10:08 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-21 10:08 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-21 10:08 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-21 10:08 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-21 10:08 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-21 10:08 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-21 10:08 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-21 10:08 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-21 10:08 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-21 10:08 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-21 10:08 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-21 10:08 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-21 10:08 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-21 10:08 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-20 22:44 - 2014-08-20 22:47 - 00000000 ____D () C:\Users\UliMx921\Downloads\1 - Stall
2014-08-20 18:12 - 2014-08-20 18:12 - 00029215 _____ () C:\ComboFix.txt
2014-08-20 18:04 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-20 18:04 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-20 18:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-20 18:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-20 18:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-20 18:04 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-20 18:04 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-20 18:04 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-20 18:03 - 2014-08-20 18:12 - 00000000 ____D () C:\Qoobox
2014-08-20 18:03 - 2014-08-20 18:11 - 00000000 ____D () C:\Windows\erdnt
2014-08-20 17:57 - 2014-08-20 17:57 - 05572251 ____R (Swearware) C:\Users\UliMx921\Desktop\ComboFix.exe
2014-08-20 13:27 - 2014-08-20 13:27 - 00000902 _____ () C:\Windows\SysWOW64\InstallUtil.InstallLog
2014-08-20 12:16 - 2014-08-20 13:07 - 00008747 _____ () C:\Users\UliMx921\Desktop\avgrep.txt
2014-08-20 12:13 - 2014-08-20 12:13 - 00000000 ____D () C:\Windows\Minidump
2014-08-20 12:07 - 2014-08-20 12:07 - 00000631 _____ () C:\Users\UliMx921\Desktop\Gmer.txt
2014-08-20 11:17 - 2014-08-20 11:17 - 00380416 _____ () C:\Users\UliMx921\Desktop\Gmer-19357.exe
2014-08-20 11:16 - 2014-08-20 11:19 - 00037264 _____ () C:\Users\UliMx921\Desktop\Addition.txt
2014-08-20 11:15 - 2014-08-21 19:54 - 00016447 _____ () C:\Users\UliMx921\Desktop\FRST.txt
2014-08-20 11:15 - 2014-08-21 19:54 - 00000000 ____D () C:\FRST
2014-08-20 11:14 - 2014-08-20 11:14 - 02101760 _____ (Farbar) C:\Users\UliMx921\Desktop\FRST64.exe
2014-08-20 11:13 - 2014-08-20 11:13 - 00000478 _____ () C:\Users\UliMx921\Desktop\defogger_disable.log
2014-08-20 11:13 - 2014-08-20 11:13 - 00000000 _____ () C:\Users\UliMx921\defogger_reenable
2014-08-20 11:09 - 2014-08-20 11:09 - 00017960 _____ () C:\Users\UliMx921\Documents\Mappe1 (Automatisch gespeichert).xlsx
2014-08-20 11:06 - 2014-08-20 11:06 - 00050477 _____ () C:\Users\UliMx921\Desktop\Defogger.exe
2014-08-20 10:16 - 2014-08-20 10:16 - 18594480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-08-20 09:51 - 2014-08-21 19:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-20 09:51 - 2014-08-20 10:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-20 09:51 - 2014-08-20 09:51 - 00002168 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\Program Files (x86)\McAfee Security Scan
2014-08-20 09:36 - 2014-08-20 09:36 - 00000000 ____D () C:\Users\UliMx921\Downloads\padre
2014-08-19 21:19 - 2014-08-19 21:22 - 00000000 ____D () C:\Users\UliMx921\Downloads\ShinoKCR
2014-08-19 21:16 - 2014-08-19 21:16 - 00000000 ____D () C:\Users\UliMx921\Downloads\marilu
2014-08-19 21:02 - 2014-08-20 10:25 - 00000000 ____D () C:\Users\UliMx921\Downloads\~Monica~
2014-08-19 20:49 - 2014-08-19 20:50 - 00000000 ____D () C:\Users\UliMx921\Downloads\mirake
2014-08-19 20:32 - 2014-08-20 10:24 - 00000000 ____D () C:\Users\UliMx921\Downloads\steffor
2014-08-19 18:38 - 2014-08-19 19:45 - 00000000 ____D () C:\Users\UliMx921\Downloads\thesimsresource.com
2014-08-19 14:22 - 2014-08-19 14:22 - 00000000 ____D () C:\Users\UliMx921\Downloads\thevintagesim.blogspot.de
2014-08-19 14:04 - 2014-08-19 14:23 - 00000000 ____D () C:\Users\UliMx921\Downloads\beosboxboy.blogspot.de
2014-08-19 13:44 - 2014-08-19 13:45 - 00000000 ____D () C:\Users\UliMx921\Downloads\kunoichikatie.dreamwidth.org..21689.html
2014-08-18 11:21 - 2014-08-18 11:21 - 00000000 ____D () C:\Users\UliMx921\Downloads\www.simplystyling.de
2014-08-16 14:32 - 2014-08-16 14:33 - 00000000 ____D () C:\Users\UliMx921\Downloads\All4sims.de
2014-08-16 14:30 - 2014-08-16 14:30 - 01909992 _____ () C:\Users\UliMx921\Downloads\Buggybooz_KIA.rar
2014-08-15 03:03 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-15 03:03 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-15 03:03 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 03:03 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 03:03 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-15 03:03 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-15 03:03 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-15 03:03 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 19:35 - 2014-07-24 21:28 - 17861120 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-14 19:35 - 2014-07-24 21:12 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-14 19:35 - 2014-07-24 21:10 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-14 19:35 - 2014-07-24 21:07 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-14 19:35 - 2014-07-24 21:06 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-14 19:35 - 2014-07-24 21:05 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-14 19:35 - 2014-07-24 21:05 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-14 19:35 - 2014-07-24 21:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-14 19:35 - 2014-07-24 21:04 - 02155520 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-14 19:35 - 2014-07-24 21:04 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-14 19:35 - 2014-07-24 21:04 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-14 19:35 - 2014-07-24 21:04 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-14 19:35 - 2014-07-24 21:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-14 19:35 - 2014-07-24 21:04 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-14 19:35 - 2014-07-24 21:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-14 19:35 - 2014-07-24 21:03 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-14 19:35 - 2014-07-24 21:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-14 19:35 - 2014-07-24 21:03 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-14 19:35 - 2014-07-24 21:03 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-14 19:35 - 2014-07-24 21:03 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-14 19:35 - 2014-07-24 21:02 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-14 19:35 - 2014-07-24 20:07 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-14 19:35 - 2014-07-24 19:58 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-14 19:35 - 2014-07-24 19:57 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-14 19:35 - 2014-07-24 19:52 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-14 19:35 - 2014-07-24 19:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-14 19:35 - 2014-07-24 19:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-14 19:35 - 2014-07-24 19:50 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-08-14 19:35 - 2014-07-24 19:50 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-14 19:35 - 2014-07-24 19:49 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-14 19:35 - 2014-07-24 19:49 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-14 19:35 - 2014-07-24 19:49 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-14 19:35 - 2014-07-24 19:49 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-14 19:35 - 2014-07-24 19:49 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-14 19:35 - 2014-07-24 19:48 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-14 19:35 - 2014-07-24 19:48 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-14 19:35 - 2014-07-24 19:48 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-14 19:35 - 2014-07-24 19:48 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-14 19:35 - 2014-07-24 19:48 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-08-14 19:35 - 2014-07-24 19:48 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-08-14 19:35 - 2014-07-24 19:48 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-08-14 19:35 - 2014-07-24 19:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-14 19:35 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-14 19:35 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-14 19:35 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-14 19:35 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-14 19:35 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-14 19:35 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-14 19:35 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-14 19:35 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-14 19:35 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-14 19:35 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-14 19:35 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-14 19:35 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-14 19:34 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-14 19:34 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-14 19:34 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-14 19:34 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-14 19:34 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-14 19:34 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-14 19:34 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-14 19:34 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 19:34 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-14 19:34 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-14 19:34 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-14 19:34 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 19:34 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 19:34 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 19:34 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 19:34 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 19:34 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 19:34 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 19:34 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-07-25 17:58 - 2014-07-25 17:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-21 19:54 - 2014-08-20 11:15 - 00016447 _____ () C:\Users\UliMx921\Desktop\FRST.txt
2014-08-21 19:54 - 2014-08-20 11:15 - 00000000 ____D () C:\FRST
2014-08-21 19:53 - 2014-08-21 19:53 - 00001436 _____ () C:\Users\UliMx921\Desktop\JRT.txt
2014-08-21 19:50 - 2009-07-14 06:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-21 19:50 - 2009-07-14 06:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-21 19:45 - 2014-08-21 19:45 - 00009594 _____ () C:\Users\UliMx921\Desktop\AdwCleaner[S0].txt
2014-08-21 19:45 - 2014-08-21 19:45 - 00000000 ____D () C:\Windows\ERUNT
2014-08-21 19:44 - 2014-08-21 19:14 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-21 19:44 - 2012-02-16 11:09 - 00000000 ____D () C:\ProgramData\PDFC
2014-08-21 19:43 - 2013-04-11 03:19 - 00303584 _____ () C:\Windows\PFRO.log
2014-08-21 19:43 - 2013-04-08 22:09 - 00020294 _____ () C:\Windows\setupact.log
2014-08-21 19:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-21 19:42 - 2012-12-16 00:54 - 01334396 _____ () C:\Windows\WindowsUpdate.log
2014-08-21 19:40 - 2014-08-21 19:39 - 00000000 ____D () C:\AdwCleaner
2014-08-21 19:35 - 2014-08-21 19:35 - 01016261 _____ (Thisisu) C:\Users\UliMx921\Desktop\JRT.exe
2014-08-21 19:32 - 2014-08-21 19:32 - 01364531 _____ () C:\Users\UliMx921\Desktop\adwcleaner_3.308.exe
2014-08-21 19:32 - 2014-08-21 19:32 - 00006153 _____ () C:\Users\UliMx921\Desktop\mbam.txt
2014-08-21 19:30 - 2014-08-21 19:30 - 00029224 _____ () C:\Users\UliMx921\Desktop\combofix.txt
2014-08-21 19:26 - 2013-04-11 03:19 - 00275856 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-21 19:24 - 2012-12-16 01:52 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-351139012-3454371372-141882758-1000UA.job
2014-08-21 19:16 - 2014-08-20 09:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-21 19:13 - 2014-08-21 19:13 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:13 - 2014-08-21 19:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-21 19:13 - 2014-08-21 19:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:13 - 2014-08-21 19:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:12 - 2013-03-07 21:19 - 00000000 ____D () C:\ProgramData\MFAData
2014-08-21 19:10 - 2014-08-21 19:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\UliMx921\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-21 19:09 - 2012-12-16 01:01 - 00003954 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{B4831B8C-91D3-432E-AFEF-559F989D3C7C}
2014-08-21 10:02 - 2012-12-16 01:52 - 00001080 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-351139012-3454371372-141882758-1000Core.job
2014-08-20 22:47 - 2014-08-20 22:44 - 00000000 ____D () C:\Users\UliMx921\Downloads\1 - Stall
2014-08-20 22:37 - 2014-02-08 13:21 - 00003204 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForUliMx921
2014-08-20 22:37 - 2014-02-08 13:21 - 00000344 _____ () C:\Windows\Tasks\HPCeeScheduleForUliMx921.job
2014-08-20 18:17 - 2014-03-07 21:33 - 00000000 ____D () C:\Users\UliMx921\AppData\Roaming\SoftGrid Client
2014-08-20 18:12 - 2014-08-20 18:12 - 00029215 _____ () C:\ComboFix.txt
2014-08-20 18:12 - 2014-08-20 18:03 - 00000000 ____D () C:\Qoobox
2014-08-20 18:12 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-08-20 18:11 - 2014-08-20 18:03 - 00000000 ____D () C:\Windows\erdnt
2014-08-20 18:10 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-20 18:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-20 17:57 - 2014-08-20 17:57 - 05572251 ____R (Swearware) C:\Users\UliMx921\Desktop\ComboFix.exe
2014-08-20 15:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-20 13:27 - 2014-08-20 13:27 - 00000902 _____ () C:\Windows\SysWOW64\InstallUtil.InstallLog
2014-08-20 13:07 - 2014-08-20 12:16 - 00008747 _____ () C:\Users\UliMx921\Desktop\avgrep.txt
2014-08-20 12:13 - 2014-08-20 12:13 - 00000000 ____D () C:\Windows\Minidump
2014-08-20 12:13 - 2012-12-16 09:48 - 00287327 ____N () C:\Windows\Minidump\082014-26254-01.dmp
2014-08-20 12:07 - 2014-08-20 12:07 - 00000631 _____ () C:\Users\UliMx921\Desktop\Gmer.txt
2014-08-20 11:19 - 2014-08-20 11:16 - 00037264 _____ () C:\Users\UliMx921\Desktop\Addition.txt
2014-08-20 11:17 - 2014-08-20 11:17 - 00380416 _____ () C:\Users\UliMx921\Desktop\Gmer-19357.exe
2014-08-20 11:14 - 2014-08-20 11:14 - 02101760 _____ (Farbar) C:\Users\UliMx921\Desktop\FRST64.exe
2014-08-20 11:13 - 2014-08-20 11:13 - 00000478 _____ () C:\Users\UliMx921\Desktop\defogger_disable.log
2014-08-20 11:13 - 2014-08-20 11:13 - 00000000 _____ () C:\Users\UliMx921\defogger_reenable
2014-08-20 11:13 - 2012-12-16 00:55 - 00000000 ____D () C:\Users\UliMx921
2014-08-20 11:09 - 2014-08-20 11:09 - 00017960 _____ () C:\Users\UliMx921\Documents\Mappe1 (Automatisch gespeichert).xlsx
2014-08-20 11:06 - 2014-08-20 11:06 - 00050477 _____ () C:\Users\UliMx921\Desktop\Defogger.exe
2014-08-20 10:25 - 2014-08-19 21:02 - 00000000 ____D () C:\Users\UliMx921\Downloads\~Monica~
2014-08-20 10:24 - 2014-08-19 20:32 - 00000000 ____D () C:\Users\UliMx921\Downloads\steffor
2014-08-20 10:17 - 2014-08-20 09:51 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-20 10:17 - 2014-05-06 13:06 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-20 10:17 - 2012-02-16 11:05 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-20 10:16 - 2014-08-20 10:16 - 18594480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-08-20 09:51 - 2014-08-20 09:51 - 00002168 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-20 09:51 - 2014-08-20 09:51 - 00000000 ____D () C:\Program Files (x86)\McAfee Security Scan
2014-08-20 09:36 - 2014-08-20 09:36 - 00000000 ____D () C:\Users\UliMx921\Downloads\padre
2014-08-19 21:22 - 2014-08-19 21:19 - 00000000 ____D () C:\Users\UliMx921\Downloads\ShinoKCR
2014-08-19 21:16 - 2014-08-19 21:16 - 00000000 ____D () C:\Users\UliMx921\Downloads\marilu
2014-08-19 20:50 - 2014-08-19 20:49 - 00000000 ____D () C:\Users\UliMx921\Downloads\mirake
2014-08-19 19:45 - 2014-08-19 18:38 - 00000000 ____D () C:\Users\UliMx921\Downloads\thesimsresource.com
2014-08-19 14:23 - 2014-08-19 14:04 - 00000000 ____D () C:\Users\UliMx921\Downloads\beosboxboy.blogspot.de
2014-08-19 14:22 - 2014-08-19 14:22 - 00000000 ____D () C:\Users\UliMx921\Downloads\thevintagesim.blogspot.de
2014-08-19 13:45 - 2014-08-19 13:44 - 00000000 ____D () C:\Users\UliMx921\Downloads\kunoichikatie.dreamwidth.org..21689.html
2014-08-18 23:04 - 2013-01-21 21:20 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-08-18 23:04 - 2012-12-17 21:59 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-08-18 11:21 - 2014-08-18 11:21 - 00000000 ____D () C:\Users\UliMx921\Downloads\www.simplystyling.de
2014-08-16 14:33 - 2014-08-16 14:32 - 00000000 ____D () C:\Users\UliMx921\Downloads\All4sims.de
2014-08-16 14:30 - 2014-08-16 14:30 - 01909992 _____ () C:\Users\UliMx921\Downloads\Buggybooz_KIA.rar
2014-08-15 17:09 - 2012-12-16 01:52 - 00002335 _____ () C:\Users\UliMx921\Desktop\Google Chrome.lnk
2014-08-15 03:35 - 2014-05-06 13:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-15 03:02 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 19:35 - 2014-03-31 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-08-14 19:35 - 2014-03-16 15:58 - 00000983 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-08-07 04:06 - 2014-08-14 19:34 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-14 19:34 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-04 22:49 - 2013-01-10 13:19 - 00000000 ____D () C:\Users\UliMx921\AppData\Local\CrashDumps
2014-08-04 22:16 - 2012-12-17 14:37 - 00000000 ____D () C:\Users\UliMx921\AppData\Roaming\vlc
2014-07-30 18:04 - 2014-05-06 13:33 - 00000000 ____D () C:\Users\UliMx921\dwhelper
2014-07-30 18:02 - 2014-05-06 13:33 - 00000000 ____D () C:\Users\UliMx921\Downloads\Germany's Next Topmodel
2014-07-30 17:29 - 2013-12-27 19:58 - 00000000 ____D () C:\Users\UliMx921\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-27 12:25 - 2013-03-14 04:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-27 12:25 - 2013-03-14 04:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-27 12:23 - 2012-12-17 20:06 - 00000000 ____D () C:\Users\UliMx921\AppData\Roaming\uTorrent
2014-07-26 03:02 - 2013-03-14 04:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-25 17:58 - 2014-07-25 17:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-24 21:28 - 2014-08-14 19:35 - 17861120 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-24 21:12 - 2014-08-14 19:35 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-24 21:10 - 2014-08-14 19:35 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-24 21:07 - 2014-08-14 19:35 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-24 21:06 - 2014-08-14 19:35 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-24 21:05 - 2014-08-14 19:35 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-24 21:05 - 2014-08-14 19:35 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-07-24 21:05 - 2014-08-14 19:35 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-24 21:04 - 2014-08-14 19:35 - 02155520 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-24 21:04 - 2014-08-14 19:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-24 21:04 - 2014-08-14 19:35 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-24 21:04 - 2014-08-14 19:35 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-24 21:04 - 2014-08-14 19:35 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-24 21:04 - 2014-08-14 19:35 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-24 21:03 - 2014-08-14 19:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-24 21:03 - 2014-08-14 19:35 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-24 21:03 - 2014-08-14 19:35 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-24 21:03 - 2014-08-14 19:35 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-07-24 21:03 - 2014-08-14 19:35 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-07-24 21:03 - 2014-08-14 19:35 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-07-24 21:02 - 2014-08-14 19:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-24 20:07 - 2014-08-14 19:35 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-24 19:58 - 2014-08-14 19:35 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-24 19:57 - 2014-08-14 19:35 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-24 19:52 - 2014-08-14 19:35 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-24 19:51 - 2014-08-14 19:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-24 19:51 - 2014-08-14 19:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-24 19:50 - 2014-08-14 19:35 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-07-24 19:50 - 2014-08-14 19:35 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-24 19:49 - 2014-08-14 19:35 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-24 19:49 - 2014-08-14 19:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-24 19:49 - 2014-08-14 19:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-24 19:49 - 2014-08-14 19:35 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-24 19:49 - 2014-08-14 19:35 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-24 19:48 - 2014-08-14 19:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-24 19:48 - 2014-08-14 19:35 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-24 19:48 - 2014-08-14 19:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-24 19:48 - 2014-08-14 19:35 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-24 19:48 - 2014-08-14 19:35 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-07-24 19:48 - 2014-08-14 19:35 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-07-24 19:48 - 2014-08-14 19:35 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-07-24 19:47 - 2014-08-14 19:35 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
Some content of TEMP:
====================
C:\Users\UliMx921\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-20 15:47
==================== End Of Log ============================ --- --- ---
--- --- ---
Liebe Grüße,
Music.Junky
Hallo Schrauber,
ich bin ab morgen für 2 Wochen nicht erreichbar.
Ich melde mich wieder.
Nur, damit Du Bescheid weißt und Dich nicht wunderst,
wenn während dieser Zeit keine Antworten von mir kommen.
Liebe Grüße,
Musik.Junky |