Schmuckler | 18.09.2014 09:26 | Guten Morgen Schrauber.
Wieder Danke für deine Mühe.
Hier die Texte Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.09.2014
Suchlauf-Zeit: 08:18:18
Logdatei: Malewarebytes 18.09.2014.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.18.02
Rootkit Datenbank: v2014.09.15.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Rolf Börne
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 297621
Verstrichene Zeit: 8 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 26
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\APPID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}, , [23f7d31cdc9fc86e562cfbc6e91902fe],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}, , [e3379f50a7d45cda136e526fd0325ca4],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\esrv.BabylonESrvc.1, , [e3379f50a7d45cda136e526fd0325ca4],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\esrv.BabylonESrvc, , [e3379f50a7d45cda136e526fd0325ca4],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}, , [b76327c8fa818caa6e17c100e022db25],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\b, , [b76327c8fa818caa6e17c100e022db25],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6E8BF012-2C85-4834-B10A-1B31AF173D70}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{706D4A4B-184A-4434-B331-296B07493D2D}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8BE10F21-185F-4CA0-B789-9921674C3993}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{94C0B25D-3359-4B10-B227-F96A77DB773F}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B173667F-8395-4317-8DD6-45AD1FE00047}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B32672B3-F656-46E0-B584-FE61C0BB6037}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{BFE569F7-646C-4512-969B-9BE3E580D393}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C2996524-2187-441F-A398-CD6CB6B3D020}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E047E227-5342-4D94-80F7-CFB154BF55BD}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}, , [54c6599633487cbaf78c9d24c042ec14],
PUP.Optional.Babylon.A, HKU\S-1-5-21-4071752470-356845625-1869480124-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [73a7519ee794a78f47e5305730d21ce4],
PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}, , [6eac707fd2a9b5813b49c9f8fe045ca4],
PUP.Optional.Babylon.A, HKLM\SOFTWARE\BabylonToolbar, , [72a83eb16615270fff2c6de1729219e7],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4071752470-356845625-1869480124-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [23f715da2f4c93a328795def6f956799],
PUP.Optional.Softonic.A, HKU\S-1-5-21-4071752470-356845625-1869480124-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [8d8dbd32b5c643f38ae540e5db2821df],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4071752470-356845625-1869480124-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0N1L1H1E1U1N1TtG0T0A, , [23f715da2f4c93a328795def6f956799]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 3
PUP.Optional.DownloadGuide.A, C:\Users\Rolf Börne\AppData\Local\DownloadGuide, , [1bff48a7403bae88ca292a2dcd37ff01],
PUP.Optional.DownloadGuide.A, C:\Users\Rolf Börne\AppData\Local\DownloadGuide\Offers, , [1bff48a7403bae88ca292a2dcd37ff01],
PUP.Optional.PriceAlarm.A, C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab, , [fb1f45aa3348033376209c512cd69e62],
Dateien: 29
Malware.Trace, C:\Users\Rolf Börne\AppData\Roaming\Adobe\shed\thr1.chm, , [05151fd0126991a5155f9649c63dfe02],
Trojan.Agent, C:\Users\Rolf Börne\AppData\Roaming\597831.exe, , [a07aad4281fa4aec7db9b3637d87748c],
PUP.Optional.DownloadGuide.A, C:\Users\Rolf Börne\AppData\Local\DownloadGuide\amazon.ico, , [1bff48a7403bae88ca292a2dcd37ff01],
PUP.Optional.DownloadGuide.A, C:\Users\Rolf Börne\AppData\Local\DownloadGuide\medusa4_v5_1_2_windows_personal.exe, , [1bff48a7403bae88ca292a2dcd37ff01],
PUP.Optional.DownloadGuide.A, C:\Users\Rolf Börne\AppData\Local\DownloadGuide\medusa4_v5_1_2_windows_personal.exe_date, , [1bff48a7403bae88ca292a2dcd37ff01],
PUP.Optional.DownloadGuide.A, C:\Users\Rolf Börne\AppData\Local\DownloadGuide\Offers\vis-freeware.exe, , [1bff48a7403bae88ca292a2dcd37ff01],
PUP.Optional.PriceAlarm.A, C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html, , [fb1f45aa3348033376209c512cd69e62],
PUP.Optional.PriceAlarm.A, C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.js, , [fb1f45aa3348033376209c512cd69e62],
PUP.Optional.PriceAlarm.A, C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\fire.js, , [fb1f45aa3348033376209c512cd69e62],
PUP.Optional.PriceAlarm.A, C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\manifest.json, , [fb1f45aa3348033376209c512cd69e62],
PUP.Optional.PriceAlarm.A, C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\refire.js, , [fb1f45aa3348033376209c512cd69e62],
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.babylon.com/?AF=110000&babsrc=adbartrp&mntrId=c866ff2c00000000000094445243d390&q=");), ,[53c79a5508736ec80113a888818402fe]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), ,[3cdef0ffd2a99d9951f5d957b055ec14]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), ,[8a90e708fe7d53e34df9012f48bdca36]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110000");), ,[8793bc33cab191a50a3c86aa49bc47b9]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.hardId", "c866ff2c00000000000094445243d390");), ,[9c7edb14f08b21157ccabb75798cdd23]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.id", "c866ff2c00000000000094445243d390");), ,[a67429c69be0979fca7c29076c9947b9]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlDay", "15381");), ,[b268b936592256e02026ff31f80d5ea2]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), ,[3cde44abde9d6bcbf84eb57b41c437c9]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", true);), ,[c951ec03f38865d13a0c0d23f70ed030]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?AF=110000&babsrc=NT_ss&mntrId=c866ff2c00000000000094445243d390");), ,[65b5707fd0ab7fb710361c1434d1b14f]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), ,[0713589786f5072f172fec44f70e3bc5]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), ,[4dcd00efed8eca6c2a1c9799957017e9]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), ,[a179ce21bcbf0d2993b31d1319ec936d]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), ,[51c9ba357dfe78bed373c46c48bdf907]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");), ,[63b71bd4077473c324224ce462a335cb]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), ,[a971cb241566d85e16307bb538cd11ef]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1712:36:10");), ,[5ebc955a26551a1cb195003026dfcd33]
PUP.Optional.Babylon.A, C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), ,[8298a44ba7d478be5aec032d0005b050]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.310 - Bericht erstellt am 18/09/2014 um 08:43:51
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Rolf Börne - ROLFBÖRNE-PC
# Gestartet von : C:\Users\Rolf Börne\Desktop\Trojaner Board\AdwCleaner_3.310.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\Common Files\Plasmoo
Ordner Gelöscht : C:\Users\Rolf Börne\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\Rolf Börne\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Rolf Börne\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Rolf Börne\AppData\Roaming\dvdvideosoftiehelpers
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\babylon.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\registrybooster_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\registrybooster_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_a9cad_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_a9cad_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_abbyy-finereader_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_abbyy-finereader_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_archery-3d_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_archery-3d_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_nitro-pdf-reader_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_nitro-pdf-reader_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_passbildgenerator_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_passbildgenerator_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{0C58B7D1-D415-492B-A149-E976156BD3B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v32.0.1 (x86 de)
[ Datei : C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\prefs.js ]
Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Zeile gelöscht : user_pref("browser.search.order.1", "Search the web (Babylon)");
-\\ Google Chrome v
[ Datei : C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [6042 octets] - [18/09/2014 08:40:34]
AdwCleaner[S0].txt - [5880 octets] - [18/09/2014 08:43:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5940 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.6 (09.18.2014:1)
OS: Windows 7 Home Premium x86
Ran by Rolf B”rne on 18.09.2014 at 9:16:18,45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sbregrebootcleaner
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Rolf B”rne\AppData\Roaming\getrighttogo"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Emptied folder: C:\Users\Rolf B”rne\AppData\Roaming\mozilla\firefox\profiles\xfh3925w.default\minidumps [37 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.09.2014 at 9:18:02,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2014
Ran by Rolf Börne (administrator) on ROLFBÖRNE-PC on 18-09-2014 10:13:56
Running from C:\Users\Rolf Börne\Desktop\Trojaner Board
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVM Berlin) C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Robert McNeel & Associates) C:\Program Files\McNeelUpdate\5.0\McNeelUpdateService.exe
(Nitro PDF Software) C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
(Sunbelt Software) C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
(Sunbelt Software) C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Tablet Driver) C:\Windows\System32\drivers\WTSrv.exe
(X10) C:\Program Files\Common Files\X10\Common\X10nets.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Tablet Driver) C:\Windows\System32\WTClient.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Sunbelt Software) C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
(AVM Berlin) C:\Program Files\FRITZ!DSL\FwebProt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVM Berlin) C:\Program Files\FRITZ!DSL\StCenter.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-12-03] (Realtek Semiconductor)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\Run: [WTClient] => C:\Windows\system32\WTClient.exe [32768 2010-08-31] (Tablet Driver)
HKLM\...\Run: [FreePDF Assistant] => C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [TkBellExe] => c:\program files\real\realplayer\Update\realsched.exe [273544 2011-07-13] (RealNetworks, Inc.)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [SBAMTray] => C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe [1357136 2011-09-06] (Sunbelt Software)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-08-11] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-4071752470-356845625-1869480124-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-4071752470-356845625-1869480124-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk
ShortcutTarget: FRITZ!DSL Protect.lnk -> C:\Program Files\FRITZ!DSL\FwebProt.exe (AVM Berlin)
Startup: C:\Users\Rolf Börne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live Toolbar Helper -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKCU - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Winsock: Catalog5 08 C:\Program Files\FRITZ!DSL\\sarah.dll [28472] (AVM Berlin)
Winsock: Catalog9 01 C:\Program Files\FRITZ!DSL\\sarah.dll [28472] (AVM Berlin)
Winsock: Catalog9 02 C:\Program Files\FRITZ!DSL\\sarah.dll [28472] (AVM Berlin)
Winsock: Catalog9 03 C:\Program Files\FRITZ!DSL\\sarah.dll [28472] (AVM Berlin)
Winsock: Catalog9 15 C:\Program Files\FRITZ!DSL\\sarah.dll [28472] (AVM Berlin)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default
FF DefaultSearchEngine: Startpage HTTPS - Deutsch
FF SelectedSearchEngine: Startpage HTTPS - Deutsch
FF Homepage: https://startpage.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=12.0.1.647 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=12.0.1.647 -> c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=12.0.1.647 -> c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: NitroPDF -> C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF SearchPlugin: C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\searchplugins\googlede.xml
FF SearchPlugin: C:\Users\Rolf Börne\AppData\Roaming\Mozilla\Firefox\Profiles\xfh3925w.default\searchplugins\startpage-https---deutsch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-07-13]
Chrome:
=======
CHR CustomProfile: C:\Users\Rolf Börne\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2011-07-13]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 IGDCTRL; C:\Program Files\FRITZ!DSL\IGDCTRL.EXE [73528 2009-07-28] (AVM Berlin)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 McNeelUpdate; C:\Program Files\McNeelUpdate\5.0\McNeelUpdateService.exe [68192 2013-12-13] (Robert McNeel & Associates)
R2 NitroReaderDriverReadSpool2; C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe [196912 2011-06-21] (Nitro PDF Software)
R2 SBAMSvc; C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe [2804280 2011-09-06] (Sunbelt Software)
R2 SBPIMSvc; C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe [181584 2011-09-06] (Sunbelt Software)
R2 WinTabService; C:\Windows\System32\Drivers\WTSRV.EXE [73728 2010-08-31] (Tablet Driver) [File not signed]
R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed]
S4 OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AtiHdmiService; C:\Windows\System32\drivers\AtiHdmi.sys [100352 2010-01-28] (ATI Technologies, Inc.) [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-09-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1558368 2010-02-04] (NXP Semiconductors Germany GmbH)
R3 PTSimBus; C:\Windows\System32\DRIVERS\PTSimBus.sys [23208 2009-06-22] (PenTablet Driver)
S3 PTSimHid; C:\Windows\System32\DRIVERS\PTSimHid.sys [14504 2009-06-22] (PenTablet Driver)
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [86824 2008-10-21] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-10-21] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [114600 2008-10-21] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [108328 2008-10-21] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [26024 2008-10-21] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [104616 2008-10-21] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [109736 2008-10-21] (MCCI Corporation)
R2 sbapifs; C:\Windows\System32\DRIVERS\sbapifs.sys [74456 2011-08-29] (Sunbelt Software)
R1 SBRE; C:\Windows\system32\drivers\SBREdrv.sys [101720 2011-08-29] (Sunbelt Software)
R1 SbTis; C:\Windows\System32\drivers\sbtis.sys [78936 2011-04-05] (Sunbelt Software, Inc.)
S3 TClass2k; C:\Windows\System32\DRIVERS\TClass2k.sys [23208 2009-06-22] (Tablet Driver)
S3 UCTblHid; C:\Windows\System32\DRIVERS\UCTblHid.sys [19624 2009-06-22] (Tablet Driver)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13720 2009-05-13] (X10 Wireless Technology, Inc.)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27160 2009-05-13] (X10 Wireless Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\ROLFBR~1\AppData\Local\Temp\catchme.sys [X]
S3 Tablet2k; "%SystemRoot%\System32\Drivers\Tablet2k.sys" [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-18 09:43 - 2014-09-18 09:43 - 01097728 _____ (Farbar) C:\Users\Rolf Börne\Downloads\FRST.exe
2014-09-18 09:16 - 2014-09-18 09:16 - 00000000 ____D () C:\Windows\ERUNT
2014-09-18 08:40 - 2014-09-18 08:44 - 00000000 ____D () C:\AdwCleaner
2014-09-18 08:15 - 2014-09-18 09:59 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-18 08:02 - 2014-09-18 08:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-18 08:02 - 2014-09-18 08:02 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-18 08:02 - 2014-09-18 08:02 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-18 08:02 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-18 08:02 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-18 08:02 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-17 09:14 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-17 09:14 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-17 09:14 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-17 09:14 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-17 09:14 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-17 09:14 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-17 09:14 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-17 09:14 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-17 09:13 - 2014-09-17 09:37 - 00000000 ____D () C:\Windows\erdnt
2014-09-17 09:13 - 2014-09-17 09:37 - 00000000 ____D () C:\Qoobox
2014-09-17 08:18 - 2014-09-17 08:18 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-09-17 08:17 - 2014-09-17 08:17 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Rolf Börne\Downloads\revosetup95.exe
2014-09-16 11:18 - 2014-09-18 08:39 - 00002047 _____ () C:\Users\Rolf Börne\Desktop\Neues Textdokument.txt
2014-09-16 11:13 - 2014-09-18 10:13 - 00000000 ____D () C:\Users\Rolf Börne\Desktop\Trojaner Board
2014-09-16 11:05 - 2014-09-18 10:14 - 00000000 ____D () C:\FRST
2014-09-16 11:03 - 2014-09-16 11:03 - 00000000 _____ () C:\Users\Rolf Börne\defogger_reenable
2014-09-16 09:15 - 2014-09-16 12:26 - 00503235 _____ () C:\Users\Rolf Börne\Desktop\Jarosch Ring 3d2.1 Längs.3dm
2014-09-16 09:15 - 2014-09-16 09:15 - 00547329 _____ () C:\Users\Rolf Börne\Desktop\Jarosch Ring 3d2.1 Längs.3dmbak
2014-09-10 11:36 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-10 11:36 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-10 11:36 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-10 11:36 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-10 11:36 - 2014-08-18 23:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-10 11:36 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-10 11:36 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-10 11:36 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-10 11:36 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-10 11:36 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-10 11:36 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-10 11:36 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-10 11:36 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-10 11:36 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-10 11:36 - 2014-08-18 23:36 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-10 11:36 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-10 11:36 - 2014-08-18 23:30 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-10 11:36 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-10 11:36 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-10 11:36 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-10 11:36 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-10 11:36 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-10 11:36 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-10 11:36 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-10 11:36 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-10 11:36 - 2014-08-18 23:08 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-10 11:36 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-10 11:36 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-10 11:36 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-10 11:36 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-10 11:25 - 2014-09-10 11:25 - 00000000 ____D () C:\ProgramData\ATI
2014-09-10 11:25 - 2014-09-10 11:25 - 00000000 ____D () C:\Program Files\AMD AVT
2014-09-10 11:24 - 2014-09-10 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-09-10 10:12 - 2014-07-07 03:40 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-10 10:12 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-09 11:31 - 2014-09-09 11:31 - 11683699 _____ () C:\Users\Rolf Börne\Downloads\Studio_HDR_giveaway_by_zbyg.zip
2014-08-28 08:07 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 08:07 - 2014-08-23 02:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 11:24 - 2014-08-21 11:24 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Roaming\Buhl Data Service
2014-08-21 11:23 - 2014-08-21 11:23 - 00002005 _____ () C:\Users\Rolf Börne\Desktop\Mein Verein.lnk
2014-08-21 11:23 - 2014-08-21 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mein Verein
2014-08-21 11:22 - 2014-08-21 11:23 - 00000000 ____D () C:\ProgramData\Buhl Data Service GmbH
2014-08-21 11:22 - 2014-08-21 11:22 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Local\Buhl Data Service
2014-08-21 11:22 - 2014-08-21 11:22 - 00000000 ____D () C:\Program Files\Buhl
2014-08-21 11:22 - 2002-08-23 10:00 - 04082688 _____ (Borland Software Corporation) C:\Windows\system32\qtintf70.dll
2014-08-21 11:19 - 2014-08-21 11:20 - 90900792 _____ () C:\Users\Rolf Börne\Downloads\MV2015Trial.exe
2014-08-21 11:13 - 2014-08-21 11:13 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Local\J._Göldenitz_Software
2014-08-21 10:45 - 2014-09-05 13:14 - 00000000 ____D () C:\Users\Rolf Börne\Documents\JoGoVEREIN
2014-08-21 10:45 - 2014-08-21 10:45 - 00002721 _____ () C:\Users\Public\Desktop\JoGoVEREIN.lnk
2014-08-21 10:45 - 2014-08-21 10:45 - 00002715 _____ () C:\Users\Public\Desktop\JoGoLISTE.lnk
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ihr Firmenname
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files\JoGoVEREIN
2014-08-21 10:43 - 2014-08-21 10:43 - 08995629 _____ () C:\Users\Rolf Börne\Downloads\JoGoVEREIN-Setup.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-18 10:14 - 2014-09-16 11:05 - 00000000 ____D () C:\FRST
2014-09-18 10:13 - 2014-09-16 11:13 - 00000000 ____D () C:\Users\Rolf Börne\Desktop\Trojaner Board
2014-09-18 10:13 - 2010-07-14 09:38 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Roaming\FRITZ!
2014-09-18 10:05 - 2009-07-14 06:34 - 00009888 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-18 10:05 - 2009-07-14 06:34 - 00009888 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-18 09:59 - 2014-09-18 08:15 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-18 09:59 - 2011-03-04 09:50 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-18 09:59 - 2010-07-14 09:38 - 02597471 _____ () C:\Users\Rolf Börne\DesktopStCenter.txt
2014-09-18 09:58 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-18 09:58 - 2009-07-14 06:39 - 00090996 _____ () C:\Windows\setupact.log
2014-09-18 09:57 - 2010-07-12 11:19 - 01059961 _____ () C:\Windows\WindowsUpdate.log
2014-09-18 09:44 - 2014-04-28 10:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-18 09:43 - 2014-09-18 09:43 - 01097728 _____ (Farbar) C:\Users\Rolf Börne\Downloads\FRST.exe
2014-09-18 09:24 - 2011-03-04 09:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-18 09:16 - 2014-09-18 09:16 - 00000000 ____D () C:\Windows\ERUNT
2014-09-18 08:45 - 2010-03-05 15:11 - 00026208 _____ () C:\Windows\PFRO.log
2014-09-18 08:44 - 2014-09-18 08:40 - 00000000 ____D () C:\AdwCleaner
2014-09-18 08:39 - 2014-09-16 11:18 - 00002047 _____ () C:\Users\Rolf Börne\Desktop\Neues Textdokument.txt
2014-09-18 08:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Speech
2014-09-18 08:02 - 2014-09-18 08:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-18 08:02 - 2014-09-18 08:02 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-18 08:02 - 2014-09-18 08:02 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-17 11:49 - 2013-12-10 11:07 - 00000000 ____D () C:\Jarosch ring
2014-09-17 09:37 - 2014-09-17 09:13 - 00000000 ____D () C:\Windows\erdnt
2014-09-17 09:37 - 2014-09-17 09:13 - 00000000 ____D () C:\Qoobox
2014-09-17 09:37 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-09-17 09:35 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-09-17 09:22 - 2009-07-14 04:03 - 58720256 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-09-17 09:22 - 2009-07-14 04:03 - 19660800 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-09-17 09:22 - 2009-07-14 04:03 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-09-17 09:22 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-09-17 09:22 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-09-17 08:18 - 2014-09-17 08:18 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-09-17 08:17 - 2014-09-17 08:17 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Rolf Börne\Downloads\revosetup95.exe
2014-09-17 08:13 - 2012-04-26 10:48 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-09-16 12:26 - 2014-09-16 09:15 - 00503235 _____ () C:\Users\Rolf Börne\Desktop\Jarosch Ring 3d2.1 Längs.3dm
2014-09-16 11:03 - 2014-09-16 11:03 - 00000000 _____ () C:\Users\Rolf Börne\defogger_reenable
2014-09-16 11:03 - 2010-07-12 11:19 - 00000000 ____D () C:\Users\Rolf Börne
2014-09-16 10:56 - 2014-02-19 12:22 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-09-16 09:15 - 2014-09-16 09:15 - 00547329 _____ () C:\Users\Rolf Börne\Desktop\Jarosch Ring 3d2.1 Längs.3dmbak
2014-09-16 08:11 - 2009-07-14 06:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-13 13:18 - 2011-08-20 09:19 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Roaming\DVDVideoSoft
2014-09-13 13:18 - 2011-06-16 21:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-09-13 13:18 - 2011-06-16 21:37 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2014-09-13 13:18 - 2011-06-16 21:37 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-09-13 12:50 - 2014-02-19 11:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeOCR
2014-09-13 12:47 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-09-13 12:45 - 2010-03-05 15:58 - 00000000 ____D () C:\Program Files\Windows Live
2014-09-13 12:43 - 2013-05-27 08:54 - 00000000 ____D () C:\Program Files\Passbild-Drucker 1
2014-09-13 12:42 - 2010-07-13 09:31 - 00000000 ____D () C:\Program Files\Google
2014-09-13 12:40 - 2011-03-03 12:18 - 00000000 ____D () C:\Program Files\Amazon
2014-09-10 12:46 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-09-10 12:05 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-09-10 11:44 - 2014-07-14 19:44 - 17328816 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-10 11:44 - 2013-03-12 17:33 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-10 11:44 - 2011-06-17 08:03 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-10 11:35 - 2013-08-15 10:43 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-10 11:31 - 2010-03-05 15:29 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-10 11:29 - 2010-03-05 14:50 - 01648250 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-10 11:25 - 2014-09-10 11:25 - 00000000 ____D () C:\ProgramData\ATI
2014-09-10 11:25 - 2014-09-10 11:25 - 00000000 ____D () C:\Program Files\AMD AVT
2014-09-10 11:25 - 2014-02-27 14:59 - 00000000 ____D () C:\ProgramData\AMD
2014-09-10 11:24 - 2014-09-10 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-09-10 11:24 - 2011-09-08 08:54 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-09-10 11:14 - 2014-02-27 14:48 - 00000000 ____D () C:\AMD
2014-09-09 11:31 - 2014-09-09 11:31 - 11683699 _____ () C:\Users\Rolf Börne\Downloads\Studio_HDR_giveaway_by_zbyg.zip
2014-09-05 13:14 - 2014-08-21 10:45 - 00000000 ____D () C:\Users\Rolf Börne\Documents\JoGoVEREIN
2014-09-04 12:55 - 2013-11-27 16:47 - 00000000 ____D () C:\Users\Rolf Börne\Desktop\Jarosch ring
2014-09-04 12:53 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-01 08:22 - 2009-07-14 06:33 - 00416584 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-23 03:46 - 2014-08-28 08:07 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 02:42 - 2014-08-28 08:07 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 11:24 - 2014-08-21 11:24 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Roaming\Buhl Data Service
2014-08-21 11:24 - 2010-07-12 11:20 - 00111176 _____ () C:\Users\Rolf Börne\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-21 11:23 - 2014-08-21 11:23 - 00002005 _____ () C:\Users\Rolf Börne\Desktop\Mein Verein.lnk
2014-08-21 11:23 - 2014-08-21 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mein Verein
2014-08-21 11:23 - 2014-08-21 11:22 - 00000000 ____D () C:\ProgramData\Buhl Data Service GmbH
2014-08-21 11:22 - 2014-08-21 11:22 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Local\Buhl Data Service
2014-08-21 11:22 - 2014-08-21 11:22 - 00000000 ____D () C:\Program Files\Buhl
2014-08-21 11:20 - 2014-08-21 11:19 - 90900792 _____ () C:\Users\Rolf Börne\Downloads\MV2015Trial.exe
2014-08-21 11:13 - 2014-08-21 11:13 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Local\J._Göldenitz_Software
2014-08-21 10:45 - 2014-08-21 10:45 - 00002721 _____ () C:\Users\Public\Desktop\JoGoVEREIN.lnk
2014-08-21 10:45 - 2014-08-21 10:45 - 00002715 _____ () C:\Users\Public\Desktop\JoGoLISTE.lnk
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ihr Firmenname
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files\JoGoVEREIN
2014-08-21 10:44 - 2011-04-11 16:43 - 00000000 ____D () C:\Users\Rolf Börne\AppData\Local\Downloaded Installations
2014-08-21 10:43 - 2014-08-21 10:43 - 08995629 _____ () C:\Users\Rolf Börne\Downloads\JoGoVEREIN-Setup.exe
2014-08-19 19:39 - 2014-09-10 11:36 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-19 00:26 - 2014-09-10 11:36 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-19 00:08 - 2014-09-10 11:36 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
Some content of TEMP:
====================
C:\Users\Rolf Börne\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-16 10:26
==================== End Of Log ============================ --- --- ---
--- --- ---
:dankeschoen:
Hoffe du hast einen guten Tag.
Mit freundlichen Grüßen |