LennardR | 26.07.2013 11:49 | okidoki. hier hätten wir also schon mal die JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.2 (07.22.2013:2)
OS: Windows 7 Home Premium x64
Ran by Lennard on 26.07.2013 at 12:31:42,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Bar
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\\Default
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{38ADCC79-E997-4394-A052-14FAAB20EB96}
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho2338.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3FCA.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoBA94.tmp
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{0006D237-1A46-4049-A904-CF217B23B537}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{0AB6B3AC-C367-414B-8DA9-26008E8B0283}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{0E3CDFAF-C798-4C70-98B5-5075D6619D2A}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{10953D7A-5F53-4D2C-AA31-7D2394154853}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{182B96CE-574B-4032-92DF-F912BF2B24BB}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{1BE715F8-964B-4767-8C3F-9A4DA54FC301}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{1CF99B6C-AA2A-46D7-BBD9-C4F3FFE5D13F}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{23BABA11-9B84-47F8-925C-59790854BB2A}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{28AEF81E-5C69-46C2-874D-80C6CEDEDF45}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{293A72B2-DAF8-4977-ADD9-FCB27C47C410}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{2DF831AA-5501-421D-8704-ADF3D4524CC9}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{2E0C289F-A958-4E7E-8A8D-18CB7FE2FF59}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{2EC452F9-475D-444C-8CDD-CAE534ED1A1D}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{340896D0-C16A-4501-B631-B2E0FA6B116A}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{3ED5E531-3F05-439F-A597-96BF3C8FD44F}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{409BE307-212F-41DC-8BBB-1E44960F471E}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{4108605A-64D4-42E6-B05C-A9EE585B24F9}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{419A87A1-40E7-43D5-B993-D13CAA0FDB42}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{4759106A-FD16-4B8E-91AA-6D20DBF2482E}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{4D29861C-080B-4A04-AA4F-B72526F16DDF}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{4FC1939A-C5DF-45BC-9C54-3A5511CE6B83}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{54784A93-92D5-4F10-AF2C-8A6D747BA7A7}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{547FF6BA-BC51-4E96-A355-7575F97DE303}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{5B168B9E-5834-4AAD-B235-8E0469E94FD9}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{605F19AB-89AD-4D90-8A2D-203A59945BFA}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{60C27853-19F0-4441-BD04-03BDFF05D7A7}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{623E3DC7-1A55-475F-9EBA-7FA109C97D9F}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{6743E078-B905-458B-BCFD-D45F5464B113}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{6760C65B-FE9E-4F89-9266-637B47E95A76}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{6C066D8C-5F3B-499E-80B4-B2163C4800A0}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{6CAD7DBE-A53B-40FF-AE97-CD20A7AB0CF1}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{70FEF10D-08A5-4E63-9D3C-089A37F78F76}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{7A3243AB-4332-4F57-8380-8F29001DD642}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{7D12FBFE-10D1-43FB-8417-8A2CD434E79D}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{851A2E02-ECC3-4369-A307-437C5FC465A4}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{853B2F6D-00BD-43A0-BCC8-7D0F5D9A21EF}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{87C9F18D-1DA8-4BCD-A7B2-92C76DD1EFE0}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{8A239745-9084-42E9-9348-E7A98FDF574C}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{8D1949F5-8773-408A-A19D-57F0C0D46C8B}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{8E42B55B-1132-477B-85B3-5021837DBE9A}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{8E67F500-6884-4A69-A031-80A102CE2956}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{8EB390FE-F4E9-4F21-860B-F35F124FFAD1}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{96129861-DAB9-43A2-B009-C3B2242837BE}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{97EAE7F9-E503-408F-939D-EB55A93EB780}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{984DB3AE-D8B4-4144-8895-AEB3077D6996}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{98C71538-5216-46FE-ADDD-5F27A500EC59}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{9CCACDFA-CA59-49CA-ACB3-C865A0D761BF}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{9E42F0EF-140A-46C6-9334-0B3AA1D21C22}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{A6E59116-415C-4C03-B318-BEE4D71C0033}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{A7AA3AD4-8269-4D42-8DB5-4AB234F71F87}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{AF9BBB47-E6A3-4041-A1F7-28E5608D3B18}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{B3908F7D-D2E6-4B5E-9726-FC3D2742373A}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{B550521E-C69B-4F5B-B0D8-5A7495BAD6F3}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{C0041D96-C350-48C7-87FB-854B3422C2EE}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{C46E19EA-F1F3-4C36-B778-8A10A759684D}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{D6907372-9B65-43DF-A3F2-9765D02D286B}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{DD62FD71-C64C-4438-90D9-D7C3BD5EA828}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{E21758FA-853E-4C3C-9EE9-9A4C56C535E5}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{E65ED59D-CE51-4C9C-AB3A-4C43E01F1E63}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{E7722A6C-7333-45BC-B454-A6F2073774F2}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{ECE59B16-5EEE-406F-B46F-751FFE5C049E}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{F118D7C8-6F02-4DB5-A434-7039201A7E9D}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{F16DF0DD-587A-4E21-A94F-60990E307CA4}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{F3921047-8E86-4EFB-92CE-743574573E99}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{F7280E9C-7936-4F6C-8738-00FB6DA6AE7B}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{F8B738BE-D8C1-48A0-A841-F938A3FB0B84}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{F8BA2410-8833-4AB0-B34D-BD92883819C8}
Successfully deleted: [Empty Folder] C:\Users\Lennard\appdata\local\{FD8D7502-DC95-46C2-81C7-5F357BDAEB35}
~~~ FireFox
Successfully deleted: [File] C:\Users\Lennard\AppData\Roaming\mozilla\firefox\profiles\xahpfm2h.default\invalidprefs.js
Successfully deleted the following from C:\Users\Lennard\AppData\Roaming\mozilla\firefox\profiles\xahpfm2h.default\prefs.js
user_pref("extensions.defaulttab.active.affiliate", 3802);
user_pref("extensions.defaulttab.active.overridechromesearch", false);
user_pref("extensions.defaulttab.active.overridekeywordsearch", false);
user_pref("extensions.defaulttab.browserID", "32EC969F58152750B70C9CB50F5B4867");
user_pref("extensions.defaulttab.firstrun", false);
user_pref("extensions.defaulttab.installedVersion", "2.0");
user_pref("iminent.webbooster.scripts.minibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
user_pref("iminent.webbooster.scripts.minibar.ShowThankyouPixel", "0");
user_pref("iminent.webbooster.scripts.minibar.displayFavLinks", "1");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent109", "1368200053351");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent111", "1368200053355");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent122", "1368200053358");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent134", "1368201043679");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent140", "1368203616346");
user_pref("iminent.webbooster.scripts.sslminibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
user_pref("iminent.webbooster.scripts.sslminibar.ShowThankyouPixel", "0");
user_pref("iminent.webbooster.scripts.sslminibar.displayFavLinks", "1");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent102", "1368199308956");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent109", "1369848580962");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent110", "1368217499788");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent111", "1369848580964");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent112", "1369848587480");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent122", "1369848580965");
Emptied folder: C:\Users\Lennard\AppData\Roaming\mozilla\firefox\profiles\xahpfm2h.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.07.2013 at 12:35:45,35
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.log kommt gleich.... ;)
Und hier die FRST.txt....allerdings hat das mit dem herunterladen der aktuellsten version nicht geklappt, so dass es die version ist, die ich auch vor 5 tagen benutzte (ausm märz dieses jahres glaub ich war die) Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-07-2013 (ATTENTION: FRST version is 7 days old)
Ran by Lennard (administrator) on 26-07-2013 12:44:25
Running from C:\Users\Lennard\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\system32\IProsetMonitor.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Pinnacle Systems) C:\Program Files (x86)\Pinnacle\Shared Files\Programs\Remote\remoterm.exe
(Spotify Ltd) C:\Users\Lennard\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Avid Development GmbH) C:\Program Files (x86)\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11774568 2011-01-13] (Realtek Semiconductor)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [652624 2007-10-25] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1840720 2007-09-13] (CANON INC.)
Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll (Kaspersky Lab ZAO)
HKCU\...\Run: [PMCRemote] - C:\Program Files (x86)\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe [226576 2008-09-22] (Pinnacle Systems)
HKCU\...\Run: [PMCLoader] - C:\Program Files (x86)\Pinnacle\TVCenter Pro\PMCLoader.exe [644368 2008-09-23] (Pinnacle Systems GmbH)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Lennard\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1199576 2013-01-26] (Spotify Ltd)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CLMLServer] - "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink)
HKLM-x32\...\Run: [AVP] - "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [206448 2012-10-30] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [WinampAgent] - "C:\Program Files (x86)\Winamp\winampa.exe" [74752 2012-06-20] (Nullsoft, Inc.)
HKLM-x32\...\Run: [] - [x]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Pinnacle Streaming Server.lnk
ShortcutTarget: Pinnacle Streaming Server.lnk -> C:\Program Files (x86)\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe (Avid Development GmbH)
Startup: C:\Users\Lennard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lennard\AppData\Roaming\Mozilla\Firefox\Profiles\xahpfm2h.default
FF NewTab: hxxp://www.google.com/firefox
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com/firefox
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF Extension: No Name - C:\Users\Lennard\AppData\Roaming\Mozilla\Firefox\Profiles\xahpfm2h.default\Extensions\{84bada77-573f-4f8b-9beb-f5495133135c}
FF Extension: No Name - C:\Users\Lennard\AppData\Roaming\Mozilla\Firefox\Profiles\xahpfm2h.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF Extension: Kaspersky Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\Lennard\AppData\LocalLow\proxtube\CHROME\proxtube.crx
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ChromeExt\ab.crx
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-30] (Kaspersky Lab ZAO)
S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer Free\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
==================== Drivers (Whitelisted) ====================
S3 azvusb; C:\Windows\System32\DRIVERS\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-12-17] (Intel Corporation)
S3 IAMTXPE; C:\Windows\system32\drivers\IAMTXPE.sys [51096 2010-12-17] (Intel Corporation)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [460888 2011-03-04] (Kaspersky Lab ZAO)
R1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11864 2011-03-04] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [637272 2012-10-30] (Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29488 2011-03-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [22544 2009-11-02] (Kaspersky Lab)
S3 Ph6xIB64; C:\Windows\System32\DRIVERS\Ph6xIB64.sys [1512832 2009-06-10] (NXP Semiconductors GmbH)
S3 PhilCap64; C:\Windows\System32\DRIVERS\PhilCap64.sys [1070240 2007-07-30] (NXP Semiconductors Germany GmbH)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-26 12:43 - 2013-07-26 12:44 - 01779853 _____ (Farbar) C:\Users\Lennard\Downloads\FRST64 (2).exe
2013-07-26 12:42 - 2013-07-26 12:42 - 01779853 _____ (Farbar) C:\Users\Lennard\Downloads\FRST64 (1).exe
2013-07-26 12:35 - 2013-07-26 12:35 - 00011462 _____ C:\Users\Lennard\Desktop\JRT.txt
2013-07-26 12:31 - 2013-07-26 12:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-25 19:05 - 2013-07-25 19:06 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Lennard\Desktop\JRT.exe
2013-07-25 18:47 - 2013-07-25 18:48 - 00023302 _____ C:\AdwCleaner[S1].txt
2013-07-22 20:23 - 2013-07-22 20:23 - 00666633 _____ C:\Users\Lennard\Desktop\adwcleaner.exe
2013-07-21 23:01 - 2013-07-21 23:01 - 00034713 _____ C:\Users\Lennard\Downloads\FRST.txt
2013-07-21 23:01 - 2013-07-21 23:01 - 00021334 _____ C:\Users\Lennard\Downloads\Addition.txt
2013-07-21 23:00 - 2013-07-21 23:00 - 00000000 ____D C:\FRST
2013-07-21 22:57 - 2013-07-21 22:57 - 01779345 _____ (Farbar) C:\Users\Lennard\Desktop\FRST64.exe
2013-07-21 22:56 - 2013-07-21 22:57 - 01779345 _____ (Farbar) C:\Users\Lennard\Downloads\FRST64.exe
2013-07-21 22:04 - 2013-07-22 18:51 - 00000000 ____D C:\test pics
2013-07-21 21:20 - 2013-07-21 21:21 - 02828552 _____ (AVAST Software) C:\Users\Lennard\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-07-21 21:18 - 2013-07-21 21:18 - 01059480 _____ C:\Users\Lennard\Downloads\setup (1).exe
2013-07-19 17:41 - 2013-07-19 17:41 - 00000600 _____ C:\Windows\PFRO.log
2013-07-18 03:00 - 2013-07-18 03:03 - 00000000 ____D C:\Windows\system32\MRT
2013-07-15 21:54 - 2013-07-15 21:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-15 21:04 - 2013-07-15 21:04 - 00155619 _____ C:\Users\Lennard\Downloads\04-05-2011-adblock_1_1_2 (1).crx
2013-07-15 21:03 - 2013-07-15 21:03 - 00155619 _____ C:\Users\Lennard\Downloads\04-05-2011-adblock_1_1_2.crx
2013-07-15 21:01 - 2013-07-15 21:01 - 00421137 _____ C:\Users\Lennard\Downloads\extension_2_6_2.crx
2013-07-15 20:57 - 2013-07-15 20:57 - 00306267 _____ C:\Users\Lennard\Downloads\extension_1_5 (1).crx
2013-07-15 20:56 - 2013-07-15 20:57 - 00306267 _____ C:\Users\Lennard\Downloads\extension_1_5.crx
2013-07-15 20:46 - 2013-07-15 20:46 - 00205312 _____ C:\Users\Lennard\Downloads\05_final_time_schedule.xls
2013-07-15 17:55 - 2013-07-15 17:59 - 29403457 _____ (SRWare ) C:\Users\Lennard\Downloads\srware_iron_27.0.1500.0.exe
2013-07-14 22:32 - 2013-07-14 22:33 - 00903080 _____ (Oracle Corporation) C:\Users\Lennard\Downloads\chromeinstall-7u25 (1).exe
2013-07-14 22:30 - 2013-07-14 22:30 - 00903080 _____ (Oracle Corporation) C:\Users\Lennard\Downloads\chromeinstall-7u25.exe
2013-07-13 23:02 - 2013-07-13 23:02 - 00000197 _____ C:\Users\Lennard\Downloads\dlf.m3u
2013-07-13 03:06 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-13 03:06 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-13 03:06 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-13 03:06 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-13 03:06 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-13 03:06 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-13 03:06 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-13 03:06 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-13 03:06 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-13 03:06 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-13 03:06 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-13 03:06 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-13 03:06 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-13 03:06 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-13 03:06 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-13 03:06 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-13 03:06 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-13 03:06 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-13 03:06 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-13 03:06 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-13 03:06 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-13 03:06 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-12 03:43 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-12 03:43 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-12 03:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-12 03:43 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-12 03:43 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-12 03:42 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-12 03:42 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 23:47 - 2013-07-11 23:47 - 00021011 _____ C:\Users\Lennard\Downloads\aschezuasche_juni2013.odt
2013-07-06 18:47 - 2013-07-26 12:18 - 00000504 _____ C:\Windows\setupact.log
2013-07-06 18:47 - 2013-07-06 18:47 - 00000000 _____ C:\Windows\setuperr.log
2013-06-28 23:06 - 2013-06-28 23:06 - 01624112 _____ (Bandoo Media Inc) C:\Users\Lennard\Downloads\iLividSetup-r362-n-bc (3).exe
2013-06-28 23:06 - 2013-06-28 23:06 - 01624112 _____ (Bandoo Media Inc) C:\Users\Lennard\Downloads\iLividSetup-r362-n-bc (2).exe
2013-06-28 23:01 - 2013-06-28 23:01 - 01624112 _____ (Bandoo Media Inc) C:\Users\Lennard\Downloads\iLividSetup-r362-n-bc (1).exe
2013-06-26 11:41 - 2013-06-26 11:41 - 00009928 _____ C:\Users\Lennard\Desktop\sister birthday.odt
==================== One Month Modified Files and Folders =======
2013-07-26 12:44 - 2013-07-26 12:43 - 01779853 _____ (Farbar) C:\Users\Lennard\Downloads\FRST64 (2).exe
2013-07-26 12:42 - 2013-07-26 12:42 - 01779853 _____ (Farbar) C:\Users\Lennard\Downloads\FRST64 (1).exe
2013-07-26 12:37 - 2011-11-15 20:12 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-07-26 12:35 - 2013-07-26 12:35 - 00011462 _____ C:\Users\Lennard\Desktop\JRT.txt
2013-07-26 12:31 - 2013-07-26 12:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-26 12:26 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-26 12:26 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-26 12:19 - 2011-11-23 04:17 - 00000349 _____ C:\Users\Public\Documents\PCLECHAL.INI
2013-07-26 12:18 - 2013-07-06 18:47 - 00000504 _____ C:\Windows\setupact.log
2013-07-26 12:18 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-26 08:55 - 2011-11-16 04:57 - 01760743 _____ C:\Windows\WindowsUpdate.log
2013-07-25 19:06 - 2013-07-25 19:05 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Lennard\Desktop\JRT.exe
2013-07-25 18:51 - 2012-12-15 02:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-25 18:48 - 2013-07-25 18:47 - 00023302 _____ C:\AdwCleaner[S1].txt
2013-07-25 18:46 - 2011-11-29 22:56 - 00000000 ____D C:\schriftliches
2013-07-22 20:23 - 2013-07-22 20:23 - 00666633 _____ C:\Users\Lennard\Desktop\adwcleaner.exe
2013-07-22 18:51 - 2013-07-21 22:04 - 00000000 ____D C:\test pics
2013-07-21 23:01 - 2013-07-21 23:01 - 00034713 _____ C:\Users\Lennard\Downloads\FRST.txt
2013-07-21 23:01 - 2013-07-21 23:01 - 00021334 _____ C:\Users\Lennard\Downloads\Addition.txt
2013-07-21 23:00 - 2013-07-21 23:00 - 00000000 ____D C:\FRST
2013-07-21 22:57 - 2013-07-21 22:57 - 01779345 _____ (Farbar) C:\Users\Lennard\Desktop\FRST64.exe
2013-07-21 22:57 - 2013-07-21 22:56 - 01779345 _____ (Farbar) C:\Users\Lennard\Downloads\FRST64.exe
2013-07-21 21:25 - 2011-12-22 22:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-07-21 21:22 - 2012-01-18 21:19 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-21 21:22 - 2012-01-18 21:19 - 00000000 ____D C:\Users\Lennard\AppData\Roaming\Skype
2013-07-21 21:22 - 2012-01-18 21:19 - 00000000 ____D C:\ProgramData\Skype
2013-07-21 21:21 - 2013-07-21 21:20 - 02828552 _____ (AVAST Software) C:\Users\Lennard\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-07-21 21:18 - 2013-07-21 21:18 - 01059480 _____ C:\Users\Lennard\Downloads\setup (1).exe
2013-07-21 20:40 - 2011-11-20 18:24 - 00000000 ____D C:\fotos
2013-07-19 17:41 - 2013-07-19 17:41 - 00000600 _____ C:\Windows\PFRO.log
2013-07-19 17:37 - 2011-11-18 15:48 - 00000000 ____D C:\Users\Lennard\AppData\Roaming\SoftGrid Client
2013-07-18 03:03 - 2013-07-18 03:00 - 00000000 ____D C:\Windows\system32\MRT
2013-07-15 21:54 - 2013-07-15 21:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-15 21:19 - 2011-10-10 21:33 - 00000000 ____D C:\filme
2013-07-15 21:04 - 2013-07-15 21:04 - 00155619 _____ C:\Users\Lennard\Downloads\04-05-2011-adblock_1_1_2 (1).crx
2013-07-15 21:03 - 2013-07-15 21:03 - 00155619 _____ C:\Users\Lennard\Downloads\04-05-2011-adblock_1_1_2.crx
2013-07-15 21:01 - 2013-07-15 21:01 - 00421137 _____ C:\Users\Lennard\Downloads\extension_2_6_2.crx
2013-07-15 20:57 - 2013-07-15 20:57 - 00306267 _____ C:\Users\Lennard\Downloads\extension_1_5 (1).crx
2013-07-15 20:57 - 2013-07-15 20:56 - 00306267 _____ C:\Users\Lennard\Downloads\extension_1_5.crx
2013-07-15 20:51 - 2011-11-15 20:47 - 00001012 _____ C:\Users\Public\Desktop\SRWare Iron.lnk
2013-07-15 20:51 - 2011-11-15 20:47 - 00000000 ____D C:\Program Files (x86)\SRWare Iron
2013-07-15 20:46 - 2013-07-15 20:46 - 00205312 _____ C:\Users\Lennard\Downloads\05_final_time_schedule.xls
2013-07-15 17:59 - 2013-07-15 17:55 - 29403457 _____ (SRWare ) C:\Users\Lennard\Downloads\srware_iron_27.0.1500.0.exe
2013-07-14 22:33 - 2013-07-14 22:32 - 00903080 _____ (Oracle Corporation) C:\Users\Lennard\Downloads\chromeinstall-7u25 (1).exe
2013-07-14 22:30 - 2013-07-14 22:30 - 00903080 _____ (Oracle Corporation) C:\Users\Lennard\Downloads\chromeinstall-7u25.exe
2013-07-13 23:02 - 2013-07-13 23:02 - 00000197 _____ C:\Users\Lennard\Downloads\dlf.m3u
2013-07-13 04:29 - 2012-05-03 18:48 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-13 04:29 - 2011-11-22 20:21 - 00000000 ____D C:\Users\Lennard\AppData\Local\Adobe
2013-07-13 04:29 - 2011-11-15 21:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-13 03:30 - 2009-07-14 06:45 - 02242184 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-13 03:29 - 2013-03-21 18:08 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-13 03:29 - 2013-03-21 18:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-13 03:28 - 2010-11-21 09:17 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-13 03:28 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-13 03:28 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-13 03:11 - 2011-03-11 11:20 - 00697292 _____ C:\Windows\system32\perfh007.dat
2013-07-13 03:11 - 2011-03-11 11:20 - 00148330 _____ C:\Windows\system32\perfc007.dat
2013-07-13 03:11 - 2009-07-14 07:13 - 01635980 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-11 23:47 - 2013-07-11 23:47 - 00021011 _____ C:\Users\Lennard\Downloads\aschezuasche_juni2013.odt
2013-07-11 23:06 - 2011-06-16 19:33 - 00000000 ____D C:\mucke
2013-07-11 22:42 - 2012-07-12 21:22 - 00000000 ____D C:\bewerbung
2013-07-06 18:47 - 2013-07-06 18:47 - 00000000 _____ C:\Windows\setuperr.log
2013-07-05 11:15 - 2012-01-09 22:35 - 00000000 ____D C:\stick die erste
2013-07-05 11:12 - 2012-07-03 14:13 - 00000000 ____D C:\kochrezepte
2013-07-03 11:48 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-06-28 23:06 - 2013-06-28 23:06 - 01624112 _____ (Bandoo Media Inc) C:\Users\Lennard\Downloads\iLividSetup-r362-n-bc (3).exe
2013-06-28 23:06 - 2013-06-28 23:06 - 01624112 _____ (Bandoo Media Inc) C:\Users\Lennard\Downloads\iLividSetup-r362-n-bc (2).exe
2013-06-28 23:01 - 2013-06-28 23:01 - 01624112 _____ (Bandoo Media Inc) C:\Users\Lennard\Downloads\iLividSetup-r362-n-bc (1).exe
2013-06-28 21:50 - 2011-11-23 04:43 - 00000000 ____D C:\Windows\Minidump
2013-06-28 21:32 - 2011-11-23 04:43 - 335265246 _____ C:\Windows\MEMORY.DMP
2013-06-26 11:41 - 2013-06-26 11:41 - 00009928 _____ C:\Users\Lennard\Desktop\sister birthday.odt
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit |