Malwarebytes Anti-Malware (Test) 1.75.0.1300
Malwarebytes : Free anti-malware download
Datenbank Version: v2013.04.04.07
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Sven :: SVEN-MSI [Administrator]
Schutz: Aktiviert
07.09.2013 14:12:44
mbam-log-2013-09-07 (14-12-44).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|W:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 365964
Laufzeit: 48 Minute(n), 27 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
D:\Setups\actualspy.exe (Application.ActualSpy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.002 - Bericht erstellt am 07/09/2013 um 15:59:46
# Updated 01/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Sven - SVEN-MSI
# Gestartet von : C:\Users\Sven\Desktop\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : SearchAnonymizer
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\windows\System32\Tasks\Scheduled Update for Ask Toolbar
Ordner Gefunden C:\Program Files\Ask.com
Ordner Gefunden C:\Program Files\Common Files\DVDVideoSoft\TB
Ordner Gefunden C:\Program Files\ICQ6Toolbar
Ordner Gefunden C:\Program Files\software4u
Ordner Gefunden C:\ProgramData\Ask
Ordner Gefunden C:\ProgramData\ICQ\ICQToolbar
Ordner Gefunden C:\Users\Sven\AppData\LocalLow\AskToolbar
Ordner Gefunden C:\Users\Sven\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gefunden C:\Users\Sven\AppData\Roaming\OCS
Ordner Gefunden C:\Users\Sven\AppData\Roaming\software4u
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Produkt Gefunden : Ask Toolbar
Produkt Gefunden : Google Update Helper
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gefunden : HKCU\Software\Ask.com
Schlüssel Gefunden : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKLM\Software\AskToolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gefunden : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OCS_Sm
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\Scheduled Update for Ask Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\Scheduled Update for Ask Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16490
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] - hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
-\\ Google Chrome v27.0.1453.110
[ Datei : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [4247 octets] - [07/09/2013 15:59:46]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4307 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.8 (09.05.2013:1)
OS: Windows 7 Home Premium x86
Ran by Sven on 07.09.2013 at 16:07:39,31
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\a28b4d68debaa244eb686953b7074fef
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\a28b4d68debaa244eb686953b7074fef
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\taskhost_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\taskhost_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{93E1FB0E-440C-42B9-B5FD-09E61C068E98}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.09.2013 at 16:11:25,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-08-2013 02 (ATTENTION: ====> FRST version is 13 days old and could be outdated)
Ran by Sven (administrator) on 07-09-2013 16:13:40
Running from C:\Users\Sven\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
==================== Registry (Whitelisted) ==================
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {CA367895-CAA8-4C2F-8961-7D498186545D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAMI&src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {188584E5-C573-4227-9799-BBD3B958F9D8} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=a3f8a22d-1464-4775-8a4a-eb996cbdb7c8&pid=icqt&mode=bounce&k=0
SearchScopes: HKCU - {188584E5-C573-4227-9799-BBD3B958F9D8} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=a3f8a22d-1464-4775-8a4a-eb996cbdb7c8&pid=icqt&mode=bounce&k=0
SearchScopes: HKCU - {6F857B82-5ABB-43F8-AF45-A1528881CC4F} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=a3f8a22d-1464-4775-8a4a-eb996cbdb7c8&pid=icqt&mode=bounce&k=0
SearchScopes: HKCU - {9D14E7EA-0FD4-4F88-BA06-592F1EA0EE76} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=a3f8a22d-1464-4775-8a4a-eb996cbdb7c8&pid=icqt&mode=bounce&k=0
SearchScopes: HKCU - {A97585E6-FF9B-448C-8C0C-1D394AB1CFEA} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=a3f8a22d-1464-4775-8a4a-eb996cbdb7c8&pid=icqt&mode=bounce&k=0
SearchScopes: HKCU - {CA367895-CAA8-4C2F-8961-7D498186545D} URL =
SearchScopes: HKCU - {D76649B4-1153-406E-8807-65258E193E19} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=a3f8a22d-1464-4775-8a4a-eb996cbdb7c8&pid=icqt&mode=bounce&k=0
SearchScopes: HKCU - {E856D6BD-56A0-4FB5-96D7-34104C59EF5D} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=a3f8a22d-1464-4775-8a4a-eb996cbdb7c8&pid=icqt&mode=bounce&k=0
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKCU -&Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.110\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Gmail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
========================== Services (Whitelisted) =================
S4 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S4 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [136360 2011-04-27] (Avira GmbH)
S4 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [269480 2011-06-30] (Avira GmbH)
S4 ETSCSERVICE; C:\Program Files\IdeaCom\TSC\ETSCSERVICE.exe [204800 2009-09-05] (IdeaCom Technology Inc.)
S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S4 WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [101376 2009-09-25] (MICRO-STAR INT'L,.LTD.)
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-25] (ArcSoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2011-06-30] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2011-06-30] (Avira GmbH)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 enecirhid; C:\Windows\system32\DRIVERS\enecirhid.sys [11776 2009-05-20] (ENE TECHNOLOGY INC.)
S3 enecirhidma; C:\Windows\system32\DRIVERS\enecirhidma.sys [5632 2008-04-25] (ENE TECHNOLOGY INC.)
S3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [25112 2010-07-29] (Initio Corporation)
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [722416 2010-10-17] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH)
S3 catchme; \??\C:\Users\Sven\AppData\Local\Temp\catchme.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-07 16:11 - 2013-09-07 16:11 - 00001357 _____ C:\Users\Sven\Desktop\JRT.txt
2013-09-07 16:07 - 2013-09-07 16:07 - 00000000 ____D C:\windows\ERUNT
2013-09-07 16:03 - 2013-09-07 16:03 - 00004387 _____ C:\Users\Sven\Desktop\AdwCleaner[R0].txt
2013-09-07 15:59 - 2013-09-07 16:03 - 00000000 ____D C:\AdwCleaner
2013-09-07 14:11 - 2013-09-07 14:11 - 00001081 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-07 14:11 - 2013-09-07 14:11 - 00000000 ____D C:\Users\Sven\AppData\Roaming\Malwarebytes
2013-09-07 14:11 - 2013-09-07 14:11 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-07 14:11 - 2013-09-07 14:11 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-07 14:11 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-09-07 14:10 - 2013-09-07 14:07 - 01028823 _____ (Thisisu) C:\Users\Sven\Desktop\JRT.exe
2013-09-07 14:10 - 2013-09-07 14:06 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sven\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-07 14:10 - 2013-09-07 14:06 - 01037222 _____ C:\Users\Sven\Desktop\adwcleaner.exe
2013-09-06 22:51 - 2013-09-06 22:51 - 00008452 _____ C:\ComboFix.txt
2013-09-06 22:42 - 2013-09-06 22:51 - 00000000 ____D C:\ComboFix
2013-09-06 22:22 - 2013-09-06 22:51 - 00000000 ____D C:\Qoobox
2013-09-06 22:22 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe
2013-09-06 22:22 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe
2013-09-06 22:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2013-09-06 22:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2013-09-06 22:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2013-09-06 22:22 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe
2013-09-06 22:22 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe
2013-09-06 22:22 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe
2013-09-06 22:21 - 2013-09-06 22:36 - 00000000 ____D C:\windows\erdnt
2013-09-06 22:12 - 2013-09-06 22:11 - 05120615 ____R (Swearware) C:\Users\Sven\Desktop\ComboFix.exe
2013-08-30 18:51 - 2013-08-30 18:51 - 00000000 ____D C:\FRST
2013-08-18 22:45 - 2013-08-18 22:45 - 00000000 ____D C:\ProgramData\Kaspersky Lab
==================== One Month Modified Files and Folders =======
2013-09-07 16:11 - 2013-09-07 16:11 - 00001357 _____ C:\Users\Sven\Desktop\JRT.txt
2013-09-07 16:11 - 2009-07-14 06:34 - 00017376 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-07 16:11 - 2009-07-14 06:34 - 00017376 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-07 16:07 - 2013-09-07 16:07 - 00000000 ____D C:\windows\ERUNT
2013-09-07 16:05 - 2012-04-23 13:06 - 00001090 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-07 16:04 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-09-07 16:03 - 2013-09-07 16:03 - 00004387 _____ C:\Users\Sven\Desktop\AdwCleaner[R0].txt
2013-09-07 16:03 - 2013-09-07 15:59 - 00000000 ____D C:\AdwCleaner
2013-09-07 16:03 - 2010-09-21 21:01 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-09-07 16:03 - 2010-05-22 09:30 - 02044669 _____ C:\windows\WindowsUpdate.log
2013-09-07 16:03 - 2010-05-21 20:53 - 00000000 ____D C:\ProgramData\ICQ
2013-09-07 15:53 - 2009-10-07 10:38 - 00404236 _____ C:\windows\PFRO.log
2013-09-07 15:52 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Web
2013-09-07 15:27 - 2012-04-23 13:06 - 00001094 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-07 14:11 - 2013-09-07 14:11 - 00001081 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-07 14:11 - 2013-09-07 14:11 - 00000000 ____D C:\Users\Sven\AppData\Roaming\Malwarebytes
2013-09-07 14:11 - 2013-09-07 14:11 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-07 14:11 - 2013-09-07 14:11 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-07 14:07 - 2013-09-07 14:10 - 01028823 _____ (Thisisu) C:\Users\Sven\Desktop\JRT.exe
2013-09-07 14:06 - 2013-09-07 14:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sven\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-07 14:06 - 2013-09-07 14:10 - 01037222 _____ C:\Users\Sven\Desktop\adwcleaner.exe
2013-09-06 23:03 - 2013-04-15 19:36 - 00000000 ____D C:\Users\Sven\Desktop\Bewerbung
2013-09-06 22:51 - 2013-09-06 22:51 - 00008452 _____ C:\ComboFix.txt
2013-09-06 22:51 - 2013-09-06 22:42 - 00000000 ____D C:\ComboFix
2013-09-06 22:51 - 2013-09-06 22:22 - 00000000 ____D C:\Qoobox
2013-09-06 22:50 - 2009-07-14 04:04 - 00000215 _____ C:\windows\system.ini
2013-09-06 22:38 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-09-06 22:36 - 2013-09-06 22:21 - 00000000 ____D C:\windows\erdnt
2013-09-06 22:27 - 2009-10-07 10:40 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI
2013-09-06 22:11 - 2013-09-06 22:12 - 05120615 ____R (Swearware) C:\Users\Sven\Desktop\ComboFix.exe
2013-08-30 18:51 - 2013-08-30 18:51 - 00000000 ____D C:\FRST
2013-08-25 19:11 - 2013-09-07 16:13 - 01070523 _____ (Farbar) C:\Users\Sven\Desktop\FRST.exe
2013-08-18 22:56 - 2011-12-17 21:38 - 03470848 ___SH C:\Users\Sven\Desktop\Thumbs.db
2013-08-18 22:45 - 2013-08-18 22:45 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-08-18 22:43 - 2010-05-24 12:18 - 00000000 ____D C:\Users\Sven\Desktop\Bilder
Files to move or delete:
====================
C:\Users\Sven\AppData\Local\Temp\Quarantine.exe
C:\Users\Sven\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Sven\AppData\Local\Temp\jrt\erunt\ERUNT.EXE.manifest
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-07 15:26
==================== End Of Log ============================
--- --- ---
--- --- ---