Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.27.03
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
Mathias :: MATHIAS-PC [Administrator]
Schutz: Aktiviert
27.08.2013 12:53:08
mbam-log-2013-08-27 (12-53-08).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 206191
Laufzeit: 5 Minute(n), 38 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 2
C:\Users\Mathias\Downloads\PhotoScape_V3.6.3.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Mathias\Downloads\rcpsetupmarm1_marm10de.exe (PUP.Optional.RegCleanerPro) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.001 - Report created 27/08/2013 at 13:13:10
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Mathias - MATHIAS-PC
# Running from : C:\Users\Mathias\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : Updater Service for AMZN
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\Amazon Browser Bar
Folder Deleted : C:\Users\Mathias\AppData\Local\Amazon Browser Bar
Folder Deleted : C:\Users\Mathias\AppData\Roaming\Systweak
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AlxSSB.AlxTBSSB
Key Deleted : HKLM\SOFTWARE\Classes\AlxSSB.AlxTBSSB.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1F02FB61-2BE5-4C16-8199-AEAA16EB0342}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E57091A7-B5F0-4C42-9329-72ED3E59ED31}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51F04BD6-3888-4849-864C-617FAE709CE0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C953EC4-8CFA-44FB-B32E-1249E5505091}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4E394E0-D331-431F-B76D-E3A19193D5F6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DA9FC525-41ED-4C00-B046-946DA7CDD305}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E57091A7-B5F0-4C42-9329-72ED3E59ED31}
Key Deleted : HKCU\Software\distromatic
Key Deleted : HKLM\Software\Amazon Browser Bar
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Amazon Browser Bar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
*************************
AdwCleaner[R0].txt - [3461 octets] - [27/08/2013 13:10:46]
AdwCleaner[S0].txt - [3462 octets] - [27/08/2013 13:13:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3522 octets] ##########
--- --- ---
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.4 (08.22.2013:1)
OS: Windows 7 Home Premium x86
Ran by Mathias on 27.08.2013 at 13:22:36,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.08.2013 at 13:24:58,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-08-2013 01
Ran by Mathias (administrator) on 27-08-2013 13:31:14
Running from C:\Users\Mathias\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [997920 2011-06-16] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
========================== Services (Whitelisted) =================
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [11736 2011-04-28] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [208944 2011-04-28] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
==================== Drivers (Whitelisted) ====================
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
R3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [43392 2011-04-18] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Mathias\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-27 13:24 - 2013-08-27 13:24 - 00000627 _____ C:\Users\Mathias\Desktop\JRT.txt
2013-08-27 13:22 - 2013-08-27 13:22 - 00000000 ____D C:\Windows\ERUNT
2013-08-27 13:20 - 2013-08-27 13:20 - 01021434 _____ (Thisisu) C:\Users\Mathias\Desktop\JRT.exe
2013-08-27 13:09 - 2013-08-27 13:13 - 00000000 ____D C:\AdwCleaner
2013-08-27 13:08 - 2013-08-27 13:09 - 00994642 _____ C:\Users\Mathias\Desktop\adwcleaner.exe
2013-08-27 12:50 - 2013-08-27 12:50 - 00001078 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-27 12:50 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-27 12:49 - 2013-08-27 12:49 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mathias\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-27 11:29 - 2013-08-27 11:29 - 00014171 _____ C:\ComboFix.txt
2013-08-27 11:21 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-27 11:21 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-27 11:21 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-27 11:21 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-27 11:21 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-27 11:21 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-27 11:21 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-27 11:21 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-27 11:16 - 2013-08-27 11:29 - 00000000 ____D C:\Qoobox
2013-08-27 11:16 - 2013-08-27 11:28 - 00000000 ____D C:\Windows\erdnt
2013-08-27 11:15 - 2013-08-27 11:16 - 05113393 ____R (Swearware) C:\Users\Mathias\Desktop\ComboFix.exe
2013-08-26 21:57 - 2013-08-26 21:57 - 00000000 ____D C:\FRST
2013-08-26 21:51 - 2013-08-27 11:08 - 00001668 _____ C:\Windows\system32\ASOROSet.bin
2013-08-26 21:51 - 2013-08-26 21:52 - 00000000 ____D C:\Windows\system32\config\RCCBakup
2013-08-25 23:21 - 2013-08-25 23:21 - 00000000 ____D C:\Users\Mathias\AppData\Roaming\Malwarebytes
2013-08-25 23:20 - 2013-08-27 12:50 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-25 23:20 - 2013-08-25 23:20 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-25 22:47 - 2013-08-25 22:47 - 00000000 ____D C:\Users\Mathias\AppData\Local\Dell
2013-08-25 22:38 - 2013-08-25 22:38 - 00000000 ____D C:\ProgramData\Simply Super Software
2013-08-20 20:45 - 2013-08-20 20:45 - 00146848 _____ C:\Windows\Minidump\082013-32963-01.dmp
2013-08-20 20:39 - 2013-08-20 20:59 - 00000000 ____D C:\Users\Mathias\AppData\Local\Google
2013-08-20 20:39 - 2013-08-20 20:59 - 00000000 ____D C:\Program Files\Google
2013-08-20 20:39 - 2013-08-20 20:39 - 00000000 ____D C:\Users\Mathias\AppData\Local\Apps\2.0
2013-08-20 20:38 - 2013-08-20 20:52 - 00000000 ____D C:\Users\Mathias\AppData\Local\Deployment
2013-08-16 20:56 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-16 20:56 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-16 20:56 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-16 20:56 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-16 20:56 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-16 20:56 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-16 20:56 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-16 20:56 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-16 20:56 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-16 18:22 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-16 18:22 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-16 18:22 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-16 18:22 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-16 18:22 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-16 18:22 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-16 18:22 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-16 18:22 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-16 18:22 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-16 18:22 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-16 18:22 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-16 18:22 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-09 23:03 - 2013-08-09 23:03 - 00003288 ____N C:\bootsqm.dat
==================== One Month Modified Files and Folders =======
2013-08-27 13:30 - 2013-08-27 13:30 - 01072785 _____ (Farbar) C:\Users\Mathias\Desktop\FRST.exe
2013-08-27 13:24 - 2013-08-27 13:24 - 00000627 _____ C:\Users\Mathias\Desktop\JRT.txt
2013-08-27 13:22 - 2013-08-27 13:22 - 00000000 ____D C:\Windows\ERUNT
2013-08-27 13:22 - 2009-07-14 06:34 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-27 13:22 - 2009-07-14 06:34 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-27 13:20 - 2013-08-27 13:20 - 01021434 _____ (Thisisu) C:\Users\Mathias\Desktop\JRT.exe
2013-08-27 13:19 - 2010-11-20 23:01 - 01619012 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-27 13:18 - 2013-06-04 18:40 - 01267283 _____ C:\Windows\WindowsUpdate.log
2013-08-27 13:14 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-27 13:14 - 2009-07-14 06:39 - 00045477 _____ C:\Windows\setupact.log
2013-08-27 13:13 - 2013-08-27 13:09 - 00000000 ____D C:\AdwCleaner
2013-08-27 13:09 - 2013-08-27 13:08 - 00994642 _____ C:\Users\Mathias\Desktop\adwcleaner.exe
2013-08-27 13:04 - 2010-11-20 23:48 - 00009588 _____ C:\Windows\PFRO.log
2013-08-27 13:00 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\SchCache
2013-08-27 12:50 - 2013-08-27 12:50 - 00001078 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-27 12:50 - 2013-08-25 23:20 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-27 12:49 - 2013-08-27 12:49 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mathias\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-27 12:33 - 2013-06-05 07:49 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-27 11:29 - 2013-08-27 11:29 - 00014171 _____ C:\ComboFix.txt
2013-08-27 11:29 - 2013-08-27 11:16 - 00000000 ____D C:\Qoobox
2013-08-27 11:29 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2013-08-27 11:29 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-08-27 11:28 - 2013-08-27 11:16 - 00000000 ____D C:\Windows\erdnt
2013-08-27 11:27 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-08-27 11:16 - 2013-08-27 11:15 - 05113393 ____R (Swearware) C:\Users\Mathias\Desktop\ComboFix.exe
2013-08-27 11:09 - 2013-06-04 10:08 - 00000000 ____D C:\Users\Mathias
2013-08-27 11:08 - 2013-08-26 21:51 - 00001668 _____ C:\Windows\system32\ASOROSet.bin
2013-08-27 11:08 - 2009-07-14 04:03 - 35127296 _____ C:\Windows\system32\config\software.bak
2013-08-27 11:08 - 2009-07-14 04:03 - 12845056 _____ C:\Windows\system32\config\system.bak
2013-08-27 11:08 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-08-27 07:23 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp
2013-08-27 07:23 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration
2013-08-27 07:20 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles
2013-08-27 01:40 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-08-26 21:57 - 2013-08-26 21:57 - 00000000 ____D C:\FRST
2013-08-26 21:52 - 2013-08-26 21:51 - 00000000 ____D C:\Windows\system32\config\RCCBakup
2013-08-25 23:21 - 2013-08-25 23:21 - 00000000 ____D C:\Users\Mathias\AppData\Roaming\Malwarebytes
2013-08-25 23:20 - 2013-08-25 23:20 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-25 22:47 - 2013-08-25 22:47 - 00000000 ____D C:\Users\Mathias\AppData\Local\Dell
2013-08-25 22:38 - 2013-08-25 22:38 - 00000000 ____D C:\ProgramData\Simply Super Software
2013-08-25 21:58 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-20 21:12 - 2009-07-14 06:53 - 00019276 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-20 20:59 - 2013-08-20 20:39 - 00000000 ____D C:\Users\Mathias\AppData\Local\Google
2013-08-20 20:59 - 2013-08-20 20:39 - 00000000 ____D C:\Program Files\Google
2013-08-20 20:52 - 2013-08-20 20:38 - 00000000 ____D C:\Users\Mathias\AppData\Local\Deployment
2013-08-20 20:45 - 2013-08-20 20:45 - 00146848 _____ C:\Windows\Minidump\082013-32963-01.dmp
2013-08-20 20:45 - 2013-06-05 09:26 - 00000000 ____D C:\Windows\Minidump
2013-08-20 20:45 - 2013-06-05 09:25 - 254231346 _____ C:\Windows\MEMORY.DMP
2013-08-20 20:39 - 2013-08-20 20:39 - 00000000 ____D C:\Users\Mathias\AppData\Local\Apps\2.0
2013-08-18 03:23 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-16 21:03 - 2013-07-25 20:59 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 21:02 - 2013-06-16 22:33 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-12 20:00 - 2012-09-20 15:25 - 00000000 ____D C:\Windows\system32\Drivers\de-DE
2013-08-12 20:00 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-08-12 19:59 - 2013-07-25 21:08 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-12 19:59 - 2010-11-21 02:46 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-08-09 23:03 - 2013-08-09 23:03 - 00003288 ____N C:\bootsqm.dat
Files to move or delete:
====================
C:\Users\Mathias\AppData\Local\Temp\Quarantine.exe
C:\Users\Mathias\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-12 19:04
==================== End Of Log ============================
--- --- ---
--- --- ---