Alexandra81 | 29.08.2013 08:27 | Guten Morgen,
hier die gewünschten Logfiles, diesmal auch mit Codes...
1. Malwarebytes Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.29.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Name :: Name [Administrator]
Schutz: Aktiviert
29.08.2013 07:48:09
mbam-log-2013-08-29 (07-48-09).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 409134
Laufzeit: 49 Minute(n), 33 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 6
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92bbb980-50f0-4b30-acfc-3c7567703447} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{097ecbf6-8ea7-4321-8b3f-33037c61b4f7} (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{097ECBF6-8EA7-4321-8B3F-33037C61B4F7} (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{dc838290-68de-4339-910f-550a4480feaf} (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Interface\{bd54a493-a329-4f12-9e7d-13aa27699fb3} (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 1
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0N2P2W1F0Z1S1U1H -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 1
C:\Program Files (x86)\LyriXeeker (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 24
C:\Program Files (x86)\LyriXeeker\LyriXupdate.exe (PUP.Optional.AdLyrics) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\Uninstall.exe (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Name\AppData\Local\Temp\ICReinstall_ZipOpenerSetup.exe (PUP.Optional.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Name\AppData\Local\Temp\is1177715538\DeltaTB.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Name\AppData\Local\Temp\is357113909\DeltaTB.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Name\Downloads\ZipOpenerSetup.exe (PUP.Optional.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\WINDOWS\Installer\6eb80.msi (Worm.Waledac) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\chrome.manifest (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\00.crx (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\00.xpi (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\01.crx (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\01.xpi (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\02.crx (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\02.xpi (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\130.crx (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\130.dat (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\130.dll (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\130.xpi (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\crx.dat (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\crx.db (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\sqlite3.dll (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\xpi.dat (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyriXeeker\xpi.db (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\WINDOWS\Tasks\LyricXeeker Update.job (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) 2. AdwCleaner Code:
# AdwCleaner v3.001 - Report created 29/08/2013 at 08:50:59
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Name - Name
# Running from : C:\Users\Name\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\iMesh Applications
File Deleted : C:\Users\Name\AppData\Roaming\Mozilla\Firefox\Profiles\rcrppi2x.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKCU\Software\AppDataLow\Software\lyrixeeker
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\Name\AppData\Roaming\Mozilla\Firefox\Profiles\rcrppi2x.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [1198 octets] - [29/08/2013 08:50:05]
AdwCleaner[S0].txt - [1131 octets] - [29/08/2013 08:50:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1191 octets] ########## 3. Junkware Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Windows 7 Professional x64
Ran by Name on 29.08.2013 at 8:56:23,89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Name\AppData\Roaming\mozilla\firefox\profiles\rcrppi2x.default\minidumps [4 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.08.2013 at 9:06:28,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 4. frisches FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Alexandra Leykauf (administrator) on 29-08-2013 09:08:23
Running from C:\Users\Name\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Windows\system32\mfevtps.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Cypress Semiconductor Corporation) C:\Program Files\Cypress\TrackPad\CyCpIo.exe
(Cypress Semiconductor, Inc.) C:\Program Files\Cypress\TrackPad\CyHidWin.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
() C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
() C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
() C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
(PFU LIMITED) C:\WINDOWS\SSDriver\fi5110\SsWiaChecker.exe
(Microsoft Corporation) C:\Windows\System32\wiawow64.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
(Dell) C:\Users\Name\AppData\Local\Apps\2.0\TQEETVRA.A03\PCO4Q89K.RZ5\dell..tion_0f612f649c4a10af_0005.0000_a97905297feaae2c\DellSystemDetect.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
() C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
(Star Finanz - Software Entwicklung und Vertriebs GmbH) Z:\StarMoney Business 4.0\offlagent4\offlagent.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(McAfee, Inc.) c:\PROGRA~1\mcafee.com\agent\mcagent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Nero AG) C:\Program Files (x86)\Nero\SyncUP\SyncUP.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Nero AG) C:\Program Files (x86)\Nero\SyncUP\Nero.AndroidServer.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [CyCpIo] - C:\Program Files\Cypress\TrackPad\CyCpIo.exe [2375168 2011-10-20] (Cypress Semiconductor Corporation)
HKLM\...\Run: [CyHidWin] - C:\Program Files\Cypress\TrackPad\CyHidWin.exe [2354176 2011-10-19] (Cypress Semiconductor, Inc.)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7214696 2011-05-26] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-18] (Realtek Semiconductor)
HKLM\...\Run: [FreeFallProtection] - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()
HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [10357008 2011-10-18] (Intel Corporation)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-09-16] (Intel(R) Corporation)
HKLM\...\Run: [QuickSet] - c:\Program Files\Dell\QuickSet\QuickSet.exe [4146848 2011-07-13] (Dell Inc.)
HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] ()
HKLM\...\Run: [Stage Remote] - C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe [2022976 2011-06-28] ()
HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [207845 2011-04-30] ()
HKLM\...\Run: [NVHotkey] - C:\Windows\system32\nvHotkey.dll [540992 2011-11-04] (NVIDIA Corporation)
HKCU\...\Run: [DellSystemDetect] - C:\Users\Name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms [370 2013-07-01] ()
HKCU\...\Run: [] - [x]
HKCU\...\Run: [NokiaSuite.exe] - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-04-19] (Nokia)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [38984 2013-05-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840768 2013-05-10] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-13] (Creative Technology Ltd)
HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.)
HKLM-x32\...\Run: [RoxWatchTray] - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [1675160 2012-03-21] (McAfee, Inc.)
HKLM-x32\...\Run: [NeroLauncher] - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [67496 2012-08-21] ()
HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj [2825741 2011-04-30] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [SMB50StarMoneyRunEntry] - Z:\Programme\StarMoney Business 5.0\app\oflagent.exe [56976 2013-08-15] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
HKLM-x32\...\Run: [StarMoneyRunEntry] - Z:\StarMoney Business 4.0\app\oflagent.exe [57864 2011-09-22] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] - C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [241984 2011-11-04] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [203072 2011-11-04] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CardMinder Viewer.lnk
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\In PDF-Datei mit ScanSnap Organizer konvertieren.lnk
ShortcutTarget: In PDF-Datei mit ScanSnap Organizer konvertieren.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lexware Info Service.lnk
ShortcutTarget: Lexware Info Service.lnk -> C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
SearchScopes: HKLM - DefaultScope {7211AC85-6D3C-4528-8CCB-3537E5B66F66} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {7211AC85-6D3C-4528-8CCB-3537E5B66F66} URL =
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20130622163131.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20130622163131.dll (McAfee, Inc.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - No File
Handler-x32: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - C:\Program Files (x86)\Haufe\HaufeReader\HRInstmon.dll (Haufe Mediengruppe)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.3.100 192.168.3.1
FireFox:
========
FF ProfilePath: C:\Users\Name\AppData\Roaming\Mozilla\Firefox\Profiles\rcrppi2x.default
FF Homepage: hxxp://www.google.de/ig
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] C:\Program Files (x86)\Common Files\McAfee\SystemCore
FF Extension: McAfee ScriptScan for Firefox - C:\Program Files (x86)\Common Files\McAfee\SystemCore
FF HKCU\...\Firefox\Extensions: [{60525b7e-56a2-4031-a4f4-35eb2c9dd4d8}] C:\Program Files (x86)\LyriXeeker\130.xpi
==================== Services (Whitelisted) =================
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
S3 DATEV Update-Service; C:\DATEV\PROGRAMM\INSTALL\DvInesASDSvc.Exe [172640 2011-07-25] (DATEV eG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McAWFwk; c:\PROGRA~1\mcafee\msc\mcawfwk.exe [224704 2011-03-09] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.)
R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.)
R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [502064 2012-08-23] (McAfee, Inc.)
S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199304 2012-05-25] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [210616 2012-05-25] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [162224 2012-05-25] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-09-16] ()
==================== Drivers (Whitelisted) ====================
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65264 2012-02-22] (McAfee, Inc.)
R3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT)
R3 cyhid; C:\Windows\System32\DRIVERS\cyhid.sys [117248 2011-10-22] (Cypress Semiconductor, Inc.)
R3 cykbfltrService; C:\Windows\System32\DRIVERS\cykbfltr.sys [13824 2011-10-19] (Cypress Semiconductor, Inc.)
R3 cymfltrService; C:\Windows\System32\DRIVERS\cymfltr.sys [79872 2011-10-22] (Cypress Semiconductor, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [160792 2012-02-22] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [229528 2012-02-22] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [487296 2012-02-22] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [647208 2012-02-22] (McAfee, Inc.)
R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75936 2012-02-22] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100912 2012-02-22] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [289664 2012-02-22] (McAfee, Inc.)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [249152 2011-11-04] (NVIDIA Corporation)
U3 mfeavfk01; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 09:06 - 2013-08-29 09:06 - 00000887 _____ C:\Users\Alexandra Leykauf\Desktop\JRT.txt
2013-08-29 08:56 - 2013-08-29 08:56 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 08:55 - 2013-08-29 08:55 - 01023533 _____ (Thisisu) C:\Users\Name\Downloads\JRT.exe
2013-08-29 08:52 - 2013-08-29 08:52 - 00001271 _____ C:\Users\Alexandra Leykauf\Desktop\2AdwCleaner[S0].txt
2013-08-29 08:49 - 2013-08-29 08:51 - 00000000 ____D C:\AdwCleaner
2013-08-29 08:48 - 2013-08-29 08:48 - 00994642 _____ C:\Users\Name\Downloads\adwcleaner.exe
2013-08-29 07:44 - 2013-08-29 07:44 - 00000000 ____D C:\Users\Name\AppData\Roaming\Malwarebytes
2013-08-29 07:41 - 2013-08-29 07:41 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Name\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 07:41 - 2013-08-29 07:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 07:41 - 2013-08-29 07:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-29 07:41 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-28 15:40 - 2013-08-29 08:44 - 00013972 _____ C:\Users\Name\Desktop\Kuxxx.xlsx
2013-08-28 14:32 - 2013-08-28 14:32 - 00026817 _____ C:\Users\Name\Downloads\Addition.txt
2013-08-28 14:31 - 2013-08-28 14:31 - 01579080 _____ (Farbar) C:\Users\Name\Downloads\FRST64.exe
2013-08-28 14:31 - 2013-08-28 14:31 - 00000000 ____D C:\FRST
2013-08-28 13:03 - 2013-08-28 13:02 - 00088172 _____ C:\Users\Name\Downloads\DarlehenFree.exe
2013-08-28 13:02 - 2013-08-28 13:02 - 00623680 _____ C:\Users\Name\Downloads\DarlehenFree-Downloader.exe
2013-08-28 13:00 - 2013-08-28 13:00 - 01333552 _____ (iMesh Inc) C:\Users\Name\Downloads\iMeshSetup-r1487-w-bf.exe
2013-08-19 11:53 - 2013-08-19 11:53 - 00000000 ___SD C:\Users\Name\Documents\Meine Datenquellen
2013-08-19 11:39 - 2013-08-19 11:39 - 00000000 ____D C:\Users\Name\Mein Backup Datei
2013-08-19 09:26 - 2013-08-19 09:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 11:30 - 2013-08-16 11:30 - 00000000 ____D C:\Users\Name\Documents\Nokia Suite
2013-08-16 11:23 - 2013-08-16 11:24 - 00000000 ____D C:\Users\Name\AppData\Roaming\Nokia
2013-08-16 11:23 - 2013-08-16 11:23 - 00000000 ____D C:\Users\Name\AppData\Roaming\Nokia Suite
2013-08-16 11:17 - 2013-08-16 11:17 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2013-08-16 11:16 - 2013-08-16 11:19 - 00000000 ____D C:\Users\Name\AppData\Roaming\PC Suite
2013-08-16 11:16 - 2013-08-16 11:19 - 00000000 ____D C:\Users\ALEXAN~1\AppData\Local\NokiaAccount
2013-08-16 11:16 - 2013-08-16 11:16 - 00000000 ____D C:\Users\ALEXAN~1\AppData\Local\Nokia
2013-08-16 11:16 - 2013-08-16 11:16 - 00000000 ____D C:\ProgramData\PC Suite
2013-08-16 11:16 - 2013-08-16 11:16 - 00000000 ____D C:\ProgramData\Nokia
2013-08-16 11:15 - 2013-08-16 11:16 - 00000000 ____D C:\Program Files (x86)\Nokia
2013-08-16 11:15 - 2013-08-16 11:15 - 00000000 ____D C:\ProgramData\NokiaInstallerCache
2013-08-16 11:15 - 2013-08-16 11:15 - 00000000 ____D C:\Program Files\DIFX
2013-08-16 11:15 - 2013-08-16 11:15 - 00000000 ____D C:\Program Files (x86)\PC Connectivity Solution
2013-08-16 11:15 - 2013-01-23 10:31 - 00057856 _____ (Nokia) C:\Windows\system32\nmwcdclsX64.dll
2013-08-16 11:15 - 2012-10-17 14:53 - 00026112 _____ (Nokia) C:\Windows\system32\Drivers\pccsmcfdx64.sys
2013-08-16 11:14 - 2013-08-16 11:14 - 106311632 _____ C:\Users\Name\Downloads\Nokia_Suite383_webinstaller_ALL.exe
2013-08-15 17:21 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-15 17:21 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-15 17:21 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-15 17:21 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-15 17:21 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-15 17:21 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-15 17:21 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-15 17:21 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-15 17:21 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-15 17:21 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-15 17:21 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-15 17:21 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-15 17:21 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-15 17:21 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-15 17:19 - 2013-08-15 17:20 - 00000000 ____D C:\Windows\system32\MRT
2013-08-15 08:50 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 08:50 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-15 08:50 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 08:50 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-15 08:50 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 08:50 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 08:50 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-15 08:50 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 08:50 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 08:50 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 08:50 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 08:50 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 08:50 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-15 08:50 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-15 08:50 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-15 08:50 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-15 08:50 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-15 08:50 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-15 08:50 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-15 08:50 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-15 08:50 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-15 08:50 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-15 08:50 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-15 08:50 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-15 08:50 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-15 08:50 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 08:50 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-09 09:03 - 2013-08-09 09:03 - 00034709 _____ C:\Users\Name\Desktop\Abrufpositionen-1.xlsx
==================== One Month Modified Files and Folders =======
2013-08-29 09:07 - 2013-08-29 09:07 - 00000887 _____ C:\Users\Name\Desktop\3JRT.txt
2013-08-29 09:07 - 2013-06-22 14:08 - 00000000 ____D C:\Users\ALEXAN~1\AppData\Local\Nero
2013-08-29 09:06 - 2013-08-29 09:06 - 00000887 _____ C:\Users\Name\Desktop\JRT.txt
2013-08-29 08:59 - 2009-07-14 06:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-29 08:59 - 2009-07-14 06:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-29 08:56 - 2013-08-29 08:56 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 08:56 - 2010-11-21 08:50 - 00707956 _____ C:\Windows\system32\perfh007.dat
2013-08-29 08:56 - 2010-11-21 08:50 - 00153410 _____ C:\Windows\system32\perfc007.dat
2013-08-29 08:56 - 2009-07-14 07:13 - 01643622 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-29 08:55 - 2013-08-29 08:55 - 01023533 _____ (Thisisu) C:\Users\Name\Downloads\JRT.exe
2013-08-29 08:52 - 2013-08-29 08:52 - 00001271 _____ C:\Users\Alexandra Leykauf\Desktop\2AdwCleaner[S0].txt
2013-08-29 08:52 - 2013-07-01 16:51 - 00000000 ____D C:\Users\ALEXAN~1\AppData\Local\Deployment
2013-08-29 08:52 - 2013-06-22 17:21 - 00000120 _____ C:\Windows\system32\config\netlogon.ftl
2013-08-29 08:52 - 2012-01-10 09:22 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2013-08-29 08:52 - 2012-01-10 09:22 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2013-08-29 08:52 - 2012-01-10 09:19 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-08-29 08:51 - 2013-08-29 08:49 - 00000000 ____D C:\AdwCleaner
2013-08-29 08:51 - 2012-01-10 08:59 - 01752639 _____ C:\Windows\WindowsUpdate.log
2013-08-29 08:51 - 2012-01-10 08:57 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-29 08:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-29 08:51 - 2009-07-14 06:51 - 00059506 _____ C:\Windows\setupact.log
2013-08-29 08:48 - 2013-08-29 08:48 - 00994642 _____ C:\Users\Name\Downloads\adwcleaner.exe
2013-08-29 08:45 - 2010-11-21 05:47 - 00062932 _____ C:\Windows\PFRO.log
2013-08-29 08:44 - 2013-08-28 15:40 - 00013972 _____ C:\Users\Name\Desktop\Kuxxx.xlsx
2013-08-29 08:44 - 2013-06-22 13:57 - 00000000 ____D C:\Users\Name\Documents\Outlook-Dateien
2013-08-29 08:40 - 2013-06-22 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-29 07:44 - 2013-08-29 07:44 - 00000000 ____D C:\Users\Name\AppData\Roaming\Malwarebytes
2013-08-29 07:41 - 2013-08-29 07:41 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Name\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 07:41 - 2013-08-29 07:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 07:41 - 2013-08-29 07:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-28 15:29 - 2013-06-30 10:09 - 00000000 ____D C:\ProgramData\Lexware
2013-08-28 14:32 - 2013-08-28 14:32 - 00026817 _____ C:\Users\Name\Downloads\Addition.txt
2013-08-28 14:31 - 2013-08-28 14:31 - 01579080 _____ (Farbar) C:\Users\Name\Downloads\FRST64.exe
2013-08-28 14:31 - 2013-08-28 14:31 - 00000000 ____D C:\FRST
2013-08-28 13:02 - 2013-08-28 13:03 - 00088172 _____ C:\Users\Name\Downloads\DarlehenFree.exe
2013-08-28 13:02 - 2013-08-28 13:02 - 00623680 _____ C:\Users\Name\Downloads\DarlehenFree-Downloader.exe
2013-08-28 13:00 - 2013-08-28 13:00 - 01333552 _____ (iMesh Inc) C:\Users\Name\Downloads\iMeshSetup-r1487-w-bf.exe
2013-08-28 12:01 - 2013-06-23 14:06 - 00003440 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2013-08-28 10:59 - 2013-07-03 14:05 - 00000000 ____D C:\Users\Name\Documents\Stick
2013-08-27 15:32 - 2013-07-17 13:49 - 00169984 _____ C:\Users\Name\Desktop\Zuarbeit T&P 20130321 Investitionsuebersicht und Ermittlung_I_Zulage fuer 2013.xls
2013-08-26 15:25 - 2013-07-01 09:56 - 00000000 ____D C:\Users\Name\AppData\Roaming\Skype
2013-08-21 10:40 - 2013-06-22 17:10 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-21 10:40 - 2013-06-22 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-21 10:40 - 2012-01-10 09:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-21 09:02 - 2013-06-22 15:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-19 12:40 - 2013-07-01 13:30 - 00000000 ____D C:\Users\Name\Documents\Alexandra
2013-08-19 11:53 - 2013-08-19 11:53 - 00000000 ___SD C:\Users\Name\Documents\Meine Datenquellen
2013-08-19 11:39 - 2013-08-19 11:39 - 00000000 ____D C:\Users\Name\Mein Backup Datei
2013-08-19 11:39 - 2013-06-22 01:03 - 00000000 ____D C:\Users\Name
2013-08-19 11:39 - 2013-06-22 01:03 - 00000000 ____D C:\Users\ALEXAN~1\AppData\Local\SoftThinks
2013-08-19 09:26 - 2013-08-19 09:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 16:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-16 11:30 - 2013-08-16 11:30 - 00000000 ____D C:\Users\Name\Documents\Nokia Suite
2013-08-16 11:24 - 2013-08-16 11:23 - 00000000 ____D C:\Users\Name\AppData\Roaming\Nokia
2013-08-16 11:23 - 2013-08-16 11:23 - 00000000 ____D C:\Users\Name\AppData\Roaming\Nokia Suite
2013-08-16 11:19 - 2013-08-16 11:16 - 00000000 ____D C:\Users\Name\AppData\Roaming\PC Suite
2013-08-16 11:19 - 2013-08-16 11:16 - 00000000 ____D C:\Users\ALEXAN~1\AppData\Local\NokiaAccount
2013-08-16 11:17 - 2013-08-16 11:17 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2013-08-16 11:16 - 2013-08-16 11:16 - 00000000 ____D C:\Users\ALEXAN~1\AppData\Local\Nokia
2013-08-16 11:16 - 2013-08-16 11:16 - 00000000 ____D C:\ProgramData\PC Suite
2013-08-16 11:16 - 2013-08-16 11:16 - 00000000 ____D C:\ProgramData\Nokia
2013-08-16 11:16 - 2013-08-16 11:15 - 00000000 ____D C:\Program Files (x86)\Nokia
2013-08-16 11:15 - 2013-08-16 11:15 - 00000000 ____D C:\ProgramData\NokiaInstallerCache
2013-08-16 11:15 - 2013-08-16 11:15 - 00000000 ____D C:\Program Files\DIFX
2013-08-16 11:15 - 2013-08-16 11:15 - 00000000 ____D C:\Program Files (x86)\PC Connectivity Solution
2013-08-16 11:15 - 2012-01-10 09:14 - 00024954 _____ C:\Windows\DPINST.LOG
2013-08-16 11:14 - 2013-08-16 11:14 - 106311632 _____ C:\Users\Name\Downloads\Nokia_Suite383_webinstaller_ALL.exe
2013-08-15 17:20 - 2013-08-15 17:19 - 00000000 ____D C:\Windows\system32\MRT
2013-08-15 17:19 - 2013-06-22 16:52 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 14:02 - 2013-07-12 11:19 - 00000000 ____D C:\Users\Name\Desktop\Pendel
2013-08-09 09:03 - 2013-08-09 09:03 - 00034709 _____ C:\Users\Name\Desktop\Abrufpositionen-1.xlsx
2013-08-07 09:02 - 2012-01-10 09:34 - 00000000 ____D C:\Program Files (x86)\McAfee
Files to move or delete:
====================
C:\Users\Alexandra Leykauf\GoToAssistDownloadHelper.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\MSN8048.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\nvStInst.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\Quarantine.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\SkypeSetup.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\_is904D.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\_isFC29.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\{EBA57E2C-F980-4D33-9E95-54F77CE1ED49}\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{E5939887-A112-4AAF-9D33-00FDB5BA72F1}\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{9EBF4BAF-E169-47C9-8421-021AF734EFD5}\setup.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{e2fea5db-9e78-400a-96fc-9fae55261d23}\Isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{e2fea5db-9e78-400a-96fc-9fae55261d23}\MMObjHelper.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{e2fea5db-9e78-400a-96fc-9fae55261d23}\_Isres.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{CF17DA33-3FB5-4EB4-994F-38BDC29CBCE4}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{CF17DA33-3FB5-4EB4-994F-38BDC29CBCE4}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{CF17DA33-3FB5-4EB4-994F-38BDC29CBCE4}\_ISUser.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{c04e79c8-58cb-4daf-b6de-4d8470474817}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{c04e79c8-58cb-4daf-b6de-4d8470474817}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{b2c7a262-69c2-4135-af27-81d48b0be814}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{b2c7a262-69c2-4135-af27-81d48b0be814}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{ab3d15c6-1549-4f7e-93ef-b78894718fe5}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{ab3d15c6-1549-4f7e-93ef-b78894718fe5}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{a5884bee-38c2-4b3e-bfac-13470fd0a80e}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{a5884bee-38c2-4b3e-bfac-13470fd0a80e}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{93676a6f-24a6-4635-badf-3c8cb7dbe232}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{93676a6f-24a6-4635-badf-3c8cb7dbe232}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{906ee967-824c-4aa3-a6b7-4666363458b1}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{906ee967-824c-4aa3-a6b7-4666363458b1}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{8bdbaa56-873f-45fe-afd7-5e01bf575e4e}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{8bdbaa56-873f-45fe-afd7-5e01bf575e4e}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{78102a90-7f0c-4833-8a4e-67857c074202}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{78102a90-7f0c-4833-8a4e-67857c074202}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{70039d50-fff5-4afc-97ad-35e4bb8b5ddd}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{70039d50-fff5-4afc-97ad-35e4bb8b5ddd}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{51decf52-5008-4227-907c-3fbf7601689c}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{51decf52-5008-4227-907c-3fbf7601689c}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{51474a0a-b6ed-422e-b513-2879b260cb31}\Isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{51474a0a-b6ed-422e-b513-2879b260cb31}\MMObjHelper.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{51474a0a-b6ed-422e-b513-2879b260cb31}\_Isres.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{4bc501a0-9699-489c-8ebb-2df540cfcf44}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{4bc501a0-9699-489c-8ebb-2df540cfcf44}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{31f30ff3-b673-40d4-9d5a-0538075bb989}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{31f30ff3-b673-40d4-9d5a-0538075bb989}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{21321a85-8b24-49f7-a853-9918e3ac679b}\Isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{21321a85-8b24-49f7-a853-9918e3ac679b}\MMObjHelper.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{21321a85-8b24-49f7-a853-9918e3ac679b}\_Isres.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{036dfef8-a447-4c74-947e-23527d34140d}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{036dfef8-a447-4c74-947e-23527d34140d}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{01fbb20b-abf1-42ee-93ed-6d5b9c5d9c71}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{70F3C771-F8BA-407C-B368-01D70FCAEA80}\{01fbb20b-abf1-42ee-93ed-6d5b9c5d9c71}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{e2fea5db-9e78-400a-96fc-9fae55261d23}\Isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{e2fea5db-9e78-400a-96fc-9fae55261d23}\MMObjHelper.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{e2fea5db-9e78-400a-96fc-9fae55261d23}\_Isres.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{CF17DA33-3FB5-4EB4-994F-38BDC29CBCE4}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{CF17DA33-3FB5-4EB4-994F-38BDC29CBCE4}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{CF17DA33-3FB5-4EB4-994F-38BDC29CBCE4}\_ISUser.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{c04e79c8-58cb-4daf-b6de-4d8470474817}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{c04e79c8-58cb-4daf-b6de-4d8470474817}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{b2c7a262-69c2-4135-af27-81d48b0be814}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{b2c7a262-69c2-4135-af27-81d48b0be814}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{ab3d15c6-1549-4f7e-93ef-b78894718fe5}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{ab3d15c6-1549-4f7e-93ef-b78894718fe5}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{a5884bee-38c2-4b3e-bfac-13470fd0a80e}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{a5884bee-38c2-4b3e-bfac-13470fd0a80e}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{93676a6f-24a6-4635-badf-3c8cb7dbe232}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{93676a6f-24a6-4635-badf-3c8cb7dbe232}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{906ee967-824c-4aa3-a6b7-4666363458b1}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{906ee967-824c-4aa3-a6b7-4666363458b1}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{8bdbaa56-873f-45fe-afd7-5e01bf575e4e}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{8bdbaa56-873f-45fe-afd7-5e01bf575e4e}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{78102a90-7f0c-4833-8a4e-67857c074202}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{78102a90-7f0c-4833-8a4e-67857c074202}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{70039d50-fff5-4afc-97ad-35e4bb8b5ddd}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{70039d50-fff5-4afc-97ad-35e4bb8b5ddd}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{51decf52-5008-4227-907c-3fbf7601689c}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{51decf52-5008-4227-907c-3fbf7601689c}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{51474a0a-b6ed-422e-b513-2879b260cb31}\Isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{51474a0a-b6ed-422e-b513-2879b260cb31}\MMObjHelper.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{51474a0a-b6ed-422e-b513-2879b260cb31}\_Isres.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{4bc501a0-9699-489c-8ebb-2df540cfcf44}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{4bc501a0-9699-489c-8ebb-2df540cfcf44}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{31f30ff3-b673-40d4-9d5a-0538075bb989}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{31f30ff3-b673-40d4-9d5a-0538075bb989}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{21321a85-8b24-49f7-a853-9918e3ac679b}\Isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{21321a85-8b24-49f7-a853-9918e3ac679b}\MMObjHelper.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{21321a85-8b24-49f7-a853-9918e3ac679b}\_Isres.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{036dfef8-a447-4c74-947e-23527d34140d}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{036dfef8-a447-4c74-947e-23527d34140d}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{01fbb20b-abf1-42ee-93ed-6d5b9c5d9c71}\isrt.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{6DA459F4-F547-4D6E-A340-C80A7FC8DDA1}\{01fbb20b-abf1-42ee-93ed-6d5b9c5d9c71}\_IsRes.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{3611D404-2E9A-45DE-B08D-56CB6CB3BFDD}\ISSetup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{3611D404-2E9A-45DE-B08D-56CB6CB3BFDD}\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{0F8FF9CE-47CE-442E-B558-8F701208461C}\ISSetup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\{0F8FF9CE-47CE-442E-B558-8F701208461C}\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_o9b4gex.zip\x64\Setup.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_o9b4gex.zip\x64\misc\DiasSetup.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_o9b4gex.zip\x64\misc\DiasUninst.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_o9b4gex.zip\x64\misc\InsCmn.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_o9b4gex.zip\x64\misc\SetupUIG.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_o9b4gex.zip\x64\misc\UNINSTAL.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_o9b4gex.zip\x64\misc\UninsUIG.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\Temp1_darlehen.zip\darlehen.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\ALEXAN~1\AppData\Local\Temp\ispDD47.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\ispA6FB.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\isp7DBB.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\isp7A70.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\isp76B8.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\isp6ECC.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\isp50F0.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\isp2A9B.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\isp2722.tmp\_Setup.dll
C:\Users\ALEXAN~1\AppData\Local\Temp\is357113909\OpenItSetup.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\is357113909\wajam_validate.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\is1177715538\wajam_validate.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\DvInes\B0000048\DvInesAutostartHelperStop.Exe
C:\Users\ALEXAN~1\AppData\Local\Temp\darlehen\darlehen.exe
C:\Users\ALEXAN~1\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-22 12:16
==================== End Of Log ============================ --- --- ---
--- --- ---
Vielen Dank!
Alexandra |