Paraglider58 | 10.09.2013 14:57 | Hier die Logfiles:
Malwarebytes: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.10.07
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
PC 1 :: PC1-PC [Administrator]
Schutz: Aktiviert
10.09.2013 15:20:49
mbam-log-2013-09-10 (15-20-49).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 268356
Laufzeit: 5 Minute(n), 45 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) AdwCleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v3.003 - Bericht erstellt am 09/09/2013 um 15:42:10
# Updated 07/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : PC 1 - PC1-PC
# Gestartet von : D:\Downloads\Büro\Antiviruspgms\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\driver-soft
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\Common\LuaRT
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\DataMgr
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\fbDownloader
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\Intermediate
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\SCheck
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\SSync
Datei Gelöscht : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\om@offermosquito.com.xpi
Datei Gelöscht : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\searchplugins\search.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DataMgr]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Intermediate]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [scheck]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ssync]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_barcode-forge_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_barcode-forge_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_blender_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_blender_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fwsim_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fwsim_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gamespy-arcade_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gamespy-arcade_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Softonic
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://searchqm.com/search.php?channel=msus200fbdgy6&q=");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://searchqm.com/?channel=msus200fbdgy6");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://searchqm.com/search.php?channel=msus200fbdgy6&q=");
Zeile gelöscht : user_pref("om.config", "{\"active\":true,\"name\":\"sfprt\",\"id\":9,\"dispId\":\"CH-9\",\"aboutLink\":\"\",\"trackingGeneral\":true,\"gaAccount\":\"UA-39484183-1\",\"gaDomain\":\"offermosquito.com\",[...]
*************************
AdwCleaner[R0].txt - [4004 octets] - [09/09/2013 15:40:34]
AdwCleaner[S0].txt - [3939 octets] - [09/09/2013 15:42:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3999 octets] ########## --- --- ---
AdwCleaner Logfile: Code:
# AdwCleaner v3.003 - Bericht erstellt am 10/09/2013 um 15:37:25
# Updated 07/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : PC 1 - PC1-PC
# Gestartet von : C:\Users\PC 1\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\om@offermosquito.com.xpi
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\prefs.js ]
Zeile gelöscht : user_pref("om.config", "{\"active\":true,\"name\":\"sfprt\",\"id\":9,\"dispId\":\"CH-9\",\"aboutLink\":\"\",\"trackingGeneral\":true,\"gaAccount\":\"UA-39484183-1\",\"gaDomain\":\"offermosquito.com\",[...]
*************************
AdwCleaner[R0].txt - [5211 octets] - [09/09/2013 15:40:34]
AdwCleaner[S0].txt - [5147 octets] - [09/09/2013 15:42:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5207 octets] ########## --- --- ---
JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.9 (09.07.2013:1)
OS: Windows 7 Home Premium x86
Ran by PC 1 on 10.09.2013 at 15:42:18,66
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\PC 1\appdata\local\adawarebp"
~~~ FireFox
Emptied folder: C:\Users\PC 1\AppData\Roaming\mozilla\firefox\profiles\17thmgg3.default\minidumps [46 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.09.2013 at 15:45:41,79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 01
Ran by PC 1 (administrator) on PC1-PC on 10-09-2013 15:46:43
Running from C:\Users\PC 1\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files\GNU\GnuPG\dirmngr.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
() C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\system32\UI0Detect.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\ipoint.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files\Smart PDF Converter Pro\SmartSoft PDF Printer Agent.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
() C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
(Bartels Media GmbH) D:\Program Files\PhraseExpress\phraseexpress.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [153672 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [IntelliType Pro] - C:\Program Files\Microsoft Device Center\itype.exe [1109072 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft Device Center\ipoint.exe [1629280 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SmartSoft PDF Printer Agent] - C:\Program Files\Smart PDF Converter Pro\SmartSoft PDF Printer Agent.exe [52952 2011-12-12] ()
HKLM\...\Run: [LifeCam] - C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft)
HKLM\...\Run: [HOSTS Anti-Adware_PUPs] - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961 2013-09-09] ()
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Run: [Snoozer] - C:\Users\PC 1\AppData\Roaming\Snz\Snz.exe [1137683 2013-07-23] ()
HKCU\...\Policies\Explorer: [NoDrives] 0
Lsa: [Authentication Packages] msv1_0 relog_ap
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PhraseExpress.lnk
ShortcutTarget: PhraseExpress.lnk -> D:\Program Files\PhraseExpress\phraseexpress.exe (Bartels Media GmbH)
Startup: C:\Users\PC 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {40E1CB6C-A17F-496D-B213-873DC0467429} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS
SearchScopes: HKCU - {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-flv
BHO: LastPass Vault - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files\LastPass\LPToolbar.dll (LastPass)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll (LastPass)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 33 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default
FF DefaultSearchEngine: Search
FF Homepage: http://www.trojaner-board.de/141283-...ml#post1151816
FF NetworkProxy: "ftp", "62.162.6.11"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "http", "62.162.6.11"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "62.162.6.11"
FF NetworkProxy: "socks_port", 3128
FF NetworkProxy: "ssl", "62.162.6.11"
FF NetworkProxy: "ssl_port", 3128
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.4 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\fb_add_on@avm.de
FF Extension: LastPass - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\support@lastpass.com
FF Extension: DownloadHelper - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D}
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\7a05ead03bbae1ec9295bcf8836b8a28270676558747f31d563e66739e36a29b_lp.key
FF Extension: elemhidehelper - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\elemhidehelper@adblockplus.org.xpi
FF Extension: firefox - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\firefox@ghostery.com.xpi
FF Extension: firejump - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\firejump@firejump.net.xpi
FF Extension: stealthyextension - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\stealthyextension@gmail.com.xpi
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
========================== Services (Whitelisted) =================
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [427288 2007-12-03] (Acronis)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [218112 2013-05-28] ()
S2 HOSTS Anti-PUPs; C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2013-09-09] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14573856 2013-08-27] (NVIDIA Corporation)
S3 Samsung UPD Service; C:\Windows\System32\SUPDSvc.exe [131888 2010-08-09] (Samsung Electronics CO., LTD.)
R2 TryAndDecideService; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [498792 2007-12-03] ()
==================== Drivers (Whitelisted) ====================
R2 ACEDRV05; C:\Windows\system32\drivers\ACEDRV05.sys [97792 2013-01-26] (Protect Software GmbH)
R0 amd_sata; C:\Windows\System32\drivers\amd_sata.sys [70784 2011-12-12] (Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\drivers\amd_xata.sys [34944 2011-12-12] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-25] (Avira Operations GmbH & Co. KG)
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2013-08-24] (AVM Berlin)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-08-16] (GFI Software)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [91248 2012-03-02] (Qualcomm Atheros Co., Ltd.)
S3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [30360 2011-09-02] (Logitech, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 NvStUSB; C:\Windows\system32\drivers\nvstusb.sys [429800 2012-08-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [33568 2013-08-20] (NVIDIA Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-10-09] (Avira GmbH)
R0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [368480 2012-09-24] (Acronis)
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2012-09-24] (Acronis)
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.)
R3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.)
R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.)
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\PC1~1\AppData\Local\Temp\catchme.sys [x]
S1 HWiNFO32; \??\C:\Program Files\Driver-Soft\DriverGenius\HWiNFO32.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-10 15:38 - 2013-09-10 15:38 - 00000022 _____ C:\Windows\S.dirmngr
2013-09-10 15:30 - 2013-09-10 15:30 - 01029490 _____ (Thisisu) C:\Users\PC 1\Desktop\JRT.exe
2013-09-10 15:29 - 2013-09-10 15:29 - 01037278 _____ C:\Users\PC 1\Desktop\adwcleaner.exe
2013-09-10 14:13 - 2013-09-10 14:13 - 96922344 _____ C:\Windows\system32\ꮯˀ바_
2013-09-10 13:20 - 2013-09-10 13:20 - 00020668 _____ C:\ComboFix.txt
2013-09-10 12:59 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-10 12:59 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-10 12:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-10 12:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-10 12:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-10 12:59 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-10 12:59 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-10 12:59 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-10 12:58 - 2013-09-10 13:20 - 00000000 ____D C:\Qoobox
2013-09-10 12:58 - 2013-09-10 13:14 - 00000000 ____D C:\Windows\erdnt
2013-09-10 12:57 - 2013-09-10 12:57 - 05125565 ____R (Swearware) C:\Users\PC 1\Desktop\ComboFix.exe
2013-09-10 11:37 - 2013-09-10 11:37 - 00023245 _____ C:\Users\PC 1\Desktop\Addition.txt
2013-09-10 11:36 - 2013-09-10 11:36 - 00000000 ____D C:\FRST
2013-09-10 11:35 - 2013-09-10 11:35 - 01082349 _____ (Farbar) C:\Users\PC 1\Desktop\FRST.exe
2013-09-09 18:16 - 2013-09-09 18:16 - 96732368 _____ C:\Windows\system32\鳜�바o
2013-09-09 17:28 - 2013-09-10 15:14 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\PC 1\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-09 17:17 - 2013-09-09 17:17 - 00000747 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-09 17:02 - 2013-09-09 17:03 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Foxit Software
2013-09-09 17:02 - 2013-09-09 17:02 - 00002018 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-09-09 17:02 - 2013-09-09 17:02 - 00000000 ____D C:\Program Files\Foxit Software
2013-09-09 17:02 - 2013-06-09 21:59 - 00216064 _____ C:\Windows\system32\gcapi_dll.dll
2013-09-09 16:25 - 2013-09-09 16:25 - 00000000 ____D C:\Program Files\ESET
2013-09-09 16:21 - 2013-09-10 13:22 - 00001140 _____ C:\Windows\PFRO.log
2013-09-09 16:10 - 2013-09-10 15:15 - 00001077 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-09 16:10 - 2013-09-10 15:15 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Malwarebytes
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-09 16:10 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-09 16:03 - 2013-09-09 16:03 - 00000000 ____D C:\Windows\ERUNT
2013-09-09 15:58 - 2013-09-09 15:58 - 00001149 _____ C:\Users\PC 1\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2013-09-09 15:58 - 2013-09-09 15:58 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs
2013-09-09 15:44 - 2013-09-10 15:39 - 00000840 _____ C:\Windows\setupact.log
2013-09-09 15:44 - 2013-09-09 15:44 - 00000000 _____ C:\Windows\setuperr.log
2013-09-09 15:40 - 2013-09-10 15:37 - 00000000 ____D C:\AdwCleaner
2013-09-09 15:34 - 2013-09-09 15:34 - 00000975 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-09 13:33 - 2013-09-09 13:34 - 11634176 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2013-09-09 13:33 - 2013-09-09 13:33 - 06484992 _____ C:\Program Files\LPPlugin.dll
2013-09-09 13:33 - 2013-09-09 13:33 - 01068544 _____ (LastPass) C:\Program Files\LPIEHome.ocx
2013-09-09 13:33 - 2013-09-09 13:33 - 00612864 _____ (LastPass) C:\Program Files\LPToolbar.dll
2013-09-09 13:33 - 2013-09-09 13:33 - 00180736 _____ C:\Program Files\WinBioStandalone.exe
2013-09-09 13:33 - 2013-09-09 13:33 - 00058282 _____ C:\Program Files\iehome2.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00023666 _____ C:\Program Files\iehome.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00006582 _____ C:\Program Files\vaultcommonc.js
2013-09-09 13:33 - 2013-09-09 13:33 - 00006260 _____ C:\Program Files\menu.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00002972 _____ C:\Program Files\json2c.js
2013-09-09 13:33 - 2013-09-09 13:33 - 00001174 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2013-09-09 13:33 - 2013-09-09 13:33 - 00000716 _____ C:\Program Files\context.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00000223 _____ C:\Program Files\img.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00000081 _____ C:\Program Files\programfiles.txt
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deleteprogramfiles.txt
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deletelocallowlastpass.txt
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\lang
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\images
2013-09-09 13:32 - 2013-09-09 13:34 - 00000000 ____D C:\Program Files\LastPass
2013-09-06 14:24 - 2013-09-06 14:24 - 96334488 _____ C:\Windows\system32\覑�바_
2013-09-05 15:39 - 2013-09-05 15:39 - 00000000 ____D C:\Program Files\BrainWave Generator
2013-09-05 14:44 - 2013-09-05 14:44 - 00001294 _____ C:\Users\Public\Desktop\Paint.NET.lnk
2013-09-04 15:38 - 2013-09-04 15:38 - 00002133 _____ C:\Users\Public\Desktop\PC-Kaufmann Komplettpaket Pro 2014.lnk
2013-09-02 15:49 - 2013-09-02 15:49 - 00001159 _____ C:\Users\PC 1\Desktop\Bwgen.lnk
2013-09-02 15:32 - 1997-11-19 15:49 - 00303616 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2013-08-30 08:32 - 2013-08-20 15:33 - 00033568 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2013-08-24 07:54 - 2013-08-24 07:54 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys
2013-08-18 12:01 - 2013-08-18 12:01 - 00000000 ____D C:\Users\PC 1\Desktop\Komunikation
2013-08-18 12:00 - 2013-08-18 12:04 - 00000000 ____D C:\Users\PC 1\Desktop\Film und Ton
2013-08-18 11:57 - 2013-08-18 12:32 - 00000000 ____D C:\Users\PC 1\Desktop\Systemprogramme
2013-08-18 11:42 - 2013-08-18 12:39 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-08-18 11:42 - 2013-08-18 11:50 - 00000000 ____D C:\Program Files\Security Task Manager
2013-08-18 11:07 - 2013-08-18 11:08 - 00000000 ____D C:\Program Files\Sysinternals
2013-08-17 11:02 - 2013-08-17 11:02 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\LavasoftStatistics
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\ProgramData\Ad-Aware Antivirus
2013-08-16 14:23 - 2013-08-16 14:32 - 00000000 ____D C:\Program Files\Ad-Aware Antivirus
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Lavasoft
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection
2013-08-16 14:22 - 2013-08-16 14:33 - 00000000 ____D C:\Program Files\Lavasoft
2013-08-16 14:21 - 2013-08-16 14:31 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Ad-Aware Antivirus
2013-08-16 14:21 - 2013-08-16 14:21 - 00044424 _____ (GFI Software) C:\Windows\system32\sbbd.exe
2013-08-16 14:21 - 2013-08-16 14:21 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys
2013-08-14 06:47 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 06:47 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 06:47 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 06:47 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 06:47 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 06:47 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 06:47 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 06:47 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 06:47 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 06:33 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 06:33 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 06:33 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-14 06:33 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 06:33 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 06:33 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 06:33 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 06:33 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 06:33 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 06:33 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 06:33 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 06:33 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-11 07:57 - 2013-08-11 07:58 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Axialis
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\NewFreeScreensavers
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\Common Files\NewFreeScreensavers
2013-08-11 07:57 - 2011-05-11 16:56 - 11046329 _____ (Axialis Software) C:\Windows\system32\nfsFireworks2.scr
==================== One Month Modified Files and Folders =======
2013-09-10 15:46 - 2009-07-14 06:34 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-10 15:46 - 2009-07-14 06:34 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-10 15:45 - 2013-09-10 15:45 - 00000926 _____ C:\Users\PC 1\Desktop\JRT.txt
2013-09-10 15:45 - 2010-11-20 23:01 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-10 15:44 - 2013-02-28 11:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-10 15:43 - 2013-03-27 11:56 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-10 15:39 - 2013-09-09 15:44 - 00000840 _____ C:\Windows\setupact.log
2013-09-10 15:38 - 2013-09-10 15:38 - 00000022 _____ C:\Windows\S.dirmngr
2013-09-10 15:38 - 2013-08-10 09:16 - 01804100 _____ C:\Windows\WindowsUpdate.log
2013-09-10 15:38 - 2013-03-27 11:56 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-10 15:38 - 2012-09-19 10:10 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-10 15:38 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-10 15:37 - 2013-09-09 15:40 - 00000000 ____D C:\AdwCleaner
2013-09-10 15:30 - 2013-09-10 15:30 - 01029490 _____ (Thisisu) C:\Users\PC 1\Desktop\JRT.exe
2013-09-10 15:29 - 2013-09-10 15:29 - 01037278 _____ C:\Users\PC 1\Desktop\adwcleaner.exe
2013-09-10 15:15 - 2013-09-09 16:10 - 00001077 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-10 15:15 - 2013-09-09 16:10 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-10 15:14 - 2013-09-09 17:28 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\PC 1\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-10 14:13 - 2013-09-10 14:13 - 96922344 _____ C:\Windows\system32\ꮯˀ바_
2013-09-10 13:22 - 2013-09-09 16:21 - 00001140 _____ C:\Windows\PFRO.log
2013-09-10 13:21 - 2012-09-21 14:43 - 00000000 ____D C:\Users\PC 1\Documents\PhraseExpress
2013-09-10 13:20 - 2013-09-10 13:20 - 00020668 _____ C:\ComboFix.txt
2013-09-10 13:20 - 2013-09-10 12:58 - 00000000 ____D C:\Qoobox
2013-09-10 13:20 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-09-10 13:14 - 2013-09-10 12:58 - 00000000 ____D C:\Windows\erdnt
2013-09-10 13:09 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-09-10 12:57 - 2013-09-10 12:57 - 05125565 ____R (Swearware) C:\Users\PC 1\Desktop\ComboFix.exe
2013-09-10 11:37 - 2013-09-10 11:37 - 00023245 _____ C:\Users\PC 1\Desktop\Addition.txt
2013-09-10 11:36 - 2013-09-10 11:36 - 00000000 ____D C:\FRST
2013-09-10 11:35 - 2013-09-10 11:35 - 01082349 _____ (Farbar) C:\Users\PC 1\Desktop\FRST.exe
2013-09-09 19:21 - 2012-09-21 13:12 - 00000234 _____ C:\Windows\ktel.ini
2013-09-09 18:16 - 2013-09-09 18:16 - 96732368 _____ C:\Windows\system32\鳜�바o
2013-09-09 17:17 - 2013-09-09 17:17 - 00000747 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-09 17:17 - 2012-11-28 15:34 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\vlc
2013-09-09 17:03 - 2013-09-09 17:02 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Foxit Software
2013-09-09 17:02 - 2013-09-09 17:02 - 00002018 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-09-09 17:02 - 2013-09-09 17:02 - 00000000 ____D C:\Program Files\Foxit Software
2013-09-09 16:25 - 2013-09-09 16:25 - 00000000 ____D C:\Program Files\ESET
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Malwarebytes
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-09 16:03 - 2013-09-09 16:03 - 00000000 ____D C:\Windows\ERUNT
2013-09-09 15:58 - 2013-09-09 15:58 - 00001149 _____ C:\Users\PC 1\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk
2013-09-09 15:58 - 2013-09-09 15:58 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs
2013-09-09 15:44 - 2013-09-09 15:44 - 00000000 _____ C:\Windows\setuperr.log
2013-09-09 15:42 - 2013-02-01 12:25 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Common
2013-09-09 15:37 - 2012-03-16 08:58 - 00000000 ____D C:\Windows\Panther
2013-09-09 15:34 - 2013-09-09 15:34 - 00000975 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-09 15:34 - 2012-09-24 13:45 - 00000000 ____D C:\Program Files\CCleaner
2013-09-09 13:34 - 2013-09-09 13:33 - 11634176 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2013-09-09 13:34 - 2013-09-09 13:32 - 00000000 ____D C:\Program Files\LastPass
2013-09-09 13:33 - 2013-09-09 13:33 - 06484992 _____ C:\Program Files\LPPlugin.dll
2013-09-09 13:33 - 2013-09-09 13:33 - 01068544 _____ (LastPass) C:\Program Files\LPIEHome.ocx
2013-09-09 13:33 - 2013-09-09 13:33 - 00612864 _____ (LastPass) C:\Program Files\LPToolbar.dll
2013-09-09 13:33 - 2013-09-09 13:33 - 00180736 _____ C:\Program Files\WinBioStandalone.exe
2013-09-09 13:33 - 2013-09-09 13:33 - 00058282 _____ C:\Program Files\iehome2.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00023666 _____ C:\Program Files\iehome.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00006582 _____ C:\Program Files\vaultcommonc.js
2013-09-09 13:33 - 2013-09-09 13:33 - 00006260 _____ C:\Program Files\menu.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00002972 _____ C:\Program Files\json2c.js
2013-09-09 13:33 - 2013-09-09 13:33 - 00001174 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2013-09-09 13:33 - 2013-09-09 13:33 - 00000716 _____ C:\Program Files\context.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00000223 _____ C:\Program Files\img.html
2013-09-09 13:33 - 2013-09-09 13:33 - 00000081 _____ C:\Program Files\programfiles.txt
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deleteprogramfiles.txt
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deletelocallowlastpass.txt
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\lang
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\images
2013-09-06 17:55 - 2012-10-03 16:45 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Skype
2013-09-06 17:41 - 2013-06-24 11:56 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Paint.NET
2013-09-06 14:24 - 2013-09-06 14:24 - 96334488 _____ C:\Windows\system32\覑�바_
2013-09-05 15:39 - 2013-09-05 15:39 - 00000000 ____D C:\Program Files\BrainWave Generator
2013-09-05 14:44 - 2013-09-05 14:44 - 00001294 _____ C:\Users\Public\Desktop\Paint.NET.lnk
2013-09-05 14:43 - 2013-06-24 11:56 - 00000000 ____D C:\Program Files\Paint.NET
2013-09-04 16:14 - 2012-09-21 13:02 - 00000052 _____ C:\Windows\seumain.INI
2013-09-04 15:39 - 2012-09-19 10:12 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-09-04 15:38 - 2013-09-04 15:38 - 00002133 _____ C:\Users\Public\Desktop\PC-Kaufmann Komplettpaket Pro 2014.lnk
2013-09-04 15:38 - 2012-09-21 13:00 - 00271906 _____ C:\outlooksync.log
2013-09-04 15:38 - 2012-09-21 13:00 - 00148852 _____ C:\eBay.log
2013-09-04 15:38 - 2012-09-21 12:59 - 00278084 _____ C:\BankCom.log
2013-09-04 15:38 - 2012-09-21 12:59 - 00205086 _____ C:\ElsterShared.log
2013-09-04 15:37 - 2012-09-21 12:59 - 00228068 _____ C:\BankContacts.log
2013-09-04 15:37 - 2012-09-21 12:59 - 00159364 _____ C:\Saip.log
2013-09-04 15:37 - 2012-09-21 12:59 - 00152570 _____ C:\Cockpit.log
2013-09-04 15:37 - 2012-09-21 12:59 - 00000000 ____D C:\Program Files\Common Files\Sage KHK Shared
2013-09-04 15:37 - 2012-09-21 12:59 - 00000000 ____D C:\Program Files\Common Files\Sage Group
2013-09-04 15:37 - 2012-09-21 12:47 - 00000000 ____D C:\Program Files\Common Files\Sage Software Shared
2013-09-04 13:59 - 2013-05-02 11:12 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-09-04 13:59 - 2012-10-09 13:31 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-04 13:59 - 2012-10-09 13:31 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-02 15:49 - 2013-09-02 15:49 - 00001159 _____ C:\Users\PC 1\Desktop\Bwgen.lnk
2013-09-01 09:09 - 2013-07-31 11:00 - 00000000 ____D C:\Users\PC1~1\AppData\Local\FRITZ!
2013-08-31 09:59 - 2012-09-21 13:07 - 00000000 ___RD C:\Users\PC 1\Desktop\Büro
2013-08-30 08:32 - 2012-09-19 10:10 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-08-28 14:55 - 2013-05-01 16:16 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Deployment
2013-08-24 07:54 - 2013-08-24 07:54 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys
2013-08-22 12:28 - 2012-10-19 12:54 - 00000000 ____D C:\Users\PC 1\dwhelper
2013-08-20 15:33 - 2013-08-30 08:32 - 00033568 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2013-08-20 15:32 - 2013-07-31 07:52 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2013-08-19 16:51 - 2012-10-24 15:59 - 00000000 ____D C:\Users\PC 1\Documents\FW-Sim
2013-08-19 16:48 - 2012-10-24 15:49 - 00000571 _____ C:\Users\Public\Desktop\FWsim.lnk
2013-08-18 12:39 - 2013-08-18 11:42 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-08-18 12:32 - 2013-08-18 11:57 - 00000000 ____D C:\Users\PC 1\Desktop\Systemprogramme
2013-08-18 12:04 - 2013-08-18 12:00 - 00000000 ____D C:\Users\PC 1\Desktop\Film und Ton
2013-08-18 12:04 - 2012-09-25 15:32 - 00000000 ___RD C:\Users\PC 1\Desktop\Flugsimulator
2013-08-18 12:01 - 2013-08-18 12:01 - 00000000 ____D C:\Users\PC 1\Desktop\Komunikation
2013-08-18 11:50 - 2013-08-18 11:42 - 00000000 ____D C:\Program Files\Security Task Manager
2013-08-18 11:08 - 2013-08-18 11:07 - 00000000 ____D C:\Program Files\Sysinternals
2013-08-18 07:45 - 2012-09-21 12:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-17 11:02 - 2013-08-17 11:02 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-16 14:33 - 2013-08-16 14:22 - 00000000 ____D C:\Program Files\Lavasoft
2013-08-16 14:32 - 2013-08-16 14:23 - 00000000 ____D C:\Program Files\Ad-Aware Antivirus
2013-08-16 14:31 - 2013-08-16 14:21 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Ad-Aware Antivirus
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\LavasoftStatistics
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\ProgramData\Ad-Aware Antivirus
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Lavasoft
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection
2013-08-16 14:23 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-08-16 14:21 - 2013-08-16 14:21 - 00044424 _____ (GFI Software) C:\Windows\system32\sbbd.exe
2013-08-16 14:21 - 2013-08-16 14:21 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys
2013-08-16 09:48 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-08-16 09:20 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-15 13:00 - 2012-09-21 12:59 - 01045776 _____ (Microsoft Corporation) C:\Windows\system32\msjet35.dll
2013-08-15 13:00 - 2012-09-21 12:59 - 00487424 _____ (Microsoft Corporation) C:\Windows\system32\msvcp70.dll
2013-08-15 13:00 - 2012-09-21 12:59 - 00407312 _____ (Microsoft Corporation) C:\Windows\system32\msrepl35.dll
2013-08-15 13:00 - 2012-09-21 12:59 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msvcr70.dll
2013-08-15 13:00 - 2012-09-21 12:59 - 00252176 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x35.dll
2013-08-15 13:00 - 2012-09-21 12:59 - 00123664 _____ (Microsoft Corporation) C:\Windows\system32\msjint35.dll
2013-08-15 13:00 - 2012-09-21 12:59 - 00098304 _____ (Inner Media, Inc.) C:\Windows\system32\dunzip32.dll
2013-08-15 13:00 - 2012-09-21 12:59 - 00024848 _____ (Microsoft Corporation) C:\Windows\system32\msjter35.dll
2013-08-15 09:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-14 06:52 - 2013-07-26 21:18 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 06:50 - 2012-09-26 08:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 06:50 - 2012-09-21 11:39 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-11 07:58 - 2013-08-11 07:57 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Axialis
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\NewFreeScreensavers
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\Common Files\NewFreeScreensavers
Files to move or delete:
====================
C:\Users\PC1~1\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!
LastRegBack: 2013-09-02 12:11
==================== End Of Log =========================== --- --- ---
--- --- ---
Gruß Paraglider58 |