MBAM: Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.10.28.06
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16721
Benutzer :: BENUTZER-PC [Administrator]
28.10.2013 17:13:12
mbam-log-2013-10-28 (17-13-12).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 255966
Laufzeit: 16 Minute(n), 21 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 4
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 4
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (Hijack.SearchPage) -> Bösartig: (hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1372101133778&tguid=46364-3869-1372101133778-497233FBF3FB57291EB9C35158D4AC3A&st=chrome&q=) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Bösartig: (hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1372101133778&tguid=46364-3869-1372101133778-497233FBF3FB57291EB9C35158D4AC3A&st=chrome&q=) Gut: (hxxp://www.google.com/) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Bösartig: (hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1372101133778&tguid=46364-3869-1372101133778-497233FBF3FB57291EB9C35158D4AC3A&st=chrome&q=) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Bösartig: (hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1372101133778&tguid=46364-3869-1372101133778-497233FBF3FB57291EB9C35158D4AC3A&st=chrome&q=) Gut: (hxxp://www.google.com/) -> Erfolgreich ersetzt und in Quarantäne gestellt.
Infizierte Verzeichnisse: 9
C:\Users\Benutzer\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\RelevantKnowledge (PUP.Spyware.MarketScore) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Roaming\OpenCandy\79D79AC95DDB4AA4B36A88A3F785EB31 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Roaming\OpenCandy\B0C8F119017047F7879E101AF2B6D2EF (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Roaming\OpenCandy\CDFE40C87F7E4A6B860E8FE72B3DD5B6 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\mt_ffx\Delta\delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.21.5 (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 29
C:\Users\Benutzer\AppData\Roaming\OpenCandy\B0C8F119017047F7879E101AF2B6D2EF\DeltaTB.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Roaming\OpenCandy\CDFE40C87F7E4A6B860E8FE72B3DD5B6\DeltaTB.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\DeltaTB.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\82F2C33C-BAB0-7891-9D94-09C8CB24F5E5\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\82F2C33C-BAB0-7891-9D94-09C8CB24F5E5\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\82F2C33C-BAB0-7891-9D94-09C8CB24F5E5\Latest\ccp.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\82F2C33C-BAB0-7891-9D94-09C8CB24F5E5\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\82F2C33C-BAB0-7891-9D94-09C8CB24F5E5\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\82F2C33C-BAB0-7891-9D94-09C8CB24F5E5\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\91F2F1E9-BAB0-7891-9864-5BB2C8D1EB53\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\91F2F1E9-BAB0-7891-9864-5BB2C8D1EB53\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\91F2F1E9-BAB0-7891-9864-5BB2C8D1EB53\Latest\ccp.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\91F2F1E9-BAB0-7891-9864-5BB2C8D1EB53\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\91F2F1E9-BAB0-7891-9864-5BB2C8D1EB53\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\91F2F1E9-BAB0-7891-9864-5BB2C8D1EB53\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\A3883B61-BAB0-7891-85FE-B771F6FF70DB\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\A3883B61-BAB0-7891-85FE-B771F6FF70DB\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\A3883B61-BAB0-7891-85FE-B771F6FF70DB\Latest\ccp.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\A3883B61-BAB0-7891-85FE-B771F6FF70DB\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\A3883B61-BAB0-7891-85FE-B771F6FF70DB\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\A3883B61-BAB0-7891-85FE-B771F6FF70DB\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\updA806\BabMaint.x (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Temp\OCS\ocs_v6r.exe (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\Downloads\winamp5621_full_emusic-7plus_all.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\Downloads\SciLorsGroovesharkcomDownloader.exe (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\Bundled software uninstaller\biclient.exe (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Local\DownloadGuide\Offers\plushd.exe (PUP.Optional.CrossRider) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Benutzer\AppData\Roaming\OpenCandy\79D79AC95DDB4AA4B36A88A3F785EB31\driverscannerROE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) AdwCleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v3.010 - Report created 28/10/2013 at 17:40:53
# Updated 20/10/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Benutzer - BENUTZER-PC
# Running from : C:\Users\Benutzer\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : SystemStoreService
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\Program Files\SoftwareUpdater
Folder Deleted : C:\Users\Benutzer\AppData\Local\Bundled software uninstaller
Folder Deleted : C:\Users\Benutzer\AppData\Local\DownloadGuide
Folder Deleted : C:\Users\Benutzer\AppData\Local\Temp\OCS
Folder Deleted : C:\Users\Benutzer\AppData\LocalLow\SimplyTech
Folder Deleted : C:\Users\Benutzer\AppData\Roaming\DesktopIconForAmazon
Folder Deleted : C:\Users\Benutzer\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\Benutzer\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\firejump@firejump.net
File Deleted : C:\Users\Benutzer\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\bProtector_extensions.rdf
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\11-suche.xml
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\Babylon.xml
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\BrowserDefender.xml
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\daemon-search.xml
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\delta.xml
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\Web Search.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Web Search.xml
File Deleted : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\user.js
File Deleted : C:\Windows\System32\Tasks\FreeDriverScout
File Deleted : C:\Windows\System32\Tasks\Software Updater Ui
File Deleted : C:\Windows\System32\Tasks\Software Updater
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FreeDriverScout
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FED60A91-0B98-48CD-8B88-26E7472EB2A4}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FED60A91-0B98-48CD-8B88-26E7472EB2A4}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Updater Ui
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1CB60AA-DCBB-4551-9CFC-AF8EDDFCDEF3}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B1CB60AA-DCBB-4551-9CFC-AF8EDDFCDEF3}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Updater
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77D72AB6-7EF0-486B-AA2E-93A798F5A2B4}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{77D72AB6-7EF0-486B-AA2E-93A798F5A2B4}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftwareUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftwareUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\5ee8f8dbd69ea48
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\simplytech
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\simplytech
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\Uniblue\DriverScanner
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16720
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
-\\ Mozilla Firefox v24.0 (de)
[ File : C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\prefs.js ]
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "de");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "58ad9e69000000000000001c25821c31");
Line Deleted : user_pref("extensions.delta.instlDay", "15888");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.21.5");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.21.518:30:27");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.21.5");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=121562&tsp=4931");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
*************************
AdwCleaner[R0].txt - [10962 octets] - [28/10/2013 17:38:59]
AdwCleaner[S0].txt - [10459 octets] - [28/10/2013 17:40:53]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10520 octets] ########## JRT:
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.7 (10.15.2013:3)
OS: Windows 7 Ultimate x86
Ran by Benutzer on 28.10.2013 at 17:49:58,30
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\bittorrentbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2638634555-1777476862-3134666796-1000\Software\SweetIM
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\Benutzer\appdata\locallow\bittorrentbar"
~~~ FireFox
Successfully deleted: [File] C:\Users\Benutzer\AppData\Roaming\mozilla\firefox\profiles\j4z76fcr.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Emptied folder: C:\Users\Benutzer\AppData\Roaming\mozilla\firefox\profiles\j4z76fcr.default\minidumps [190 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.10.2013 at 17:52:29,98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
Frisches FRT32:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-10-2013
Ran by Benutzer (administrator) on BENUTZER-PC on 28-10-2013 17:58:27
Running from C:\Users\Benutzer\Downloads
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\system32\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Akamai Technologies, Inc.) C:\Users\Benutzer\AppData\Local\Akamai\netsession_win.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Akamai Technologies, Inc.) C:\Users\Benutzer\AppData\Local\Akamai\netsession_win.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.Exe [55824 2007-09-21] (Logitech, Inc.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [58656 2011-04-20] (Apple Inc.)
HKLM\...\Run: [WinampAgent] - "C:\Program Files\Winamp\winampa.exe"
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-05] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2345296 2013-10-01] (LogMeIn Inc.)
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1813928 2013-10-09] (Valve Corporation)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Benutzer\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
MountPoints2: {54890270-5a64-11e1-8e84-001c25821c31} - J:\Setup.exe
HKU\Bettina\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-10-09] (Valve Corporation)
HKU\Bettina\...\Run: [Akamai NetSession Interface] - C:\Users\Benutzer\AppData\Local\Akamai\netsession_win.exe [ 2013-06-05] (Akamai Technologies, Inc.)
Startup: C:\Users\Benutzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC0CAC4763C45CB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKCU - (No Name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 45 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 82.212.62.62 78.42.43.62 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default
FF NewTab: hxxp://www.google.com/firefox
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com/firefox|www.youtube.com|www.spiegel.de|
FF NetworkProxy: "http", "178.18.17.250"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @raidcall.en/RCplugin - C:\Users\Benutzer\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\s-amazon-de.xml
FF SearchPlugin: C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FoxyProxy Basic - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\foxyproxy@eric.h.jung
FF Extension: Flagfox - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: DownloadHelper - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: extension - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\extension@preispilot.com.xpi
FF Extension: newtabgoogle - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\newtabgoogle@graememcc.co.uk.xpi
FF Extension: noscript - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: tamperdata - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi
FF Extension: defaults - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
FF Extension: Adblock Plus - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\Extensions\{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKCU\...\Firefox\Extensions: [extension@preispilot.com] - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\j4z76fcr.default\extensions\extension@preispilot.com
========================== Services (Whitelisted) =================
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1612112 2013-10-01] (LogMeIn Inc.)
R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [8704 2012-08-15] (Hi-Rez Studios)
R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2013-08-26] (LogMeIn, Inc.)
S3 npggsvc; C:\Windows\system32\GameMon.des [4023760 2010-11-30] (INCA Internet Co., Ltd.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14573856 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2011-03-08] ()
S2 SetupARService; C:\Program Files\Realtek\Audio\SetupAfterRebootService.exe [24576 2013-06-24] (Realtek Semiconductor.)
S2 Mercury; "C:\xampp\xampp_service_mercury.exe" [x]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-06] (Avira Operations GmbH & Co. KG)
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2010-02-03] (LogMeIn, Inc.)
S3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [19720 2009-11-23] (Logitech Inc.)
S3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [14856 2009-11-23] (Logitech Inc.)
R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28432 2007-09-21] (Logitech, Inc.)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [33568 2013-08-20] (NVIDIA Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-06] (Avira GmbH)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [25216 2010-02-25] (The OpenVPN Project)
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
S3 XDva383; \??\C:\Windows\system32\XDva383.sys [x]
S3 XDva393; \??\C:\Windows\system32\XDva393.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-28 17:52 - 2013-10-28 17:52 - 00001649 _____ C:\Users\Benutzer\Desktop\JRT.txt
2013-10-28 17:49 - 2013-10-28 17:49 - 00000000 ____D C:\Windows\ERUNT
2013-10-28 17:38 - 2013-10-28 17:41 - 00000000 ____D C:\AdwCleaner
2013-10-28 16:58 - 2013-10-28 16:58 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-28 16:58 - 2013-10-28 16:58 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Malwarebytes
2013-10-28 16:57 - 2013-10-28 16:58 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-28 16:57 - 2013-10-28 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-28 16:57 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-28 16:53 - 2013-10-28 16:54 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Benutzer\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-28 14:22 - 2013-10-28 14:22 - 00020864 _____ C:\Users\Benutzer\Downloads\Addition.txt
2013-10-28 14:19 - 2013-10-28 14:19 - 00000000 ____D C:\FRST
2013-10-28 14:18 - 2013-10-28 14:18 - 01089183 _____ (Farbar) C:\Users\Benutzer\Downloads\FRST.exe
2013-10-28 11:27 - 2013-10-28 11:27 - 01033335 _____ (Thisisu) C:\Users\Benutzer\Downloads\JRT.exe
2013-10-28 11:26 - 2013-10-28 11:25 - 01060070 _____ C:\Users\Benutzer\Desktop\adwcleaner.exe
2013-10-28 11:23 - 2013-10-28 11:23 - 01956538 _____ (Farbar) C:\Users\Benutzer\Downloads\FRST64.exe
2013-10-26 10:38 - 2013-10-26 10:38 - 00000164 _____ C:\Users\Benutzer\Downloads\QJ1I2FG0
2013-10-26 10:36 - 2013-10-26 10:35 - 00000165 _____ C:\Users\Benutzer\Downloads\_0YeECwk
2013-10-13 23:06 - 2004-12-26 18:58 - 00054784 _____ C:\Users\Benutzer\Desktop\Rinces Gewichtstabelle Herren.xls
2013-10-13 23:04 - 2013-10-13 23:03 - 00024301 _____ C:\Users\Benutzer\Downloads\Rinces Gewichtstabelle Herren.zip
2013-10-10 22:50 - 2013-10-10 22:50 - 00000000 ____D C:\f3548c547328adbdffc8f54e
2013-10-10 22:49 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 22:49 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 22:49 - 2013-09-23 00:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-10 22:49 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 22:49 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-10 22:49 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 22:49 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 17:34 - 2013-09-08 03:07 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-10 17:34 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-10 17:34 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 17:34 - 2013-07-03 05:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 17:34 - 2013-07-03 04:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 17:34 - 2013-07-03 04:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 17:33 - 2013-09-14 01:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-10 17:33 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-10-10 17:33 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-10 17:33 - 2013-08-29 02:50 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-10 17:33 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-10 17:33 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-10 17:33 - 2013-08-28 02:04 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 17:33 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-10 17:33 - 2013-08-01 12:03 - 00729024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 17:33 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 17:33 - 2013-07-12 11:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 17:33 - 2013-07-12 11:07 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2013-10-10 17:33 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-10 17:33 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-10 17:33 - 2013-07-04 10:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-10 17:33 - 2013-06-25 23:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 17:33 - 2013-06-06 05:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 17:33 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 17:33 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 17:33 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 17:33 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-08 19:12 - 2013-10-08 20:06 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2013-10-04 10:14 - 2013-10-04 10:14 - 00000000 ____D C:\Users\Benutzer\AppData\Local\LogMeIn
2013-10-04 10:14 - 2013-10-04 10:14 - 00000000 ____D C:\ProgramData\LogMeIn
2013-10-03 18:47 - 2013-10-03 18:47 - 00000000 ____D C:\Program Files\LogMeIn Hamachi
2013-10-02 20:42 - 2013-08-20 14:33 - 00033568 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2013-10-02 20:42 - 2013-08-20 14:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2013-10-01 16:43 - 2013-10-01 16:43 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-01 15:44 - 2013-10-01 21:43 - 98612549 _____ C:\Windows\system32\ 沯i
==================== One Month Modified Files and Folders =======
2013-10-28 17:52 - 2013-10-28 17:52 - 00001649 _____ C:\Users\Benutzer\Desktop\JRT.txt
2013-10-28 17:52 - 2009-07-14 05:34 - 00020352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-28 17:52 - 2009-07-14 05:34 - 00020352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-28 17:49 - 2013-10-28 17:49 - 00000000 ____D C:\Windows\ERUNT
2013-10-28 17:49 - 2010-09-07 10:19 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-28 17:47 - 2010-08-26 17:12 - 00006486 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-28 17:44 - 2010-11-05 21:47 - 00000000 ____D C:\Users\Benutzer\AppData\Local\Deployment
2013-10-28 17:44 - 2010-10-05 20:58 - 00000000 ____D C:\Program Files\Steam
2013-10-28 17:43 - 2011-03-20 18:16 - 00000000 ____D C:\Program Files\Common Files\Akamai
2013-10-28 17:43 - 2010-10-07 18:04 - 00000000 ____D C:\Users\Benutzer\AppData\Local\LogMeIn Hamachi
2013-10-28 17:42 - 2012-11-26 16:49 - 00039491 _____ C:\Windows\setupact.log
2013-10-28 17:42 - 2010-09-07 10:19 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-28 17:42 - 2010-08-26 20:20 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-28 17:42 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-28 17:41 - 2013-10-28 17:38 - 00000000 ____D C:\AdwCleaner
2013-10-28 17:41 - 2010-09-19 12:21 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\TS3Client
2013-10-28 17:41 - 2010-08-26 17:03 - 01600141 _____ C:\Windows\WindowsUpdate.log
2013-10-28 17:33 - 2012-12-14 13:41 - 00023900 _____ C:\Windows\PFRO.log
2013-10-28 17:32 - 2010-08-26 17:10 - 00000000 ____D C:\Users\Benutzer
2013-10-28 17:06 - 2012-11-26 00:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-28 17:06 - 2010-08-26 19:28 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Skype
2013-10-28 16:58 - 2013-10-28 16:58 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-28 16:58 - 2013-10-28 16:58 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Malwarebytes
2013-10-28 16:58 - 2013-10-28 16:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-28 16:57 - 2013-10-28 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-28 16:54 - 2013-10-28 16:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Benutzer\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-28 14:52 - 2011-03-05 17:37 - 00000000 ____D C:\Users\Benutzer\AppData\Local\PMB Files
2013-10-28 14:22 - 2013-10-28 14:22 - 00020864 _____ C:\Users\Benutzer\Downloads\Addition.txt
2013-10-28 14:19 - 2013-10-28 14:19 - 00000000 ____D C:\FRST
2013-10-28 14:18 - 2013-10-28 14:18 - 01089183 _____ (Farbar) C:\Users\Benutzer\Downloads\FRST.exe
2013-10-28 11:27 - 2013-10-28 11:27 - 01033335 _____ (Thisisu) C:\Users\Benutzer\Downloads\JRT.exe
2013-10-28 11:25 - 2013-10-28 11:26 - 01060070 _____ C:\Users\Benutzer\Desktop\adwcleaner.exe
2013-10-28 11:23 - 2013-10-28 11:23 - 01956538 _____ (Farbar) C:\Users\Benutzer\Downloads\FRST64.exe
2013-10-27 23:49 - 2011-03-05 17:37 - 00000000 ____D C:\ProgramData\PMB Files
2013-10-26 10:38 - 2013-10-26 10:38 - 00000164 _____ C:\Users\Benutzer\Downloads\QJ1I2FG0
2013-10-26 10:35 - 2013-10-26 10:36 - 00000165 _____ C:\Users\Benutzer\Downloads\_0YeECwk
2013-10-26 09:57 - 2009-07-14 05:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-22 13:37 - 2013-09-05 00:32 - 00001384 _____ C:\Users\Benutzer\Desktop\schmied.txt
2013-10-21 19:55 - 2010-08-26 19:26 - 00000000 ___RD C:\Program Files\Skype
2013-10-21 19:55 - 2010-08-26 19:26 - 00000000 ____D C:\ProgramData\Skype
2013-10-13 23:17 - 2010-10-06 23:29 - 00000000 ____D C:\Users\Benutzer\Pierre
2013-10-13 23:03 - 2013-10-13 23:04 - 00024301 _____ C:\Users\Benutzer\Downloads\Rinces Gewichtstabelle Herren.zip
2013-10-13 18:28 - 2010-10-05 20:58 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-10-13 04:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-10-11 15:10 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-10-11 15:03 - 2009-07-14 05:33 - 00522536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-11 14:57 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\fr-FR
2013-10-11 14:57 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-10-10 22:50 - 2013-10-10 22:50 - 00000000 ____D C:\f3548c547328adbdffc8f54e
2013-10-10 22:50 - 2013-07-19 00:30 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 22:50 - 2010-08-26 19:57 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-08 20:06 - 2013-10-08 19:12 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2013-10-08 20:06 - 2012-11-26 00:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-08 20:06 - 2012-11-26 00:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-04 10:58 - 2010-11-16 16:15 - 00000000 ____D C:\Program Files\StarCraft II
2013-10-04 10:14 - 2013-10-04 10:14 - 00000000 ____D C:\Users\Benutzer\AppData\Local\LogMeIn
2013-10-04 10:14 - 2013-10-04 10:14 - 00000000 ____D C:\ProgramData\LogMeIn
2013-10-03 18:47 - 2013-10-03 18:47 - 00000000 ____D C:\Program Files\LogMeIn Hamachi
2013-10-03 18:47 - 2010-10-07 18:03 - 00000896 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2013-10-03 09:43 - 2013-06-25 17:01 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-02 20:44 - 2010-08-26 20:10 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-10-02 16:08 - 2010-08-26 18:51 - 00000000 ____D C:\Users\Benutzer\AppData\Local\Mozilla
2013-10-01 21:43 - 2013-10-01 15:44 - 98612549 _____ C:\Windows\system32\ 沯i
2013-10-01 21:10 - 2010-09-19 12:20 - 00000000 ____D C:\Users\Benutzer\AppData\Local\TeamSpeak 3 Client
2013-10-01 16:43 - 2013-10-01 16:43 - 00000000 ____D C:\Program Files\Mozilla Firefox
Some content of TEMP:
====================
C:\Users\Benutzer\AppData\Local\Temp\AskSLib.dll
C:\Users\Benutzer\AppData\Local\Temp\GenericWndApi.dll
C:\Users\Benutzer\AppData\Local\Temp\HomePageV9.exe
C:\Users\Benutzer\AppData\Local\Temp\install.exe
C:\Users\Benutzer\AppData\Local\Temp\install_flashplayer11x32_mssd_aih(1).exe
C:\Users\Benutzer\AppData\Local\Temp\install_flashplayer11x32_mssd_aih_1.exe
C:\Users\Benutzer\AppData\Local\Temp\install_flashplayer11x32_mssd_aih_2.exe
C:\Users\Benutzer\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe
C:\Users\Benutzer\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Benutzer\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Benutzer\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Benutzer\AppData\Local\Temp\kvdjdvxd.dll
C:\Users\Benutzer\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Benutzer\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Benutzer\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Benutzer\AppData\Local\Temp\nvStInst.exe
C:\Users\Benutzer\AppData\Local\Temp\Quarantine.exe
C:\Users\Benutzer\AppData\Local\Temp\setpointdeu.exe
C:\Users\Benutzer\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Benutzer\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\Benutzer\AppData\Local\Temp\tbuDE7B.exe
C:\Users\Benutzer\AppData\Local\Temp\uninst1.exe
C:\Users\Benutzer\AppData\Local\Temp\unwise.exe
C:\Users\Benutzer\AppData\Local\Temp\vlc-2.0.6-win32.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-28 04:28
==================== End Of Log ============================ --- --- ---
--- --- ---
Vielen dank schonma muss jetzt leider erstma weg ich schau nachher wieder rein !:) |