Malwarebytes Anti-Malware Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.11.28.06
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Markus :: MÖP [Administrator]
Schutz: Aktiviert
28.11.2013 13:06:23
mbam-log-2013-11-28 (13-06-23).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 252436
Laufzeit: 8 Minute(n), 50 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 3
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 1
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0L1N1H2O1S -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage) -> Bösartig: (hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=E036001DE0B84AC1&affID=119357&tt=160913_c1&tsp=5013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
Infizierte Verzeichnisse: 1
C:\Users\Markus\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 3
C:\Windows\System32\H@tKeysH@@k.DLL (HackTool.HotKeyHook) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Markus\Downloads\DTLite4471-0333.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Markus\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) AdwCleaner Code:
# AdwCleaner v3.013 - Bericht erstellt am 28/11/2013 um 13:28:19
# Updated 24/11/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Markus - MÖP
# Gestartet von : C:\Users\Markus\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Datei Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
Datei Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\searchplugins\iminent.xml
Datei Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\babylon.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\e6dddfbc68ba48
Schlüssel Gelöscht : HKLM\SOFTWARE\e6dddfbc68ba48
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F1AF26F8-1828-4279-ABCE-074EF3235BD7}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16514
-\\ Mozilla Firefox v25.0.1 (de)
[ Datei : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www2.delta-search.com/?babsrc=NT_ss&mntrId=E036001DE0B84AC1&affID=119357&tt=160913_c1&tsp=5013");
Zeile gelöscht : user_pref("extensions.crossrider.bic", "141332ce3ef82d2578aa8aa96a28faac");
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "e0368df9000000000000001de0b84ac1");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15970");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "coupon1");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.61:35:04");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=160913_c1&tsp=5013");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.iminent.admin", false);
Zeile gelöscht : user_pref("extensions.iminent.aflt", "orgnl");
Zeile gelöscht : user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}");
Zeile gelöscht : user_pref("extensions.iminent.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.iminent.dfltLng", "");
Zeile gelöscht : user_pref("extensions.iminent.excTlbr", false);
Zeile gelöscht : user_pref("extensions.iminent.ffxUnstlRst", false);
Zeile gelöscht : user_pref("extensions.iminent.id", "e0368df9000000000000001de0b84ac1");
Zeile gelöscht : user_pref("extensions.iminent.instlDay", "15964");
Zeile gelöscht : user_pref("extensions.iminent.instlRef", "");
Zeile gelöscht : user_pref("extensions.iminent.newTab", false);
Zeile gelöscht : user_pref("extensions.iminent.prdct", "iminent");
Zeile gelöscht : user_pref("extensions.iminent.prtnrId", "iminent");
Zeile gelöscht : user_pref("extensions.iminent.rvrt", "false");
Zeile gelöscht : user_pref("extensions.iminent.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.iminent.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");
Zeile gelöscht : user_pref("extensions.iminent.vrsn", "1.8.25.0");
Zeile gelöscht : user_pref("extensions.iminent.vrsnTs", "1.8.25.014:12:15");
Zeile gelöscht : user_pref("extensions.iminent.vrsni", "1.8.25.0");
[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\37t97kra.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [31490 octets] - [18/09/2013 23:09:01]
AdwCleaner[R1].txt - [7591 octets] - [28/11/2013 13:25:59]
AdwCleaner[S0].txt - [29503 octets] - [18/09/2013 23:10:03]
AdwCleaner[S1].txt - [7514 octets] - [28/11/2013 13:28:19]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7574 octets] ########## Junkware Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Markus on 28.11.2013 at 13:35:35,37
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2477354313-3567984285-364137450-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181110}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [File] C:\Users\Markus\AppData\Roaming\mozilla\firefox\profiles\2mk15yd8.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Successfully deleted the following from C:\Users\Markus\AppData\Roaming\mozilla\firefox\profiles\2mk15yd8.default\prefs.js
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/530e52021dc20843b1aa62957edeb9f8.value", "%22var%20adsDe
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/833447eaff04548ccb80787286a7cad9_DE.value", "%22var%20ca
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.monetization_plugin_last_executable_request.value", "%22hxxp%3
Emptied folder: C:\Users\Markus\AppData\Roaming\mozilla\firefox\profiles\2mk15yd8.default\minidumps [876 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.11.2013 at 13:41:11,02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-11-2013 01
Ran by Markus (administrator) on MÖP on 28-11-2013 13:45:32
Running from C:\Users\Markus\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Egis Incorporated) C:\ACER\Empowering Technology\eDataSecurity\x86\eDSService.exe
(Acer Inc.) C:\ACER\Empowering Technology\eLock\Service\eLockServ.exe
(Acer Inc.) C:\ACER\Empowering Technology\eNet\eNet Service.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\ACER\Mobility Center\MobilityService.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
() C:\ACER\Empowering Technology\eSettings\Service\capuserv.exe
(acer) C:\ACER\Empowering Technology\ePower\ePowerSvc.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Realtek Semiconductor Corp.) C:\Users\Markus\AppData\Local\temp\RtkBtMnt.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\QtZgAcer.EXE
(Egis Incorporated) C:\ACER\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
(CyberLink) C:\ACER\Empowering Technology\eAudio\eAudio.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Spotify Ltd) C:\Users\Markus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(Acer Inc.) C:\ACER\Empowering Technology\eNet\eNMTray.exe
(Acer Inc.) C:\ACER\Empowering Technology\ePower\ePower_DMC.exe
(Acer Inc.) C:\ACER\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Markus\Desktop\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6294048 2008-09-18] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Windows\SkyTel.exe [1833504 2008-09-18] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [159744 2008-01-24] (Alps Electric Co., Ltd.)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\QtZgAcer.EXE [817672 2008-06-17] (Dritek System Inc.)
HKLM\...\Run: [eDataSecurity Loader] - C:\ACER\Empowering Technology\eDataSecurity\x86\eDSLoader.exe [521776 2008-01-03] (Egis Incorporated)
HKLM\...\Run: [eAudio] - C:\ACER\Empowering Technology\eAudio\eAudio.exe [1286144 2007-10-10] (CyberLink)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKLM\...\Run: [Nokia FastStart] - "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart
HKLM\...\Run: [TkBellExe] - C:\Program Files\Common Files\Real\Update_OB\realsched.exe [202256 2010-03-11] (RealNetworks, Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [2516296 2010-03-25] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenuEx] - C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKCU\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [135168 2008-11-17] (Acer)
HKCU\...\Run: [ICQ] - "D:\PROGRA~1\ICQ6.5\ICQ.exe" silent
HKCU\...\Run: [NokiaOviSuite2] - C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Markus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-11-24] (Spotify Ltd)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\Gast\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Gast\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
Startup: C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\ACER\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @bittorrent.com/BitTorrentDNA - C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.709 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.709 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.709 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101727.dll (Amazon.com, Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\Extensions\ich@maltegoetz.de
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}
FF Extension: prefs - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\Extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi
FF Extension: Adblock Plus - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\2mk15yd8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [506416 2008-01-03] (Egis Incorporated)
R2 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-10-01] (Acer Inc.)
R2 eNet Service; C:\ACER\Empowering Technology\eNet\eNet Service.exe [131072 2007-12-20] (Acer Inc.)
R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] ()
R2 NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [4230144 2011-12-16] (Native Instruments GmbH)
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144632 2008-09-23] (NewTech Infosystems, Inc.)
S4 RemoteAccess; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [167936 2007-09-20] (acer)
S3 WinDefend; %ProgramFiles%\Windows Defender\mpsvc.dll [x]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-08-15] (DT Soft Ltd)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 hamachi_oem; C:\Windows\System32\DRIVERS\gan_adapter.sys [10664 2006-08-28] (Applied Networking Inc.)
R3 kx1avs; C:\Windows\System32\Drivers\kx1avs.sys [346192 2011-07-07] (Native Instruments GmbH)
S3 kx1usb; C:\Windows\System32\Drivers\kx1usb.sys [70736 2011-07-07] (Native Instruments GmbH)
R3 kx1usb_svc; C:\Windows\System32\Drivers\kx1usb.sys [70736 2011-07-07] (Native Instruments GmbH)
S3 L1E; C:\Windows\System32\DRIVERS\L1E60x86.sys [47616 2008-07-22] (Atheros Communications, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 RL_DJIFIE2_MIDI; C:\Windows\System32\drivers\rldjif2m.sys [25088 2009-04-16] (Ploytec GmbH)
S3 RL_DJIFIE2_USB; C:\Windows\System32\Drivers\rldjif2u.sys [371200 2009-04-16] (Ploytec GmbH)
S3 RL_DJIFIE2_WDM; C:\Windows\System32\drivers\rldjif2a.sys [33792 2009-04-16] (Ploytec GmbH)
R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [155808 2008-12-25] (Realtek Semiconductor Corp.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH)
R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2007-03-28] (Winbond Electronics Corporation)
S3 ysusb32; C:\Windows\System32\drivers\ysusb32.sys [66248 2010-02-03] (Yamaha Corporation)
S3 AgereSoftModem; system32\DRIVERS\AGRSM.sys [x]
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Markus\AppData\Local\Temp\catchme.sys [x]
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [x]
S3 XDva385; \??\C:\Windows\system32\XDva385.sys [x]
S3 XDva391; \??\C:\Windows\system32\XDva391.sys [x]
S3 XDva398; \??\C:\Windows\system32\XDva398.sys [x]
S3 XDva399; \??\C:\Windows\system32\XDva399.sys [x]
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-28 13:45 - 2013-11-28 13:45 - 01091827 _____ (Farbar) C:\Users\Markus\Desktop\FRST(1).exe
2013-11-28 13:43 - 2013-11-28 13:43 - 01091827 _____ (Farbar) C:\Users\Markus\Downloads\FRST.exe
2013-11-28 13:41 - 2013-11-28 13:41 - 00002237 _____ C:\Users\Markus\Desktop\JRT.txt
2013-11-28 13:35 - 2013-11-28 13:35 - 00000000 ____D C:\Windows\ERUNT
2013-11-28 13:33 - 2013-11-28 13:33 - 00007654 _____ C:\Users\Markus\Desktop\AdwCleaner[S1].txt
2013-11-28 13:25 - 2013-11-28 13:25 - 01034531 _____ (Thisisu) C:\Users\Markus\Desktop\JRT.exe
2013-11-28 13:17 - 2013-11-28 13:17 - 01091882 _____ C:\Users\Markus\Desktop\adwcleaner.exe
2013-11-28 13:04 - 2013-11-28 13:04 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Malwarebytes
2013-11-28 13:03 - 2013-11-28 13:03 - 00000910 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-28 13:03 - 2013-11-28 13:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 13:03 - 2013-11-28 13:03 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-28 13:03 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-27 20:04 - 2013-11-27 20:23 - 59664405 _____ C:\Users\Markus\Downloads\Leawo.TMCU.5.1.0.0.rar
2013-11-27 18:10 - 2013-11-27 18:10 - 00012159 _____ C:\ComboFix.txt
2013-11-27 17:50 - 2013-11-27 18:10 - 00000000 ____D C:\ComboFix
2013-11-27 17:49 - 2013-11-27 17:49 - 05150163 ____R (Swearware) C:\Users\Markus\Desktop\ComboFix.exe
2013-11-27 17:48 - 2013-11-27 17:49 - 05150163 _____ (Swearware) C:\Users\Markus\Downloads\ComboFix.exe
2013-11-26 20:58 - 2013-11-26 21:18 - 63109035 _____ C:\Users\Markus\Downloads\Celemony.Melodyne.Studio.Edition.v3.2.2.2.Incl.Keygen-AiR.rar
2013-11-26 20:41 - 2013-11-26 20:42 - 00024099 _____ C:\Users\Markus\Desktop\Addition.txt
2013-11-26 20:40 - 2013-11-28 13:45 - 00017829 _____ C:\Users\Markus\Desktop\FRST.txt
2013-11-26 15:41 - 2013-11-26 15:41 - 00000000 ____D C:\Program Files\Celemony
2013-11-26 15:40 - 2013-11-26 15:40 - 00000000 ____D C:\Program Files\Common Files\Celemony
2013-11-26 15:39 - 2013-11-26 15:39 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Celemony
2013-11-25 19:42 - 2013-11-25 19:42 - 01639668 ____H C:\Users\Markus\Desktop\Sem Vox - Debut.mp3.zpa
2013-11-18 18:13 - 2013-11-18 18:13 - 00001668 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-18 18:13 - 2013-11-18 18:13 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-11-18 18:13 - 2013-11-18 18:13 - 00000000 ____D C:\Program Files\iTunes
2013-11-18 18:13 - 2013-11-18 18:13 - 00000000 ____D C:\Program Files\iPod
2013-11-13 17:35 - 2013-11-13 17:35 - 00017379 _____ C:\Users\Markus\Downloads\5319Medienwirtschaft_29.10.odt
2013-11-12 19:59 - 2013-11-12 19:59 - 00000000 ____D C:\Users\Markus\Desktop\KeyFinder-WIN
2013-11-12 19:52 - 2013-11-12 19:54 - 33963493 _____ C:\Users\Markus\Downloads\KeyFinder-WIN.zip
2013-11-12 19:49 - 2013-11-12 19:49 - 00618912 _____ C:\Users\Markus\Downloads\Magical Jelly Bean Keyfinder - CHIP-Downloader.exe
2013-11-07 09:12 - 2013-11-26 13:34 - 00000000 ____D C:\Users\Markus\Desktop\FHM
2013-10-30 21:45 - 2013-10-30 21:46 - 05176208 _____ C:\Users\Markus\Downloads\Image_Line_Gross_Beat_1.0.1.rar
2013-10-29 20:35 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-29 20:35 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-29 20:35 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-29 20:35 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-29 20:35 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-29 20:35 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-29 20:35 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-29 20:35 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-29 20:34 - 2013-11-27 18:10 - 00000000 ____D C:\Qoobox
2013-10-29 20:34 - 2013-10-29 20:59 - 00000000 ____D C:\Windows\erdnt
2013-10-29 19:54 - 2013-10-29 19:54 - 00000000 ____D C:\FRST
2013-10-29 17:54 - 2013-10-29 17:54 - 00000000 ____D C:\Users\Markus\AppData\Roaming\FixZeroAccess
2013-10-29 17:52 - 2013-10-29 17:51 - 01805736 _____ (Symantec Corporation) C:\Users\Markus\Downloads\FixZeroAccess.exe
2013-10-29 15:00 - 2013-10-29 15:00 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dada Life
2013-10-29 14:59 - 2013-10-29 14:59 - 01700352 _____ (Microsoft Corporation) C:\Windows\system32\gdiplus.dll
==================== One Month Modified Files and Folders =======
2013-11-28 13:46 - 2013-11-26 20:40 - 00017829 _____ C:\Users\Markus\Desktop\FRST.txt
2013-11-28 13:45 - 2013-11-28 13:45 - 01091827 _____ (Farbar) C:\Users\Markus\Desktop\FRST(1).exe
2013-11-28 13:43 - 2013-11-28 13:43 - 01091827 _____ (Farbar) C:\Users\Markus\Downloads\FRST.exe
2013-11-28 13:41 - 2013-11-28 13:41 - 00002237 _____ C:\Users\Markus\Desktop\JRT.txt
2013-11-28 13:37 - 2008-01-21 08:16 - 01558924 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-28 13:35 - 2013-11-28 13:35 - 00000000 ____D C:\Windows\ERUNT
2013-11-28 13:35 - 2009-12-08 09:26 - 01977452 _____ C:\Windows\WindowsUpdate.log
2013-11-28 13:33 - 2013-11-28 13:33 - 00007654 _____ C:\Users\Markus\Desktop\AdwCleaner[S1].txt
2013-11-28 13:30 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-28 13:30 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-28 13:30 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-28 13:29 - 2008-01-21 03:47 - 05709120 _____ C:\Windows\PFRO.log
2013-11-28 13:29 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\L2Schemas
2013-11-28 13:28 - 2013-09-18 23:08 - 00000000 ____D C:\AdwCleaner
2013-11-28 13:28 - 2006-11-02 14:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-28 13:25 - 2013-11-28 13:25 - 01034531 _____ (Thisisu) C:\Users\Markus\Desktop\JRT.exe
2013-11-28 13:17 - 2013-11-28 13:17 - 01091882 _____ C:\Users\Markus\Desktop\adwcleaner.exe
2013-11-28 13:10 - 2012-06-04 18:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-28 13:04 - 2013-11-28 13:04 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Malwarebytes
2013-11-28 13:03 - 2013-11-28 13:03 - 00000910 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-28 13:03 - 2013-11-28 13:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 13:03 - 2013-11-28 13:03 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-27 20:23 - 2013-11-27 20:04 - 59664405 _____ C:\Users\Markus\Downloads\Leawo.TMCU.5.1.0.0.rar
2013-11-27 18:10 - 2013-11-27 18:10 - 00012159 _____ C:\ComboFix.txt
2013-11-27 18:10 - 2013-11-27 17:50 - 00000000 ____D C:\ComboFix
2013-11-27 18:10 - 2013-10-29 20:34 - 00000000 ____D C:\Qoobox
2013-11-27 18:10 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-11-27 18:07 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini
2013-11-27 17:49 - 2013-11-27 17:49 - 05150163 ____R (Swearware) C:\Users\Markus\Desktop\ComboFix.exe
2013-11-27 17:49 - 2013-11-27 17:48 - 05150163 _____ (Swearware) C:\Users\Markus\Downloads\ComboFix.exe
2013-11-26 21:18 - 2013-11-26 20:58 - 63109035 _____ C:\Users\Markus\Downloads\Celemony.Melodyne.Studio.Edition.v3.2.2.2.Incl.Keygen-AiR.rar
2013-11-26 20:42 - 2013-11-26 20:41 - 00024099 _____ C:\Users\Markus\Desktop\Addition.txt
2013-11-26 20:33 - 2013-03-06 12:56 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Spotify
2013-11-26 17:49 - 2013-03-06 12:57 - 00000000 ____D C:\Users\Markus\AppData\Local\Spotify
2013-11-26 15:41 - 2013-11-26 15:41 - 00000000 ____D C:\Program Files\Celemony
2013-11-26 15:40 - 2013-11-26 15:40 - 00000000 ____D C:\Program Files\Common Files\Celemony
2013-11-26 15:39 - 2013-11-26 15:39 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Celemony
2013-11-26 13:34 - 2013-11-07 09:12 - 00000000 ____D C:\Users\Markus\Desktop\FHM
2013-11-25 19:42 - 2013-11-25 19:42 - 01639668 ____H C:\Users\Markus\Desktop\Sem Vox - Debut.mp3.zpa
2013-11-25 13:19 - 2012-11-04 23:03 - 00000000 ____D C:\Users\Markus\Desktop\Nysto
2013-11-19 11:01 - 2013-08-06 10:58 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 11:01 - 2013-08-06 10:58 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-18 18:13 - 2013-11-18 18:13 - 00001668 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-18 18:13 - 2013-11-18 18:13 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-11-18 18:13 - 2013-11-18 18:13 - 00000000 ____D C:\Program Files\iTunes
2013-11-18 18:13 - 2013-11-18 18:13 - 00000000 ____D C:\Program Files\iPod
2013-11-18 18:13 - 2012-04-30 18:31 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-11-18 11:11 - 2012-06-04 15:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-17 22:02 - 2013-09-18 18:45 - 00000000 ____D C:\Users\Markus\Desktop\FL Studio
2013-11-17 12:39 - 2013-09-19 13:48 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-14 22:42 - 2012-06-14 20:05 - 00000000 ____D C:\Users\Markus\AppData\Roaming\com.beatport.BeatportDownloader
2013-11-14 22:41 - 2012-06-14 20:04 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2013-11-13 17:35 - 2013-11-13 17:35 - 00017379 _____ C:\Users\Markus\Downloads\5319Medienwirtschaft_29.10.odt
2013-11-12 22:41 - 2013-02-17 17:25 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-11-12 19:59 - 2013-11-12 19:59 - 00000000 ____D C:\Users\Markus\Desktop\KeyFinder-WIN
2013-11-12 19:54 - 2013-11-12 19:52 - 33963493 _____ C:\Users\Markus\Downloads\KeyFinder-WIN.zip
2013-11-12 19:49 - 2013-11-12 19:49 - 00618912 _____ C:\Users\Markus\Downloads\Magical Jelly Bean Keyfinder - CHIP-Downloader.exe
2013-11-12 00:18 - 2012-09-26 19:12 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Audacity
2013-11-07 20:35 - 2009-12-10 18:45 - 00000000 ____D C:\Users\Markus\AppData\Roaming\vlc
2013-10-30 21:46 - 2013-10-30 21:45 - 05176208 _____ C:\Users\Markus\Downloads\Image_Line_Gross_Beat_1.0.1.rar
2013-10-29 20:59 - 2013-10-29 20:34 - 00000000 ____D C:\Windows\erdnt
2013-10-29 19:54 - 2013-10-29 19:54 - 00000000 ____D C:\FRST
2013-10-29 17:54 - 2013-10-29 17:54 - 00000000 ____D C:\Users\Markus\AppData\Roaming\FixZeroAccess
2013-10-29 17:51 - 2013-10-29 17:52 - 01805736 _____ (Symantec Corporation) C:\Users\Markus\Downloads\FixZeroAccess.exe
2013-10-29 16:29 - 2012-11-13 17:20 - 00000000 ____D C:\ProgramData\Ableton
2013-10-29 16:24 - 2009-01-15 02:48 - 00000000 ____D C:\Program Files\Google
2013-10-29 16:24 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Help
2013-10-29 15:55 - 2009-12-08 09:43 - 00000000 ____D C:\Users\Markus\AppData\Local\Google
2013-10-29 15:42 - 2013-09-02 13:02 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2013-10-29 15:00 - 2013-10-29 15:00 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dada Life
2013-10-29 14:59 - 2013-10-29 14:59 - 01700352 _____ (Microsoft Corporation) C:\Windows\system32\gdiplus.dll
Some content of TEMP:
====================
C:\Users\Markus\AppData\Local\temp\avgnt.exe
C:\Users\Markus\AppData\Local\temp\Quarantine.exe
C:\Users\Markus\AppData\Local\temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-28 13:37
==================== End Of Log ============================ --- --- ---
--- --- --- |