Rettetmich | 02.12.2013 13:33 | Malwarebytes Anti-Malware 1.75.0.1300
Malwarebytes : Free anti-malware download
Datenbank Version: v2013.12.02.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16428
Marina :: NETBOOK [Administrator]
02.12.2013 10:20:00
mbam-log-2013-12-02 (10-20-00).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM | P2P
Deaktivierte Suchlaufeinstellungen:
Durchsuchte Objekte: 210416
Laufzeit: 9 Minute(n), 37 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
Malwarebytes habe ich letzte woche schonmal drüber laufen lassen....
AdwCleaner Logfile: Code:
# AdwCleaner v3.014 - Bericht erstellt am 02/12/2013 um 12:58:23
# Updated 01/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : M- NETBOOK
# Gestartet von : C:\Users\M\Desktop\AdwCleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Program Files\Babylon
Ordner Gelöscht : C:\Program Files\Conduit
Ordner Gelöscht : C:\Program Files\myfree codec
Ordner Gelöscht : C:\Users\M\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\M\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\M\AppData\Roaming\digitalsite
Ordner Gelöscht : C:\Users\M\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Conduit
Ordner Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\CT2720081
Ordner Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Ordner Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Extensions\ffxtlbra@softonic.com
Ordner Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Extensions\pdfforge@mybrowserbar.com
Ordner Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Extensions\wtxpcom@mybrowserbar.com
Ordner Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Extensions\{ce18769b-c7fa-42d2-860d-17c4662c70ad}
Datei Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\searchplugins\Babylon.xml
Datei Gelöscht : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\Dealply
Datei Gelöscht : C:\Windows\System32\Tasks\QtraxPlayer
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E89CD22F-AA0D-4333-A0C9-7EBBE7B76000}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E89CD22F-AA0D-4333-A0C9-7EBBE7B76000}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ADEC5CA7-ADDA-4F7B-AC0B-1D5914D5361B}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ADEC5CA7-ADDA-4F7B-AC0B-1D5914D5361B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\d6ddd8e034b910
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2720081
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bluesoleil_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bluesoleil_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyrixeeker
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v
[ Datei : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\prefs.js ]
Zeile gelöscht : user_pref("CT2720081.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gelöscht : user_pref("CT2720081.CTID", "CT2720081");
Zeile gelöscht : user_pref("CT2720081.CurrentServerDate", "1-10-2011");
Zeile gelöscht : user_pref("CT2720081.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2720081.DownloadReferralCookieData", "");
Zeile gelöscht : user_pref("CT2720081.EMailNotifierPollDate", "Sat Oct 01 2011 20:11:15 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.FeedLastCount129248891425073064", 200);
Zeile gelöscht : user_pref("CT2720081.FeedPollDate129225116238185771", "Sat Oct 01 2011 19:51:16 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.FeedPollDate129225147492879732", "Sat Oct 01 2011 19:51:16 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.FeedPollDate129245643951202078", "Sat Oct 01 2011 19:51:16 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.FeedPollDate129245643951202084", "Sat Oct 01 2011 19:51:16 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.FeedTTL129225116238185771", 40);
Zeile gelöscht : user_pref("CT2720081.FeedTTL129225147492879732", 40);
Zeile gelöscht : user_pref("CT2720081.FeedTTL129245643951202078", 40);
Zeile gelöscht : user_pref("CT2720081.FeedTTL129245643951202084", 40);
Zeile gelöscht : user_pref("CT2720081.FirstServerDate", "1-11-2010");
Zeile gelöscht : user_pref("CT2720081.FirstTime", true);
Zeile gelöscht : user_pref("CT2720081.FirstTimeFF3", true);
Zeile gelöscht : user_pref("CT2720081.FirstTimeSettingsDone", true);
Zeile gelöscht : user_pref("CT2720081.FixPageNotFoundErrors", true);
Zeile gelöscht : user_pref("CT2720081.GroupingServerCheckInterval", 1440);
Zeile gelöscht : user_pref("CT2720081.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gelöscht : user_pref("CT2720081.Initialize", true);
Zeile gelöscht : user_pref("CT2720081.InitializeCommonPrefs", true);
Zeile gelöscht : user_pref("CT2720081.InstallationAndCookieDataSentCount", 3);
Zeile gelöscht : user_pref("CT2720081.InstallationType", "UnknownIntegration");
Zeile gelöscht : user_pref("CT2720081.InstalledDate", "Mon Nov 01 2010 19:15:31 GMT+0100");
Zeile gelöscht : user_pref("CT2720081.InvalidateCache", false);
Zeile gelöscht : user_pref("CT2720081.IsGrouping", false);
Zeile gelöscht : user_pref("CT2720081.IsMulticommunity", false);
Zeile gelöscht : user_pref("CT2720081.IsOpenThankYouPage", false);
Zeile gelöscht : user_pref("CT2720081.IsOpenUninstallPage", true);
Zeile gelöscht : user_pref("CT2720081.LanguagePackLastCheckTime", "Sat Oct 01 2011 19:51:17 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.LanguagePackReloadIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2720081.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gelöscht : user_pref("CT2720081.LastLogin_2.7.2.0", "Sat Oct 01 2011 19:51:15 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.LatestVersion", "3.7.0.6");
Zeile gelöscht : user_pref("CT2720081.Locale", "en");
Zeile gelöscht : user_pref("CT2720081.LoginCache", 4);
Zeile gelöscht : user_pref("CT2720081.MCDetectTooltipHeight", "83");
Zeile gelöscht : user_pref("CT2720081.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gelöscht : user_pref("CT2720081.MCDetectTooltipWidth", "295");
Zeile gelöscht : user_pref("CT2720081.RadioIsPodcast", false);
Zeile gelöscht : user_pref("CT2720081.RadioLastCheckTime", "Sat Oct 01 2011 19:51:16 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.RadioLastUpdateIPServer", "3");
Zeile gelöscht : user_pref("CT2720081.RadioLastUpdateServer", "129248947734170000");
Zeile gelöscht : user_pref("CT2720081.RadioMediaID", "21079850");
Zeile gelöscht : user_pref("CT2720081.RadioMediaType", "Media Player");
Zeile gelöscht : user_pref("CT2720081.RadioMenuSelectedID", "EBRadioMenu_CT272008121079850");
Zeile gelöscht : user_pref("CT2720081.RadioStationName", "AHL%20-%20Grand%20Rapids%20Griffins");
Zeile gelöscht : user_pref("CT2720081.RadioStationURL", "hxxp://cdncon.wm.llnwd.net/cdncon_neulion1_ahl_griffins?eid=2037&pid=2037&gid=101]]");
Zeile gelöscht : user_pref("CT2720081.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2720081&octid=EB_ORIGINAL_CTID&SearchSource=1");
Zeile gelöscht : user_pref("CT2720081.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("CT2720081.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2720081&q=");
Zeile gelöscht : user_pref("CT2720081.SearchInNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2720081.SearchInNewTabIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2720081.SearchInNewTabLastCheckTime", "Sat Oct 01 2011 19:51:13 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2720081.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2720081.SettingsCheckIntervalMin", 120);
Zeile gelöscht : user_pref("CT2720081.SettingsLastCheckTime", "Sat Oct 01 2011 19:51:13 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.SettingsLastUpdate", "1299591661");
Zeile gelöscht : user_pref("CT2720081.ThirdPartyComponentsInterval", 504);
Zeile gelöscht : user_pref("CT2720081.ThirdPartyComponentsLastCheck", "Sat Oct 01 2011 19:51:13 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.ThirdPartyComponentsLastUpdate", "1312887586");
Zeile gelöscht : user_pref("CT2720081.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2720081.UserID", "UN77985035236064226");
Zeile gelöscht : user_pref("CT2720081.WeatherNetwork", "");
Zeile gelöscht : user_pref("CT2720081.WeatherPollDate", "Sat Oct 01 2011 19:51:17 GMT+0200");
Zeile gelöscht : user_pref("CT2720081.WeatherUnit", "C");
Zeile gelöscht : user_pref("CT2720081.alertChannelId", "1112366");
Zeile gelöscht : user_pref("CT2720081.backendstorage.ct2720081ads1", "25374225323261647325323225334125354225374225323261696425323225334125323232343533372532322532432532327469746C652532322533412532322575323731332532304[...]
Zeile gelöscht : user_pref("CT2720081.backendstorage.ct2720081current_term", "");
Zeile gelöscht : user_pref("CT2720081.backendstorage.ct2720081sdate", "31");
Zeile gelöscht : user_pref("CT2720081.clientLogIsEnabled", false);
Zeile gelöscht : user_pref("CT2720081.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2720081.myStuffEnabled", true);
Zeile gelöscht : user_pref("CT2720081.myStuffPublihserMinWidth", 400);
Zeile gelöscht : user_pref("CT2720081.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2720081.myStuffServiceIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2720081.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gelöscht : user_pref("CT2720081.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.babylon.com/?babsrc=adbartrp&AF=15000&q=");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2720081");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2720081");
Zeile gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Oct 01 2011 19:51:15 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.twitter.user_14293310.LastCheckTime", "Sat Oct 01 2011 19:51:17 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.twitter.user_2557521.LastCheckTime", "Sat Oct 01 2011 19:51:17 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.twitter.user_428333.LastCheckTime", "Sat Oct 01 2011 19:51:17 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.twitter.user_807095.LastCheckTime", "Sat Oct 01 2011 19:51:17 GMT+0200");
Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "1");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15000");
Zeile gelöscht : user_pref("extensions.Softonic.admin", false);
Zeile gelöscht : user_pref("extensions.Softonic.aflt", "orgnl");
Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "");
Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false);
Zeile gelöscht : user_pref("extensions.Softonic.id", "f031d8ea00000000000000030d000001");
Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "15494");
Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MON00001");
Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic");
Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic");
Zeile gelöscht : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search settings, Click No to restore original settings");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource=1&cc=&q=");
Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.5.24.3");
Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.5.24.3");
Zeile gelöscht : user_pref("extensions.Softonic_i.newTab", false);
Zeile gelöscht : user_pref("extensions.Softonic_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.Softonic_i.vrsnTs", "1.5.24.319:38:18");
-\\ Google Chrome v31.0.1650.57
[ Datei : C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [21423 octets] - [02/12/2013 12:57:00]
AdwCleaner[S0].txt - [21437 octets] - [02/12/2013 12:58:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [21498 octets] ########## --- --- ---JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x86
Ran by Marina on 02.12.2013 at 13:11:33,28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{AD79BAD6-9504-4F09-ACEC-7B319584A4C1}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1219656536-1975504004-2675106834-1000\Software\sweetim
~~~ Files
Successfully deleted: [File] "C:\Users\Marina\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
~~~ Folders
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.12.2013 at 13:14:26,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2013
Ran by Marina (administrator) on NETBOOK on 02-12-2013 13:27:08
Running from C:\Users\M\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Deutsche Telekom AG) C:\Program Files\Telekom\Mediencenter\DTAG.Mediencenter.BackgroundService.exe
(Egis Technology Inc.) C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7539232 2009-06-09] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [703008 2009-08-28] (Acer Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1434920 2009-02-27] (Synaptics Incorporated)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Runonce: [AvgUninstallURL] - cmd.exe /c start hxxp://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMgBHADMASwAtADgANwBXAFUAVQAtADIAVABWAEgAQQAtAFgANgBEAEYAOAAtAEwANgBQAEEATgA"&"inst=NwA3AC0ANAAxADcANQA0ADcAOAAxADkALQBCAEEAUgA5AEcAKwAxAC0ARgBMACsAOQAtAEYAOQBNADYAKwAxAC0AWABPADMANgArADEALQBGADkATQA3AEMAKwA1AC0AWABPADkAKwAxAC0ARgA5AE0AMwArADEALQBEAEQAVAArADQAMgA5ADQAOQAwADMAOQA5ADAALQBTAFQAOQAwAEYAQQBQAFAAKwAxAC0ARABEADkAMABGACsAMQAtAEYAOQAwAE0AMQAyAFIAKwAxAC0AVgBJAFAAMQAyACsAMQA"&"prod=90"&"ver=9.0.894
HKCU\...\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation)
HKU\Default\...\RunOnce: [ScrSav] -
HKU\Default\...\RunOnce: [RUN] -
HKU\Default User\...\RunOnce: [ScrSav] -
HKU\Default User\...\RunOnce: [RUN] -
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Bing
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {ABF17040-DF58-48F6-8E6B-980C19A8A814} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll (EldoS Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {0006F063-0000-0000-C000-000000000046} hxxp://activex.microsoft.com/activex/controls/office/outlctlx.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5EA13312-8764-496F-B4AB-F7A872B51E14} hxxp://cdn03.oovoo.com/oovoomelink/oovoome/webvc/ooVooWeb.dll
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default
FF Homepage: user_pref("browser.startup.homepage", );
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Marina\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.de/", "https://www.google.de/search?q=google&aq=f&oq=google&sugexp=chrome,mod=5&sourceid=chrome&ie=UTF-8"
CHR Extension: (Google Drive) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
========================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2010-02-28] ()
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [727584 2009-08-28] (Acer Incorporated)
R2 MCSWASVR; C:\Program Files\Telekom\Mediencenter\DTAG.Mediencenter.BackgroundService.exe [12800 2011-11-23] (Deutsche Telekom AG)
R2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-05-14] (Egis Technology Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [237568 2009-02-05] (Acer Incorporated)
==================== Drivers (Whitelisted) ====================
R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [20104 2010-04-06] (IVT Corporation.)
S3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [25864 2010-04-06] ()
R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [265800 2010-05-15] (EldoS Corporation)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
R1 DPMemGridVista; C:\Program Files\GridVista\DPMemGridVista.sys [10504 2008-10-01] (Dritek System Inc.)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36640 2010-10-25] ()
S3 int15.sys; C:\Windows\System32\OEM\Factory\int15.sys [69632 2003-10-01] ()
S3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [23048 2010-04-06] (IVT Corporation.)
R3 L1C; C:\Windows\System32\DRIVERS\L1C60x86.sys [50176 2009-04-27] (Atheros Communications, Inc.)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [19504 2008-12-04] (Egis Incorporated.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2008-12-04] (Egis Incorporated.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [59952 2008-12-04] (Egis Incorporated.)
S3 sscebus; C:\Windows\System32\DRIVERS\sscebus.sys [98560 2010-08-27] (MCCI Corporation)
S3 sscemdfl; C:\Windows\System32\DRIVERS\sscemdfl.sys [14848 2010-08-27] (MCCI Corporation)
S3 sscemdm; C:\Windows\System32\DRIVERS\sscemdm.sys [123648 2010-08-27] (MCCI Corporation)
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [100352 2010-08-27] (MCCI Corporation)
S3 SSDISK; C:\Windows\System32\DRIVERS\SSDISK.sys [10752 2009-03-30] (Alcor Micro, Corp.)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181432 2012-02-24] (DEVGURU Co., LTD.(???? | ????? ???? ?????.))
S3 SSUSB; C:\Windows\System32\DRIVERS\SSUSB.sys [14848 2009-04-07] (Alcor Micro, Corp.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 BT; system32\DRIVERS\btnetdrv.sys [x]
S3 BTCOM; system32\DRIVERS\btcomport.sys [x]
S3 BTCOMBUS; System32\Drivers\btcombus.sys [x]
S3 Btcsrusb; System32\Drivers\btcusb.sys [x]
S3 catchme; \??\C:\Users\Marina\AppData\Local\Temp\catchme.sys [x]
S3 dgderdrv; System32\drivers\dgderdrv.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-02 13:27 - 2013-12-02 13:27 - 00012782 _____ C:\Users\Marina\Desktop\FRST.txt
2013-12-02 13:26 - 2013-12-02 13:27 - 01092187 _____ (Farbar) C:\Users\Marina\Desktop\FRST.exe
2013-12-02 13:14 - 2013-12-02 13:14 - 00001166 _____ C:\Users\Marina\Desktop\JRT.txt
2013-12-02 13:11 - 2013-12-02 13:11 - 00000000 ____D C:\Windows\ERUNT
2013-12-02 13:10 - 2013-12-02 13:11 - 01034531 _____ (Thisisu) C:\Users\Marina\Desktop\JRT.exe
2013-12-02 12:56 - 2013-12-02 12:58 - 00000000 ____D C:\AdwCleaner
2013-12-02 12:56 - 2013-12-02 12:56 - 01110034 _____ C:\Users\Marina\Desktop\AdwCleaner.exe
2013-11-29 09:06 - 2013-11-29 09:06 - 00018531 _____ C:\ComboFix.txt
2013-11-29 08:41 - 2013-11-29 09:06 - 00000000 ____D C:\Qoobox
2013-11-29 08:41 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-11-29 08:41 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-11-29 08:41 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-11-29 08:40 - 2013-11-29 09:03 - 00000000 ____D C:\Windows\erdnt
2013-11-29 08:38 - 2013-11-29 08:38 - 05150163 ____R (Swearware) C:\Users\Marina\Desktop\ComboFix.exe
2013-11-28 17:07 - 2013-11-28 17:07 - 00000000 ____D C:\Program Files\Common Files\PDF Architect
2013-11-28 17:06 - 2013-11-28 17:06 - 00001641 _____ C:\Users\Marina\AppData\Local\MyWinLockerInstaller.txt-20131128.log
2013-11-28 16:40 - 2013-11-28 16:42 - 00002236 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-28 16:37 - 2013-12-02 13:00 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-28 16:37 - 2013-12-02 12:54 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-28 14:54 - 2013-11-28 14:54 - 00000000 ____D C:\FRST
2013-11-28 14:26 - 2013-11-28 14:26 - 00001110 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Users\Marina\AppData\Roaming\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-28 14:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-25 20:14 - 2013-11-25 20:14 - 00001464 _____ C:\Users\Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-25 19:56 - 2013-11-25 19:56 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-25 19:56 - 2013-11-25 19:56 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-25 19:56 - 2013-11-25 19:56 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-25 19:56 - 2013-11-25 19:56 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-25 19:56 - 2013-11-25 19:56 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-22 04:30 - 2013-11-25 20:00 - 00025780 _____ C:\Windows\IE11_main.log
2013-11-17 08:26 - 2013-11-17 08:29 - 00000000 ____D C:\1cb2e59b94e0900e24283259f1
2013-11-17 08:21 - 2013-11-17 08:21 - 00145856 _____ C:\Windows\Minidump\111713-32666-01.dmp
2013-11-15 07:55 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-15 07:55 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-15 07:55 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-15 07:55 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-15 07:55 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-15 07:55 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-15 07:55 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-15 07:55 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-15 07:55 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-15 07:55 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-15 07:55 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-15 07:55 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-15 07:55 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-15 07:55 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-15 07:55 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-15 07:55 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-15 07:55 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-15 07:55 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
==================== One Month Modified Files and Folders =======
2013-12-02 13:27 - 2013-12-02 13:27 - 00012782 _____ C:\Users\Marina\Desktop\FRST.txt
2013-12-02 13:27 - 2013-12-02 13:26 - 01092187 _____ (Farbar) C:\Users\Marina\Desktop\FRST.exe
2013-12-02 13:14 - 2013-12-02 13:14 - 00001166 _____ C:\Users\M\Desktop\JRT.txt
2013-12-02 13:11 - 2013-12-02 13:11 - 00000000 ____D C:\Windows\ERUNT
2013-12-02 13:11 - 2013-12-02 13:10 - 01034531 _____ (Thisisu) C:\Users\M\Desktop\JRT.exe
2013-12-02 13:07 - 2010-03-04 16:14 - 00010880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-02 13:07 - 2010-03-04 16:14 - 00010880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-02 13:04 - 2010-03-04 16:39 - 01335229 _____ C:\Windows\WindowsUpdate.log
2013-12-02 13:00 - 2013-11-28 16:37 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-02 13:00 - 2012-08-24 08:42 - 00137422 _____ C:\Windows\PFRO.log
2013-12-02 13:00 - 2012-08-19 03:56 - 00159683 _____ C:\Windows\setupact.log
2013-12-02 13:00 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-02 12:58 - 2013-12-02 12:56 - 00000000 ____D C:\AdwCleaner
2013-12-02 12:56 - 2013-12-02 12:56 - 01110034 _____ C:\Users\M\Desktop\AdwCleaner.exe
2013-12-02 12:54 - 2013-11-28 16:37 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-02 12:54 - 2012-04-18 07:15 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-29 10:57 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-11-29 10:13 - 2009-12-29 15:04 - 00000000 ____D C:\Users\M\AppData\Roaming\Adobe
2013-11-29 10:13 - 2009-06-29 14:35 - 00000000 ____D C:\ProgramData\Adobe
2013-11-29 09:06 - 2013-11-29 09:06 - 00018531 _____ C:\ComboFix.txt
2013-11-29 09:06 - 2013-11-29 08:41 - 00000000 ____D C:\Qoobox
2013-11-29 09:06 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default
2013-11-29 09:06 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2013-11-29 09:03 - 2013-11-29 08:40 - 00000000 ____D C:\Windows\erdnt
2013-11-29 09:02 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2013-11-29 08:38 - 2013-11-29 08:38 - 05150163 ____R (Swearware) C:\Users\M\Desktop\ComboFix.exe
2013-11-29 08:34 - 2010-01-03 22:05 - 00000000 ____D C:\Windows\system32\Drivers\Avg
2013-11-28 17:07 - 2013-11-28 17:07 - 00000000 ____D C:\Program Files\Common Files\PDF Architect
2013-11-28 17:06 - 2013-11-28 17:06 - 00001641 _____ C:\Users\M\AppData\Local\MyWinLockerInstaller.txt-20131128.log
2013-11-28 17:05 - 2012-08-03 15:22 - 00000000 ____D C:\Program Files\Mueller Foto
2013-11-28 17:04 - 2009-06-29 14:35 - 00000000 ____D C:\Program Files\Adobe
2013-11-28 16:42 - 2013-11-28 16:40 - 00002236 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-28 16:40 - 2009-12-29 14:48 - 00000000 ____D C:\Users\M\AppData\Local\Google
2013-11-28 16:40 - 2009-06-29 13:57 - 00000000 ____D C:\Program Files\Google
2013-11-28 16:37 - 2012-10-01 06:44 - 00000000 ____D C:\Users\M\AppData\Local\Deployment
2013-11-28 16:26 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-11-28 14:54 - 2013-11-28 14:54 - 00000000 ____D C:\FRST
2013-11-28 14:26 - 2013-11-28 14:26 - 00001110 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Users\M\AppData\Roaming\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-25 20:19 - 2010-03-04 16:52 - 01503478 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-25 20:14 - 2013-11-25 20:14 - 00001464 _____ C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-25 20:13 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-25 20:00 - 2013-11-22 04:30 - 00025780 _____ C:\Windows\IE11_main.log
2013-11-25 19:56 - 2013-11-25 19:56 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-25 19:56 - 2013-11-25 19:56 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-25 19:56 - 2013-11-25 19:56 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-25 19:56 - 2013-11-25 19:56 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-25 19:56 - 2013-11-25 19:56 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-19 03:33 - 2010-01-05 14:57 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-18 17:47 - 2011-08-12 17:03 - 00000000 ____D C:\Users\Marina\AppData\Local\Samsung
2013-11-18 17:47 - 2010-12-03 14:43 - 00000000 ____D C:\ProgramData\Samsung
2013-11-18 17:47 - 2009-06-29 13:34 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-17 08:32 - 2009-06-29 13:58 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-17 08:29 - 2013-11-17 08:26 - 00000000 ____D C:\1cb2e59b94e0900e24283259f1
2013-11-17 08:29 - 2013-08-16 09:35 - 00000000 ____D C:\Windows\system32\MRT
2013-11-17 08:26 - 2010-08-23 19:52 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-17 08:21 - 2013-11-17 08:21 - 00145856 _____ C:\Windows\Minidump\111713-32666-01.dmp
2013-11-17 08:21 - 2012-11-07 18:45 - 257856247 _____ C:\Windows\MEMORY.DMP
2013-11-17 08:21 - 2010-07-02 12:10 - 00000000 ____D C:\Windows\Minidump
Some content of TEMP:
====================
C:\Users\M\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-02 11:10
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2013
Ran by Marina (administrator) on NETBOOK on 02-12-2013 13:27:08
Running from C:\Users\M\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Deutsche Telekom AG) C:\Program Files\Telekom\Mediencenter\DTAG.Mediencenter.BackgroundService.exe
(Egis Technology Inc.) C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7539232 2009-06-09] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [703008 2009-08-28] (Acer Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1434920 2009-02-27] (Synaptics Incorporated)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Runonce: [AvgUninstallURL] - cmd.exe /c start hxxp://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMgBHADMASwAtADgANwBXAFUAVQAtADIAVABWAEgAQQAtAFgANgBEAEYAOAAtAEwANgBQAEEATgA"&"inst=NwA3AC0ANAAxADcANQA0ADcAOAAxADkALQBCAEEAUgA5AEcAKwAxAC0ARgBMACsAOQAtAEYAOQBNADYAKwAxAC0AWABPADMANgArADEALQBGADkATQA3AEMAKwA1AC0AWABPADkAKwAxAC0ARgA5AE0AMwArADEALQBEAEQAVAArADQAMgA5ADQAOQAwADMAOQA5ADAALQBTAFQAOQAwAEYAQQBQAFAAKwAxAC0ARABEADkAMABGACsAMQAtAEYAOQAwAE0AMQAyAFIAKwAxAC0AVgBJAFAAMQAyACsAMQA"&"prod=90"&"ver=9.0.894
HKCU\...\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation)
HKU\Default\...\RunOnce: [ScrSav] -
HKU\Default\...\RunOnce: [RUN] -
HKU\Default User\...\RunOnce: [ScrSav] -
HKU\Default User\...\RunOnce: [RUN] -
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Bing
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {ABF17040-DF58-48F6-8E6B-980C19A8A814} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll (EldoS Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {0006F063-0000-0000-C000-000000000046} hxxp://activex.microsoft.com/activex/controls/office/outlctlx.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5EA13312-8764-496F-B4AB-F7A872B51E14} hxxp://cdn03.oovoo.com/oovoomelink/oovoome/webvc/ooVooWeb.dll
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default
FF Homepage: user_pref("browser.startup.homepage", );
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Marina\AppData\Roaming\Mozilla\Firefox\Profiles\df7w6zci.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.de/", "https://www.google.de/search?q=google&aq=f&oq=google&sugexp=chrome,mod=5&sourceid=chrome&ie=UTF-8"
CHR Extension: (Google Drive) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Marina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
========================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2010-02-28] ()
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [727584 2009-08-28] (Acer Incorporated)
R2 MCSWASVR; C:\Program Files\Telekom\Mediencenter\DTAG.Mediencenter.BackgroundService.exe [12800 2011-11-23] (Deutsche Telekom AG)
R2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-05-14] (Egis Technology Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [237568 2009-02-05] (Acer Incorporated)
==================== Drivers (Whitelisted) ====================
R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [20104 2010-04-06] (IVT Corporation.)
S3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [25864 2010-04-06] ()
R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [265800 2010-05-15] (EldoS Corporation)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
R1 DPMemGridVista; C:\Program Files\GridVista\DPMemGridVista.sys [10504 2008-10-01] (Dritek System Inc.)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36640 2010-10-25] ()
S3 int15.sys; C:\Windows\System32\OEM\Factory\int15.sys [69632 2003-10-01] ()
S3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [23048 2010-04-06] (IVT Corporation.)
R3 L1C; C:\Windows\System32\DRIVERS\L1C60x86.sys [50176 2009-04-27] (Atheros Communications, Inc.)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [19504 2008-12-04] (Egis Incorporated.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2008-12-04] (Egis Incorporated.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [59952 2008-12-04] (Egis Incorporated.)
S3 sscebus; C:\Windows\System32\DRIVERS\sscebus.sys [98560 2010-08-27] (MCCI Corporation)
S3 sscemdfl; C:\Windows\System32\DRIVERS\sscemdfl.sys [14848 2010-08-27] (MCCI Corporation)
S3 sscemdm; C:\Windows\System32\DRIVERS\sscemdm.sys [123648 2010-08-27] (MCCI Corporation)
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [100352 2010-08-27] (MCCI Corporation)
S3 SSDISK; C:\Windows\System32\DRIVERS\SSDISK.sys [10752 2009-03-30] (Alcor Micro, Corp.)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181432 2012-02-24] (DEVGURU Co., LTD.(???? | ????? ???? ?????.))
S3 SSUSB; C:\Windows\System32\DRIVERS\SSUSB.sys [14848 2009-04-07] (Alcor Micro, Corp.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 BT; system32\DRIVERS\btnetdrv.sys [x]
S3 BTCOM; system32\DRIVERS\btcomport.sys [x]
S3 BTCOMBUS; System32\Drivers\btcombus.sys [x]
S3 Btcsrusb; System32\Drivers\btcusb.sys [x]
S3 catchme; \??\C:\Users\Marina\AppData\Local\Temp\catchme.sys [x]
S3 dgderdrv; System32\drivers\dgderdrv.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-02 13:27 - 2013-12-02 13:27 - 00012782 _____ C:\Users\Marina\Desktop\FRST.txt
2013-12-02 13:26 - 2013-12-02 13:27 - 01092187 _____ (Farbar) C:\Users\Marina\Desktop\FRST.exe
2013-12-02 13:14 - 2013-12-02 13:14 - 00001166 _____ C:\Users\Marina\Desktop\JRT.txt
2013-12-02 13:11 - 2013-12-02 13:11 - 00000000 ____D C:\Windows\ERUNT
2013-12-02 13:10 - 2013-12-02 13:11 - 01034531 _____ (Thisisu) C:\Users\Marina\Desktop\JRT.exe
2013-12-02 12:56 - 2013-12-02 12:58 - 00000000 ____D C:\AdwCleaner
2013-12-02 12:56 - 2013-12-02 12:56 - 01110034 _____ C:\Users\Marina\Desktop\AdwCleaner.exe
2013-11-29 09:06 - 2013-11-29 09:06 - 00018531 _____ C:\ComboFix.txt
2013-11-29 08:41 - 2013-11-29 09:06 - 00000000 ____D C:\Qoobox
2013-11-29 08:41 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-11-29 08:41 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-11-29 08:41 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-11-29 08:41 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-11-29 08:40 - 2013-11-29 09:03 - 00000000 ____D C:\Windows\erdnt
2013-11-29 08:38 - 2013-11-29 08:38 - 05150163 ____R (Swearware) C:\Users\Marina\Desktop\ComboFix.exe
2013-11-28 17:07 - 2013-11-28 17:07 - 00000000 ____D C:\Program Files\Common Files\PDF Architect
2013-11-28 17:06 - 2013-11-28 17:06 - 00001641 _____ C:\Users\Marina\AppData\Local\MyWinLockerInstaller.txt-20131128.log
2013-11-28 16:40 - 2013-11-28 16:42 - 00002236 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-28 16:37 - 2013-12-02 13:00 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-28 16:37 - 2013-12-02 12:54 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-28 14:54 - 2013-11-28 14:54 - 00000000 ____D C:\FRST
2013-11-28 14:26 - 2013-11-28 14:26 - 00001110 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Users\Marina\AppData\Roaming\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-28 14:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-25 20:14 - 2013-11-25 20:14 - 00001464 _____ C:\Users\Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-25 19:56 - 2013-11-25 19:56 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-25 19:56 - 2013-11-25 19:56 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-25 19:56 - 2013-11-25 19:56 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-25 19:56 - 2013-11-25 19:56 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-25 19:56 - 2013-11-25 19:56 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-22 04:30 - 2013-11-25 20:00 - 00025780 _____ C:\Windows\IE11_main.log
2013-11-17 08:26 - 2013-11-17 08:29 - 00000000 ____D C:\1cb2e59b94e0900e24283259f1
2013-11-17 08:21 - 2013-11-17 08:21 - 00145856 _____ C:\Windows\Minidump\111713-32666-01.dmp
2013-11-15 07:55 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-15 07:55 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-15 07:55 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-15 07:55 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-15 07:55 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-15 07:55 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-15 07:55 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-15 07:55 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-15 07:55 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-15 07:55 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-15 07:55 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-15 07:55 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-15 07:55 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-15 07:55 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-15 07:55 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-15 07:55 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-15 07:55 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-15 07:55 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
==================== One Month Modified Files and Folders =======
2013-12-02 13:27 - 2013-12-02 13:27 - 00012782 _____ C:\Users\Marina\Desktop\FRST.txt
2013-12-02 13:27 - 2013-12-02 13:26 - 01092187 _____ (Farbar) C:\Users\Marina\Desktop\FRST.exe
2013-12-02 13:14 - 2013-12-02 13:14 - 00001166 _____ C:\Users\M\Desktop\JRT.txt
2013-12-02 13:11 - 2013-12-02 13:11 - 00000000 ____D C:\Windows\ERUNT
2013-12-02 13:11 - 2013-12-02 13:10 - 01034531 _____ (Thisisu) C:\Users\M\Desktop\JRT.exe
2013-12-02 13:07 - 2010-03-04 16:14 - 00010880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-02 13:07 - 2010-03-04 16:14 - 00010880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-02 13:04 - 2010-03-04 16:39 - 01335229 _____ C:\Windows\WindowsUpdate.log
2013-12-02 13:00 - 2013-11-28 16:37 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-02 13:00 - 2012-08-24 08:42 - 00137422 _____ C:\Windows\PFRO.log
2013-12-02 13:00 - 2012-08-19 03:56 - 00159683 _____ C:\Windows\setupact.log
2013-12-02 13:00 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-02 12:58 - 2013-12-02 12:56 - 00000000 ____D C:\AdwCleaner
2013-12-02 12:56 - 2013-12-02 12:56 - 01110034 _____ C:\Users\M\Desktop\AdwCleaner.exe
2013-12-02 12:54 - 2013-11-28 16:37 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-02 12:54 - 2012-04-18 07:15 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-29 10:57 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-11-29 10:13 - 2009-12-29 15:04 - 00000000 ____D C:\Users\M\AppData\Roaming\Adobe
2013-11-29 10:13 - 2009-06-29 14:35 - 00000000 ____D C:\ProgramData\Adobe
2013-11-29 09:06 - 2013-11-29 09:06 - 00018531 _____ C:\ComboFix.txt
2013-11-29 09:06 - 2013-11-29 08:41 - 00000000 ____D C:\Qoobox
2013-11-29 09:06 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default
2013-11-29 09:06 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2013-11-29 09:03 - 2013-11-29 08:40 - 00000000 ____D C:\Windows\erdnt
2013-11-29 09:02 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2013-11-29 08:38 - 2013-11-29 08:38 - 05150163 ____R (Swearware) C:\Users\M\Desktop\ComboFix.exe
2013-11-29 08:34 - 2010-01-03 22:05 - 00000000 ____D C:\Windows\system32\Drivers\Avg
2013-11-28 17:07 - 2013-11-28 17:07 - 00000000 ____D C:\Program Files\Common Files\PDF Architect
2013-11-28 17:06 - 2013-11-28 17:06 - 00001641 _____ C:\Users\M\AppData\Local\MyWinLockerInstaller.txt-20131128.log
2013-11-28 17:05 - 2012-08-03 15:22 - 00000000 ____D C:\Program Files\Mueller Foto
2013-11-28 17:04 - 2009-06-29 14:35 - 00000000 ____D C:\Program Files\Adobe
2013-11-28 16:42 - 2013-11-28 16:40 - 00002236 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-28 16:40 - 2009-12-29 14:48 - 00000000 ____D C:\Users\M\AppData\Local\Google
2013-11-28 16:40 - 2009-06-29 13:57 - 00000000 ____D C:\Program Files\Google
2013-11-28 16:37 - 2012-10-01 06:44 - 00000000 ____D C:\Users\M\AppData\Local\Deployment
2013-11-28 16:26 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-11-28 14:54 - 2013-11-28 14:54 - 00000000 ____D C:\FRST
2013-11-28 14:26 - 2013-11-28 14:26 - 00001110 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Users\M\AppData\Roaming\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 14:26 - 2013-11-28 14:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-25 20:19 - 2010-03-04 16:52 - 01503478 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-25 20:14 - 2013-11-25 20:14 - 00001464 _____ C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-25 20:13 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-25 20:00 - 2013-11-22 04:30 - 00025780 _____ C:\Windows\IE11_main.log
2013-11-25 19:56 - 2013-11-25 19:56 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-25 19:56 - 2013-11-25 19:56 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-25 19:56 - 2013-11-25 19:56 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-25 19:56 - 2013-11-25 19:56 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-25 19:56 - 2013-11-25 19:56 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-25 19:56 - 2013-11-25 19:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-25 19:56 - 2013-11-25 19:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-19 03:33 - 2010-01-05 14:57 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-18 17:47 - 2011-08-12 17:03 - 00000000 ____D C:\Users\Marina\AppData\Local\Samsung
2013-11-18 17:47 - 2010-12-03 14:43 - 00000000 ____D C:\ProgramData\Samsung
2013-11-18 17:47 - 2009-06-29 13:34 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-17 08:32 - 2009-06-29 13:58 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-17 08:29 - 2013-11-17 08:26 - 00000000 ____D C:\1cb2e59b94e0900e24283259f1
2013-11-17 08:29 - 2013-08-16 09:35 - 00000000 ____D C:\Windows\system32\MRT
2013-11-17 08:26 - 2010-08-23 19:52 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-17 08:21 - 2013-11-17 08:21 - 00145856 _____ C:\Windows\Minidump\111713-32666-01.dmp
2013-11-17 08:21 - 2012-11-07 18:45 - 257856247 _____ C:\Windows\MEMORY.DMP
2013-11-17 08:21 - 2010-07-02 12:10 - 00000000 ____D C:\Windows\Minidump
Some content of TEMP:
====================
C:\Users\M\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-02 11:10
==================== End Of Log ============================ --- --- ---
--- --- --- |