Leopardgecko | 20.12.2013 15:18 | Malwarebytes Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.12.20.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Maurice :: MAURICE-PC [Administrator]
Schutz: Aktiviert
20.12.2013 10:36:44
mbam-log-2013-12-20 (10-36-44).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|G:\|H:\|I:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 396532
Laufzeit: 49 Minute(n), 23 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 7
C:\Users\Maurice\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\1F4456ACB7EA44D594D68D66E7C22BB2 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\218225117CEF4DA5B7D7F8C73629083E (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\519A629F19FE4E97B2175B3EDF91C031 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\788567C8E74641FAB0FDBF083F9DC00C (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\891823018CE140B0A543F0F4EEB54AA7 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\EB0E5B23594643B9A0FED88CAE5A43C7 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 12
C:\Windows\temp\svchost.exe (Trojan.Agent.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\temp\phatk121016.cl (Trojan.BitcoinMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\temp\scrypt130511.cl (Trojan.BitcoinMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\temp\diablo130302.cl (Trojan.BitcoinMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\temp\poclbm130302.cl (Trojan.BitcoinMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\temp\diakgcn121016.cl (Trojan.BitcoinMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\1F4456ACB7EA44D594D68D66E7C22BB2\Setupsft_chr_p1v7.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\218225117CEF4DA5B7D7F8C73629083E\TuneUpUtilities2012_de-DE_1002174.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\519A629F19FE4E97B2175B3EDF91C031\TuneUpUtilities2012_de-DE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\788567C8E74641FAB0FDBF083F9DC00C\TuneUpUtilities2012_de-DE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\891823018CE140B0A543F0F4EEB54AA7\TuneUpUtilities2012_de-DE_1002174.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Maurice\AppData\Roaming\OpenCandy\EB0E5B23594643B9A0FED88CAE5A43C7\speedupmypcROE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) AdwCleaner Logfile: Code:
# AdwCleaner v3.015 - Bericht erstellt am 19/12/2013 um 08:02:11
# Updated 10/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Maurice - MAURICE-PC
# Gestartet von : C:\Users\Maurice\Documents\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\simplitec
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Maurice\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\Maurice\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Maurice\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Datei Gelöscht : C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\bv3nntkh.default-1382368656388\searchplugins\softonic.xml
Datei Gelöscht : C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\bv3nntkh.default-1382368656388\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bus-simulator-2012_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bus-simulator-2012_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photofiltre_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photofiltre_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_watermark-image_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_watermark-image_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\Software\Uniblue
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v25.0.1 (de)
[ Datei : C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\bv3nntkh.default-1382368656388\prefs.js ]
Zeile gelöscht : user_pref("extensions.Softonic.admin", false);
Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC");
Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true);
Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false);
Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false);
Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true);
Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=204c3cc00000000000000008ca41342e");
Zeile gelöscht : user_pref("extensions.Softonic.id", "204c3cc00000000000000008ca41342e");
Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16040");
Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621");
Zeile gelöscht : user_pref("extensions.Softonic.newTab", true);
Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=204c3cc00000000000000008ca41342e");
Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic");
Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic");
Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=204c3cc00000000000000008ca41342e&q=");
Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14");
Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1413:58:01");
Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14");
*************************
AdwCleaner[R0].txt - [5979 octets] - [19/12/2013 07:58:23]
AdwCleaner[S0].txt - [5759 octets] - [19/12/2013 08:02:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5819 octets] ########## --- --- ---
AdwCleaner Logfile: Code:
# AdwCleaner v3.015 - Bericht erstellt am 20/12/2013 um 11:40:23
# Updated 10/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Maurice - MAURICE-PC
# Gestartet von : C:\Users\Maurice\Documents\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\simplitec
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Maurice\AppData\Roaming\simplitec
Ordner Gelöscht : C:\Users\Maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Datei Gelöscht : C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\bv3nntkh.default-1382368656388\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bus-simulator-2012_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bus-simulator-2012_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photofiltre_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photofiltre_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_watermark-image_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_watermark-image_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\Software\Uniblue
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\bv3nntkh.default-1382368656388\prefs.js ]
Zeile gelöscht : user_pref("extensions.Softonic.admin", false);
Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC");
Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true);
Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false);
Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false);
Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true);
Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=204c3cc00000000000000008ca41342e");
Zeile gelöscht : user_pref("extensions.Softonic.id", "204c3cc00000000000000008ca41342e");
Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16040");
Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621");
Zeile gelöscht : user_pref("extensions.Softonic.newTab", true);
Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=204c3cc00000000000000008ca41342e");
Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic");
Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic");
Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=204c3cc00000000000000008ca41342e&q=");
Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14");
Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1413:58:01");
Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14");
*************************
AdwCleaner[R0].txt - [11367 octets] - [19/12/2013 07:58:23]
AdwCleaner[S0].txt - [11010 octets] - [19/12/2013 08:02:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11071 octets] ########## --- --- --- Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Maurice on 20.12.2013 at 11:45:15,95
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9A203B24-DD4C-4992-B9C7-D974E67F0B5A}
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\shoCFC1.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoD911.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{148565C1-5ABE-4630-BB7D-22907773FEA0}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{1A4B1853-EC3C-4482-8F7B-E4E6DC1C19B6}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{24763554-83B0-4130-BAC1-B02C2F34475A}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{2897AD8E-5B3E-4C45-B694-B53598D06928}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{31979A5F-ED67-4679-B732-3CDB61B24A4E}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{38850D4E-85D7-49C2-A0DB-CBE277E150EB}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{46C25096-16B5-4C55-99BB-96A66DD38DFC}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{48BEA5AD-D22C-47EF-8481-3D929209A1D2}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{4E4D6804-1AE9-4C17-96D9-887EE21BE3DF}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{6EF73E9F-393D-4EE5-8652-06FB28951FDD}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{70BE8FDD-8E60-4AB3-A689-2CAFBF845E59}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{721F0BD5-7EB3-4573-9942-09EE72EB0267}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{95CDBB12-1E52-4C30-A97A-E3AB0008CEBE}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{D26C609E-BBD6-4570-AA70-512E4CE7F386}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{EF01A621-5FB6-4A4F-A626-1A8095E7CBC6}
Successfully deleted: [Empty Folder] C:\Users\Maurice\appdata\local\{F7A9188B-6C80-4DD1-8DDA-824720F243B5}
~~~ FireFox
Emptied folder: C:\Users\Maurice\AppData\Roaming\mozilla\firefox\profiles\bv3nntkh.default-1382368656388\minidumps [6 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.12.2013 at 11:50:03,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-12-2013
Ran by Maurice (administrator) on MAURICE-PC on 20-12-2013 11:52:28
Running from C:\Users\Maurice\Documents\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
() C:\Windows\SysWOW64\PnkBstrA.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(ashampoo GmbH & Co. KG) C:\Program Files (x86)\Medion MediaPack 2\Ashampoo Snap\ashsnap.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
() C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\klwtblfs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\klwtblfs.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKCU\...\Run: [AshSnap] - C:\Program Files (x86)\Medion MediaPack 2\Ashampoo Snap\ashsnap.exe [1721344 2011-04-14] (ashampoo GmbH & Co. KG)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKCU\...\Run: [TomTomHOME.exe] - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-08-27] (TomTom)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-08-11] (Macrovision Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-23] ()
HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-23] ()
HKU\UpdatusUser\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
HKU\UpdatusUser\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-23] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-219675657-2299708246-2159064094-1001\FireFox
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx
==================== Services (Whitelisted) =================
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-12-11] ()
==================== Drivers (Whitelisted) ====================
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-19] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620640 2013-12-19] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2013-12-19] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S1 prodrv06; C:\Windows\SysWow64\drivers\prodrv06.sys [77184 2004-03-09] (Protection Technology)
S0 prohlp02; C:\Windows\SysWow64\drivers\prohlp02.sys [65504 2004-03-09] (Protection Technology)
S0 sfhlp01; C:\Windows\SysWow64\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-20 11:50 - 2013-12-20 11:50 - 00002845 _____ C:\Users\Maurice\Desktop\JRT.txt
2013-12-20 11:45 - 2013-12-20 11:45 - 00000000 ____D C:\Windows\ERUNT
2013-12-20 11:23 - 2013-12-20 11:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 10:34 - 2013-12-20 10:34 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-20 10:34 - 2013-12-20 10:34 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\Malwarebytes
2013-12-20 10:34 - 2013-12-20 10:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-20 10:34 - 2013-12-20 10:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-20 10:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-19 15:15 - 2013-12-19 15:15 - 00000000 ___SD C:\Users\Maurice\Documents\Meine Datenquellen
2013-12-19 14:56 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-19 14:56 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-19 14:56 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-19 14:56 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-19 14:56 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-19 14:56 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-19 14:56 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-19 14:56 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-19 14:56 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-19 14:56 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-19 14:56 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-19 14:56 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-19 14:56 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-19 14:56 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-19 14:56 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-19 14:56 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-19 14:56 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-19 14:56 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-19 14:56 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-19 14:56 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-19 14:56 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-19 14:56 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-19 14:56 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-19 14:56 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-19 14:56 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-19 14:56 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-19 14:56 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-19 14:56 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-19 14:56 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-19 14:56 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-19 14:56 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-19 14:50 - 2013-12-19 14:50 - 00025276 _____ C:\ComboFix.txt
2013-12-19 14:43 - 2013-12-19 14:50 - 00000000 ____D C:\Qoobox
2013-12-19 14:43 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-12-19 14:43 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-12-19 14:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-12-19 14:43 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-12-19 14:43 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-12-19 14:43 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-12-19 14:43 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-12-19 14:43 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-12-19 14:42 - 2013-12-19 14:48 - 00000000 ____D C:\Windows\erdnt
2013-12-19 12:54 - 2013-12-19 12:54 - 00002334 _____ C:\Users\Maurice\Desktop\Sicherer Zahlungsverkehr.lnk
2013-12-19 12:54 - 2013-12-19 12:54 - 00001128 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2013-12-19 12:54 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2013-12-19 12:53 - 2013-12-19 12:59 - 00620640 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-12-19 12:53 - 2013-12-19 12:53 - 00000000 ____D C:\Windows\ELAMBKUP
2013-12-19 12:53 - 2013-12-19 12:53 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2013-12-19 12:53 - 2013-06-08 20:18 - 00112224 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2013-12-19 09:20 - 2013-12-20 11:42 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-12-19 08:48 - 2013-12-19 08:48 - 00000000 ____D C:\FRST
2013-12-19 08:22 - 2013-12-19 08:22 - 00000000 ____D C:\Users\Maurice\AppData\Local\Secunia PSI
2013-12-19 07:58 - 2013-12-20 11:40 - 00000000 ____D C:\AdwCleaner
2013-12-18 13:35 - 2013-12-18 13:35 - 00000000 ____D C:\ProgramData\Oracle
2013-12-17 12:04 - 2013-12-19 11:07 - 00000000 ____D C:\Program Files (x86)\Der Planer 4
2013-12-16 14:57 - 2013-12-16 14:57 - 00000000 ____D C:\Users\Maurice\Desktop\Carlo & Jazz
2013-12-16 14:46 - 2013-12-16 14:46 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\AVAST Software
2013-12-14 09:53 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-14 09:50 - 2013-12-14 09:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-14 09:50 - 2013-12-14 09:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-14 09:50 - 2013-12-14 09:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-14 09:50 - 2013-12-14 09:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-14 09:50 - 2013-12-14 09:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-14 09:50 - 2013-12-14 09:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-14 09:50 - 2013-12-14 09:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-14 09:48 - 2013-12-14 09:53 - 00010277 _____ C:\Windows\IE11_main.log
2013-12-12 17:06 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 17:06 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 17:06 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 17:06 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 16:18 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 16:18 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 16:18 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 16:18 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 16:18 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 16:18 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 16:18 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 16:18 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 16:18 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 16:18 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 16:18 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 16:18 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 16:18 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 16:18 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 16:18 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 16:18 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 16:18 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 16:18 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 16:18 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 20:06 - 2013-12-11 20:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf
2013-12-11 18:16 - 2013-12-11 18:16 - 00000000 ____D C:\Users\Maurice\AppData\Local\ESN
2013-12-11 17:42 - 2013-12-19 11:07 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-12-11 17:41 - 2013-12-11 17:41 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-11 17:41 - 2013-12-11 17:41 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-12-11 17:41 - 2013-12-11 17:41 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-12-11 17:40 - 2013-12-11 17:41 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-09 16:27 - 2013-12-09 16:27 - 00000000 ____D C:\Program Files (x86)\TomTom HOME 2
2013-12-09 16:25 - 2013-12-09 16:25 - 30992256 _____ C:\Users\Maurice\Desktop\TomTomHOME2winlatest.exe
2013-12-07 14:31 - 2013-12-07 14:31 - 00002218 _____ C:\Users\Public\Desktop\t@x 2014.lnk
2013-12-07 14:28 - 2013-12-07 14:28 - 00000000 ____D C:\Program Files (x86)\Buhl finance
2013-12-02 17:02 - 2013-12-02 17:02 - 00003126 _____ C:\Windows\System32\Tasks\{42C82175-785D-4740-BD9F-AB51649AAF9D}
2013-12-02 17:00 - 2013-12-19 11:07 - 00000000 ____D C:\Program Files (x86)\Battlefield 4
2013-12-01 16:56 - 2013-12-16 14:06 - 00000000 ____D C:\ProgramData\Origin
2013-12-01 16:50 - 2013-12-11 17:04 - 00000000 ___HD C:\Users\Maurice\AppData\Roaming\Origin
2013-12-01 16:50 - 2013-12-01 16:50 - 00003128 _____ C:\Windows\System32\Tasks\Origin
==================== One Month Modified Files and Folders =======
2013-12-20 11:50 - 2013-12-20 11:50 - 00002845 _____ C:\Users\Maurice\Desktop\JRT.txt
2013-12-20 11:49 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-20 11:49 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-20 11:45 - 2013-12-20 11:45 - 00000000 ____D C:\Windows\ERUNT
2013-12-20 11:45 - 2012-03-29 17:19 - 01823131 _____ C:\Windows\WindowsUpdate.log
2013-12-20 11:42 - 2013-12-19 09:20 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-12-20 11:41 - 2012-10-15 16:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-20 11:41 - 2012-01-24 17:36 - 00081018 _____ C:\Windows\setupact.log
2013-12-20 11:41 - 2012-01-24 00:22 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-20 11:41 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-20 11:40 - 2013-12-19 07:58 - 00000000 ____D C:\AdwCleaner
2013-12-20 11:34 - 2010-11-21 04:47 - 00491854 _____ C:\Windows\PFRO.log
2013-12-20 11:23 - 2013-12-20 11:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 10:57 - 2012-04-06 09:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-20 10:34 - 2013-12-20 10:34 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-20 10:34 - 2013-12-20 10:34 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\Malwarebytes
2013-12-20 10:34 - 2013-12-20 10:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-20 10:34 - 2013-12-20 10:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-19 15:15 - 2013-12-19 15:15 - 00000000 ___SD C:\Users\Maurice\Documents\Meine Datenquellen
2013-12-19 14:56 - 2013-08-15 17:51 - 00000000 ____D C:\Windows\system32\MRT
2013-12-19 14:55 - 2011-07-18 21:31 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-19 14:50 - 2013-12-19 14:50 - 00025276 _____ C:\ComboFix.txt
2013-12-19 14:50 - 2013-12-19 14:43 - 00000000 ____D C:\Qoobox
2013-12-19 14:48 - 2013-12-19 14:42 - 00000000 ____D C:\Windows\erdnt
2013-12-19 14:48 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2013-12-19 13:29 - 2012-03-29 17:22 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-19 12:59 - 2013-12-19 12:53 - 00620640 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-12-19 12:59 - 2013-10-17 15:47 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2013-12-19 12:59 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2013-12-19 12:54 - 2013-12-19 12:54 - 00002334 _____ C:\Users\Maurice\Desktop\Sicherer Zahlungsverkehr.lnk
2013-12-19 12:54 - 2013-12-19 12:54 - 00001128 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2013-12-19 12:53 - 2013-12-19 12:53 - 00000000 ____D C:\Windows\ELAMBKUP
2013-12-19 12:53 - 2013-12-19 12:53 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2013-12-19 12:50 - 2012-07-29 12:27 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-19 12:45 - 2012-03-29 17:23 - 00000000 ____D C:\Program Files\Google
2013-12-19 12:36 - 2012-03-29 17:38 - 00000000 ____D C:\Users\Maurice\AppData\Local\Google
2013-12-19 12:35 - 2013-07-25 17:47 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\GHISLER
2013-12-19 12:35 - 2013-07-25 17:47 - 00000000 ____D C:\totalcmd
2013-12-19 11:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-19 11:09 - 2013-01-28 14:27 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\RDecke
2013-12-19 11:09 - 2012-08-06 16:45 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\Thunderbird
2013-12-19 11:09 - 2012-06-26 19:17 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\MAGIX
2013-12-19 11:09 - 2012-04-09 09:09 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\TS3Client
2013-12-19 11:09 - 2012-04-07 09:05 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-12-19 11:09 - 2012-03-29 17:43 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\SoftGrid Client
2013-12-19 11:09 - 2012-03-29 17:30 - 00000000 ____D C:\Users\Maurice
2013-12-19 11:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-12-19 11:08 - 2013-11-02 16:39 - 00000000 ____D C:\Program Files (x86)\WRC 4 FIA World Rally Championship
2013-12-19 11:08 - 2013-07-25 19:14 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-12-19 11:08 - 2012-04-07 09:05 - 00000000 ____D C:\Program Files (x86)\WinRAR
2013-12-19 11:07 - 2013-12-17 12:04 - 00000000 ____D C:\Program Files (x86)\Der Planer 4
2013-12-19 11:07 - 2013-12-11 17:42 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-12-19 11:07 - 2013-12-02 17:00 - 00000000 ____D C:\Program Files (x86)\Battlefield 4
2013-12-19 11:07 - 2013-07-25 18:58 - 00000000 ____D C:\OpenSSL-Win64
2013-12-19 11:05 - 2011-04-12 09:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-19 11:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-19 08:48 - 2013-12-19 08:48 - 00000000 ____D C:\FRST
2013-12-19 08:22 - 2013-12-19 08:22 - 00000000 ____D C:\Users\Maurice\AppData\Local\Secunia PSI
2013-12-18 13:35 - 2013-12-18 13:35 - 00000000 ____D C:\ProgramData\Oracle
2013-12-16 14:57 - 2013-12-16 14:57 - 00000000 ____D C:\Users\Maurice\Desktop\Carlo & Jazz
2013-12-16 14:46 - 2013-12-16 14:46 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\AVAST Software
2013-12-16 14:06 - 2013-12-01 16:56 - 00000000 ____D C:\ProgramData\Origin
2013-12-16 14:05 - 2012-10-03 09:54 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-12-16 14:05 - 2012-05-04 19:25 - 00000000 ____D C:\Users\Maurice\AppData\Roaming\DVDVideoSoft
2013-12-16 14:02 - 2011-07-18 22:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-16 12:46 - 2012-07-29 12:27 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-16 12:41 - 2012-07-29 12:27 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-12-15 06:12 - 2011-05-16 15:04 - 00702980 _____ C:\Windows\system32\perfh007.dat
2013-12-15 06:12 - 2011-05-16 15:04 - 00150620 _____ C:\Windows\system32\perfc007.dat
2013-12-15 06:12 - 2009-07-14 06:13 - 01629444 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-14 11:25 - 2013-03-23 10:58 - 00001425 _____ C:\Users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-14 11:22 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-14 09:53 - 2013-12-14 09:48 - 00010277 _____ C:\Windows\IE11_main.log
2013-12-14 09:50 - 2013-12-14 09:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-14 09:50 - 2013-12-14 09:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-14 09:50 - 2013-12-14 09:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-14 09:50 - 2013-12-14 09:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-14 09:50 - 2013-12-14 09:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-14 09:50 - 2013-12-14 09:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-14 09:50 - 2013-12-14 09:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-14 09:50 - 2013-12-14 09:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-14 09:50 - 2013-12-14 09:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-14 07:24 - 2013-11-10 12:47 - 00000000 ____D C:\Users\Maurice\Desktop\NZ 112013
2013-12-13 20:04 - 2009-07-14 05:45 - 05154632 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-12 17:06 - 2012-05-09 16:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 20:06 - 2013-12-11 20:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf
2013-12-11 18:57 - 2012-04-06 09:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 18:57 - 2012-04-06 09:37 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 18:57 - 2011-12-01 22:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 18:16 - 2013-12-11 18:16 - 00000000 ____D C:\Users\Maurice\AppData\Local\ESN
2013-12-11 17:41 - 2013-12-11 17:41 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-11 17:41 - 2013-12-11 17:41 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-12-11 17:41 - 2013-12-11 17:41 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-12-11 17:41 - 2013-12-11 17:40 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-11 17:40 - 2011-07-18 21:49 - 00130176 _____ C:\Windows\DirectX.log
2013-12-11 17:04 - 2013-12-01 16:50 - 00000000 ___HD C:\Users\Maurice\AppData\Roaming\Origin
2013-12-09 16:27 - 2013-12-09 16:27 - 00000000 ____D C:\Program Files (x86)\TomTom HOME 2
2013-12-09 16:25 - 2013-12-09 16:25 - 30992256 _____ C:\Users\Maurice\Desktop\TomTomHOME2winlatest.exe
2013-12-08 12:26 - 2013-04-09 16:27 - 00000000 ____D C:\Users\Maurice\AppData\Local\Downloaded Installations
2013-12-07 15:27 - 2013-02-14 09:07 - 00000000 ____D C:\Users\Maurice\Documents\tax
2013-12-07 14:31 - 2013-12-07 14:31 - 00002218 _____ C:\Users\Public\Desktop\t@x 2014.lnk
2013-12-07 14:31 - 2013-02-14 08:55 - 00000684 _____ C:\Windows\wiso.ini
2013-12-07 14:31 - 2013-02-14 08:55 - 00000000 ____D C:\Users\Maurice\AppData\Local\Buhl
2013-12-07 14:31 - 2013-02-14 08:47 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-07 14:28 - 2013-12-07 14:28 - 00000000 ____D C:\Program Files (x86)\Buhl finance
2013-12-02 17:02 - 2013-12-02 17:02 - 00003126 _____ C:\Windows\System32\Tasks\{42C82175-785D-4740-BD9F-AB51649AAF9D}
2013-12-01 16:50 - 2013-12-01 16:50 - 00003128 _____ C:\Windows\System32\Tasks\Origin
2013-12-01 14:58 - 2013-10-12 09:57 - 00000000 ____D C:\Users\Maurice\Maurice
2013-11-26 12:54 - 2013-12-19 14:56 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 12:25 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-26 11:19 - 2013-12-19 14:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 11:18 - 2013-12-19 14:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 11:11 - 2013-12-19 14:56 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 10:48 - 2013-12-19 14:56 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 10:46 - 2013-12-19 14:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 10:41 - 2013-12-19 14:56 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 10:29 - 2013-12-19 14:56 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 10:27 - 2013-12-19 14:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 10:23 - 2013-12-19 14:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 10:21 - 2013-12-19 14:56 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 10:18 - 2013-12-19 14:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 10:18 - 2013-12-19 14:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 10:16 - 2013-12-19 14:56 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 09:57 - 2013-12-19 14:56 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 09:38 - 2013-12-19 14:56 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 09:38 - 2013-12-19 14:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 09:35 - 2013-12-19 14:56 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 09:32 - 2013-12-19 14:56 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 09:28 - 2013-12-19 14:56 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 09:16 - 2013-12-19 14:56 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 09:02 - 2013-12-19 14:56 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 08:48 - 2013-12-19 14:56 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 08:32 - 2013-12-19 14:56 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 08:26 - 2013-12-19 14:56 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 08:07 - 2013-12-19 14:56 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 07:40 - 2013-12-19 14:56 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 07:34 - 2013-12-19 14:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 07:34 - 2013-12-19 14:56 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 07:33 - 2013-12-19 14:56 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 07:27 - 2013-12-19 14:56 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-23 19:26 - 2013-12-12 16:18 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-23 18:47 - 2013-12-12 16:18 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
Files to move or delete:
====================
C:\Users\Maurice\AppData\Roaming\Origin\update.vbe
Some content of TEMP:
====================
C:\Users\Maurice\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-19 11:40
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-12-2013
Ran by Maurice at 2013-12-20 11:52:43
Running from C:\Users\Maurice\Documents\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
Adobe AIR (x32 Version: 3.8.0.1280)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Adobe Shockwave Player 11.6 (x32 Version: 11.6.3.633)
Apple Application Support (x32 Version: 2.3.2)
Ashampoo Burning Studio (x32 Version: 10.0.10)
Ashampoo Photo Commander (x32 Version: 9.2.0)
Ashampoo Photo Optimizer (x32 Version: 4.0.0)
Ashampoo Snap (x32 Version: 4.3.0)
Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.12.9.0)
AVM FRITZ!Box Dokumentation (x32)
Bildschutz Pro (x32 Version: 2.0)
Bonjour (Version: 3.0.0.10)
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2)
CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0)
CorelDRAW Essentials X5 - Extra Content (x32)
CorelDRAW Graphics Suite X3 (x32 Version: 13.0)
CyberLink LabelPrint (x32 Version: 2.5.3624)
CyberLink MediaEspresso (x32 Version: 6.5.1817_38674)
CyberLink PhotoDirector 2011 (x32 Version: 2.0.2430)
CyberLink Power2Go (x32 Version: 7.0.0.1327)
CyberLink PowerDVD Copy (x32 Version: 1.5.2408)
CyberLink PowerRecover (x32 Version: 5.5.4125)
D3DX10 (x32 Version: 15.4.2368.0902)
DE (x32 Version: 13.0)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
EPSON Stylus SX200 Series Printer Uninstall
FontNav (x32 Version: 5.0)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922)
Free YouTube to MP3 Converter version 3.11.32.918 (x32 Version: 3.11.32.918)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
GIMP 2.8.4 (Version: 2.8.4)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Rapid Storage Technology (x32 Version: 10.6.0.1002)
iTunes (Version: 11.0.1.12)
Java 7 Update 25 (x32 Version: 7.0.250)
Java 7 Update 40 (64-bit) (Version: 7.0.400)
Java Auto Updater (x32 Version: 2.1.9.5)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Kaspersky Internet Security (x32 Version: 14.0.0.4651)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (x32 Version: 15.4.5722.2)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Medion Home Cinema (x32 Version: 8.0.3216)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4.5 (Version: 4.5.50709)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.88.0)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office 2010 Service Pack 1 (SP1) (x32)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (x32 Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610)
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0)
Mozilla Maintenance Service (x32 Version: 26.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
Nero Backup Drivers (Version: 1.0.11100.8.0)
NVIDIA 3D Vision Controller-Treiber 314.22 (Version: 314.22)
NVIDIA 3D Vision Treiber 314.22 (Version: 314.22)
NVIDIA Grafiktreiber 314.22 (Version: 314.22)
NVIDIA HD-Audiotreiber 1.3.23.1 (Version: 1.3.23.1)
NVIDIA Install Application (Version: 2.1002.115.743)
NVIDIA PhysX (x32 Version: 9.12.1031)
NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1422)
NVIDIA Systemsteuerung 314.22 (Version: 314.22)
NVIDIA Update 1.12.12 (Version: 1.12.12)
NVIDIA Update Components (Version: 1.12.12)
OpenAL (x32)
OpenSSL 1.0.1e Light (64-bit)
PCSUITE SHREDDER (x32)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
Pošta Windows Live (x32 Version: 15.4.3502.0922)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6438)
Simulationsprogramm Integrierte Leitstelle 1.0 (x32)
Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0)
swMSM (x32 Version: 12.0.0.1)
t@x 2014 (x32 Version: 21.00.8480)
Terraniser (x32)
TomTom HOME (x32 Version: 2.9.7)
TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2)
Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553065) (x32)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2566458) (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32)
Update Manager (x32 Version: 4.60)
VBA (x32 Version: 6.2)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3538.0513)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922)
Windows Live Fotótár (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinRAR 4.11 (32-Bit) (x32 Version: 4.11.0)
WinZip 16.0 (x32 Version: 16.0.9715)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922)
==================== Restore Points =========================
19-12-2013 11:47:29 avast! antivirus system restore point
19-12-2013 13:54:58 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:34 - 2013-12-19 14:48 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {0F8DD524-0CB5-4B03-B138-DBB7DD735DD7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated)
Task: {83E0C157-6D3A-4708-AC1B-BDEF756BF826} - System32\Tasks\Origin => C:\Users\Maurice\AppData\Roaming\Origin\update.vbe [2013-12-01] () <==== ATTENTION
Task: {89358956-54FA-4443-89FE-53BBFEE68071} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2012-01-24 00:45 - 2011-04-18 23:47 - 04190568 _____ () C:\Program Files (x86)\Medion MediaPack 2\Ashampoo Snap\ash_inet2.dll
2012-01-24 00:45 - 2011-04-01 18:10 - 00065904 _____ () C:\Program Files (x86)\Medion MediaPack 2\Ashampoo Snap\MouseHook.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-12-07 14:28 - 2013-10-30 17:45 - 09572944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wgui14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 00034896 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsdcom48.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 00308816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rscorewinapi48.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 00321616 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsguiwinapi48.dll
2013-12-07 14:28 - 2013-10-30 17:46 - 03674192 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wcore14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 00136272 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsodbc48.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 02467408 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfvie14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01855568 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wsteu14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01904208 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wreli14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 04277840 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wauff14.dll
2013-12-07 14:28 - 2013-10-30 17:37 - 01043456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-core.dll
2013-12-07 14:28 - 2013-10-30 17:37 - 00094720 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-shared.dll
2013-12-07 14:28 - 2013-10-30 17:37 - 00250368 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-contribs-lib.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01396816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wmain14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 05019728 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae114.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01666128 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae214.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01786448 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae314.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01624144 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae414.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01125456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau114.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01316944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau214.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01278544 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wwerb14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 06818384 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wkont14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01266768 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wimp14.dll
2013-12-07 14:28 - 2013-10-30 17:45 - 01322064 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfabu14.dll
2010-08-04 00:39 - 2010-08-04 00:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-04 00:39 - 2010-08-04 00:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2013-08-17 08:02 - 2013-08-17 08:02 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\1beb84c27c2edeb38839916524b9df4d\IsdiInterop.ni.dll
2012-01-23 23:47 - 2011-05-20 19:05 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-12-20 11:23 - 2013-12-20 11:23 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-12-11 18:57 - 2013-12-11 18:57 - 16242056 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2013-12-20 10:56:09.748
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-12-20 10:56:09.748
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-12-20 10:56:09.748
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-12-20 10:48:07.971
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-12-20 10:48:07.971
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-12-20 10:48:07.971
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-12-19 14:47:59.585
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-12-19 14:47:59.538
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-12-19 14:44:14.304
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-12-19 14:44:14.304
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 42%
Total physical RAM: 4077.64 MB
Available physical RAM: 2332.03 MB
Total Pagefile: 8153.46 MB
Available Pagefile: 6207.52 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:880.41 GB) (Free:812.91 GB) NTFS
Drive d: (Recover) (Fixed) (Total:50 GB) (Free:7.18 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 58F6BA5B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=880 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
==================== End Of Log ============================ Habe festgestellt
habe 5 Trojaner.BitcoNMiner und ein ein Trojaner.Agent cn drauf
wenn ich sie lösche und dann den PC neustarte kommen die wieder
wie bekomme ich die komplett los
ESET FILE Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=04e296e04d500a44bd294a51c9c6dae6
# engine=16343
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-12-20 02:10:11
# local_time=2013-12-20 03:10:11 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 15511 139178461 0 0
# scanned=236484
# found=0
# cleaned=0
# scan_time=7348 Security Check Code:
Results of screen317's Security Check version 0.99.77
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Kaspersky Internet Security
Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 25
Java version out of Date!
Adobe Flash Player 11.9.900.170
Adobe Reader XI
Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent````````
Kaspersky Lab Kaspersky Internet Security 14.0.0 klwtblfs.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |