schnüffel | 12.01.2014 11:09 | Code:
# AdwCleaner v3.016 - Bericht erstellt am 11/01/2014 um 12:58:23
# Aktualisiert 23/12/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Sabrina - SABRINA-THINK
# Gestartet von : C:\Users\Sabrina\Downloads\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gefunden C:\Program Files (x86)\MyPC Backup
Ordner Gefunden C:\Program Files (x86)\YoutubeAdblocker
Ordner Gefunden C:\ProgramData\YoutubeAdblocker
Ordner Gefunden C:\Users\Sabrina\AppData\Local\torch
Ordner Gefunden C:\Users\UpdatusUser\AppData\Local\torch
Ordner Gefunden C:\Windows\System32\ljkb
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gefunden : HKCU\Software\WEDLMNGR
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gefunden : [x64] HKCU\Software\WEDLMNGR
Schlüssel Gefunden : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{4C836512-BB70-11D2-A5A7-00105A9C91C6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DB797690-40E0-11D2-9BD5-0060082AE372}
Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\547B38670606DF14AA57B0BB83F3AE4D
Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\547B38670606DF14AA57B0BB83F3AE4D
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{DB797681-40E0-11D2-9BD5-0060082AE372}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://websearch.searchsunmy.info/?pid=377&r=2014/01/04&hid=6896541430164809529&lg=EN&cc=CH&unqvl=45
Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://websearch.searchsunmy.info/?pid=377&r=2014/01/04&hid=6896541430164809529&lg=EN&cc=CH&unqvl=45
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\prefs.js ]
Zeile gefunden : user_pref("browser.search.defaultenginename", "WebSearch");
Zeile gefunden : user_pref("browser.search.defaultenginename,S", "WebSearch");
Zeile gefunden : user_pref("browser.search.defaulturl", "hxxp://websearch.searchsunmy.info/?pid=377&r=2014/01/04&hid=6896541430164809529&lg=EN&cc=CH&unqvl=45&l=1&q=");
Zeile gefunden : user_pref("browser.search.order.1", "WebSearch");
Zeile gefunden : user_pref("browser.search.order.1,S", "WebSearch");
Zeile gefunden : user_pref("browser.search.selectedEngine", "WebSearch");
Zeile gefunden : user_pref("browser.search.selectedEngine,S", "WebSearch");
Zeile gefunden : user_pref("extensions.JnkGPYLJwX.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.hostname.indexOf('mail.')==-1)\r\n{try{for(i=0;i<5;i+[...]
Zeile gefunden : user_pref("extensions.LTQ5hNWIrrY.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.protocol.indexOf('hxxp')>-1 && window.self==window.t[...]
Zeile gefunden : user_pref("extensions.p1LpPE.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self==window.top){var script=document.createElement('script');script.ty[...]
Zeile gefunden : user_pref("keyword.URL", "hxxp://websearch.searchsunmy.info/?pid=377&r=2014/01/04&hid=6896541430164809529&lg=EN&cc=CH&unqvl=45&l=1&q=");
-\\ Google Chrome v31.0.1650.63
[ Datei : C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gefunden : homepage
Gefunden : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [9030 octets] - [21/10/2013 13:26:05]
AdwCleaner[R1].txt - [5102 octets] - [11/01/2014 12:58:23]
AdwCleaner[S0].txt - [8615 octets] - [21/10/2013 13:27:20]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [5222 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Professional x64
Ran by Sabrina on 11.01.2014 at 13:07:58.84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{159BC49F-2CD6-4CB7-932B-1027665E58BD}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{159BC49F-2CD6-4CB7-932B-1027665E58BD}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{159BC49F-2CD6-4CB7-932B-1027665E58BD}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F72390C-3192-91EF-ECD9-D90061D298A2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4F72390C-3192-91EF-ECD9-D90061D298A2}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4F72390C-3192-91EF-ECD9-D90061D298A2}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Sabrina\appdata\local\{0DA2FFD1-951C-4F5C-9323-B7ED3425597A}
Successfully deleted: [Empty Folder] C:\Users\Sabrina\appdata\local\{D78211E7-6B7D-4FDF-806D-2AC5F1A4005B}
~~~ FireFox
Successfully deleted the following from C:\Users\Sabrina\AppData\Roaming\mozilla\firefox\profiles\9ulbhy7c.default\prefs.js
user_pref("extensions.JnkGPYLJwX.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.hostname.indexOf('mail.')==-
user_pref("extensions.LTQ5hNWIrrY.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.protocol.indexOf('hxxp')>-1
user_pref("extensions.p1LpPE.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self==window.top){var script=document.createEl
user_pref("extensions.p1LpPE.url", "hxxp://jpi-syncs.info/sync2/?q=hfZ9ofV9CShEAen0rHC6tMqLDe49CNU0n9YMCMlNhd9FqdaFrdnFqHaHrjaMBzqUojw9rdwFrjwGrds8qSh7hfs0pihPBMn0rjkEpdsGpdwE
Emptied folder: C:\Users\Sabrina\AppData\Roaming\mozilla\firefox\profiles\9ulbhy7c.default\minidumps [8 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.01.2014 at 13:14:09.43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST funktioniert nun leider nicht mehr :-(.
Folgende Fehlermeldung erscheint.
AutoIt Errer
Line 10181 (File "c:\users\sabrina\downloads\FRST64.exe")
Error: Array variable has incorrect number of subscripts or subscript dimension range exceeded.
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-01-2014 05
Ran by Sabrina (administrator) on SABRINA-THINK on 12-01-2014 11:08:22
Running from C:\Users\Sabrina\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(UPEK Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\ProgramData\SoftWarehouse\GS.Enabler\GS.Enabler.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Swisscom) C:\Program Files (x86)\Swisscom\Sesam\BIN\SecMIPService.exe
(Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe
(Swisscom) C:\Program Files (x86)\Swisscom\Unlimited Data Manager\DashBoardS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Avanquest Software ) C:\Program Files (x86)\Digital Line Detect\DLG.exe
(Dropbox, Inc.) C:\Users\Sabrina\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Windows\Samsung\PanelMgr\caller64.exe
(Swisscom) C:\Program Files (x86)\Swisscom\Quick Help\SwisscomQuickHelp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\System Update\SUService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
() C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Farbar) C:\Users\Sabrina\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2789160 2011-05-19] (Synaptics Incorporated)
HKLM\...\Run: [TpShocks] - C:\Windows\system32\TpShocks.exe [380776 2010-12-09] (Lenovo.)
HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2011-03-14] (Conexant systems, Inc.)
HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [40808 2011-05-31] (Lenovo Group Limited)
HKLM\...\Run: [ALCKRESI.EXE] - C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE [281960 2011-05-25] (Lenovo Group Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RotateImage] - C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-31] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [PWMTRV] - rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
HKLM-x32\...\Run: [Lenovo Registration] - C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-14] (Lenovo, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [606208 2009-10-13] ()
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [Swisscom Quick Help] - C:\Program Files (x86)\Swisscom\Quick Help\SwisscomQuickHelp.exe [16668080 2013-10-02] (Swisscom)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [522744 2012-06-07] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (UPEK Inc.)
HKCU\...\Run: [LTT] - C:\Program Files\PC-Doctor\EnableToolbarW32.exe [23120 2011-06-27] (PC-Doctor, Inc.)
HKU\Default\...\RunOnce: [] - [x]
HKU\Default\...\RunOnce: [Lenovoautoqdrive] - C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe [159744 2009-03-24] ()
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\SWTOOLS\SimpleTap DeskBand\ShowBand.exe [156472 2011-12-21] ()
HKU\Default User\...\RunOnce: [] - [x]
HKU\Default User\...\RunOnce: [Lenovoautoqdrive] - C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe [159744 2009-03-24] ()
HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\SWTOOLS\SimpleTap DeskBand\ShowBand.exe [156472 2011-12-21] ()
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-11-02] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll [202600 2012-11-02] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
Startup: C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Sabrina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
ProxyServer: proxy.lfrz.at:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad
URLSearchHook: HKLM-x32 - Default Value = {74198672-5F7D-4FE9-A611-4AC1D5A66A15}
URLSearchHook: HKLM-x32 - SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll (SimilarGroup)
URLSearchHook: HKCU - Default Value = {74198672-5F7D-4FE9-A611-4AC1D5A66A15}
URLSearchHook: HKCU - SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll (SimilarGroup)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP_deCH472
BHO: YoutubeAdblocker - {159BC49F-2CD6-4CB7-932B-1027665E58BD} - C:\Program Files (x86)\YoutubeAdblocker\_2iD.x64.dll No File
BHO: greaotssaVer - {4F72390C-3192-91EF-ECD9-D90061D298A2} - C:\Program Files (x86)\greaotssaVer\2ZKW9c.x64.dll ()
BHO: SNT - {847493A0-9B57-E1D5-FE2C-CC1B12BC46CB} - C:\Program Files (x86)\SNT\p7T2DTlA.x64.dll ()
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation)
BHO-x32: SNT - {847493A0-9B57-E1D5-FE2C-CC1B12BC46CB} - C:\Program Files (x86)\SNT\p7T2DTlA.dll ()
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation)
Toolbar: HKLM-x32 - SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll (SimilarGroup)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D5A2C57D-7554-4054-AE53-57D7A4D0B831}: [NameServer]195.186.152.33 195.186.216.33
FireFox:
========
FF ProfilePath: C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default
FF Homepage: https://www.google.ch/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YoutubeAdblocker - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\ae1p.9uu@oeydjckxxkya-.co.uk [2014-01-04]
FF Extension: SimilarWeb - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\FirefoxAddon@similarWeb.com [2013-04-12]
FF Extension: goreatsoAvver - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\x-7oyya@odukqlwm-.org [2014-01-04]
FF Extension: SNT - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\yurxzs.t@iiio-eyule.edu [2014-01-04]
FF Extension: Swisscom Quick Help - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\{6A6114A5-EEF5-45F4-BCD1-B00A7B33E04B} [2012-10-17]
FF Extension: iMacros for Firefox - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2013-11-25]
FF Extension: Firebug - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\firebug@software.joehewitt.com.xpi [2013-02-17]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\9ulbhy7c.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-20]
FF HKLM-x32\...\Firefox\Extensions: [VIP@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\
FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ []
FF HKLM-x32\...\Firefox\Extensions: [{E4D8AFFF-DA7C-412F-A976-05ED142C7806}] - C:\Program Files (x86)\Swisscom\Unlimited Data Manager\FireFox_Remote\
FF Extension: Unlimited Data Manager - C:\Program Files (x86)\Swisscom\Unlimited Data Manager\FireFox_Remote\ []
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (YTBBookMark) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\amabcieebhjofcnbdphdmfkfcdgfilgk\1.1 [2014-01-04]
CHR Extension: (YouTube) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0 [2012-02-25]
CHR Extension: (goreatsoAvver) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmnkecdffcoibofckamdddfgeohpikij\2.7 [2014-01-04]
CHR Extension: (Google Search) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0 [2012-02-25]
CHR Extension: () - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnpicgdnjfnbkibnicdnnpkkpklkjkki\2.0.0.4_0 [2013-04-12]
CHR Extension: (Speedy Shopper) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\ganlifbpkcplnldliibcbegplfmcfigp\167 [2014-01-04]
CHR Extension: (SNT) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcgmnfaeohlofnjigiimjlbjleaomlei\2.1 [2014-01-04]
CHR Extension: (YoutubeAdblocker) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfpknoifpolmopniafjdmhgpeobpcbba\1.0 [2014-01-04]
CHR Extension: (Norton Identity Protection) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0 [2012-02-25]
CHR Extension: (Gmail) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0 [2012-02-25]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-01-15]
==================== Services (Whitelisted) =================
S2 1a34a8e0; C:\Program Files (x86)\GSSvc.dll [146768 2014-01-04] ()
S2 1a34a8e0; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation)
S3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2011-08-31] (Lenovo.)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited)
R2 SesamService; C:\Program Files (x86)\Swisscom\Sesam\BIN\SecMIPService.exe [1482240 2011-05-16] (Swisscom)
R2 SwiCardDetectSvc; C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe [307568 2010-09-22] (Sierra Wireless, Inc.)
R2 UDM Service; C:\Program Files (x86)\Swisscom\Unlimited Data Manager\DashBoardS.exe [182128 2011-05-20] (Swisscom)
R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [82544 2011-06-30] (Symantec Corporation)
==================== Drivers (Whitelisted) ====================
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-25] (Samsung Electronics Co., Ltd.)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2011-02-18] (Huawei Technologies Co., Ltd.)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284008 2012-11-02] (NVIDIA Corporation)
R2 smihlp; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13840 2009-03-13] (UPEK Inc.)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [41536 2009-09-24] (Lenovo (United States) Inc.)
R3 WtSmpAdap; C:\Windows\System32\DRIVERS\wtsmpadap.sys [56688 2011-04-11] (Swisscom)
R1 WtSmpFlt; C:\Windows\System32\DRIVERS\wtsmpflt.sys [409456 2011-04-11] (Swisscom)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-12 11:07 - 2014-01-12 11:08 - 02076672 _____ (Farbar) C:\Users\Sabrina\Downloads\FRST64(1).exe
2014-01-11 13:27 - 2014-01-11 13:27 - 00000000 ____D C:\Users\Sabrina\Downloads\FRST-OlderVersion
2014-01-11 13:14 - 2014-01-11 13:14 - 00002739 _____ C:\Users\Sabrina\Desktop\JRT.txt
2014-01-11 13:07 - 2014-01-11 13:07 - 01037068 _____ (Thisisu) C:\Users\Sabrina\Downloads\JRT.exe
2014-01-11 12:57 - 2014-01-11 12:57 - 01233962 _____ C:\Users\Sabrina\Downloads\adwcleaner.exe
2014-01-11 00:14 - 2014-01-11 00:14 - 00038897 _____ C:\ComboFix.txt
2014-01-10 23:56 - 2014-01-10 23:56 - 05162489 _____ (Swearware) C:\Users\Sabrina\Downloads\ComboFix(1).exe
2014-01-10 23:55 - 2014-01-10 23:56 - 05162489 ____R (Swearware) C:\Users\Sabrina\Downloads\ComboFix.exe
2014-01-07 17:07 - 2014-01-11 13:27 - 02076160 _____ (Farbar) C:\Users\Sabrina\Downloads\FRST64.exe
2014-01-06 22:19 - 2014-01-06 22:20 - 00000093 _____ C:\Users\Sabrina\AppData\Roaming\ARCompanion.log
2014-01-05 14:51 - 2014-01-05 14:51 - 00001179 _____ C:\Users\UpdatusUser\Desktop\CH-Finance.lnk
2014-01-05 14:51 - 2014-01-05 14:51 - 00001179 _____ C:\Users\Sabrina\Desktop\CH-Finance.lnk
2014-01-05 14:51 - 2014-01-05 14:51 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amadeus Informatik
2014-01-05 14:51 - 2014-01-05 14:51 - 00000000 ____D C:\Program Files (x86)\Amadeus Informatik
2014-01-04 18:10 - 2014-01-04 18:14 - 00000000 ____D C:\Users\Sabrina\Documents\Decrypt Output
2014-01-04 18:09 - 2014-01-04 18:09 - 08098484 _____ (Epubor.com. ) C:\Users\Sabrina\Downloads\epubee.exe
2014-01-04 18:09 - 2014-01-04 18:09 - 00524384 _____ C:\Users\Sabrina\Downloads\epubee drm removal setup(1).exe
2014-01-04 18:08 - 2014-01-04 18:08 - 00524384 _____ C:\Users\Sabrina\Downloads\epubee drm removal setup.exe
2014-01-04 18:05 - 2014-01-04 18:05 - 00000000 ____D C:\ProgramData\SNT
2014-01-04 18:05 - 2014-01-04 18:05 - 00000000 ____D C:\Program Files (x86)\SNT
2014-01-04 18:04 - 2014-01-11 13:22 - 00000464 ____H C:\Windows\Tasks\GS.Enabler-S-926685765.job
2014-01-04 18:04 - 2014-01-04 18:05 - 00000000 ____D C:\ProgramData\SoftWarehouse
2014-01-04 18:04 - 2014-01-04 18:04 - 03041792 _____ C:\Program Files (x86)\GS.Enabler
2014-01-04 18:04 - 2014-01-04 18:04 - 02759168 _____ C:\Program Files (x86)\GS_x64.Enabler
2014-01-04 18:04 - 2014-01-04 18:04 - 00146768 _____ C:\Program Files (x86)\GSSvc.dll
2014-01-04 18:04 - 2014-01-04 18:04 - 00002710 _____ C:\Windows\System32\Tasks\GS.Enabler-S-926685765
2014-01-04 18:03 - 2014-01-04 18:03 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Packages
2014-01-04 18:03 - 2014-01-04 18:03 - 00000000 ____D C:\ProgramData\greaotssaVer
2014-01-04 18:03 - 2014-01-04 18:03 - 00000000 ____D C:\Program Files (x86)\greaotssaVer
2014-01-04 18:02 - 2014-01-04 18:05 - 00000000 ____D C:\ProgramData\InstallMate
2014-01-04 18:02 - 2014-01-04 18:05 - 00000000 ____D C:\ProgramData\fc124d4af23c6577
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator
2014-01-04 18:01 - 2014-01-04 18:01 - 00321512 _____ (SoftWarehouse) C:\Users\Sabrina\Downloads\tools v6.0.8.exe
2014-01-04 17:51 - 2014-01-04 17:51 - 00000000 ____D C:\Users\Sabrina\AppData\Local\calibre-cache
2014-01-04 17:50 - 2014-01-04 18:27 - 00000000 ____D C:\Users\Sabrina\Documents\Calibre-Bibliothek
2014-01-04 17:50 - 2014-01-04 18:20 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\calibre
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\Users\Sabrina\Documents\My Books
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Sony Corporation
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\Users\Sabrina\AppData\Local\kinoma
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\ProgramData\Sony Corporation
2014-01-04 17:46 - 2014-01-06 22:07 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Sony Corporation
2014-01-04 17:45 - 2014-01-04 17:47 - 54211072 _____ C:\Users\Sabrina\Downloads\calibre-1.18.0.msi
2014-01-04 17:38 - 2014-01-04 17:43 - 00000000 ____D C:\Users\Sabrina\Documents\My Kindle Content
2014-01-04 17:37 - 2014-01-04 17:38 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Amazon
2014-01-04 17:37 - 2014-01-04 17:37 - 38103832 _____ (Amazon.com) C:\Users\Sabrina\Downloads\KindleForPC-installer.exe
2014-01-04 17:34 - 2014-01-04 17:38 - 44221288 _____ (Sony Corporation ) C:\Users\Sabrina\Downloads\ReaderInstaller.exe
2014-01-02 20:28 - 2014-01-02 20:28 - 00010484 _____ C:\Users\Sabrina\Desktop\Wochenplan.xlsx
2013-12-20 14:55 - 2013-12-20 14:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-19 20:43 - 2014-01-03 11:14 - 00199492 _____ C:\Windows\SysWOW64\~.tmp
==================== One Month Modified Files and Folders =======
2014-01-12 11:08 - 2014-01-12 11:07 - 02076672 _____ (Farbar) C:\Users\Sabrina\Downloads\FRST64(1).exe
2014-01-12 11:08 - 2013-10-17 21:07 - 00023010 _____ C:\Users\Sabrina\Downloads\FRST.txt
2014-01-12 11:06 - 2012-02-25 17:46 - 00000466 _____ C:\Windows\Tasks\SystemToolsDailyTest.job
2014-01-12 11:01 - 2012-04-06 13:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-12 10:36 - 2012-02-13 07:16 - 00659842 _____ C:\Windows\system32\perfh007.dat
2014-01-12 10:36 - 2012-02-13 07:16 - 00131942 _____ C:\Windows\system32\perfc007.dat
2014-01-12 10:36 - 2009-07-14 06:13 - 01507566 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-12 10:35 - 2012-02-13 08:42 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-12 09:56 - 2012-02-13 08:42 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-12 09:56 - 2012-02-13 07:46 - 01907109 _____ C:\Windows\WindowsUpdate.log
2014-01-11 17:52 - 2012-03-22 17:39 - 00000000 ____D C:\ProgramData\UDM
2014-01-11 13:30 - 2009-07-14 05:45 - 00031296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-11 13:30 - 2009-07-14 05:45 - 00031296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-11 13:27 - 2014-01-11 13:27 - 00000000 ____D C:\Users\Sabrina\Downloads\FRST-OlderVersion
2014-01-11 13:27 - 2014-01-07 17:07 - 02076160 _____ (Farbar) C:\Users\Sabrina\Downloads\FRST64.exe
2014-01-11 13:27 - 2013-10-17 21:06 - 00000000 ____D C:\FRST
2014-01-11 13:24 - 2012-04-03 21:34 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Dropbox
2014-01-11 13:23 - 2012-04-03 21:35 - 00000000 ___RD C:\Users\Sabrina\Dropbox
2014-01-11 13:22 - 2014-01-04 18:04 - 00000464 ____H C:\Windows\Tasks\GS.Enabler-S-926685765.job
2014-01-11 13:22 - 2012-02-13 08:01 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-11 13:22 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-11 13:22 - 2009-07-14 05:51 - 00112480 _____ C:\Windows\setupact.log
2014-01-11 13:14 - 2014-01-11 13:14 - 00002739 _____ C:\Users\Sabrina\Desktop\JRT.txt
2014-01-11 13:07 - 2014-01-11 13:07 - 01037068 _____ (Thisisu) C:\Users\Sabrina\Downloads\JRT.exe
2014-01-11 13:01 - 2009-07-14 05:45 - 05259168 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-11 13:00 - 2010-11-21 04:47 - 00814144 _____ C:\Windows\PFRO.log
2014-01-11 12:59 - 2013-10-21 13:25 - 00000000 ____D C:\AdwCleaner
2014-01-11 12:57 - 2014-01-11 12:57 - 01233962 _____ C:\Users\Sabrina\Downloads\adwcleaner.exe
2014-01-11 00:15 - 2013-10-20 20:51 - 00000000 ____D C:\Qoobox
2014-01-11 00:14 - 2014-01-11 00:14 - 00038897 _____ C:\ComboFix.txt
2014-01-11 00:11 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-10 23:56 - 2014-01-10 23:56 - 05162489 _____ (Swearware) C:\Users\Sabrina\Downloads\ComboFix(1).exe
2014-01-10 23:56 - 2014-01-10 23:55 - 05162489 ____R (Swearware) C:\Users\Sabrina\Downloads\ComboFix.exe
2014-01-10 23:56 - 2012-03-06 06:54 - 00000000 ____D C:\Users\Sabrina\AppData\Local\CrashDumps
2014-01-09 21:12 - 2012-02-25 10:19 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-09 18:25 - 2012-02-25 17:47 - 00117032 _____ C:\Users\Sabrina\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-09 18:25 - 2012-02-25 17:46 - 00003506 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2014-01-09 18:25 - 2012-02-25 17:46 - 00003448 _____ C:\Windows\System32\Tasks\PCDEventLauncher
2014-01-08 07:25 - 2012-02-29 21:41 - 00000000 ____D C:\Users\Sabrina\Documents\KVL
2014-01-08 07:17 - 2012-02-25 11:07 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Adobe
2014-01-07 20:27 - 2012-02-13 08:42 - 00000000 ____D C:\Program Files\Google
2014-01-07 20:27 - 2012-02-13 08:42 - 00000000 ____D C:\Program Files (x86)\Google
2014-01-06 22:20 - 2014-01-06 22:19 - 00000093 _____ C:\Users\Sabrina\AppData\Roaming\ARCompanion.log
2014-01-06 22:20 - 2013-05-15 06:51 - 00000000 ____D C:\Program Files (x86)\Citrix
2014-01-06 22:19 - 2013-05-15 06:51 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Citrix
2014-01-06 22:19 - 2012-02-25 10:11 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Mozilla
2014-01-06 22:18 - 2012-02-25 09:57 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Google
2014-01-06 22:07 - 2014-01-04 17:46 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Sony Corporation
2014-01-06 22:05 - 2012-02-13 07:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-05 14:51 - 2014-01-05 14:51 - 00001179 _____ C:\Users\UpdatusUser\Desktop\CH-Finance.lnk
2014-01-05 14:51 - 2014-01-05 14:51 - 00001179 _____ C:\Users\Sabrina\Desktop\CH-Finance.lnk
2014-01-05 14:51 - 2014-01-05 14:51 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amadeus Informatik
2014-01-05 14:51 - 2014-01-05 14:51 - 00000000 ____D C:\Program Files (x86)\Amadeus Informatik
2014-01-05 14:47 - 2012-02-25 09:58 - 00000000 ___RD C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-04 18:27 - 2014-01-04 17:50 - 00000000 ____D C:\Users\Sabrina\Documents\Calibre-Bibliothek
2014-01-04 18:20 - 2014-01-04 17:50 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\calibre
2014-01-04 18:14 - 2014-01-04 18:10 - 00000000 ____D C:\Users\Sabrina\Documents\Decrypt Output
2014-01-04 18:09 - 2014-01-04 18:09 - 08098484 _____ (Epubor.com. ) C:\Users\Sabrina\Downloads\epubee.exe
2014-01-04 18:09 - 2014-01-04 18:09 - 00524384 _____ C:\Users\Sabrina\Downloads\epubee drm removal setup(1).exe
2014-01-04 18:08 - 2014-01-04 18:08 - 00524384 _____ C:\Users\Sabrina\Downloads\epubee drm removal setup.exe
2014-01-04 18:05 - 2014-01-04 18:05 - 00000000 ____D C:\ProgramData\SNT
2014-01-04 18:05 - 2014-01-04 18:05 - 00000000 ____D C:\Program Files (x86)\SNT
2014-01-04 18:05 - 2014-01-04 18:04 - 00000000 ____D C:\ProgramData\SoftWarehouse
2014-01-04 18:05 - 2014-01-04 18:02 - 00000000 ____D C:\ProgramData\InstallMate
2014-01-04 18:05 - 2014-01-04 18:02 - 00000000 ____D C:\ProgramData\fc124d4af23c6577
2014-01-04 18:04 - 2014-01-04 18:04 - 03041792 _____ C:\Program Files (x86)\GS.Enabler
2014-01-04 18:04 - 2014-01-04 18:04 - 02759168 _____ C:\Program Files (x86)\GS_x64.Enabler
2014-01-04 18:04 - 2014-01-04 18:04 - 00146768 _____ C:\Program Files (x86)\GSSvc.dll
2014-01-04 18:04 - 2014-01-04 18:04 - 00002710 _____ C:\Windows\System32\Tasks\GS.Enabler-S-926685765
2014-01-04 18:03 - 2014-01-04 18:03 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Packages
2014-01-04 18:03 - 2014-01-04 18:03 - 00000000 ____D C:\ProgramData\greaotssaVer
2014-01-04 18:03 - 2014-01-04 18:03 - 00000000 ____D C:\Program Files (x86)\greaotssaVer
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\HomeGroupUser$
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Gast
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo
2014-01-04 18:02 - 2014-01-04 18:02 - 00000000 ____D C:\Users\Administrator
2014-01-04 18:01 - 2014-01-04 18:01 - 00321512 _____ (SoftWarehouse) C:\Users\Sabrina\Downloads\tools v6.0.8.exe
2014-01-04 17:51 - 2014-01-04 17:51 - 00000000 ____D C:\Users\Sabrina\AppData\Local\calibre-cache
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\Users\Sabrina\Documents\My Books
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Sony Corporation
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\Users\Sabrina\AppData\Local\kinoma
2014-01-04 17:47 - 2014-01-04 17:47 - 00000000 ____D C:\ProgramData\Sony Corporation
2014-01-04 17:47 - 2014-01-04 17:45 - 54211072 _____ C:\Users\Sabrina\Downloads\calibre-1.18.0.msi
2014-01-04 17:43 - 2014-01-04 17:38 - 00000000 ____D C:\Users\Sabrina\Documents\My Kindle Content
2014-01-04 17:38 - 2014-01-04 17:37 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Amazon
2014-01-04 17:38 - 2014-01-04 17:34 - 44221288 _____ (Sony Corporation ) C:\Users\Sabrina\Downloads\ReaderInstaller.exe
2014-01-04 17:37 - 2014-01-04 17:37 - 38103832 _____ (Amazon.com) C:\Users\Sabrina\Downloads\KindleForPC-installer.exe
2014-01-03 11:14 - 2013-12-19 20:43 - 00199492 _____ C:\Windows\SysWOW64\~.tmp
2014-01-02 20:28 - 2014-01-02 20:28 - 00010484 _____ C:\Users\Sabrina\Desktop\Wochenplan.xlsx
2014-01-02 16:13 - 2012-02-25 17:46 - 00000528 _____ C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2013-12-28 15:11 - 2012-02-25 17:46 - 00004246 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2013-12-23 17:03 - 2013-12-01 20:48 - 00001040 _____ C:\Users\Sabrina\Desktop\Dropbox.lnk
2013-12-23 17:03 - 2013-12-01 20:47 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-23 13:52 - 2012-02-25 10:20 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Microsoft Help
2013-12-21 12:22 - 2012-05-22 16:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-20 14:55 - 2013-12-20 14:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 07:48 - 2013-03-11 13:57 - 00000000 ____D C:\Users\Sabrina\Documents\Heino
2013-12-18 20:49 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-18 03:03 - 2013-08-02 02:00 - 00000000 ____D C:\Windows\system32\MRT
2013-12-18 03:01 - 2012-08-29 06:47 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 12:50 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
Some content of TEMP:
====================
C:\Users\Sabrina\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-09 18:56
==================== End Of Log ============================ --- --- ---
--- --- --- |