Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.01.24.06
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16476
München :: MÜNCHEN-PC [Administrator]
Schutz: Aktiviert
24.01.2014 21:28:34
mbam-log-2014-01-24 (21-28-34).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 205107
Laufzeit: 5 Minute(n), 28 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Digital Sites (PUP.Optional.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 1
C:\Users\München\AppData\Roaming\DigitalSites\UpdateProc (PUP.Optional.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 7
C:\Users\München\Downloads\rcpsetup_chip_de_chip_de.exe (PUP.Optional.RegCleanerPro) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\München\Downloads\UltimateCodec.exe (PUP.Optional.Jumpyapps) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\München\AppData\Roaming\DigitalSites\UpdateProc\UpdateTask.exe (PUP.Optional.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\München\AppData\Roaming\DigitalSites\UpdateProc\config.dat (PUP.Optional.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\München\AppData\Roaming\DigitalSites\UpdateProc\prod.dat (PUP.Optional.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\München\AppData\Roaming\DigitalSites\UpdateProc\STTL.DAT (PUP.Optional.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\München\AppData\Roaming\DigitalSites\UpdateProc\TTL.DAT (PUP.Optional.Updater) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
Ab Schritt drei mach ich morgen weiter, weil ich heute keine eventuellen mehrere Stunden mehr wach bin! Lieben Dank schonmal!
PS: War jetzt mal eineinhalb Stunden am Stück am PC und er hat sich nicht einmal runtergefahren :-) UND er ist schneller! *freu*
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=04e811121e267e439d000d22b5c7a2ef
# engine=16793
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-25 12:07:51
# local_time=2014-01-25 01:07:51 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 97986 142282862 0 0
# scanned=268029
# found=0
# cleaned=0
# scan_time=4807
Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Kaspersky Anti-Virus
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Malwarebytes Anti-Malware Version 1.75.0.1300
CCleaner
PC Cleaner
Java 7 Update 45
Java version out of Date!
Adobe Flash Player 11.9.900.170
Mozilla Firefox (26.0)
Google Chrome 31.0.1650.57
Google Chrome 31.0.1650.63
Google Chrome 32.0.1700.76
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Kaspersky Lab Kaspersky Anti-Virus 2013 avp.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2014
Ran by München (administrator) on MÜNCHEN-PC on 25-01-2014 13:23:17
Running from C:\Users\München\Downloads
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
(AVM Berlin) C:\Program Files\avmwlanstick\WLanNetService.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
(AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE
(AVM Berlin) C:\Program Files\FRITZ!DSL\StCenter.exe
(AVM Berlin) C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
() C:\Windows\System32\PSIService.exe
(TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Farbar) C:\Users\München\Downloads\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [2621440 2010-02-09] (Brother Industries, Ltd.)
HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
HKLM\...\Run: [AVMWlanClient] - C:\Program Files\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
AppInit_DLLs: C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL => File Not Found
Startup: C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Internet.lnk
ShortcutTarget: FRITZ!DSL Internet.lnk -> C:\Program Files\FRITZ!DSL\FritzDsl.exe (AVM Berlin)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.de/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - No File
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\München\AppData\Roaming\Mozilla\Firefox\Profiles\xc404q5j.default-1377376702149
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Amazon
FF SelectedSearchEngine: Google
FF Keyword.URL: hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_ff_de_display?ie=UTF8&tagbase=bds-p23&tag=bds-p23-serp-de-ff-21&tbrId=v1_abb-channel-23_daf85ab112474b8293a6184ebe2226af_39_1006_20140124_DE_ff_ab_adppi15&query=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\München\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\München\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll (Foxit Software Company)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Modul zur Link-Untersuchung - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak [2013-12-21]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-12-21]
FF HKLM\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\url_advisor@kaspersky.com [2013-04-16]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\virtual_keyboard@kaspersky.com [2013-04-16]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\content_blocker@kaspersky.com [2013-04-16]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_cr_de_display?ie=UTF8&tagbase=bds-p23&tbrId=v1_abb-channel-23_daf85ab112474b8293a6184ebe2226af_39_1006_20140124_DE_cr_sp_adppi15"
CHR DefaultSearchProvider: Amazon
CHR DefaultSearchURL: hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_cr_de_display?ie=UTF8&tagbase=bds-p23&tag=bds-p23-serp-de-cr-21&tbrId=v1_abb-channel-23_daf85ab112474b8293a6184ebe2226af_39_1006_20140124_DE_cr_ds_adppi15&query={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Users\M\u00FCnchen\AppData\Local\Google\Chrome\Application\32.0.1700.76\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\M\u00FCnchen\AppData\Local\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\M\u00FCnchen\AppData\Local\Google\Chrome\Application\32.0.1700.76\pdf.dll No File
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll (Foxit Software Company)
CHR Plugin: (Octoshape Streaming Services) - C:\Users\M\u00FCnchen\AppData\Roaming\Mozilla\plugins\npoctoshape.dll No File
CHR Plugin: (Octoshape Streaming Services) - C:\Users\M\u00FCnchen\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Users\M\u00FCnchen\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll No File
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (Auf den Amazon-Wunschzettel) - C:\Users\München\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced [2011-07-01]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\München\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2012-04-16]
CHR Extension: (Virtuelle Tastatur) - C:\Users\München\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2012-04-16]
CHR Extension: (Google Wallet) - C:\Users\München\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30]
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\ChromeExt\urladvisor.crx [2012-08-17]
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\ChromeExt\content_blocker_chrome.crx [2012-08-17]
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\ChromeExt\virtkbd.crx [2012-08-17]
CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\ChromeExt\ab.crx [2012-08-17]
CHR StartMenuInternet: Google Chrome - C:\Users\München\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor4.0; C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe [102400 2005-09-09] ()
R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.)
R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION)
R2 IGDCTRL; C:\Program Files\FRITZ!DSL\IGDCTRL.EXE [87344 2007-09-04] (AVM Berlin)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [174656 2006-11-02] ()
==================== Drivers (Whitelisted) ====================
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-01] (AVM Berlin)
R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [926080 2010-10-01] (AVM GmbH)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-12-11] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [595552 2013-10-10] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25696 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-10] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [44000 2013-06-19] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145040 2013-04-24] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MNCHEN~1\AppData\Local\Temp\catchme.sys [x]
S3 FXDrv32; \??\E:\FXDrv32.sys [x]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2013-04-24] (Kaspersky Lab ZAO)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-25 13:22 - 2014-01-25 13:23 - 01222144 _____ (Farbar) C:\Users\München\Downloads\FRST(1).exe
2014-01-25 13:18 - 2014-01-25 13:18 - 00987425 _____ C:\Users\München\Downloads\SecurityCheck.exe
2014-01-25 11:45 - 2014-01-25 11:45 - 02347384 _____ (ESET) C:\Users\München\Downloads\esetsmartinstaller_enu.exe
2014-01-24 23:07 - 2014-01-24 23:07 - 00000000 ____D C:\Windows\pss
2014-01-24 23:05 - 2014-01-24 23:05 - 00000969 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-24 23:04 - 2014-01-24 23:04 - 04721920 _____ (Piriform Ltd) C:\Users\München\Downloads\ccsetup410.exe
2014-01-24 21:27 - 2014-01-24 21:27 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-24 21:27 - 2014-01-24 21:27 - 00000000 ____D C:\Users\München\AppData\Roaming\Malwarebytes
2014-01-24 21:27 - 2014-01-24 21:27 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-24 21:27 - 2014-01-24 21:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-24 21:27 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-24 21:26 - 2014-01-24 21:26 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\München\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-24 21:24 - 2014-01-24 21:24 - 00448512 _____ (OldTimer Tools) C:\Users\München\Downloads\TFC.exe
2014-01-24 15:42 - 2014-01-24 15:42 - 00001396 _____ C:\Users\München\Desktop\JRT.txt
2014-01-24 15:38 - 2014-01-24 15:38 - 01037068 _____ (Thisisu) C:\Users\München\Downloads\JRT.exe
2014-01-24 15:38 - 2014-01-24 15:38 - 00000000 ____D C:\Windows\ERUNT
2014-01-24 15:28 - 2014-01-24 15:33 - 00000000 ____D C:\AdwCleaner
2014-01-24 15:28 - 2014-01-24 15:28 - 01236282 _____ C:\Users\München\Downloads\adwcleaner.exe
2014-01-24 15:23 - 2014-01-24 15:23 - 00000079 _____ C:\Windows\wininit.ini
2014-01-24 10:05 - 2014-01-24 15:24 - 00000000 ____D C:\Program Files\Amazon
2014-01-24 10:00 - 2014-01-24 10:00 - 00024060 _____ C:\Users\München\Downloads\Addition.txt
2014-01-24 09:59 - 2014-01-25 13:23 - 00016989 _____ C:\Users\München\Downloads\FRST.txt
2014-01-24 09:59 - 2014-01-24 09:59 - 01222144 _____ (Farbar) C:\Users\München\Downloads\FRST.exe
2014-01-24 09:59 - 2014-01-24 09:59 - 00000000 ____D C:\FRST
2014-01-24 09:57 - 2014-01-25 12:57 - 00000302 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-24 09:56 - 2014-01-24 09:56 - 00686264 _____ C:\Users\München\Downloads\ZipOpenerSetup.exe
2014-01-21 15:20 - 2014-01-21 15:20 - 00388608 _____ (Trend Micro Inc.) C:\Users\München\Downloads\HiJackThis204.exe
2014-01-20 10:43 - 2014-01-20 10:27 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.20140120-104317.backup
2014-01-20 10:35 - 2014-01-24 15:34 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2014-01-20 10:35 - 2014-01-24 15:23 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2014-01-20 10:34 - 2014-01-20 10:34 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\München\Downloads\spybot-2.2.25.exe
2014-01-20 10:31 - 2014-01-20 10:31 - 00018977 _____ C:\ComboFix.txt
2014-01-20 10:19 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-20 10:19 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-20 10:19 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-20 10:19 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-20 10:19 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-20 10:19 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-20 10:19 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-20 10:19 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-20 10:17 - 2014-01-20 10:31 - 00000000 ____D C:\Qoobox
2014-01-20 10:16 - 2014-01-20 10:30 - 00000000 ____D C:\Windows\erdnt
2014-01-20 10:16 - 2014-01-20 10:16 - 05167985 ____R (Swearware) C:\Users\München\Downloads\ComboFix.exe
2014-01-20 10:15 - 2014-01-21 15:21 - 00007733 _____ C:\Users\München\Downloads\hijackthis.log
2014-01-20 10:12 - 2014-01-20 10:14 - 00388608 _____ (Trend Micro Inc.) C:\Users\München\Downloads\hijackthis_5833.exe
2014-01-19 17:37 - 2014-01-19 17:37 - 00001373 _____ C:\Users\München\Desktop\DeleteFIX Photo.lnk
2014-01-19 17:37 - 2014-01-19 17:37 - 00000000 ____D C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DeleteFIX Photo
2014-01-19 17:37 - 2014-01-19 17:37 - 00000000 ____D C:\Users\München\AppData\Local\Cimaware
2014-01-19 17:32 - 2014-01-24 15:09 - 00000000 ____D C:\Program Files\Systweak Support Dock
2014-01-19 17:32 - 2014-01-24 10:05 - 00000000 ____D C:\Program Files\PC Cleaner
2014-01-19 17:21 - 2014-01-19 17:21 - 00614784 _____ C:\Users\München\Downloads\deletefix-photo-2-03.exe
2014-01-19 17:14 - 2014-01-19 17:14 - 00000000 ____D C:\Users\München\AppData\Roaming\DivX
2014-01-19 17:13 - 2014-01-20 09:46 - 00000000 ____D C:\Program Files\Common Files\DivX Shared
2014-01-19 17:13 - 2014-01-19 17:39 - 00000804 _____ C:\Users\München\daemonprocess.txt
2014-01-19 17:13 - 2014-01-19 17:13 - 00000000 ____D C:\Users\München\AppData\Local\cache
2014-01-19 17:13 - 2014-01-19 17:13 - 00000000 ____D C:\Users\München\.android
2014-01-19 17:11 - 2014-01-24 10:27 - 00000146 _____ C:\Users\München\AppData\Roaming\WB.CFG
2014-01-19 17:11 - 2014-01-24 10:27 - 00000005 _____ C:\Users\München\AppData\Roaming\WBPU-TTL.DAT
2014-01-19 17:11 - 2014-01-20 09:47 - 00000000 ____D C:\Program Files\DivX
2014-01-19 17:11 - 2014-01-20 09:46 - 00000000 ____D C:\ProgramData\DivX
2014-01-19 17:11 - 2014-01-20 09:45 - 00000000 ____D C:\Program Files\DSP-worx
2014-01-19 17:11 - 2014-01-20 09:45 - 00000000 ____D C:\Program Files\DirectVobSub
2014-01-19 17:11 - 2014-01-20 09:43 - 00000000 ____D C:\Program Files\OpenSource Flash Video Splitter
2014-01-19 17:11 - 2014-01-20 09:43 - 00000000 ____D C:\Program Files\Lame For Audacity
2014-01-19 17:11 - 2014-01-19 17:11 - 00000000 ____D C:\Users\München\AppData\Roaming\LavFilters
2014-01-19 17:11 - 2014-01-19 17:11 - 00000000 ____D C:\Users\München\AppData\Roaming\CDXReader
2014-01-19 17:11 - 2014-01-19 17:11 - 00000000 ____D C:\Program Files\ffdshow
2014-01-19 17:11 - 2012-02-26 16:47 - 00079360 _____ C:\Windows\system32\ff_vfw.dll
2014-01-19 17:10 - 2014-01-24 21:34 - 00000000 ____D C:\Users\München\AppData\Roaming\DigitalSites
2014-01-19 17:08 - 2014-01-19 17:08 - 00001799 _____ C:\Users\Public\Desktop\Recuva.lnk
2014-01-19 17:08 - 2014-01-19 17:08 - 00000000 ____D C:\Program Files\Recuva
2014-01-19 17:08 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-19 17:08 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-19 17:08 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-19 17:08 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-19 17:08 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-19 17:08 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-19 17:08 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-19 17:08 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-19 17:08 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-19 17:06 - 2014-01-19 17:06 - 03992416 _____ (Piriform Ltd) C:\Users\München\Downloads\rcsetup149.exe
2014-01-11 20:09 - 2014-01-11 20:09 - 00000000 ____D C:\Users\München\Documents\TomTom
2014-01-11 20:09 - 2014-01-11 20:09 - 00000000 ____D C:\ProgramData\TomTom
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Users\München\AppData\Roaming\TomTom
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Users\München\AppData\Local\TomTom
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Program Files\TomTom International B.V
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Program Files\TomTom HOME 2
2014-01-11 20:07 - 2014-01-11 20:07 - 00000000 ____D C:\Program Files\TomTom DesktopSuite
2014-01-08 17:06 - 2014-01-08 17:06 - 00000000 ____D C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\system32\GPhotos.scr
2014-01-02 21:21 - 2014-01-24 21:39 - 00000000 ___RD C:\Users\München\Dropbox
2014-01-02 21:21 - 2014-01-19 17:27 - 00001025 _____ C:\Users\München\Desktop\Dropbox.lnk
2014-01-02 21:19 - 2014-01-19 17:27 - 00000000 ____D C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-02 21:18 - 2014-01-24 21:39 - 00000000 ____D C:\Users\München\AppData\Roaming\Dropbox
2014-01-02 21:17 - 2014-01-02 21:18 - 36293880 _____ (Dropbox, Inc.) C:\Users\München\Downloads\Dropbox 2.4.10.exe
==================== One Month Modified Files and Folders =======
2014-01-25 13:23 - 2014-01-25 13:22 - 01222144 _____ (Farbar) C:\Users\München\Downloads\FRST(1).exe
2014-01-25 13:23 - 2014-01-24 09:59 - 00016989 _____ C:\Users\München\Downloads\FRST.txt
2014-01-25 13:18 - 2014-01-25 13:18 - 00987425 _____ C:\Users\München\Downloads\SecurityCheck.exe
2014-01-25 13:11 - 2013-07-15 08:46 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-25 13:04 - 2012-04-14 20:26 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-25 12:57 - 2014-01-24 09:57 - 00000302 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-25 12:43 - 2010-05-13 11:14 - 02030924 _____ C:\Windows\WindowsUpdate.log
2014-01-25 11:54 - 2010-05-17 15:25 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2014-01-25 11:45 - 2014-01-25 11:45 - 02347384 _____ (ESET) C:\Users\München\Downloads\esetsmartinstaller_enu.exe
2014-01-25 11:45 - 2010-05-13 11:26 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-25 11:45 - 2009-07-14 05:34 - 00017088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-25 11:45 - 2009-07-14 05:34 - 00017088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-25 11:38 - 2013-07-15 08:46 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-25 11:38 - 2013-06-02 10:03 - 00010812 _____ C:\Windows\setupact.log
2014-01-25 11:38 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-24 23:07 - 2014-01-24 23:07 - 00000000 ____D C:\Windows\pss
2014-01-24 23:05 - 2014-01-24 23:05 - 00000969 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-24 23:05 - 2013-01-04 23:09 - 00000000 ____D C:\Program Files\CCleaner
2014-01-24 23:04 - 2014-01-24 23:04 - 04721920 _____ (Piriform Ltd) C:\Users\München\Downloads\ccsetup410.exe
2014-01-24 22:14 - 2010-05-18 09:23 - 00002453 _____ C:\Users\Public\Desktop\FRITZ!DSL Startcenter.lnk
2014-01-24 21:39 - 2014-01-02 21:21 - 00000000 ___RD C:\Users\München\Dropbox
2014-01-24 21:39 - 2014-01-02 21:18 - 00000000 ____D C:\Users\München\AppData\Roaming\Dropbox
2014-01-24 21:38 - 2013-06-02 10:03 - 00014888 _____ C:\Windows\PFRO.log
2014-01-24 21:34 - 2014-01-19 17:10 - 00000000 ____D C:\Users\München\AppData\Roaming\DigitalSites
2014-01-24 21:27 - 2014-01-24 21:27 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-24 21:27 - 2014-01-24 21:27 - 00000000 ____D C:\Users\München\AppData\Roaming\Malwarebytes
2014-01-24 21:27 - 2014-01-24 21:27 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-24 21:27 - 2014-01-24 21:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-24 21:26 - 2014-01-24 21:26 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\München\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-24 21:24 - 2014-01-24 21:24 - 00448512 _____ (OldTimer Tools) C:\Users\München\Downloads\TFC.exe
2014-01-24 15:42 - 2014-01-24 15:42 - 00001396 _____ C:\Users\München\Desktop\JRT.txt
2014-01-24 15:38 - 2014-01-24 15:38 - 01037068 _____ (Thisisu) C:\Users\München\Downloads\JRT.exe
2014-01-24 15:38 - 2014-01-24 15:38 - 00000000 ____D C:\Windows\ERUNT
2014-01-24 15:34 - 2014-01-20 10:35 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2014-01-24 15:33 - 2014-01-24 15:28 - 00000000 ____D C:\AdwCleaner
2014-01-24 15:33 - 2013-01-04 22:50 - 00000000 ____D C:\Users\München\AppData\Roaming\Uniblue
2014-01-24 15:28 - 2014-01-24 15:28 - 01236282 _____ C:\Users\München\Downloads\adwcleaner.exe
2014-01-24 15:24 - 2014-01-24 10:05 - 00000000 ____D C:\Program Files\Amazon
2014-01-24 15:23 - 2014-01-24 15:23 - 00000079 _____ C:\Windows\wininit.ini
2014-01-24 15:23 - 2014-01-20 10:35 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2014-01-24 15:09 - 2014-01-19 17:32 - 00000000 ____D C:\Program Files\Systweak Support Dock
2014-01-24 10:27 - 2014-01-19 17:11 - 00000146 _____ C:\Users\München\AppData\Roaming\WB.CFG
2014-01-24 10:27 - 2014-01-19 17:11 - 00000005 _____ C:\Users\München\AppData\Roaming\WBPU-TTL.DAT
2014-01-24 10:05 - 2014-01-19 17:32 - 00000000 ____D C:\Program Files\PC Cleaner
2014-01-24 10:00 - 2014-01-24 10:00 - 00024060 _____ C:\Users\München\Downloads\Addition.txt
2014-01-24 09:59 - 2014-01-24 09:59 - 01222144 _____ (Farbar) C:\Users\München\Downloads\FRST.exe
2014-01-24 09:59 - 2014-01-24 09:59 - 00000000 ____D C:\FRST
2014-01-24 09:56 - 2014-01-24 09:56 - 00686264 _____ C:\Users\München\Downloads\ZipOpenerSetup.exe
2014-01-21 15:21 - 2014-01-20 10:15 - 00007733 _____ C:\Users\München\Downloads\hijackthis.log
2014-01-21 15:20 - 2014-01-21 15:20 - 00388608 _____ (Trend Micro Inc.) C:\Users\München\Downloads\HiJackThis204.exe
2014-01-20 10:34 - 2014-01-20 10:34 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\München\Downloads\spybot-2.2.25.exe
2014-01-20 10:31 - 2014-01-20 10:31 - 00018977 _____ C:\ComboFix.txt
2014-01-20 10:31 - 2014-01-20 10:17 - 00000000 ____D C:\Qoobox
2014-01-20 10:31 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default
2014-01-20 10:31 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2014-01-20 10:30 - 2014-01-20 10:16 - 00000000 ____D C:\Windows\erdnt
2014-01-20 10:27 - 2014-01-20 10:43 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.20140120-104317.backup
2014-01-20 10:27 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2014-01-20 10:25 - 2013-01-04 22:50 - 00000000 ____D C:\Program Files\Uniblue
2014-01-20 10:16 - 2014-01-20 10:16 - 05167985 ____R (Swearware) C:\Users\München\Downloads\ComboFix.exe
2014-01-20 10:14 - 2014-01-20 10:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\München\Downloads\hijackthis_5833.exe
2014-01-20 09:48 - 2009-07-14 05:33 - 00494736 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-20 09:47 - 2014-01-19 17:11 - 00000000 ____D C:\Program Files\DivX
2014-01-20 09:46 - 2014-01-19 17:13 - 00000000 ____D C:\Program Files\Common Files\DivX Shared
2014-01-20 09:46 - 2014-01-19 17:11 - 00000000 ____D C:\ProgramData\DivX
2014-01-20 09:45 - 2014-01-19 17:11 - 00000000 ____D C:\Program Files\DSP-worx
2014-01-20 09:45 - 2014-01-19 17:11 - 00000000 ____D C:\Program Files\DirectVobSub
2014-01-20 09:45 - 2013-08-15 21:43 - 00000000 ____D C:\Windows\system32\MRT
2014-01-20 09:43 - 2014-01-19 17:11 - 00000000 ____D C:\Program Files\OpenSource Flash Video Splitter
2014-01-20 09:43 - 2014-01-19 17:11 - 00000000 ____D C:\Program Files\Lame For Audacity
2014-01-20 09:43 - 2010-05-18 09:26 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-19 17:39 - 2014-01-19 17:13 - 00000804 _____ C:\Users\München\daemonprocess.txt
2014-01-19 17:37 - 2014-01-19 17:37 - 00001373 _____ C:\Users\München\Desktop\DeleteFIX Photo.lnk
2014-01-19 17:37 - 2014-01-19 17:37 - 00000000 ____D C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DeleteFIX Photo
2014-01-19 17:37 - 2014-01-19 17:37 - 00000000 ____D C:\Users\München\AppData\Local\Cimaware
2014-01-19 17:30 - 2010-05-13 12:27 - 00000000 ____D C:\Program Files\Common Files\Adobe
2014-01-19 17:27 - 2014-01-02 21:21 - 00001025 _____ C:\Users\München\Desktop\Dropbox.lnk
2014-01-19 17:27 - 2014-01-02 21:19 - 00000000 ____D C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-19 17:21 - 2014-01-19 17:21 - 00614784 _____ C:\Users\München\Downloads\deletefix-photo-2-03.exe
2014-01-19 17:21 - 2010-05-13 11:35 - 00110248 _____ C:\Users\München\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-19 17:14 - 2014-01-19 17:14 - 00000000 ____D C:\Users\München\AppData\Roaming\DivX
2014-01-19 17:13 - 2014-01-19 17:13 - 00000000 ____D C:\Users\München\AppData\Local\cache
2014-01-19 17:13 - 2014-01-19 17:13 - 00000000 ____D C:\Users\München\.android
2014-01-19 17:11 - 2014-01-19 17:11 - 00000000 ____D C:\Users\München\AppData\Roaming\LavFilters
2014-01-19 17:11 - 2014-01-19 17:11 - 00000000 ____D C:\Users\München\AppData\Roaming\CDXReader
2014-01-19 17:11 - 2014-01-19 17:11 - 00000000 ____D C:\Program Files\ffdshow
2014-01-19 17:08 - 2014-01-19 17:08 - 00001799 _____ C:\Users\Public\Desktop\Recuva.lnk
2014-01-19 17:08 - 2014-01-19 17:08 - 00000000 ____D C:\Program Files\Recuva
2014-01-19 17:06 - 2014-01-19 17:06 - 03992416 _____ (Piriform Ltd) C:\Users\München\Downloads\rcsetup149.exe
2014-01-19 17:01 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\wfp
2014-01-19 17:00 - 2013-07-14 20:22 - 00000000 ____D C:\Program Files\QuickTime
2014-01-19 17:00 - 2010-08-05 11:39 - 00000000 ____D C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-01-19 17:00 - 2010-05-13 11:27 - 00000000 ____D C:\Users\München\AppData\Roaming\GHISLER
2014-01-19 17:00 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\registration
2014-01-11 20:09 - 2014-01-11 20:09 - 00000000 ____D C:\Users\München\Documents\TomTom
2014-01-11 20:09 - 2014-01-11 20:09 - 00000000 ____D C:\ProgramData\TomTom
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Users\München\AppData\Roaming\TomTom
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Users\München\AppData\Local\TomTom
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Program Files\TomTom International B.V
2014-01-11 20:08 - 2014-01-11 20:08 - 00000000 ____D C:\Program Files\TomTom HOME 2
2014-01-11 20:07 - 2014-01-11 20:07 - 00000000 ____D C:\Program Files\TomTom DesktopSuite
2014-01-08 17:06 - 2014-01-08 17:06 - 00000000 ____D C:\Users\München\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\system32\GPhotos.scr
2014-01-02 21:18 - 2014-01-02 21:17 - 36293880 _____ (Dropbox, Inc.) C:\Users\München\Downloads\Dropbox 2.4.10.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-20 15:43
==================== End Of Log ============================
--- --- ---
--- --- ---