paula1504 | 28.03.2014 12:22 | hallo schrauber... Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.03.2014
Suchlauf-Zeit: 09:31:56
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.03.28.03
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: katrin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 211657
Verstrichene Zeit: 9 Min, 47 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemku.exe, 2412, Löschen bei Neustart, [b6ed73952754a393c3a06cf64ab715eb]
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\SystemkService.exe, 2308, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8]
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\SystemkService.exe, 2388, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8]
Module: 26
PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemk.dll, Löschen bei Neustart, [158e28e0611a0d293f244022f20f33cd],
PUP.Optional.SystemK.A, C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0}\components\SystemKHlpFF27.dll, Löschen bei Neustart, [b7ec33d597e4270f78eb72f045bc1ce4],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
Registrierungsschlüssel: 13
PUP.Optional.Linkey.A, HKU\S-1-5-21-430205881-583344909-559689374-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [4b58e12780fbbc7a7011947149b9837d],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SYSTEMK\General, In Quarantäne, [eab9c04893e841f519af4c0a4cb6e11f],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SYSTEMK, In Quarantäne, [8a1931d7e39871c58841094d7f834bb5],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-5.5, In Quarantäne, [485bbd4b641744f2074a2334bc466a96],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\SettingsManagerIEHelper.DNSGuard, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\SettingsManagerIEHelper.DNSGuard.1, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKU\S-1-5-21-430205881-583344909-559689374-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{54739D49-AC03-4C57-9264-C5195596B3A1}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{93D511B5-143B-4A99-ABFC-B5B78AD0AE1B}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA760BA8-5862-4BC5-9263-4452CBC0B264}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SystemkService, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Settings Manager, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8],
Registrierungswerte: 1
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SYSTEMK|browser, ie ff cr, In Quarantäne, [8a1931d7e39871c58841094d7f834bb5]
Registrierungsdaten: 1
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~1\SETTIN~1\systemk\syskldr.dll , Gut: (), Schlecht: (C:\PROGRA~1\SETTIN~1\systemk\syskldr.dll),Ersetzt,[059e4dbbf9821b1beaa982d3f50d28d8]
Ordner: 1
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
Dateien: 14
PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemku.exe, Löschen bei Neustart, [b6ed73952754a393c3a06cf64ab715eb],
PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemk.dll, Löschen bei Neustart, [158e28e0611a0d293f244022f20f33cd],
PUP.Optional.SystemK.A, C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0}\components\SystemKHlpFF27.dll, Löschen bei Neustart, [b7ec33d597e4270f78eb72f045bc1ce4],
PUP.Optional.Softonic.A, C:\Users\katrin\Downloads\SoftonicDownloader_fuer_unity-web-player.exe, In Quarantäne, [9c0717f1ff7ce5514b29bc5b04fdc23e],
PUP.Optional.DefaultSearch.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\default-search.xml, In Quarantäne, [7a2914f473088bab8a3477df2cd69d63],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\favicon.ico, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\Helper.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\Internet Explorer Settings.exe, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr_u.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\systemkbho.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\SystemkService.exe, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\Uninstall.exe, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.022 - Bericht erstellt am 28/03/2014 um 09:44:57
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzername : katrin - KATRIN-PC
# Gestartet von : C:\Users\katrin\Downloads\adwcleaner(1).exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Windows\System32\Tasks\SpyHunter4Startup
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\SpyHunter4Startup
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA99E34A-F4CC-4CD6-9EF2-284F62004770}
Wert Gefunden : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Wert Gefunden : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Wert Gefunden : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Wert Gefunden : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Wert Gefunden : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Wert Gefunden : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86]
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v27.0 (de)
[ Datei : C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [4036 octets] - [26/01/2014 03:09:28]
AdwCleaner[R1].txt - [4253 octets] - [20/03/2014 20:53:30]
AdwCleaner[R2].txt - [1621 octets] - [28/03/2014 09:44:57]
AdwCleaner[S0].txt - [3770 octets] - [26/01/2014 03:10:58]
AdwCleaner[S1].txt - [4144 octets] - [20/03/2014 20:54:28]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1801 octets] ########## Code:
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Ultimate x86
Ran by katrin on 28.03.2014 at 10:46:48,57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\katrin\appdata\locallow\datamngr"
~~~ FireFox
Emptied folder: C:\Users\katrin\AppData\Roaming\mozilla\firefox\profiles\4ui8084u.default\minidumps [115 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.03.2014 at 10:54:01,73
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by katrin (administrator) on KATRIN-PC on 28-03-2014 12:00:19
Running from C:\Users\katrin\Downloads
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(ICQ) C:\Users\katrin\AppData\Roaming\ICQM\icq.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\klwtblfs.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7514656 2009-05-22] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-05-22] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap.dll [982232 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [NvBackend] - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [icq] - C:\Users\katrin\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-03] (ICQ)
HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x80E8E03300FDCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms}
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: default-search.net
FF SelectedSearchEngine: Google
FF Homepage: https://apps.facebook.com/forbiddengarden/?fb_source=bookmark|hxxp://www.default-search.net/?sid=476&aid=122&itype=n&ver=11471&tm=291&src=bar
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\katrin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Settings Manager - C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\Extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0} [2014-03-19]
FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-03-26]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-03-26]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-03-26]
========================== Services (Whitelisted) =================
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation)
S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X]
S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [X]
==================== Drivers (Whitelisted) ====================
R3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [278528 2011-10-24] (AVEO)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-03-26] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-03-26] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-03-26] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-03-26] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-03-26] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-03-05] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-03-28] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-03-05] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation)
S3 athr; system32\DRIVERS\athr.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-28 10:54 - 2014-03-28 10:54 - 00000857 _____ () C:\Users\katrin\Desktop\JRT.txt
2014-03-28 09:55 - 2014-03-28 09:55 - 01038974 _____ (Thisisu) C:\Users\katrin\Downloads\JRT.exe
2014-03-28 09:44 - 2014-03-28 09:44 - 01950720 _____ () C:\Users\katrin\Downloads\adwcleaner(1).exe
2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\Users\katrin\Desktop\mbam.txt
2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\mbam.txt
2014-03-28 09:21 - 2014-03-28 10:46 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-28 09:21 - 2014-03-28 09:21 - 00001056 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-28 09:21 - 2014-03-28 09:21 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-03-28 09:21 - 2014-03-05 09:26 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-28 09:21 - 2014-03-05 09:26 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-28 09:21 - 2014-03-05 09:26 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-28 09:19 - 2014-03-28 09:20 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\katrin\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-28 09:09 - 2014-03-28 09:09 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\katrin\Downloads\revosetup95(1).exe
2014-03-27 10:12 - 2014-03-28 12:00 - 00011137 _____ () C:\Users\katrin\Downloads\FRST.txt
2014-03-27 10:12 - 2014-03-27 10:13 - 00018161 _____ () C:\Users\katrin\Downloads\Addition.txt
2014-03-27 10:11 - 2014-03-28 12:00 - 00000000 ____D () C:\FRST
2014-03-27 10:10 - 2014-03-27 10:11 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe
2014-03-27 00:29 - 2014-03-27 01:07 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi
2014-03-27 00:29 - 2014-03-27 00:53 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi
2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-03-26 21:50 - 2014-03-28 11:01 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-03-26 21:50 - 2014-03-26 22:01 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-03-26 21:50 - 2014-03-26 22:01 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-03-26 21:39 - 2014-03-28 10:45 - 00001176 _____ () C:\Windows\setupact.log
2014-03-26 21:39 - 2014-03-28 09:51 - 00006496 _____ () C:\Windows\PFRO.log
2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-26 18:23 - 2014-03-26 18:31 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe
2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr
2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe
2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk
2014-03-21 19:48 - 2014-03-21 20:59 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi
2014-03-21 19:48 - 2014-03-21 20:32 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi
2014-03-21 19:47 - 2014-03-21 20:59 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi
2014-03-21 19:47 - 2014-03-21 20:52 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi
2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups
2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log
2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe
2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls#
2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono
2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono
2014-03-19 07:33 - 2014-03-28 09:34 - 00000000 ____D () C:\Program Files\Settings Manager
2014-03-19 07:33 - 2014-03-28 09:33 - 00000000 ____D () C:\ProgramData\systemk
2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe
2014-03-18 06:22 - 2014-03-26 22:06 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype
2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype
2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-18 00:03 - 2014-03-27 11:06 - 00614400 _____ () C:\Windows\system32\Image20.dat
2014-03-16 18:24 - 2014-03-16 19:04 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi
2014-03-16 18:23 - 2014-03-16 18:52 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi
2014-03-12 20:46 - 2014-03-12 22:10 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi
2014-03-12 20:45 - 2014-03-12 22:31 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi
2014-03-12 20:45 - 2014-03-12 22:27 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi
2014-03-12 20:45 - 2014-03-12 22:26 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi
2014-03-12 20:45 - 2014-03-12 21:32 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi
2014-03-12 20:44 - 2014-03-12 21:36 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi
2014-03-12 20:44 - 2014-03-12 21:21 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi
2014-03-12 20:43 - 2014-03-12 21:59 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi
2014-03-12 20:43 - 2014-03-12 21:29 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi
2014-03-12 06:55 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 06:55 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 06:55 - 2014-03-01 05:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 06:55 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 06:55 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 06:55 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 06:55 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 06:55 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 06:55 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 06:55 - 2014-03-01 04:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 06:55 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 06:55 - 2014-03-01 04:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 06:55 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 06:55 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 06:55 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 06:55 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 06:55 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 06:55 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 06:55 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 06:55 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 06:54 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 06:54 - 2014-03-01 04:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 06:54 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 06:54 - 2014-02-07 02:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 06:54 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 06:54 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 06:54 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
==================== One Month Modified Files and Folders =======
2014-03-28 12:00 - 2014-03-27 10:12 - 00011137 _____ () C:\Users\katrin\Downloads\FRST.txt
2014-03-28 12:00 - 2014-03-27 10:11 - 00000000 ____D () C:\FRST
2014-03-28 11:46 - 2013-12-20 01:16 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\Skype
2014-03-28 11:12 - 2013-12-19 22:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-28 11:01 - 2014-03-26 21:50 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-03-28 10:54 - 2014-03-28 10:54 - 00000857 _____ () C:\Users\katrin\Desktop\JRT.txt
2014-03-28 10:53 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-28 10:53 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-28 10:49 - 2013-12-19 22:16 - 01391233 _____ () C:\Windows\WindowsUpdate.log
2014-03-28 10:46 - 2014-03-28 09:21 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-28 10:45 - 2014-03-26 21:39 - 00001176 _____ () C:\Windows\setupact.log
2014-03-28 10:45 - 2013-12-19 22:44 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-28 10:45 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-28 09:55 - 2014-03-28 09:55 - 01038974 _____ (Thisisu) C:\Users\katrin\Downloads\JRT.exe
2014-03-28 09:51 - 2014-03-26 21:39 - 00006496 _____ () C:\Windows\PFRO.log
2014-03-28 09:50 - 2014-01-26 03:09 - 00000000 ____D () C:\AdwCleaner
2014-03-28 09:44 - 2014-03-28 09:44 - 01950720 _____ () C:\Users\katrin\Downloads\adwcleaner(1).exe
2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\Users\katrin\Desktop\mbam.txt
2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\mbam.txt
2014-03-28 09:34 - 2014-03-19 07:33 - 00000000 ____D () C:\Program Files\Settings Manager
2014-03-28 09:34 - 2009-07-14 03:37 - 00000000 __RSD () C:\Windows\Media
2014-03-28 09:33 - 2014-03-19 07:33 - 00000000 ____D () C:\ProgramData\systemk
2014-03-28 09:21 - 2014-03-28 09:21 - 00001056 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-28 09:21 - 2014-03-28 09:21 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-03-28 09:21 - 2014-01-26 02:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-28 09:20 - 2014-03-28 09:19 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\katrin\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-28 09:09 - 2014-03-28 09:09 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\katrin\Downloads\revosetup95(1).exe
2014-03-28 09:09 - 2014-01-26 02:08 - 00001218 _____ () C:\Users\katrin\Desktop\Revo Uninstaller.lnk
2014-03-27 11:06 - 2014-03-18 00:03 - 00614400 _____ () C:\Windows\system32\Image20.dat
2014-03-27 10:13 - 2014-03-27 10:12 - 00018161 _____ () C:\Users\katrin\Downloads\Addition.txt
2014-03-27 10:11 - 2014-03-27 10:10 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe
2014-03-27 01:07 - 2014-03-27 00:29 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi
2014-03-27 00:53 - 2014-03-27 00:29 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi
2014-03-26 22:06 - 2014-03-18 06:22 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-26 22:06 - 2013-12-20 01:16 - 00000000 ____D () C:\ProgramData\Skype
2014-03-26 22:01 - 2014-03-26 21:50 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-03-26 22:01 - 2014-03-26 21:50 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-03-26 22:01 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2014-03-26 22:01 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2014-03-26 22:01 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-26 18:31 - 2014-03-26 18:23 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe
2014-03-26 18:16 - 2014-01-26 02:26 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr
2014-03-26 18:15 - 2014-01-26 02:26 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe
2014-03-26 15:14 - 2013-12-19 22:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-26 15:14 - 2013-12-19 22:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-26 15:14 - 2013-12-19 22:21 - 00000000 ____D () C:\Users\katrin\AppData\Local\Adobe
2014-03-25 00:17 - 2013-12-20 12:20 - 00000000 ____D () C:\Users\katrin\AppData\Local\Unity
2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk
2014-03-21 20:59 - 2014-03-21 19:48 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi
2014-03-21 20:59 - 2014-03-21 19:47 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi
2014-03-21 20:52 - 2014-03-21 19:47 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi
2014-03-21 20:32 - 2014-03-21 19:48 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi
2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups
2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log
2014-03-21 01:04 - 2013-12-19 22:18 - 00000000 ____D () C:\Users\katrin\AppData\Local\VirtualStore
2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe
2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls#
2014-03-20 06:47 - 2014-01-08 02:43 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-19 09:41 - 2014-01-08 02:43 - 00001101 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-19 09:41 - 2013-12-20 00:45 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono
2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono
2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe
2014-03-19 07:24 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-03-18 21:56 - 2011-04-12 02:38 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype
2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype
2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-18 03:02 - 2013-12-19 23:35 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 03:00 - 2012-01-10 21:50 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-16 19:04 - 2014-03-16 18:24 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi
2014-03-16 18:52 - 2014-03-16 18:23 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi
2014-03-13 06:38 - 2009-07-14 05:33 - 00295816 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-12 22:31 - 2014-03-12 20:45 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi
2014-03-12 22:27 - 2014-03-12 20:45 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi
2014-03-12 22:26 - 2014-03-12 20:45 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi
2014-03-12 22:10 - 2014-03-12 20:46 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi
2014-03-12 21:59 - 2014-03-12 20:43 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi
2014-03-12 21:36 - 2014-03-12 20:44 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi
2014-03-12 21:32 - 2014-03-12 20:45 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi
2014-03-12 21:29 - 2014-03-12 20:43 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi
2014-03-12 21:21 - 2014-03-12 20:44 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi
2014-03-05 09:26 - 2014-03-28 09:21 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-03-28 09:21 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-03-28 09:21 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-01 05:30 - 2014-03-12 06:55 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 05:11 - 2014-03-12 06:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 05:10 - 2014-03-12 06:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 04:52 - 2014-03-12 06:54 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 04:51 - 2014-03-12 06:55 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 04:47 - 2014-03-12 06:55 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 04:43 - 2014-03-12 06:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 04:43 - 2014-03-12 06:55 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 04:40 - 2014-03-12 06:55 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 04:38 - 2014-03-12 06:55 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 04:38 - 2014-03-12 06:55 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 04:37 - 2014-03-12 06:55 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 04:31 - 2014-03-12 06:55 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 04:25 - 2014-03-12 06:54 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 04:16 - 2014-03-12 06:55 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 04:14 - 2014-03-12 06:55 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 04:03 - 2014-03-12 06:55 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 04:00 - 2014-03-12 06:55 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 03:57 - 2014-03-12 06:54 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 03:32 - 2014-03-12 06:55 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 03:27 - 2014-03-12 06:55 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 03:25 - 2014-03-12 06:55 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-27 11:03 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-27 03:04 - 2010-11-20 22:01 - 01593956 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-26 09:30 - 2009-07-14 05:53 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Some content of TEMP:
====================
C:\Users\katrin\AppData\Local\Temp\avgnt.exe
C:\Users\katrin\AppData\Local\Temp\Quarantine.exe
C:\Users\katrin\AppData\Local\Temp\SHSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-20 09:49
==================== End Of Log ============================ --- --- ---
--- --- ---
schönes wochenende! |