Hi,
ja, sorry, weiß auch nicht was da passiert ist :-( Bin ja eigentlich schon sehr vorsichtig mit wo ich rauf klicke.
Also hier die Log Files:
FixLog Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by andreas at 2014-04-03 11:09:52 Run:1
Running from C:\Users\andreas\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:13828
*****************
C:\windows\system32\GroupPolicy\Machine => Moved successfully.
C:\windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully.
The system needed a reboot.
==== End of Fixlog ==== Malewarebytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.04.2014
Suchlauf-Zeit: 12:18:08
Logdatei: mbam neu.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.03.02
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: andreas
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 315679
Verstrichene Zeit: 39 Min, 35 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\RadsteroidsService.exe, 1048, Löschen bei Neustart, [5fa13ec26c94b7494661c7929869de22]
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\Radsteroids.exe, 3316, Löschen bei Neustart, [43bda35d27d924dc46615efb0af7ab55]
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable158.exe, 3732, Löschen bei Neustart, [ea16b8486a96877931120654729027d9]
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable_wd.exe, 4032, Löschen bei Neustart, [ea16b8486a96877931120654729027d9]
Module: 1
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable158.dll, Löschen bei Neustart, [ea16b8486a96877931120654729027d9],
Registrierungsschlüssel: 11
PUP.Optional.Radsteroids.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Radsteroids, In Quarantäne, [5fa13ec26c94b7494661c7929869de22],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [0bf516ea16ea649c9b998488ea1848b8],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [0bf516ea16ea649c9b998488ea1848b8],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [26daea16a25e936d8b77f61613ef34cc],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [26daea16a25e936d8b77f61613ef34cc],
PUP.Optional.Iminent.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinkHandler, In Quarantäne, [9769c7397f81916fac380d5f1ae803fd],
PUP.Optional.ReMarkable.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Re_Markable, Löschen bei Neustart, [8d730df3b9474eb243f593cbf01229d7],
PUP.Optional.ReMarkable.A, HKU\S-1-5-21-522234228-4192544273-3428825822-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Re_Markable, Löschen bei Neustart, [7987ee12946c709058e0ca9434ceb34d],
PUP.Optional.Radsteroids.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Radsteroids, In Quarantäne, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.ReMarkable.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Re-Markable, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\efbeffb6-b24d-4c4f-8cc2-06b93e00c194, In Quarantäne, [ea16b8486a96877931120654729027d9],
Registrierungswerte: 1
PUM.Bad.Proxy, HKU\S-1-5-21-522234228-4192544273-3428825822-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:13828, Löschen bei Neustart, [659bf010a55b827e9294831847bc06fa]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 3
PUP.Optional.Radsteroids.A, C:\Users\andreas\AppData\Local\Radsteroids, In Quarantäne, [5ca40ef218e8ef11ce0c95c2aa583dc3],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids, Löschen bei Neustart, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp, Löschen bei Neustart, [ea16b8486a96877931120654729027d9],
Dateien: 23
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\RadsteroidsService.exe, Löschen bei Neustart, [5fa13ec26c94b7494661c7929869de22],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\Radsteroids.exe, Löschen bei Neustart, [43bda35d27d924dc46615efb0af7ab55],
PUP.Optional.ReMarkable.A, C:\Windows\Tasks\Re-Markable Update.job, In Quarantäne, [28d86a96e02033cd89ac91cd6f938f71],
PUP.Optional.Radsteroids.A, C:\Users\andreas\AppData\Local\Radsteroids\data2.dat, In Quarantäne, [5ca40ef218e8ef11ce0c95c2aa583dc3],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\app.dat, In Quarantäne, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\data.dat, In Quarantäne, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\Radsteroids.exe.config, In Quarantäne, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\Radsteroids.ico, In Quarantäne, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\RadsteroidsService.exe.config, In Quarantäne, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.Radsteroids.A, C:\ProgramData\Radsteroids\Uninstall.exe, In Quarantäne, [c53b9a669967619fa13a4710ac56f010],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\158.crx, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\158.dat, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\158.xpi, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\a.db, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\b.db, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable158.bin, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable158.dll, Löschen bei Neustart, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable158.exe, Löschen bei Neustart, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable158.ini, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Re-Markable_wd.exe, Löschen bei Neustart, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\ReMar.exe, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Sqlite3.dll, In Quarantäne, [ea16b8486a96877931120654729027d9],
PUP.Optional.ReMarkable.A, C:\Program Files (x86)\Re-Markable Corp\Uninstall.exe, In Quarantäne, [ea16b8486a96877931120654729027d9],
Physische Sektoren: 0
(No malicious items detected)
(end) AdwareCleaner
AdwCleaner Logfile: Code:
# AdwCleaner v3.023 - Report created 03/04/2014 at 12:36:51
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : andreas - ANDREAS-PC
# Running from : C:\Users\andreas\Desktop\adwcleaner (1).exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdfidgapfiokiphmcjpmmjbdndepoja
File Deleted : C:\windows\Tasks\Re-Markable_wd.job
File Deleted : C:\windows\System32\Tasks\Re-Markable_wd
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Starfield Updater]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v27.0.1 (de)
[ File : C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\f3er6lil.default\prefs.js ]
-\\ Google Chrome v33.0.1750.154
[ File : C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [9050 octets] - [30/03/2014 18:05:21]
AdwCleaner[R1].txt - [4403 octets] - [31/03/2014 13:14:46]
AdwCleaner[R2].txt - [1465 octets] - [03/04/2014 12:33:05]
AdwCleaner[S0].txt - [8797 octets] - [30/03/2014 18:12:26]
AdwCleaner[S1].txt - [4513 octets] - [31/03/2014 13:18:37]
AdwCleaner[S2].txt - [1394 octets] - [03/04/2014 12:36:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1454 octets] ########## --- --- ---
[/CODE]
AdwCleaner Logfile: Code:
# AdwCleaner v3.023 - Report created 03/04/2014 at 12:33:05
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : andreas - ANDREAS-PC
# Running from : C:\Users\andreas\Desktop\adwcleaner (1).exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\windows\System32\Tasks\Re-Markable_wd
File Found : C:\windows\Tasks\Re-Markable_wd.job
Folder Found : C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdfidgapfiokiphmcjpmmjbdndepoja
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Starfield Updater]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v27.0.1 (de)
[ File : C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\f3er6lil.default\prefs.js ]
-\\ Google Chrome v33.0.1750.154
[ File : C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [9050 octets] - [30/03/2014 18:05:21]
AdwCleaner[R1].txt - [4403 octets] - [31/03/2014 13:14:46]
AdwCleaner[R2].txt - [1205 octets] - [03/04/2014 12:33:05]
AdwCleaner[S0].txt - [8797 octets] - [30/03/2014 18:12:26]
AdwCleaner[S1].txt - [4513 octets] - [31/03/2014 13:18:37]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1385 octets] ########## --- --- ---
[/CODE]
JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by andreas on 03.04.2014 at 12:59:33,65
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.04.2014 at 13:07:16,43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und ein frisches FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by andreas (administrator) on ANDREAS-PC on 03-04-2014 13:12:05
Running from C:\Users\andreas\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\windows\SysWOW64\svchost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Starfield Technologies) C:\Program Files (x86)\Workspace\offSyncService.exe
() C:\windows\SysWOW64\Rezip.exe
(SafeNet, Inc.) C:\Program Files\SafeNet\Authentication\SAC\x64\SACSrv.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Akamai Technologies, Inc.) C:\Users\andreas\AppData\Local\Akamai\netsession_win.exe
(Starfield Technologies) C:\Users\andreas\AppData\Local\Workspace\workspacestatus.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Starfield Technologies) C:\Users\andreas\AppData\Local\Workspace\workspaceupdate.exe
(Dropbox, Inc.) C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Akamai Technologies, Inc.) C:\Users\andreas\AppData\Local\Akamai\netsession_win.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2074408 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [NvCplDaemon] - C:\windows\system32\NvCpl.dll [16413288 2010-02-10] (NVIDIA Corporation)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [RemoteControl8] - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [198032 2011-10-21] (Lavasoft)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [X]
HKU\S-1-5-21-522234228-4192544273-3428825822-1001\...\Run: [Akamai NetSession Interface] - C:\Users\andreas\AppData\Local\Akamai\netsession_win.exe [4672920 2014-03-06] (Akamai Technologies, Inc.)
HKU\S-1-5-21-522234228-4192544273-3428825822-1001\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-06] (Google Inc.)
HKU\S-1-5-21-522234228-4192544273-3428825822-1001\...\Run: [Workspace Status] - C:\Users\andreas\AppData\Local\Workspace\workspacestatus.exe [694760 2013-07-26] (Starfield Technologies)
HKU\S-1-5-21-522234228-4192544273-3428825822-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-522234228-4192544273-3428825822-1001\...\Run: [Starfield Updater] - C:\Users\andreas\AppData\Local\Workspace\workspaceupdate.exe [35008 2013-05-26] (Starfield Technologies)
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {92C33D4D-06C3-49C7-9BDC-3A342E3899AD} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKCU - {AD20EAA2-12B9-46B5-BBB3-32A3A31661D2} URL = hxxp://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKCU - {F3EC1F04-D859-491B-921C-C994A33669CD} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=goughGA&Lan=de&q={searchTerms}&gu=386d05aab96640798e6ea6ac9f50f5fc&tu=10GXz00Au1C01g0&sku=&tstsId=&ver=&&r=334
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{011E7012-FCC3-417B-B375-8A252ADD8B30}: [NameServer]193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{708DB8B2-E39B-4BEE-842B-07EC99E3E497}: [NameServer]193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{8B8CA7B7-057C-43EE-9A22-091EB0577D86}: [NameServer]193.189.244.206 193.189.244.225
FireFox:
========
FF ProfilePath: C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\f3er6lil.default
FF Homepage: hxxp://yahoo.de/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @starfield.com/off - C:\Users\andreas\AppData\Roaming\Mozilla\Plugins\npoff.dll ( Starfield Technologies, LLC.)
FF Plugin HKCU: @starfield.com/off64 - C:\Users\andreas\AppData\Roaming\Mozilla\Plugins\npoff64.dll ( Starfield Technologies, LLC.)
FF Plugin HKCU: @starfield.com/wbe - C:\Users\andreas\AppData\Roaming\Mozilla\Plugins\npwbe.dll (Starfield Technology, LLC)
FF Plugin HKCU: @starfield.com/wbe64 - C:\Users\andreas\AppData\Roaming\Mozilla\Plugins\npwbe64.dll (Starfield Technology, LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npoff.dll ( Starfield Technologies, LLC.)
FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npoff64.dll ( Starfield Technologies, LLC.)
FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npwbe.dll (Starfield Technology, LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npwbe64.dll (Starfield Technology, LLC)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: WBE Paste - C:\Users\andreas\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\wbepaste@starfield [2013-05-26]
FF Extension: Workspace Email Zoom - C:\Users\andreas\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\zoomext@starfield [2013-05-26]
FF Extension: Bluhell Firewall - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\f3er6lil.default\Extensions\{6BB5760D-F97E-421B-AF5B-8457A90C3CED}.xpi [2013-12-15]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru [2014-02-28]
FF Extension: Anti-Banner - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak [2014-02-28]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2014-02-28]
FF Extension: Modul zur Link-Untersuchung - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak [2014-02-28]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-03]
FF HKLM-x32\...\Firefox\Extensions: [{000a9d1c-beef-4f90-9363-039d445309b8}] - C:\Program Files (x86)\Google\Google Gears\Firefox\
FF Extension: Google Gears - C:\Program Files (x86)\Google\Google Gears\Firefox\ []
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF HKCU\...\Firefox\Extensions: [{36ee80e3-92ec-4efb-b105-85435187eb87}] - C:\Program Files (x86)\Re-Markable Corp\158.xpi
Chrome:
=======
CHR DefaultSearchURL: hxxp://www.google.de/search?hl=de&source=hp&q={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-13]
CHR Extension: (Google Drive) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-13]
CHR Extension: (YouTube) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-13]
CHR Extension: (Google Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-13]
CHR Extension: (Re-Markable) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdfidgapfiokiphmcjpmmjbdndepoja [2014-03-31]
CHR Extension: (Bflix extension) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp [2014-03-04]
CHR Extension: (Skype Click to Call) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-03-04]
CHR Extension: (Google Wallet) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Gmail) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-13]
CHR HKLM-x32\...\Chrome\Extension: [jlfihafpijfdgmojeeigcldgchhojpfp] - C:\Program Files (x86)\BFlix\BFlix.crx [2011-12-19]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]
==================== Services (Whitelisted) =================
R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-20] (Avira Operations GmbH & Co. KG)
S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [77944 2011-03-08] (Autodesk)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 File Backup; C:\Program Files (x86)\Workspace\offSyncService.exe [1187040 2013-07-22] (Starfield Technologies)
R2 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] ()
R2 SACSrv; C:\Program Files\SafeNet\Authentication\SAC\x64\SACSrv.exe [10712 2011-10-02] (SafeNet, Inc.)
S4 mcmscsvc; C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe [X]
S4 McNASvc; "c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe" [X]
S4 McProxy; c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe [X]
S4 MpfService; "C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe" [X]
S2 MSK80Service; "C:\Program Files (x86)\McAfee\MSK\MskSrver.exe" [X]
==================== Drivers (Whitelisted) ====================
R3 AKSIFDH; C:\Windows\System32\DRIVERS\aksifdh.sys [62632 2008-07-30] (Aladdin Knowledge Systems, Ltd.)
S3 AKSUP; C:\Windows\System32\drivers\aksup.sys [44712 2008-07-30] (Aladdin Knowledge Systems, Ltd.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-09] (Avira Operations GmbH & Co. KG)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R3 iKeyEnum; C:\Windows\System32\DRIVERS\ikeyenum.sys [16160 2010-07-08] (SafeNet, Inc.)
R3 iKeyIFD; C:\Windows\System32\DRIVERS\ikeyifd.sys [22304 2010-07-08] (SafeNet, Inc.)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [89944 2013-02-21] (Kaspersky Lab)
S4 MPFP; C:\Windows\System32\Drivers\Mpfp.sys [176144 2010-07-15] (McAfee, Inc.)
U5 RnbToken; C:\Windows\System32\Drivers\RnbToken.sys [24352 2010-07-08] (SafeNet, Inc.)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-11-05] (Windows (R) 2003 DDK 3790 provider)
S4 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-03 13:07 - 2014-04-03 13:07 - 00000627 _____ () C:\Users\andreas\Desktop\JRT.txt
2014-04-03 12:32 - 2014-04-03 12:32 - 01426178 _____ () C:\Users\andreas\Downloads\adwcleaner (1).exe
2014-04-03 12:32 - 2014-04-03 12:32 - 01426178 _____ () C:\Users\andreas\Desktop\adwcleaner (1).exe
2014-04-03 12:30 - 2014-04-03 12:30 - 00007128 _____ () C:\Users\andreas\Desktop\mbam neu.txt
2014-04-03 11:21 - 2014-04-03 11:28 - 00001264 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk
2014-04-03 11:21 - 2014-04-03 11:28 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-03 11:21 - 2014-04-03 11:18 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Desktop\revosetup95.exe
2014-04-03 11:18 - 2014-04-03 11:18 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe
2014-04-02 14:43 - 2014-04-02 14:44 - 00035940 _____ () C:\Users\andreas\Desktop\Addition.txt
2014-04-02 14:39 - 2014-04-03 13:12 - 00021566 _____ () C:\Users\andreas\Desktop\FRST.txt
2014-03-31 22:25 - 2014-03-31 22:25 - 00987442 _____ () C:\Users\andreas\Downloads\SecurityCheck.exe
2014-03-31 22:25 - 2014-03-31 22:25 - 00987442 _____ () C:\Users\andreas\Desktop\SecurityCheck.exe
2014-03-31 15:04 - 2014-03-31 15:04 - 02347384 _____ (ESET) C:\Users\andreas\Downloads\esetsmartinstaller_enu.exe
2014-03-31 14:52 - 2014-03-31 14:51 - 01038974 _____ (Thisisu) C:\Users\andreas\Desktop\JRT (1).exe
2014-03-31 14:51 - 2014-03-31 14:51 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT (1).exe
2014-03-31 14:42 - 2014-03-31 14:42 - 00025045 _____ () C:\ComboFix.txt
2014-03-31 11:22 - 2014-04-03 11:11 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-03-31 11:22 - 2014-03-31 11:22 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-03-31 11:19 - 2014-03-31 11:19 - 00376256 _____ () C:\Users\andreas\Downloads\7zip.exe
2014-03-30 18:19 - 2014-03-30 18:19 - 00000000 ____D () C:\windows\ERUNT
2014-03-30 18:18 - 2014-03-30 18:18 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT.exe
2014-03-30 18:05 - 2014-04-03 12:36 - 00000000 ____D () C:\AdwCleaner
2014-03-30 18:02 - 2014-03-30 18:02 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe
2014-03-30 17:14 - 2014-04-03 12:27 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-30 17:14 - 2014-03-30 17:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-30 17:14 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-03-30 17:14 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-03-30 17:13 - 2014-03-30 17:14 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-28 16:05 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-03-28 16:05 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-03-28 16:05 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-03-28 16:05 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-03-28 16:05 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-03-28 16:05 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-03-28 16:05 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-03-28 16:05 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-03-28 16:04 - 2014-03-31 14:42 - 00000000 ____D () C:\Qoobox
2014-03-28 16:04 - 2014-03-28 16:26 - 00000000 ____D () C:\windows\erdnt
2014-03-28 16:03 - 2014-03-28 16:03 - 05192353 ____R (Swearware) C:\Users\andreas\Desktop\ComboFix.exe
2014-03-28 16:03 - 2014-03-28 16:03 - 05192353 _____ (Swearware) C:\Users\andreas\Downloads\ComboFix.exe
2014-03-28 14:14 - 2014-03-28 14:13 - 00380416 _____ () C:\Users\andreas\Desktop\Gmer-19357.exe
2014-03-28 14:13 - 2014-03-28 14:13 - 00380416 _____ () C:\Users\andreas\Downloads\Gmer-19357.exe
2014-03-28 14:10 - 2014-04-03 13:12 - 00000000 ____D () C:\FRST
2014-03-28 14:09 - 2014-03-28 14:09 - 02157056 _____ (Farbar) C:\Users\andreas\Desktop\FRST64.exe
2014-03-28 14:08 - 2014-03-28 14:09 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe
2014-03-28 14:07 - 2014-03-28 14:07 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe
2014-03-28 14:06 - 2014-03-28 14:06 - 00000000 _____ () C:\Users\andreas\defogger_reenable
2014-03-28 14:05 - 2014-03-28 14:05 - 00050477 _____ () C:\Users\andreas\Downloads\Defogger.exe
2014-03-28 14:05 - 2014-03-28 14:05 - 00050477 _____ () C:\Users\andreas\Desktop\Defogger.exe
2014-03-28 11:00 - 2014-03-28 11:00 - 00167424 _____ () C:\Users\andreas\Downloads\OBRASCI ZAVRSNI 2013 - SEMNONES (2).xls
2014-03-28 10:59 - 2014-03-28 10:59 - 00167424 _____ () C:\Users\andreas\Downloads\OBRASCI ZAVRSNI 2013 - SEMNONES (1).xls
2014-03-28 10:57 - 2014-03-28 10:57 - 00167424 _____ () C:\Users\andreas\Downloads\OBRASCI ZAVRSNI 2013 - SEMNONES.xls
2014-03-22 15:26 - 2014-03-22 15:33 - 00064000 ____H () C:\Users\Guest\Desktop\~WRL3555.tmp
2014-03-22 14:25 - 2014-03-22 14:34 - 00009169 _____ () C:\Users\andreas\Documents\Bieter.xlsx
2014-03-22 10:03 - 2014-03-22 10:03 - 00000000 ____D () C:\Users\Guest\AppData\Local\Adobe
2014-03-22 10:02 - 2014-03-22 10:02 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-03-22 09:35 - 2014-03-22 09:35 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Avira
2014-03-22 09:29 - 2014-03-22 09:29 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf
2014-03-22 07:45 - 2014-03-22 07:45 - 00000000 ____D () C:\Users\Guest\Desktop\Bieterregistrierungen
2014-03-21 17:09 - 2014-04-02 14:40 - 00003942 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{92299EF7-1E5C-417C-864B-B520F20C2A67}
2014-03-21 12:16 - 2014-03-21 12:16 - 01161080 _____ () C:\windows\SysWOW64\Radsteroids.33AABCF1AD13.dll
2014-03-21 00:33 - 2014-03-22 16:21 - 00000000 ____D () C:\Users\Guest\Desktop\forms
2014-03-21 00:33 - 2014-03-21 00:33 - 00000000 ____D () C:\Users\Guest\Desktop\logo avus
2014-03-21 00:20 - 2014-03-21 00:20 - 00000000 ____D () C:\Users\Guest\AppData\Local\adaware
2014-03-21 00:19 - 2014-03-25 11:52 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-03-21 00:19 - 2014-03-22 10:03 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Adobe
2014-03-21 00:19 - 2014-03-21 00:20 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-21 00:19 - 2014-03-21 00:20 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-21 00:19 - 2014-03-21 00:20 - 00000000 ____D () C:\Users\Guest\AppData\Local\VirtualStore
2014-03-21 00:19 - 2014-03-21 00:19 - 00001413 _____ () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-21 00:19 - 2014-03-21 00:19 - 00000020 ___SH () C:\Users\Guest\ntuser.ini
2014-03-21 00:19 - 2014-03-21 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\offsync
2014-03-21 00:19 - 2014-03-21 00:19 - 00000000 ____D () C:\Users\Guest
2014-03-21 00:19 - 2011-03-10 17:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Microsoft Help
2014-03-21 00:19 - 2011-03-06 20:34 - 00001135 _____ () C:\Users\Guest\Desktop\CyberLink YouCam.lnk
2014-03-21 00:19 - 2011-03-06 20:34 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
2014-03-21 00:19 - 2010-08-04 04:37 - 00001190 _____ () C:\Users\Guest\Desktop\CyberLink DVD Suite.lnk
2014-03-21 00:19 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-21 00:19 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-13 22:26 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-13 22:26 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-13 22:26 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-13 22:26 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-13 22:26 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-13 22:26 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-13 22:26 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-13 22:26 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-13 22:26 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-13 22:26 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-03-13 22:26 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-03-13 22:26 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-03-13 22:26 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-03-13 22:26 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-03-13 22:26 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-13 22:26 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-03-13 22:26 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-03-13 22:26 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-03-13 22:26 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-13 22:26 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-03-13 22:26 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-03-13 22:26 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-03-13 22:26 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-03-13 22:26 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-13 22:26 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-03-13 22:26 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-13 22:26 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-13 22:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2014-03-13 22:26 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2014-03-13 22:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-13 22:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-13 22:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-03-13 22:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-13 22:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-13 22:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-13 22:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-03-13 22:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-13 22:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-13 22:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-13 22:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-03-13 22:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-13 22:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-03-13 22:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-13 22:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-03-13 22:24 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-13 22:24 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-13 22:24 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-03-13 22:24 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-03-04 10:46 - 2014-03-04 10:46 - 00001109 _____ () C:\Users\andreas\Desktop\desktoptools.lnk
==================== One Month Modified Files and Folders =======
2014-04-03 13:12 - 2014-04-02 14:39 - 00021566 _____ () C:\Users\andreas\Desktop\FRST.txt
2014-04-03 13:12 - 2014-03-28 14:10 - 00000000 ____D () C:\FRST
2014-04-03 13:07 - 2014-04-03 13:07 - 00000627 _____ () C:\Users\andreas\Desktop\JRT.txt
2014-04-03 13:03 - 2014-01-22 10:00 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-03 13:00 - 2009-07-14 06:45 - 00014144 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-03 13:00 - 2009-07-14 06:45 - 00014144 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-03 12:54 - 2014-01-15 21:25 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Dropbox
2014-04-03 12:54 - 2011-03-06 20:21 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-04-03 12:53 - 2011-03-09 15:40 - 00001108 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-03 12:53 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-03 12:52 - 2013-12-14 14:12 - 00019876 _____ () C:\windows\setupact.log
2014-04-03 12:43 - 2014-01-15 21:44 - 00000000 ___RD () C:\Users\andreas\Desktop\Dropbox
2014-04-03 12:42 - 2011-03-06 20:52 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Skype
2014-04-03 12:42 - 2010-08-04 04:27 - 01599228 _____ () C:\windows\WindowsUpdate.log
2014-04-03 12:40 - 2011-03-09 15:40 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-03 12:37 - 2013-12-15 10:46 - 00579758 _____ () C:\windows\PFRO.log
2014-04-03 12:36 - 2014-03-30 18:05 - 00000000 ____D () C:\AdwCleaner
2014-04-03 12:32 - 2014-04-03 12:32 - 01426178 _____ () C:\Users\andreas\Downloads\adwcleaner (1).exe
2014-04-03 12:32 - 2014-04-03 12:32 - 01426178 _____ () C:\Users\andreas\Desktop\adwcleaner (1).exe
2014-04-03 12:30 - 2014-04-03 12:30 - 00007128 _____ () C:\Users\andreas\Desktop\mbam neu.txt
2014-04-03 12:27 - 2014-03-30 17:14 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 12:12 - 2011-11-10 09:54 - 00000000 ____D () C:\Users\andreas\AppData\Local\Akamai
2014-04-03 11:28 - 2014-04-03 11:21 - 00001264 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk
2014-04-03 11:28 - 2014-04-03 11:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-03 11:18 - 2014-04-03 11:21 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Desktop\revosetup95.exe
2014-04-03 11:18 - 2014-04-03 11:18 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe
2014-04-03 11:11 - 2014-03-31 11:22 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-04-03 11:09 - 2009-07-14 05:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-04-02 14:44 - 2014-04-02 14:43 - 00035940 _____ () C:\Users\andreas\Desktop\Addition.txt
2014-04-02 14:40 - 2014-03-21 17:09 - 00003942 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{92299EF7-1E5C-417C-864B-B520F20C2A67}
2014-03-31 22:25 - 2014-03-31 22:25 - 00987442 _____ () C:\Users\andreas\Downloads\SecurityCheck.exe
2014-03-31 22:25 - 2014-03-31 22:25 - 00987442 _____ () C:\Users\andreas\Desktop\SecurityCheck.exe
2014-03-31 15:04 - 2014-03-31 15:04 - 02347384 _____ (ESET) C:\Users\andreas\Downloads\esetsmartinstaller_enu.exe
2014-03-31 14:51 - 2014-03-31 14:52 - 01038974 _____ (Thisisu) C:\Users\andreas\Desktop\JRT (1).exe
2014-03-31 14:51 - 2014-03-31 14:51 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT (1).exe
2014-03-31 14:42 - 2014-03-31 14:42 - 00025045 _____ () C:\ComboFix.txt
2014-03-31 14:42 - 2014-03-28 16:04 - 00000000 ____D () C:\Qoobox
2014-03-31 14:37 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini
2014-03-31 11:22 - 2014-03-31 11:22 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-03-31 11:22 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-03-31 11:19 - 2014-03-31 11:19 - 00376256 _____ () C:\Users\andreas\Downloads\7zip.exe
2014-03-31 09:27 - 2009-07-14 07:13 - 00801824 _____ () C:\windows\system32\PerfStringBackup.INI
2014-03-30 22:56 - 2013-08-06 14:09 - 00000000 ____D () C:\Users\andreas\Desktop\Classic Car Auction
2014-03-30 18:19 - 2014-03-30 18:19 - 00000000 ____D () C:\windows\ERUNT
2014-03-30 18:18 - 2014-03-30 18:18 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT.exe
2014-03-30 18:12 - 2013-01-10 16:46 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\CheckPoint
2014-03-30 18:02 - 2014-03-30 18:02 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe
2014-03-30 17:16 - 2014-03-30 17:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-30 17:16 - 2014-01-23 16:33 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-30 17:14 - 2014-03-30 17:13 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-30 17:14 - 2013-01-10 13:46 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Malwarebytes
2014-03-30 17:14 - 2013-01-10 13:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-28 20:52 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-03-28 16:26 - 2014-03-28 16:04 - 00000000 ____D () C:\windows\erdnt
2014-03-28 16:15 - 2012-07-13 13:34 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\convert
2014-03-28 16:15 - 2012-01-26 23:21 - 00000000 ____D () C:\Program Files (x86)\BFlix
2014-03-28 16:03 - 2014-03-28 16:03 - 05192353 ____R (Swearware) C:\Users\andreas\Desktop\ComboFix.exe
2014-03-28 16:03 - 2014-03-28 16:03 - 05192353 _____ (Swearware) C:\Users\andreas\Downloads\ComboFix.exe
2014-03-28 14:13 - 2014-03-28 14:14 - 00380416 _____ () C:\Users\andreas\Desktop\Gmer-19357.exe
2014-03-28 14:13 - 2014-03-28 14:13 - 00380416 _____ () C:\Users\andreas\Downloads\Gmer-19357.exe
2014-03-28 14:09 - 2014-03-28 14:09 - 02157056 _____ (Farbar) C:\Users\andreas\Desktop\FRST64.exe
2014-03-28 14:09 - 2014-03-28 14:08 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe
2014-03-28 14:07 - 2014-03-28 14:07 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe
2014-03-28 14:06 - 2014-03-28 14:06 - 00000000 _____ () C:\Users\andreas\defogger_reenable
2014-03-28 14:06 - 2011-03-06 20:21 - 00000000 ____D () C:\Users\andreas
2014-03-28 14:05 - 2014-03-28 14:05 - 00050477 _____ () C:\Users\andreas\Downloads\Defogger.exe
2014-03-28 14:05 - 2014-03-28 14:05 - 00050477 _____ () C:\Users\andreas\Desktop\Defogger.exe
2014-03-28 11:00 - 2014-03-28 11:00 - 00167424 _____ () C:\Users\andreas\Downloads\OBRASCI ZAVRSNI 2013 - SEMNONES (2).xls
2014-03-28 10:59 - 2014-03-28 10:59 - 00167424 _____ () C:\Users\andreas\Downloads\OBRASCI ZAVRSNI 2013 - SEMNONES (1).xls
2014-03-28 10:57 - 2014-03-28 10:57 - 00167424 _____ () C:\Users\andreas\Downloads\OBRASCI ZAVRSNI 2013 - SEMNONES.xls
2014-03-25 11:52 - 2014-03-21 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-03-24 17:06 - 2014-02-22 15:14 - 00000000 ____D () C:\Users\andreas\Desktop\semnones jdoo
2014-03-22 16:21 - 2014-03-21 00:33 - 00000000 ____D () C:\Users\Guest\Desktop\forms
2014-03-22 15:33 - 2014-03-22 15:26 - 00064000 ____H () C:\Users\Guest\Desktop\~WRL3555.tmp
2014-03-22 14:34 - 2014-03-22 14:25 - 00009169 _____ () C:\Users\andreas\Documents\Bieter.xlsx
2014-03-22 10:03 - 2014-03-22 10:03 - 00000000 ____D () C:\Users\Guest\AppData\Local\Adobe
2014-03-22 10:03 - 2014-03-21 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Adobe
2014-03-22 10:02 - 2014-03-22 10:02 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-03-22 09:35 - 2014-03-22 09:35 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Avira
2014-03-22 09:29 - 2014-03-22 09:29 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf
2014-03-22 07:45 - 2014-03-22 07:45 - 00000000 ____D () C:\Users\Guest\Desktop\Bieterregistrierungen
2014-03-21 18:48 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF
2014-03-21 12:16 - 2014-03-21 12:16 - 01161080 _____ () C:\windows\SysWOW64\Radsteroids.33AABCF1AD13.dll
2014-03-21 00:33 - 2014-03-21 00:33 - 00000000 ____D () C:\Users\Guest\Desktop\logo avus
2014-03-21 00:20 - 2014-03-21 00:20 - 00000000 ____D () C:\Users\Guest\AppData\Local\adaware
2014-03-21 00:20 - 2014-03-21 00:19 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-21 00:20 - 2014-03-21 00:19 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-21 00:20 - 2014-03-21 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\VirtualStore
2014-03-21 00:19 - 2014-03-21 00:19 - 00001413 _____ () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-21 00:19 - 2014-03-21 00:19 - 00000020 ___SH () C:\Users\Guest\ntuser.ini
2014-03-21 00:19 - 2014-03-21 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\offsync
2014-03-21 00:19 - 2014-03-21 00:19 - 00000000 ____D () C:\Users\Guest
2014-03-20 22:52 - 2011-07-21 12:47 - 00000000 ____D () C:\Users\andreas\Desktop\james
2014-03-18 19:17 - 2011-04-06 11:41 - 00000000 ____D () C:\Users\andreas\Desktop\Roccadoro
2014-03-18 00:43 - 2013-08-15 08:57 - 00000000 ____D () C:\windows\system32\MRT
2014-03-18 00:41 - 2011-03-19 11:57 - 90015360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-17 10:16 - 2011-03-08 22:20 - 00000000 ____D () C:\Users\andreas\Desktop\THE VIEW Villas doo
2014-03-16 21:04 - 2011-06-04 11:26 - 00000000 ____D () C:\Users\andreas\Desktop\Inntal Montenegro
2014-03-16 20:12 - 2011-03-06 20:43 - 00000000 ___RD () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-16 16:17 - 2011-03-20 19:43 - 00000000 ____D () C:\Users\andreas\Desktop\montague stein
2014-03-15 20:29 - 2011-04-05 15:32 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-14 13:57 - 2014-02-14 10:37 - 00000000 ____D () C:\Users\andreas\Desktop\Photos portals
2014-03-14 10:32 - 2010-08-04 04:29 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-14 08:36 - 2009-07-14 06:45 - 00426592 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-14 08:34 - 2013-03-14 00:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 08:34 - 2013-03-14 00:27 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-14 03:16 - 2011-03-08 19:36 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-14 01:06 - 2013-05-26 18:55 - 00000000 ____D () C:\Users\andreas\AppData\Local\Workspace
2014-03-05 09:26 - 2014-03-30 17:14 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-03-30 17:14 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-01-23 16:33 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-03-04 10:46 - 2014-03-04 10:46 - 00001109 _____ () C:\Users\andreas\Desktop\desktoptools.lnk
Some content of TEMP:
====================
C:\Users\andreas\AppData\Local\Temp\avgnt.exe
C:\Users\andreas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpshcvvm.dll
C:\Users\andreas\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 09:45
==================== End Of Log ============================ --- --- ---
Gruß,
Andi |