Crazy112 | 06.04.2014 13:27 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 06.04.2014
Suchlauf-Zeit: 13:59:46
Logdatei: malware.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.06.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: User
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 254294
Verstrichene Zeit: 24 Min, 58 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 10
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\logekkkdbdidmmcgkonmmonclldogceg, In Quarantäne, [e917c33df10fd9270e1d485219ead32d],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1131450200-3114338295-2971485759-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [cc34f70938c8758be2bd2f3f6d95fb05],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1131450200-3114338295-2971485759-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [c93727d953ad32ce538aa7dd3ac94fb1],
PUP.Optional.ShowPassword.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{e6ecc342-230c-4f2a-9555-17b076ad7dab}, In Quarantäne, [cd336997cb35cb3534cff623d92bb34d],
PUP.Optional.ShowPassword.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E6ECC342-230C-4F2A-9555-17B076AD7DAB}, In Quarantäne, [cd336997cb35cb3534cff623d92bb34d],
PUP.Optional.ShowPassword.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{68c39399-a971-4a65-be0b-1d5d6a9d9e7b}, In Quarantäne, [cd336997cb35cb3534cff623d92bb34d],
PUP.Optional.ShowPassword.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{007656b6-49c8-4185-ae7b-a6bd55deea1b}, In Quarantäne, [cd336997cb35cb3534cff623d92bb34d],
PUP.Optional.ShowPassword.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{68c39399-a971-4a65-be0b-1d5d6a9d9e7b}, In Quarantäne, [cd336997cb35cb3534cff623d92bb34d],
PUP.Optional.ShowPassword.A, HKU\S-1-5-21-1131450200-3114338295-2971485759-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E6ECC342-230C-4F2A-9555-17B076AD7DAB}, In Quarantäne, [cd336997cb35cb3534cff623d92bb34d],
PUP.Optional.ShowPassword.A, HKU\S-1-5-21-1131450200-3114338295-2971485759-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E6ECC342-230C-4F2A-9555-17B076AD7DAB}, In Quarantäne, [cd336997cb35cb3534cff623d92bb34d],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1131450200-3114338295-2971485759-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0N2X1N, In Quarantäne, [c93727d953ad32ce538aa7dd3ac94fb1]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 3
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy, In Quarantäne, [e51bff01df21ad5344543420e81a28d8],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\4B6284B9572C46DD9D10EABC81F72E32, In Quarantäne, [e51bff01df21ad5344543420e81a28d8],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\OpenCandy_4B6284B9572C46DD9D10EABC81F72E32, In Quarantäne, [e51bff01df21ad5344543420e81a28d8],
Dateien: 2
PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\OpenCandy\4B6284B9572C46DD9D10EABC81F72E32\SSStub_SearchProtect_p1v0.exe, In Quarantäne, [689857a9ad533dc3041149ccde2304fc],
PUP.Optional.ShowPassword.A, C:\Windows\Tasks\Show-Password Update.job, In Quarantäne, [49b7eb15d42c837d69bda6f4e0232dd3],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 06.04.2014 13:33:09, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 06.04.2014 13:33:09, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 06.04.2014 13:33:09, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 06.04.2014 13:33:10, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Update, 06.04.2014 13:33:46, SYSTEM, USER-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 06.04.2014 13:33:52, SYSTEM, USER-PC, Manual, Malware Database, 2014.3.4.9, 2014.4.6.4,
Update, 06.04.2014 13:33:57, SYSTEM, USER-PC, Manual, program, 2.0.0.1000, 2.0.1.1004,
Protection, 06.04.2014 13:34:08, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 06.04.2014 13:34:09, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 06.04.2014 13:34:09, SYSTEM, USER-PC, Protection, Malware Protection, Stopping,
Protection, 06.04.2014 13:34:09, SYSTEM, USER-PC, Protection, Malware Protection, Stopped,
Protection, 06.04.2014 13:34:19, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 06.04.2014 13:34:19, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 06.04.2014 13:34:19, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 06.04.2014 13:34:19, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Update, 06.04.2014 13:34:24, SYSTEM, USER-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 06.04.2014 13:34:27, SYSTEM, USER-PC, Manual, Malware Database, 2014.3.4.9, 2014.4.6.4,
Protection, 06.04.2014 13:34:29, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 06.04.2014 13:34:29, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 06.04.2014 13:34:29, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 06.04.2014 13:34:31, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 06.04.2014 13:34:31, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 06.04.2014 13:34:32, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Protection, 06.04.2014 14:02:08, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 06.04.2014 14:02:08, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 06.04.2014 14:02:08, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 06.04.2014 14:02:11, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
(end) Code:
# AdwCleaner v3.023 - Bericht erstellt am 06/04/2014 um 14:10:41
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : User - USER-PC
# Gestartet von : C:\Users\User\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\PC Speed Maximizer
Datei Gelöscht : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\cn18asol.default-1387626871457\searchplugins\safesearch.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\cn18asol.default-1387626871457\prefs.js ]
[ Datei : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\flx3rfxw.Server2Go\prefs.js ]
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [4266 octets] - [21/12/2013 13:56:57]
AdwCleaner[R1].txt - [1209 octets] - [24/12/2013 22:22:57]
AdwCleaner[R2].txt - [2425 octets] - [06/04/2014 14:08:59]
AdwCleaner[S0].txt - [3877 octets] - [21/12/2013 14:02:21]
AdwCleaner[S1].txt - [1270 octets] - [24/12/2013 22:25:43]
AdwCleaner[S2].txt - [2340 octets] - [06/04/2014 14:10:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2400 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by User on 06.04.2014 at 14:16:57,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\cn18asol.default-1387626871457\minidumps [68 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.04.2014 at 14:23:51,51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by User (administrator) on USER-PC on 06-04-2014 14:25:44
Running from C:\Users\User\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton AntiVirus\Engine\21.2.0.38\NAV.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\NST.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Spotify Ltd) C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\User\AppData\Roaming\Spotify\spotify.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(GamersFirst) C:\Users\User\AppData\Local\GamersFirst\LIVE!\Live.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\NST.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Symantec Corporation) C:\Program Files (x86)\Norton AntiVirus\Engine\21.2.0.38\NAV.exe
() C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Farbar) C:\Users\User\Desktop\FRST64(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-02-03] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-02-26] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-1131450200-3114338295-2971485759-1000\...\Run: [Spotify Web Helper] - C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-14] (Spotify Ltd)
HKU\S-1-5-21-1131450200-3114338295-2971485759-1000\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3588952 2014-03-07] (Electronic Arts)
HKU\S-1-5-21-1131450200-3114338295-2971485759-1000\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-03] (Samsung)
HKU\S-1-5-21-1131450200-3114338295-2971485759-1000\...\Run: [Spotify] - C:\Users\User\AppData\Roaming\Spotify\spotify.exe [6118400 2014-01-14] (Spotify Ltd)
HKU\S-1-5-21-1131450200-3114338295-2971485759-1000\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-1131450200-3114338295-2971485759-1000\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
HKU\S-1-5-21-1131450200-3114338295-2971485759-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
ShortcutTarget: GamersFirst LIVE!.lnk -> C:\Users\User\AppData\Local\GamersFirst\LIVE!\Live.exe (GamersFirst)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD59217B4E087CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.0.43\coIEPlg.dll (Symantec Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\21.2.0.38\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\coIEPlg.dll (Symantec Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.0.43\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\coIEPlg.dll (Symantec Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\flx3rfxw.Server2Go
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_21.1.0.18\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_21.1.0.18\IPSFF [2013-10-26]
FF HKLM-x32\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.6.0.27\coFFPlgn\
FF Extension: Norton Identity Safe Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.6.0.27\coFFPlgn\ []
FF HKCU\...\Firefox\Extensions: [{b2375139-b908-4471-a891-0e2f76a4d88b}] - C:\Program Files (x86)\Show-Password\150.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-23]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-23]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-23]
CHR Extension: (Google-Suche) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-23]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-25]
CHR Extension: (Norton Identity Protection) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob [2013-11-22]
CHR Extension: (Google Mail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-23]
CHR HKLM-x32\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\Exts\Chrome.crx [2014-03-21]
==================== Services (Whitelisted) =================
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-02-26] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 NAV; C:\Program Files (x86)\Norton AntiVirus\Engine\21.2.0.38\NAV.exe [262968 2014-03-12] (Symantec Corporation)
R2 NCO; C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\NST.exe [130104 2014-03-11] (Symantec Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-08-24] ()
==================== Drivers (Whitelisted) ====================
R3 BHDrvx64; C:\Program Files (x86)\Norton AntiVirus\NortonData\21.1.0.18\Definitions\BASHDefs\20140319.001\BHDrvx64.sys [1525976 2014-03-19] (Symantec Corporation)
R3 ccSet_NAV; C:\Windows\system32\drivers\NAVx64\1502000.026\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 ccSet_NST; C:\Windows\system32\drivers\NSTx64\7DE07000.02B\ccSetx64.sys [162392 2013-09-27] (Symantec Corporation)
R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation)
R3 IDSVia64; C:\Program Files (x86)\Norton AntiVirus\NortonData\21.1.0.18\Definitions\IPSDefs\20140404.001\IDSvia64.sys [525016 2014-04-04] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-06] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton AntiVirus\NortonData\21.1.0.18\Definitions\VirusDefs\20140405.003\ENG64.SYS [126040 2014-04-04] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton AntiVirus\NortonData\21.1.0.18\Definitions\VirusDefs\20140405.003\EX64.SYS [2099288 2014-04-04] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\NAVx64\1502000.026\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation)
R3 SRTSPX; C:\Windows\system32\drivers\NAVx64\1502000.026\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
R3 SymDS; C:\Windows\system32\drivers\NAVx64\1502000.026\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R3 SymEFA; C:\Windows\system32\drivers\NAVx64\1502000.026\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-10-26] (Symantec Corporation)
R3 SymIRON; C:\Windows\system32\drivers\NAVx64\1502000.026\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R3 SymNetS; C:\Windows\System32\Drivers\NAVx64\1502000.026\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-06 14:23 - 2014-04-06 14:23 - 00000769 _____ () C:\Users\User\Desktop\JRT.txt
2014-04-06 14:17 - 2014-04-06 14:17 - 02157056 _____ (Farbar) C:\Users\User\Desktop\FRST64(1).exe
2014-04-06 14:14 - 2014-04-06 14:14 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
2014-04-06 14:14 - 2014-04-06 14:14 - 00002488 _____ () C:\Users\User\Desktop\AdwCleaner[S2].txt
2014-04-06 14:08 - 2014-04-06 14:08 - 01426178 _____ () C:\Users\User\Desktop\adwcleaner.exe
2014-04-06 14:05 - 2014-04-06 14:05 - 00003919 _____ () C:\Users\User\Desktop\malware.txt
2014-04-06 14:05 - 2014-04-06 14:05 - 00002700 _____ () C:\Users\User\Desktop\malware 2.txt
2014-04-06 13:33 - 2014-04-06 14:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-06 13:32 - 2014-04-06 13:34 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-06 13:32 - 2014-04-06 13:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-06 13:32 - 2014-04-06 13:32 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\User\Desktop\mbam-setup-2.0.0.1000.exe
2014-04-06 13:32 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-06 13:32 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-06 13:32 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-06 13:28 - 2014-04-06 13:28 - 00448512 _____ (OldTimer Tools) C:\Users\User\Desktop\TFC.exe
2014-04-05 10:19 - 2014-04-05 10:19 - 00004762 _____ () C:\Users\User\Desktop\Behobene Sicherheitsrisiken.txt
2014-04-05 10:15 - 2014-04-05 10:15 - 00027687 _____ () C:\Users\User\Downloads\Addition.txt
2014-04-05 10:14 - 2014-04-06 14:25 - 00017287 _____ () C:\Users\User\Desktop\FRST.txt
2014-04-05 10:12 - 2014-04-05 10:15 - 00037892 _____ () C:\Users\User\Downloads\FRST.txt
2014-04-05 10:12 - 2014-04-05 10:12 - 02157056 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-03-30 17:12 - 2014-03-30 17:12 - 00000000 ____D () C:\Windows\System32\Tasks\Norton AntiVirus
2014-03-29 18:33 - 2014-03-29 18:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-28 23:07 - 2014-03-28 23:11 - 00000000 ____D () C:\Program Files (x86)\GamersFirst
2014-03-27 22:27 - 2014-03-28 14:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Users\User\Documents\ROCCAT
2014-03-27 21:03 - 2014-03-27 21:04 - 39749408 _____ (ROCCAT GmbH ) C:\Users\User\Downloads\ROCCAT_Power_Grid_v0459.exe
2014-03-27 20:59 - 2014-03-27 20:59 - 02901340 _____ () C:\Users\User\Downloads\Minecraft_UEv9-Version-0.9.rpgp
2014-03-26 22:22 - 2014-03-28 23:02 - 00000000 ____D () C:\Users\User\AppData\Local\GamersFirst LIVE!
2014-03-26 22:21 - 2014-03-28 23:11 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst
2014-03-26 22:21 - 2014-03-26 22:21 - 00000000 ____D () C:\Users\User\AppData\Local\GamersFirst
2014-03-26 22:21 - 2014-03-26 22:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-03-26 22:17 - 2014-03-26 22:17 - 12845064 _____ (GamersFirst) C:\Users\User\Downloads\APB_GamersFirst_LIVE_Setup_EN.exe
2014-03-26 22:16 - 2014-03-26 22:16 - 00710848 _____ ( ) C:\Users\User\Downloads\COMPUTER_BILD-Download-Manager_fuer_APB_GamersFirst_LIVE_Setup_EN.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00196528 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaws.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00172976 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaw.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00172976 _____ (Sun Microsystems, Inc.) C:\Windows\system32\java.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00000000 ____D () C:\Program Files\Java
2014-03-24 20:58 - 2014-03-24 20:58 - 17355184 _____ (Sun Microsystems, Inc.) C:\Users\User\Downloads\jre-6u45-windows-x64.exe
2014-03-22 19:05 - 2014-03-22 20:07 - 00000000 ____D () C:\Users\User\Documents\Battlefield Play4Free
2014-03-19 23:02 - 2014-03-19 23:02 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-03-19 23:02 - 2014-03-19 23:02 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-03-19 23:02 - 2014-03-19 23:02 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-03-19 23:02 - 2014-03-19 23:02 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-03-19 23:02 - 2014-03-19 23:02 - 00000000 ____D () C:\Program Files (x86)\Java
2014-03-19 23:01 - 2014-03-19 23:01 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51 (3).exe
2014-03-19 22:58 - 2014-03-19 22:58 - 31714728 _____ (Oracle Corporation) C:\Users\User\Downloads\jre-7u25-windows-i586.exe
2014-03-19 22:57 - 2014-03-19 22:57 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall(1).exe
2014-03-19 22:56 - 2014-03-19 22:56 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall.exe
2014-03-19 22:56 - 2014-03-19 22:56 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51 (2).exe
2014-03-19 22:54 - 2014-03-19 22:54 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51 (1).exe
2014-03-19 22:52 - 2014-03-19 22:52 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51.exe
2014-03-14 20:52 - 2014-03-16 12:18 - 00000000 ____D () C:\Users\User\Desktop\Lukas Geuken Posts
2014-03-12 21:09 - 2014-03-12 21:09 - 00069168 _____ () C:\Users\User\AppData\Roaming\GDIPFONTCACHEV1.DAT
2014-03-12 20:04 - 2014-03-12 20:04 - 05777288 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-03-12 18:38 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 18:38 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 18:38 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 18:38 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 18:38 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 18:38 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 18:38 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 18:38 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 18:38 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 18:38 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 18:38 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 18:38 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 18:38 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-12 18:38 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 18:38 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 18:38 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-12 18:38 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 18:38 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 18:38 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-12 18:38 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-12 18:38 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-12 18:38 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-12 18:38 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-12 18:38 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 18:38 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-12 18:38 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-12 18:38 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-12 18:38 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 18:38 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 18:38 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-12 18:38 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-12 18:38 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 18:38 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-12 18:38 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-12 18:38 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-12 18:38 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 18:38 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-12 18:38 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-12 18:38 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 18:38 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-12 18:38 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 18:38 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 18:38 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-12 18:38 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-12 18:37 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 18:37 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 18:37 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-12 18:37 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
==================== One Month Modified Files and Folders =======
2014-04-06 14:25 - 2014-04-05 10:14 - 00017287 _____ () C:\Users\User\Desktop\FRST.txt
2014-04-06 14:25 - 2013-12-23 18:08 - 00000000 ____D () C:\FRST
2014-04-06 14:23 - 2014-04-06 14:23 - 00000769 _____ () C:\Users\User\Desktop\JRT.txt
2014-04-06 14:19 - 2009-07-14 06:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-06 14:19 - 2009-07-14 06:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-06 14:17 - 2014-04-06 14:17 - 02157056 _____ (Farbar) C:\Users\User\Desktop\FRST64(1).exe
2014-04-06 14:17 - 2013-10-21 15:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-06 14:14 - 2014-04-06 14:14 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
2014-04-06 14:14 - 2014-04-06 14:14 - 00002488 _____ () C:\Users\User\Desktop\AdwCleaner[S2].txt
2014-04-06 14:13 - 2014-04-06 13:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-06 14:13 - 2013-07-31 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\Spotify
2014-04-06 14:12 - 2013-10-21 15:37 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-06 14:12 - 2013-08-23 13:42 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-04-06 14:12 - 2013-08-09 21:32 - 00000000 ____D () C:\Users\User\AppData\Local\LogMeIn Hamachi
2014-04-06 14:12 - 2013-07-24 20:08 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2014-04-06 14:11 - 2013-12-25 21:59 - 00106754 _____ () C:\Windows\PFRO.log
2014-04-06 14:11 - 2013-12-23 20:09 - 00015648 _____ () C:\Windows\setupact.log
2014-04-06 14:11 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-06 14:10 - 2013-12-21 13:56 - 00000000 ____D () C:\AdwCleaner
2014-04-06 14:10 - 2013-07-23 18:13 - 01466473 _____ () C:\Windows\WindowsUpdate.log
2014-04-06 14:08 - 2014-04-06 14:08 - 01426178 _____ () C:\Users\User\Desktop\adwcleaner.exe
2014-04-06 14:08 - 2013-12-28 23:59 - 00000000 ____D () C:\Users\User\Desktop\Bilder Allgemein
2014-04-06 14:08 - 2013-08-23 13:42 - 00000000 ____D () C:\ProgramData\Origin
2014-04-06 14:08 - 2013-07-24 20:05 - 00000000 ____D () C:\Users\User\Desktop\-Pascal-
2014-04-06 14:05 - 2014-04-06 14:05 - 00003919 _____ () C:\Users\User\Desktop\malware.txt
2014-04-06 14:05 - 2014-04-06 14:05 - 00002700 _____ () C:\Users\User\Desktop\malware 2.txt
2014-04-06 14:04 - 2013-07-25 19:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-06 13:34 - 2014-04-06 13:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-06 13:34 - 2014-04-06 13:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-06 13:32 - 2014-04-06 13:32 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\User\Desktop\mbam-setup-2.0.0.1000.exe
2014-04-06 13:32 - 2013-12-24 13:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-06 13:28 - 2014-04-06 13:28 - 00448512 _____ (OldTimer Tools) C:\Users\User\Desktop\TFC.exe
2014-04-06 10:36 - 2009-07-14 19:58 - 00699190 _____ () C:\Windows\system32\perfh007.dat
2014-04-06 10:36 - 2009-07-14 19:58 - 00149330 _____ () C:\Windows\system32\perfc007.dat
2014-04-06 10:36 - 2009-07-14 07:13 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-05 22:52 - 2014-01-09 17:23 - 00000000 ____D () C:\Users\User\Desktop\CHAT BILDER
2014-04-05 20:12 - 2013-10-21 15:37 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-05 20:12 - 2013-10-21 15:37 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-05 10:19 - 2014-04-05 10:19 - 00004762 _____ () C:\Users\User\Desktop\Behobene Sicherheitsrisiken.txt
2014-04-05 10:15 - 2014-04-05 10:15 - 00027687 _____ () C:\Users\User\Downloads\Addition.txt
2014-04-05 10:15 - 2014-04-05 10:12 - 00037892 _____ () C:\Users\User\Downloads\FRST.txt
2014-04-05 10:12 - 2014-04-05 10:12 - 02157056 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-04-04 23:52 - 2014-03-05 16:56 - 00000000 ____D () C:\Users\User\AppData\Roaming\.minecraft
2014-04-04 23:52 - 2014-01-19 12:43 - 00000000 ____D () C:\Users\User\AppData\Roaming\vlc
2014-04-04 23:52 - 2013-07-23 20:37 - 00000000 ____D () C:\ProgramData\Norton
2014-04-04 23:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-04-04 23:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2014-04-03 22:10 - 2013-08-29 21:45 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps
2014-04-03 09:51 - 2014-04-06 13:32 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-06 13:32 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-06 13:32 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 12:51 - 2013-09-05 21:36 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-03-30 17:12 - 2014-03-30 17:12 - 00000000 ____D () C:\Windows\System32\Tasks\Norton AntiVirus
2014-03-30 17:12 - 2013-10-26 13:30 - 00000000 ____D () C:\Windows\system32\Drivers\NAVx64
2014-03-30 17:11 - 2013-10-26 13:31 - 00003218 _____ () C:\Windows\System32\Tasks\Norton WSC Integration
2014-03-30 17:11 - 2013-10-26 13:31 - 00002397 _____ () C:\Users\Public\Desktop\Norton AntiVirus.lnk
2014-03-30 12:47 - 2013-07-23 22:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-29 18:33 - 2014-03-29 18:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-28 23:11 - 2014-03-28 23:07 - 00000000 ____D () C:\Program Files (x86)\GamersFirst
2014-03-28 23:11 - 2014-03-26 22:21 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst
2014-03-28 23:02 - 2014-03-26 22:22 - 00000000 ____D () C:\Users\User\AppData\Local\GamersFirst LIVE!
2014-03-28 22:39 - 2014-03-02 14:05 - 00000000 ____D () C:\Users\User\Desktop\Bukkit Server 02.03.2014
2014-03-28 14:05 - 2014-03-27 22:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Users\User\Documents\ROCCAT
2014-03-27 21:04 - 2014-03-27 21:03 - 39749408 _____ (ROCCAT GmbH ) C:\Users\User\Downloads\ROCCAT_Power_Grid_v0459.exe
2014-03-27 20:59 - 2014-03-27 20:59 - 02901340 _____ () C:\Users\User\Downloads\Minecraft_UEv9-Version-0.9.rpgp
2014-03-27 17:01 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-03-26 22:21 - 2014-03-26 22:21 - 00000000 ____D () C:\Users\User\AppData\Local\GamersFirst
2014-03-26 22:21 - 2014-03-26 22:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-03-26 22:21 - 2013-07-23 18:20 - 00001425 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-26 22:21 - 2013-07-23 18:20 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-26 22:17 - 2014-03-26 22:17 - 12845064 _____ (GamersFirst) C:\Users\User\Downloads\APB_GamersFirst_LIVE_Setup_EN.exe
2014-03-26 22:16 - 2014-03-26 22:16 - 00710848 _____ ( ) C:\Users\User\Downloads\COMPUTER_BILD-Download-Manager_fuer_APB_GamersFirst_LIVE_Setup_EN.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00196528 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaws.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00172976 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaw.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00172976 _____ (Sun Microsystems, Inc.) C:\Windows\system32\java.exe
2014-03-24 20:59 - 2014-03-24 20:59 - 00000000 ____D () C:\Program Files\Java
2014-03-24 20:58 - 2014-03-24 20:58 - 17355184 _____ (Sun Microsystems, Inc.) C:\Users\User\Downloads\jre-6u45-windows-x64.exe
2014-03-24 13:04 - 2013-07-31 19:34 - 00000000 ____D () C:\Users\User\AppData\Local\Spotify
2014-03-23 17:47 - 2014-02-03 20:43 - 00001637 _____ () C:\Users\Public\Desktop\World of Tanks.lnk
2014-03-22 20:07 - 2014-03-22 19:05 - 00000000 ____D () C:\Users\User\Documents\Battlefield Play4Free
2014-03-22 20:02 - 2013-08-24 08:59 - 00282104 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-03-22 20:02 - 2013-08-10 13:11 - 00282104 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-22 19:58 - 2013-08-10 13:11 - 00234768 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-03-22 19:57 - 2013-08-24 08:59 - 00000000 ____D () C:\Users\User\AppData\Local\PunkBuster
2014-03-22 13:51 - 2013-10-26 17:31 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Identity Safe
2014-03-21 17:58 - 2013-10-26 13:31 - 00000000 ____D () C:\Windows\system32\Drivers\NSTx64
2014-03-21 13:36 - 2013-07-23 20:35 - 00069560 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-21 13:34 - 2009-07-14 06:45 - 00315448 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-19 23:02 - 2014-03-19 23:02 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-03-19 23:02 - 2014-03-19 23:02 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-03-19 23:02 - 2014-03-19 23:02 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-03-19 23:02 - 2014-03-19 23:02 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-03-19 23:02 - 2014-03-19 23:02 - 00000000 ____D () C:\Program Files (x86)\Java
2014-03-19 23:02 - 2013-11-13 17:16 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-19 23:01 - 2014-03-19 23:01 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51 (3).exe
2014-03-19 22:58 - 2014-03-19 22:58 - 31714728 _____ (Oracle Corporation) C:\Users\User\Downloads\jre-7u25-windows-i586.exe
2014-03-19 22:57 - 2014-03-19 22:57 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall(1).exe
2014-03-19 22:56 - 2014-03-19 22:56 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall.exe
2014-03-19 22:56 - 2014-03-19 22:56 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51 (2).exe
2014-03-19 22:54 - 2014-03-19 22:54 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51 (1).exe
2014-03-19 22:52 - 2014-03-19 22:52 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u51.exe
2014-03-18 22:41 - 2013-07-23 22:12 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 22:36 - 2013-07-23 21:37 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-16 12:37 - 2014-02-06 19:51 - 00000000 ____D () C:\Users\User\Desktop\Bilder Handy
2014-03-16 12:18 - 2014-03-14 20:52 - 00000000 ____D () C:\Users\User\Desktop\Lukas Geuken Posts
2014-03-16 12:18 - 2013-12-28 23:58 - 00000000 ____D () C:\Users\User\Desktop\Server Allgemein
2014-03-16 12:18 - 2013-10-28 19:57 - 00000000 ____D () C:\Users\User\Desktop\Schule
2014-03-12 21:09 - 2014-03-12 21:09 - 00069168 _____ () C:\Users\User\AppData\Roaming\GDIPFONTCACHEV1.DAT
2014-03-12 20:04 - 2014-03-12 20:04 - 05777288 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-03-12 20:04 - 2013-07-25 19:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 20:04 - 2013-07-25 19:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-12 20:04 - 2013-07-25 19:22 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-07 23:07 - 2014-03-02 14:15 - 00000000 ____D () C:\Users\User\Desktop\Neuer Ordner
Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 13:11
==================== End Of Log ============================ --- --- ---
--- --- --- |