Meister G. | 27.04.2014 19:31 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.04.2014
Suchlauf-Zeit: 19:58:46
Logdatei: mbam.txt
Administrator: Nein
Version: 2.00.1.1004
Malware Datenbank: v2014.04.27.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Michael
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 191183
Verstrichene Zeit: 5 Min, 32 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 2
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799],
Registrierungsschlüssel: 6
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [86cb63cc68130d29b0af03a512f157a9],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, Löschen bei Neustart, [f958ae81b5c6ba7cfa6d97e2df236997],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [4908949b631874c28ed1b1f74db6f010],
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, Löschen bei Neustart, [1a37111ebcbf33030618e69da75b8c74],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 6
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572),Löschen bei Neustart,[72df60cfbfbcd2649f18012662a242be]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Löschen bei Neustart,[80d18ba4a2d9a690c32543ee2cd87888]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572&q={searchTerms}),Löschen bei Neustart,[e76a979888f3ba7c8f2687a060a4ed13]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572),Löschen bei Neustart,[e56c131c473446f0feb569beb4508878]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398473747&from=exp&uid=SAMSUNGXHD103SM_S2PDJ9EB900572),Löschen bei Neustart,[193833fcaccfe84ef0c724035ea6ad53]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Löschen bei Neustart,[a5aca48b96e53bfb3cac08294eb6669a]
Ordner: 27
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader, Löschen bei Neustart, [dd74d956007bd06620f0b4e63fc42ad6],
PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\language, Löschen bei Neustart, [dd74d956007bd06620f0b4e63fc42ad6],
Dateien: 63
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [96bb002f7cff64d2420b1e171ce46799],
PUP.Optional.YourFileDownloader, C:\Users\Michael\Downloads\YourFile_downloader.exe, In Quarantäne, [73deff30dc9f072f6d99f42aa25e4cb4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, Löschen bei Neustart, [e66b40ef156670c65ec34c37986aac54],
PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\htmlayout.dll, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6],
PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\Downloader.exe, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6],
PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\uninstall.exe, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6],
PUP.Optional.YourfileDownloader.A, C:\Program Files (x86)\YourFileDownloader\YourFile.exe, In Quarantäne, [dd74d956007bd06620f0b4e63fc42ad6],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.204 - Bericht erstellt am 27/04/2014 um 20:05:07
# Aktualisiert 26/04/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Ich ohne Admin - MICHAEL-PC
# Gestartet von : C:\Users\Michael\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : IePluginService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Program Files (x86)\yourfiledownloader
Ordner Gelöscht : C:\Users\Ich ohne Admin\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Ich ohne Admin\AppData\Roaming\yourfiledownloader
Datei Gelöscht : C:\Users\Ich ohne Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\lollipop.lnk
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
Schlüssel Gelöscht : HKCU\Software\Classes\Applications\lollipop.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\webssearchesSoftware
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\Software\YourFileDownloader
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\YourFileDownloader
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
*************************
AdwCleaner[R0].txt - [4547 octets] - [27/04/2014 20:04:36]
AdwCleaner[S0].txt - [3703 octets] - [27/04/2014 20:05:07]
########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [3763 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Ich ohne Admin on 27.04.2014 at 20:10:28,60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.04.2014 at 20:13:58,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 01
Ran by Michael (ATTENTION: The logged in user is not administrator) on MICHAEL-PC on 27-04-2014 20:18:02
Running from C:\Users\Michael\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
() C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_13_0_0_182_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-01-12] (Google Inc.)
HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SecureBanking] => C:\Program Files (x86)\Secure Banking\SecureBanking.exe
HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-3315472771-574270051-2816021824-1000\...\MountPoints2: D - D:\AutoRun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF0375161D297CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Michael\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ []
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [994360 2011-10-14] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [399416 2011-10-14] (Secunia)
==================== Drivers (Whitelisted) ====================
S3 athrusb; C:\Windows\System32\DRIVERS\athrxusb.sys [1075712 2008-07-29] (Atheros Communications, Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-04-06] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32000 2013-05-04] ()
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-04-06] ()
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U0 Partizan; system32\drivers\Partizan.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-27 20:09 - 2014-04-27 20:09 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe
2014-04-27 20:04 - 2014-04-27 20:05 - 00000000 ____D () C:\AdwCleaner
2014-04-27 20:03 - 2014-04-27 20:04 - 01329501 _____ () C:\Users\Michael\Desktop\adwcleaner.exe
2014-04-27 19:49 - 2014-04-27 19:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-27 19:48 - 2014-04-27 19:48 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-27 19:48 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-27 19:48 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-27 19:48 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-27 19:45 - 2014-04-27 19:47 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieUserList
2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieSiteList
2014-04-27 03:00 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-27 03:00 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-27 03:00 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-27 03:00 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-27 03:00 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-27 03:00 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-27 03:00 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-27 03:00 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-27 03:00 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-27 03:00 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-27 03:00 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-27 03:00 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-27 03:00 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-27 03:00 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-27 03:00 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-27 03:00 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-27 03:00 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-27 03:00 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-27 03:00 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-27 03:00 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-27 03:00 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-27 03:00 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-27 03:00 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-27 03:00 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-27 03:00 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-27 03:00 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-27 03:00 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-27 03:00 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-27 03:00 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-27 03:00 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-27 03:00 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-27 03:00 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-27 03:00 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-27 03:00 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-27 03:00 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-27 03:00 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-27 03:00 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-27 03:00 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-27 03:00 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-27 03:00 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-27 03:00 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-27 03:00 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-27 03:00 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-27 03:00 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-27 03:00 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-27 03:00 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-27 03:00 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-27 03:00 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-26 21:11 - 2014-04-27 19:38 - 00000250 _____ () C:\Windows\SYSTEMLOGPARTIZAN.EXE
2014-04-26 20:47 - 2014-04-26 20:47 - 00021931 _____ () C:\ComboFix.txt
2014-04-26 20:40 - 2014-04-26 20:47 - 00000000 ____D () C:\Qoobox
2014-04-26 20:40 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-26 20:40 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-26 20:40 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-26 20:40 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-26 20:40 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-26 20:40 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-26 20:40 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-26 20:40 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-26 20:39 - 2014-04-26 20:46 - 00000000 ____D () C:\Windows\erdnt
2014-04-26 20:37 - 2014-04-26 20:37 - 05196309 ____R (Swearware) C:\Users\Michael\Desktop\ComboFix.exe
2014-04-26 18:11 - 2014-04-26 18:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DD052F0D-B654-45FF-8BED-04F98063DBC3}
2014-04-26 11:21 - 2014-04-26 11:21 - 00000000 ____D () C:\Users\Michael\AppData\Local\{860BFC87-A6D8-4AFC-91F8-750932FF51E4}
2014-04-26 10:44 - 2014-04-26 10:44 - 00032697 _____ () C:\Users\Michael\Desktop\Addition.txt
2014-04-26 10:43 - 2014-04-27 20:18 - 00011034 _____ () C:\Users\Michael\Desktop\FRST.txt
2014-04-26 10:41 - 2014-04-27 20:18 - 00000000 ____D () C:\FRST
2014-04-26 10:40 - 2014-04-26 10:41 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe
2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2
2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe
2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI
2014-04-26 03:22 - 2014-04-27 19:43 - 00000000 ____D () C:\Program Files (x86)\UnHackMe
2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat
2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT
2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT
2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender
2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache
2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender
2014-04-26 02:56 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\WPM
2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader
2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater
2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403}
2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154}
2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111}
2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930}
2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725}
2014-04-23 09:04 - 2014-04-23 09:05 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C}
2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC}
2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6}
2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3}
2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A}
2014-04-20 09:37 - 2014-04-20 09:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352}
2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3}
2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2}
2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028}
2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188}
2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B}
2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102
2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip
2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip
2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F}
2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C}
2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8}
2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075}
2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe
2014-04-11 22:32 - 2014-04-11 22:35 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe
2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611}
2014-04-10 16:38 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 16:38 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-10 16:38 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-10 16:38 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-10 16:38 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-10 16:38 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-10 16:38 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-10 16:38 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-10 16:38 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-10 16:38 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-10 16:38 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-10 16:38 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-10 16:38 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-10 16:38 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-10 16:38 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-10 16:38 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-10 16:38 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0}
2014-04-07 17:28 - 2014-04-07 17:29 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8}
2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24}
2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC}
2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14}
2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01}
2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C}
2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B}
2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\Windows\SysWOW64\C2MP
2014-03-30 19:35 - 2014-03-30 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack
2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe
2014-03-30 18:33 - 2014-04-09 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor
2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip
2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859}
2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862}
2014-03-28 18:24 - 2014-03-28 18:24 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52E18A02-578D-4E68-B51A-2E678315822A}
==================== One Month Modified Files and Folders =======
2014-04-27 20:18 - 2014-04-26 10:43 - 00011034 _____ () C:\Users\Michael\Desktop\FRST.txt
2014-04-27 20:18 - 2014-04-26 10:41 - 00000000 ____D () C:\FRST
2014-04-27 20:17 - 2012-01-03 22:43 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-27 20:13 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-27 20:13 - 2009-07-14 06:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-27 20:09 - 2014-04-27 20:09 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe
2014-04-27 20:06 - 2012-03-06 21:39 - 00104444 _____ () C:\Windows\setupact.log
2014-04-27 20:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-27 20:05 - 2014-04-27 20:04 - 00000000 ____D () C:\AdwCleaner
2014-04-27 20:05 - 2012-04-03 21:23 - 00179190 _____ () C:\Windows\PFRO.log
2014-04-27 20:05 - 2011-10-31 15:07 - 01342461 _____ () C:\Windows\WindowsUpdate.log
2014-04-27 20:04 - 2014-04-27 20:03 - 01329501 _____ () C:\Users\Michael\Desktop\adwcleaner.exe
2014-04-27 19:51 - 2014-04-27 19:49 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-27 19:48 - 2014-04-27 19:48 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-27 19:48 - 2014-04-27 19:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-27 19:48 - 2013-07-02 04:15 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-27 19:47 - 2014-04-27 19:45 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-27 19:43 - 2014-04-26 03:22 - 00000000 ____D () C:\Program Files (x86)\UnHackMe
2014-04-27 19:42 - 2012-01-03 22:43 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-27 19:38 - 2014-04-26 21:11 - 00000250 _____ () C:\Windows\SYSTEMLOGPARTIZAN.EXE
2014-04-27 16:13 - 2012-12-31 20:08 - 00000936 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000UA.job
2014-04-27 15:30 - 2013-12-10 21:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieUserList
2014-04-27 12:00 - 2014-04-27 12:00 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieSiteList
2014-04-27 03:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-26 21:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-26 21:15 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-26 21:12 - 2013-06-01 09:27 - 00002182 _____ () C:\Windows\Sandboxie.ini
2014-04-26 20:47 - 2014-04-26 20:47 - 00021931 _____ () C:\ComboFix.txt
2014-04-26 20:47 - 2014-04-26 20:40 - 00000000 ____D () C:\Qoobox
2014-04-26 20:47 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-26 20:46 - 2014-04-26 20:39 - 00000000 ____D () C:\Windows\erdnt
2014-04-26 20:46 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-26 20:37 - 2014-04-26 20:37 - 05196309 ____R (Swearware) C:\Users\Michael\Desktop\ComboFix.exe
2014-04-26 18:11 - 2014-04-26 18:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DD052F0D-B654-45FF-8BED-04F98063DBC3}
2014-04-26 11:21 - 2014-04-26 11:21 - 00000000 ____D () C:\Users\Michael\AppData\Local\{860BFC87-A6D8-4AFC-91F8-750932FF51E4}
2014-04-26 10:44 - 2014-04-26 10:44 - 00032697 _____ () C:\Users\Michael\Desktop\Addition.txt
2014-04-26 10:41 - 2014-04-26 10:40 - 02061824 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe
2014-04-26 03:31 - 2014-04-26 03:31 - 00000000 ____D () C:\Users\Michael\Documents\RegRun2
2014-04-26 03:27 - 2014-04-26 03:27 - 00040720 _____ (Greatis Software) C:\Windows\system32\Partizan.exe
2014-04-26 03:27 - 2014-04-26 03:27 - 00000069 _____ () C:\Windows\SysWOW64\Partizan.RRI
2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\winstart.bat
2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\CONFIG.NT
2014-04-26 03:22 - 2014-04-26 03:22 - 00000002 RSHOT () C:\Windows\SysWOW64\AUTOEXEC.NT
2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\HitsBlender
2014-04-26 03:00 - 2014-04-26 03:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\cache
2014-04-26 02:59 - 2014-04-26 02:59 - 00000000 ____D () C:\ProgramData\HitsBlender
2014-04-26 02:59 - 2014-04-26 02:56 - 00000000 ____D () C:\ProgramData\WPM
2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader
2014-04-26 02:55 - 2014-04-26 02:55 - 00000000 ____D () C:\Program Files (x86)\YourFileDownloader Updater
2014-04-26 02:16 - 2014-04-26 02:16 - 00000000 ____D () C:\Users\Michael\AppData\Local\{47663AA9-FDFA-4ED9-B9A1-4939F7505403}
2014-04-24 23:18 - 2014-04-24 23:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{03D1AF08-20D5-44BE-9539-CB92C3437154}
2014-04-24 23:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\Users\Michael\Documents\MailStore Home
2014-04-24 00:47 - 2013-05-27 06:16 - 00000000 ____D () C:\ProgramData\firebird
2014-04-24 00:02 - 2014-04-24 00:02 - 00000000 ____D () C:\Users\Michael\AppData\Local\{66261FFB-BE6E-4B14-AA7D-8A8262D22111}
2014-04-23 23:47 - 2014-04-23 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{A074E29D-3EF4-4456-992F-CACC159A3930}
2014-04-23 21:42 - 2014-04-23 21:42 - 00000000 ____D () C:\Users\Michael\AppData\Local\{AD40A25F-C0C8-4348-8088-3C19109D9725}
2014-04-23 19:13 - 2012-12-31 20:08 - 00000914 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3315472771-574270051-2816021824-1000Core.job
2014-04-23 09:05 - 2014-04-23 09:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BC68CFDE-14C7-429E-8269-95DF1501C05C}
2014-04-23 00:28 - 2014-04-23 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BFFFF421-ABBA-455D-B1E9-C83DF00039AC}
2014-04-22 11:52 - 2014-04-22 11:52 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C4C5A266-7A6B-4CD1-AD85-71847CF208F6}
2014-04-22 00:57 - 2014-04-22 00:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{F9E24C82-BB24-4428-AB49-746B3F3491E3}
2014-04-21 10:39 - 2014-04-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\{04A41303-4920-4F5F-B120-E857B931196A}
2014-04-20 09:38 - 2014-04-20 09:37 - 00000000 ____D () C:\Users\Michael\AppData\Local\{496EF629-A343-4B2E-98F5-7CC5A452A352}
2014-04-20 09:38 - 2009-07-14 19:58 - 00699884 _____ () C:\Windows\system32\perfh007.dat
2014-04-20 09:38 - 2009-07-14 19:58 - 00149766 _____ () C:\Windows\system32\perfc007.dat
2014-04-20 09:38 - 2009-07-14 07:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-18 23:36 - 2014-04-18 23:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D80554E0-B0EE-4C45-A450-41B1E3F44AC3}
2014-04-17 14:57 - 2014-04-17 14:57 - 00000000 ____D () C:\Users\Michael\AppData\Local\{1104AB4F-05D3-4BC3-86AD-62E0A0C20DF2}
2014-04-17 10:40 - 2014-04-17 10:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D143958E-F844-497D-B35E-8C713DF95028}
2014-04-16 12:19 - 2014-04-16 12:19 - 00000000 ____D () C:\Users\Michael\AppData\Local\{33ACB63E-55B8-4E05-8DD6-1D67A4F34188}
2014-04-15 19:18 - 2014-04-15 19:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\{BD459534-7D52-485F-9B69-020A2989BD1B}
2014-04-14 13:18 - 2014-04-14 13:18 - 00004608 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-14 13:13 - 2014-04-14 13:13 - 00000000 ____D () C:\Users\Michael\Documents\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_{{Erstellt_am}}-20140414130102
2014-04-14 13:11 - 2014-04-14 13:11 - 00002155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-04-14 13:11 - 2014-04-14 13:11 - 00002149 _____ () C:\Users\Public\Desktop\WinZip.lnk
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\WinZip
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\WinZip
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-04-14 13:11 - 2014-04-14 13:11 - 00000000 ____D () C:\Program Files\WinZip
2014-04-14 13:11 - 2011-10-31 15:13 - 00000000 ____D () C:\Users\Michael
2014-04-14 13:11 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-14 13:01 - 2014-04-14 13:01 - 02338911 _____ () C:\Users\Michael\Downloads\NW-Bad_Oeynhausen_HRB_9269+Gesellschaftsvertrag_-_Satzung_-_Statut_vom_15052012-20140414130102.zip
2014-04-14 12:48 - 2014-04-14 12:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{86895126-1069-4034-8D26-308A2BF2508F}
2014-04-13 11:02 - 2011-10-31 16:21 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\SoftGrid Client
2014-04-13 11:01 - 2014-04-13 11:01 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52EAC000-7F2F-42B0-AEEB-037BCA86179C}
2014-04-13 07:19 - 2013-12-10 21:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-13 07:19 - 2013-12-10 21:28 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-13 07:17 - 2014-04-13 07:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\{9D063EF5-BD64-4577-B392-52E98A8CD2C8}
2014-04-11 22:47 - 2014-04-11 22:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\{6E262FC2-04DA-48ED-8854-0AC285AEE075}
2014-04-11 22:36 - 2014-04-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Password Safe
2014-04-11 22:35 - 2014-04-11 22:32 - 11831576 _____ () C:\Users\Michael\Downloads\pwsafe-3.33.exe
2014-04-11 21:22 - 2013-10-17 23:33 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-10 19:15 - 2013-08-15 16:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 19:14 - 2011-10-31 17:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-10 16:40 - 2014-04-10 16:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\{DCC49992-3362-4D68-81E9-DD3DD9A91611}
2014-04-09 21:00 - 2014-04-09 21:00 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E44856CE-B529-44AE-B755-7A9BB9A7D0D0}
2014-04-09 18:26 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSDoctor
2014-04-07 17:29 - 2014-04-07 17:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\{D692A561-1307-4025-9CA0-A48C34F592F8}
2014-04-06 15:04 - 2014-04-06 15:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9EE7DDD-E1F3-4F03-BA01-1BE58B09AE24}
2014-04-06 02:06 - 2014-04-06 02:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E846459F-3CE1-4E01-A716-4C42FFA86DBC}
2014-04-03 09:51 - 2014-04-27 19:48 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-27 19:48 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-27 19:48 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 18:20 - 2014-04-02 18:20 - 00000000 ____D () C:\Users\Michael\AppData\Local\{60CCF20F-85BF-4901-8735-646CD45ECB14}
2014-04-02 18:04 - 2014-04-02 18:04 - 00000000 ____D () C:\Users\Michael\AppData\Local\{368B3626-9DF9-4CCD-94E2-AA707A380A01}
2014-04-02 11:23 - 2011-10-31 15:40 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google
2014-04-01 23:09 - 2014-04-01 23:09 - 00000000 ____D () C:\Users\Michael\AppData\Local\{3AD3D4AE-A019-45E3-93D6-D45BA041676C}
2014-03-30 19:48 - 2014-03-30 19:48 - 00000000 ____D () C:\Users\Michael\AppData\Local\{C981A33B-DCE8-414B-A8A0-B45BBE291D8B}
2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\Windows\SysWOW64\C2MP
2014-03-30 19:36 - 2014-03-30 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack
2014-03-30 18:49 - 2014-03-30 18:49 - 07346008 _____ (www.cypheros.de) C:\Users\Michael\Downloads\TSDoctor_Ger.exe
2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
2014-03-30 00:43 - 2014-03-30 00:43 - 10880816 _____ () C:\Users\Michael\Downloads\Worldmap_Tetsuya_2.1.zip
2014-03-29 15:45 - 2014-03-29 15:45 - 00000000 ____D () C:\Users\Michael\AppData\Local\{32316837-C654-42F3-AD47-5E6FFEF39859}
2014-03-29 15:38 - 2014-03-29 15:38 - 00000000 ____D () C:\Users\Michael\AppData\Local\{E9752100-0F2E-4B97-A8D6-B746D45A4862}
2014-03-28 18:24 - 2014-03-28 18:24 - 00000000 ____D () C:\Users\Michael\AppData\Local\{52E18A02-578D-4E68-B51A-2E678315822A}
Some content of TEMP:
====================
C:\Users\Michael\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- |