Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 19.05.2014
Suchlauf-Zeit: 20:22:49
Logdatei: mbam-scan-19-05-2014.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.19.09
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: FLOPPY
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 348283
Verstrichene Zeit: 26 Min, 59 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\RrFilterService64.exe, 2612, Löschen bei Neustart, [69dc2f247cff2610958b8af4887ad62a]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 26
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\net, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\net.5.14, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\net, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\net.5.14, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{94CB3B6C-CB46-9C69-21A3-E9D62B9E883A}\INPROCSERVER32, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dc69b1a2e4973afceb8a77b02ed43cc4],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dc69b1a2e4973afceb8a77b02ed43cc4],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dc69b1a2e4973afceb8a77b02ed43cc4],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dc69b1a2e4973afceb8a77b02ed43cc4],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\Rr Savings, In Quarantäne, [65e0391a7ffc69cd53b6dab10af8639d],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, In Quarantäne, [59ec1340f487f93daf5b0b80867cc43c],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{813BA625-B0FA-48D8-9B75-59759C88C219}, In Quarantäne, [fb4a183b3843999db3bd6522ac569d63],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RrSavings, In Quarantäne, [f74e0d4683f83afc5fad6427649e09f7],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Rr Savings, In Quarantäne, [61e45af9ccafd16522eeaae1748e3fc1],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\rrsavings, In Quarantäne, [430288cb26553ef83ad5276428da38c8],
PUP.Optional.WebSearchInfo, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [bb8aa3b0c4b790a634974181b35040c0],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [e560d281562544f2ab4f96f66a98e41c],
PUP.Optional.RRSavings.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RrFilterService64, In Quarantäne, [69dc2f247cff2610958b8af4887ad62a],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Conduit.A, HKU\S-1-5-21-3435828442-162049101-3775305515-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=M2E93ADB8-E83F-48CB-A3B8-EEB07BCD9A6A&SearchSource=55&CUI=&UM=5&UP=SP359BB479-5022-4142-9A4B-12CD81A52285&SSPV=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.conduit.com/?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=M2E93ADB8-E83F-48CB-A3B8-EEB07BCD9A6A&SearchSource=55&CUI=&UM=5&UP=SP359BB479-5022-4142-9A4B-12CD81A52285&SSPV=),Ersetzt,[53f275de2d4e1026a3f679cbfb09f10f]
Ordner: 4
PUP.Optional.YoutubeAdblocker.A, C:\ProgramData\YoutubeAdblocker, In Quarantäne, [c97c5201e398e056a0010d6951b1a957],
PUP.Optional.RRSavings.A, C:\Program Files\rrsavings, In Quarantäne, [d76e2c271269d561908f94ea976b8b75],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter, Löschen bei Neustart, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\SSL, In Quarantäne, [69dc2f247cff2610958b8af4887ad62a],
Dateien: 21
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\sAve! net\WyfjwWMh.x64.dll, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\sAve! net\WyfjwWMh.dll, In Quarantäne, [fa4b440f3546bd793dce3515b54ca957],
PUP.Optional.CouponDownloader.A, C:\Program Files (x86)\Rr Savings\RrSavings.dll, In Quarantäne, [dc69b1a2e4973afceb8a77b02ed43cc4],
PUP.Optional.RegCleanPro, C:\Users\FLOPPY\Downloads\rcpsetup_matomyil_myil442191.exe, In Quarantäne, [8bbab0a3601b0432a6e4231137c94ab6],
PUP.Optional.LiveLyrics.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.livelyrics00.live-lyrics.com_0.localstorage, In Quarantäne, [b590391abdbeb680c15c87fcee1411ef],
PUP.Optional.LiveLyrics.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.livelyrics00.live-lyrics.com_0.localstorage-journal, In Quarantäne, [7fc6163d1c5f7cba7f9e7a09ef131fe1],
PUP.Optional.Trovi.A, C:\Users\FLOPPY\AppData\Roaming\Mozilla\Firefox\Profiles\xl13wikb.default\searchplugins\trovi-search.xml, In Quarantäne, [7dc8e76c7407b87e9ec22560d82af10f],
PUP.Optional.LiveLyrics.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage, In Quarantäne, [c2833f14b8c3ca6c8bd77d081de5fe02],
PUP.Optional.LiveLyrics.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage-journal, In Quarantäne, [ac994b08017ab1852141dbaa91718a76],
PUP.Optional.Superfish.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [6ed75201de9d35019dc6f78e45bded13],
PUP.Optional.Superfish.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [56ef143faad124127ae91075a0620ef2],
PUP.Optional.Conduit.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.conduit.com_0.localstorage, In Quarantäne, [f055d1826a11cf67ba99d6b0ff03f010],
PUP.Optional.Conduit.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.conduit.com_0.localstorage-journal, In Quarantäne, [93b2ff547308c373f85be89eeb1758a8],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Installbat64.dll, In Quarantäne, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\nfapi.dll, Löschen bei Neustart, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\ProtocolFilters.dll, Löschen bei Neustart, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\RrFilterService64.exe, Löschen bei Neustart, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\sample.dll, In Quarantäne, [69dc2f247cff2610958b8af4887ad62a],
PUP.Optional.Conduit.A, C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "search_url": "hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=M2E93ADB8-E83F-48CB-A3B8-EEB07BCD9A6A&SearchSource=58&CUI=&UM=5&UP=SP359BB479-5022-4142-9A4B-12CD81A52285&q={searchTerms}&SSPV=",), Ersetzt,[9ea76ce7bdbebd790187cab19173e61a]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.210 - Bericht erstellt am 19/05/2014 um 20:43:36
# Aktualisiert 19/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : FLOPPY - FLOPPY-PC
# Gestartet von : C:\Users\FLOPPY\Downloads\adwcleaner_3.210.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\SNT
Ordner Gelöscht : C:\Program Files (x86)\Rr Savings
Ordner Gelöscht : C:\Program Files (x86)\SNT
Ordner Gelöscht : C:\Program Files (x86)\SW-Booster
Ordner Gelöscht : C:\Program Files (x86)\Toolbar Cleaner
Ordner Gelöscht : C:\Windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}
Ordner Gelöscht : C:\Program Files\002
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Local\torch
Ordner Gelöscht : C:\Users\FLOPPY\AppData\LocalLow\adawaretb
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Roaming\EZDownloader
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch
Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\torch
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\torch
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Roaming\Mozilla\Firefox\Profiles\xl13wikb.default\adawaretb
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bogkibnlaccdnmncohleiojlonaniedk
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bogkibnlaccdnmncohleiojlonaniedk
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bogkibnlaccdnmncohleiojlonaniedk
Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bogkibnlaccdnmncohleiojlonaniedk
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bogkibnlaccdnmncohleiojlonaniedk
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhfmobpmbmamakmailbgpehikbcgmnj
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhfmobpmbmamakmailbgpehikbcgmnj
Ordner Gelöscht : C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\kofjjfgnmnjmoihhmjpafcllkhinmboe
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\conduit.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_7-zip_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_7-zip_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Schlüssel Gelöscht : HKCU\Software\RegisteredApplicationsEx
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawarebp
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawaretb
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Schlüssel Gelöscht : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Schlüssel Gelöscht : HKLM\Software\adawaretb
Schlüssel Gelöscht : HKLM\Software\SW-Booster
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3566FB70-E722-4182-8266-815EAE862998}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\07BF6653227E2814286618E5EA689289
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\07BF6653227E2814286618E5EA689289
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\FLOPPY\AppData\Roaming\Mozilla\Firefox\Profiles\xl13wikb.default\prefs.js ]
-\\ Google Chrome v34.0.1847.131
[ Datei : C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=M2E93ADB8-E83F-48CB-A3B8-EEB07BCD9A6A&SearchSource=58&CUI=&UM=5&UP=SP359BB479-5022-4142-9A4B-12CD81A52285&q={searchTerms}&SSPV=
Gelöscht [Search Provider] : hxxp://websearch.amaizingsearches.info/?l=1&q={searchTerms}&pid=2832&r=2014/04/27&hid=5828101733941526718&lg=EN&cc=DE&unqvl=51
Gelöscht [Extension] : bogkibnlaccdnmncohleiojlonaniedk
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : bopakagnckmlgajfccecajhnimjiiedh
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : kofjjfgnmnjmoihhmjpafcllkhinmboe
Gelöscht [Extension] : obhfmobpmbmamakmailbgpehikbcgmnj
*************************
AdwCleaner[R0].txt - [8431 octets] - [19/05/2014 20:37:43]
AdwCleaner[S0].txt - [7955 octets] - [19/05/2014 20:43:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8015 octets] ########## Code:
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by FLOPPY on 19.05.2014 at 20:53:06,80
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\FLOPPY\appdata\local\{11ADAE97-4CB8-400F-A992-A920B627BCA2}
Successfully deleted: [Empty Folder] C:\Users\FLOPPY\appdata\local\{590EB2D2-819A-4CF9-92A2-F9E88F96E148}
~~~ FireFox
Successfully deleted: [Folder] C:\Users\FLOPPY\AppData\Roaming\mozilla\firefox\profiles\xl13wikb.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
Successfully deleted the following from C:\Users\FLOPPY\AppData\Roaming\mozilla\firefox\profiles\xl13wikb.default\prefs.js
user_pref("keyword.URL", "hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q=");
Emptied folder: C:\Users\FLOPPY\AppData\Roaming\mozilla\firefox\profiles\xl13wikb.default\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.05.2014 at 21:04:35,09
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und hier noch die FRST. Schaut gut aus!!
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by FLOPPY (administrator) on FLOPPY-PC on 19-05-2014 21:09:29
Running from C:\Users\FLOPPY\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Hercules®) C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Spotify Ltd) C:\Users\FLOPPY\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Users\FLOPPY\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
(Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE
(Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(Dropbox, Inc.) C:\Users\FLOPPY\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe
(Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\cpl2\HDJSeries2CPL.exe
(Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated)
HKLM\...\Run: [Power Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\...\Run: [OOTag] => C:\Program Files (x86)\Packard Bell\OOBEOffer\ootag.exe [13856 2010-02-23] (Microsoft)
HKLM\...\Run: [Hercules DJ Series TrayAgent] => C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe [3572048 2013-05-10] (Hercules®)
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe [4114264 2014-01-23] ()
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [OOTag] => C:\Program Files (x86)\Packard Bell\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [EKStatusMonitor] => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe [2750840 2013-01-15] (Eastman Kodak Company)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft)
HKLM-x32\...\Run: [Conime] => %windir%\system32\conime.exe
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3435828442-162049101-3775305515-1002\...\Run: [Spotify] => C:\Users\FLOPPY\AppData\Roaming\Spotify\Spotify.exe [5951488 2013-12-22] (Spotify Ltd)
HKU\S-1-5-21-3435828442-162049101-3775305515-1002\...\Run: [Spotify Web Helper] => C:\Users\FLOPPY\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-22] (Spotify Ltd)
HKU\S-1-5-21-3435828442-162049101-3775305515-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-3435828442-162049101-3775305515-1002\...\Run: [Amazon Cloud Player] => C:\Users\FLOPPY\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3168576 2014-03-07] ()
HKU\S-1-5-21-3435828442-162049101-3775305515-1002\...\Run: [GoogleChromeAutoLaunch_B730D1ADEAF585236182F5039200F418] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032 2014-04-24] (Google Inc.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [241984 2011-11-27] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll => c:\Windows\SysWOW64\nvinit.dll [203072 2011-11-27] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\FLOPPY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\FLOPPY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM {AA570693-00E2-4907-B6F1-60A1199B030C} https://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://webzugang.brnet.de/dana-cached/sc/JuniperSetupClient.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\FLOPPY\AppData\Roaming\Mozilla\Firefox\Profiles\xl13wikb.default
FF DefaultSearchEngine: Trovi search
FF SelectedSearchEngine: Trovi search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\FLOPPY\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\FLOPPY\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn\
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn\ []
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn\ []
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-04-27]
Chrome:
=======
CHR HomePage: https://www.google.de/
CHR StartupUrls: "hxxp://google.de/"
CHR DefaultSearchKeyword: trovi.search
CHR DefaultSearchProvider: Trovi search
CHR DefaultSearchURL: hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=M2E93ADB8-E83F-48CB-A3B8-EEB07BCD9A6A&SearchSource=58&CUI=&UM=5&UP=SP359BB479-5022-4142-9A4B-12CD81A52285&q={searchTerms}&SSPV=
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-07]
CHR Extension: (Google Drive) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-07]
CHR Extension: (YouTube) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-07]
CHR Extension: (Google Cast) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-04-19]
CHR Extension: (No Name) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bogkibnlaccdnmncohleiojlonaniedk [2014-04-27]
CHR Extension: (No Name) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-21]
CHR Extension: (Google-Suche) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-07]
CHR Extension: (SNT) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdjabpeiljihoefbmgkcmhoafnldain [2014-04-27]
CHR Extension: (No Name) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\kofjjfgnmnjmoihhmjpafcllkhinmboe [2014-04-25]
CHR Extension: (Norton Identity Protection) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2013-05-07]
CHR Extension: (Google Wallet) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-13]
CHR Extension: (No Name) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhfmobpmbmamakmailbgpehikbcgmnj [2014-04-27]
CHR Extension: (Context Menu Search) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocpcmghnefmdhljkoiapafejjohldoga [2014-04-27]
CHR Extension: (Google Mail) - C:\Users\FLOPPY\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-07]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\Exts\Chrome.crx [2013-04-28]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-08-02] (Acer Incorporated)
R2 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [36456 2011-05-30] (Acer Incorporated)
R2 HerculesDJControlMP3; C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [47104 2013-05-21] (Hercules®)
R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe [702744 2014-01-23] ()
S2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [138272 2012-06-16] (Symantec Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
S3 Bulk; C:\Windows\System32\Drivers\HDJBulk.sys [258352 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [167072 2012-06-07] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-04-17] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-04-17] (Symantec Corporation)
S3 HDJMidi; C:\Windows\System32\DRIVERS\HDJMidi.sys [274736 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20130618.001\IDSvia64.sys [513184 2013-04-17] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20130618.022\ENG64.SYS [126040 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20130618.022\EX64.SYS [2098776 2013-05-22] (Symantec Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [61736 2014-02-28] (NetFilterSDK.com)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [737952 2012-07-06] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [37536 2012-07-06] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMDS64.SYS [451192 2011-05-16] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [1129120 2012-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2013-04-20] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [190072 2012-04-18] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [405624 2012-04-18] (Symantec Corporation)
R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [329800 2013-07-17] (BitDefender S.R.L.)
S3 X86BDA; C:\Windows\System32\DRIVERS\OEMDrv.sys [268416 2011-06-08] ( )
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 PCDSRVC{D368CD8C-F99229C4-06020200}_0; \??\c:\users\admini~1\appdata\local\temp\8h8grf8pg9jx\pcdrdiag\bin\pcdsrvc_x64.pkms [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-19 21:08 - 2014-05-19 21:08 - 00000000 ____D () C:\Users\FLOPPY\Downloads\FRST-OlderVersion
2014-05-19 21:04 - 2014-05-19 21:04 - 00001641 _____ () C:\Users\FLOPPY\Desktop\JRT.txt
2014-05-19 20:53 - 2014-05-19 20:53 - 00000000 ____D () C:\Windows\ERUNT
2014-05-19 20:38 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-19 20:37 - 2014-05-19 20:43 - 00000000 ____D () C:\AdwCleaner
2014-05-19 20:35 - 2014-05-19 20:35 - 00010691 _____ () C:\Users\FLOPPY\Desktop\mbam-scan-19-05-2014.txt
2014-05-19 20:11 - 2014-05-19 20:11 - 01326389 _____ () C:\Users\FLOPPY\Downloads\adwcleaner_3.210.exe
2014-05-19 20:11 - 2014-05-19 20:11 - 01016261 _____ (Thisisu) C:\Users\FLOPPY\Downloads\JRT.exe
2014-05-19 19:55 - 2014-05-19 20:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-19 19:54 - 2014-05-19 19:54 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-19 19:54 - 2014-05-19 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-19 19:54 - 2014-05-19 19:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 19:54 - 2014-05-19 19:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-19 19:54 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-19 19:54 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-19 19:54 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-19 19:52 - 2014-05-19 19:52 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\FLOPPY\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-16 18:51 - 2014-05-16 18:51 - 00000000 __SHD () C:\Users\FLOPPY\AppData\Local\EmieUserList
2014-05-16 18:51 - 2014-05-16 18:51 - 00000000 __SHD () C:\Users\FLOPPY\AppData\Local\EmieSiteList
2014-05-16 18:47 - 2014-05-16 18:47 - 00033242 _____ () C:\ComboFix.txt
2014-05-16 18:29 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-16 18:29 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-16 18:29 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-16 18:29 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-16 18:29 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-16 18:29 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-16 18:29 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-16 18:29 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-16 18:28 - 2014-05-16 18:47 - 00000000 ____D () C:\Qoobox
2014-05-16 18:28 - 2014-05-16 18:45 - 00000000 ____D () C:\Windows\erdnt
2014-05-16 18:27 - 2014-05-16 18:27 - 05200990 ____R (Swearware) C:\Users\FLOPPY\Desktop\ComboFix.exe
2014-05-16 18:17 - 2014-05-16 18:17 - 00000000 ____D () C:\Program Files (x86)\BiTSaver
2014-05-16 18:06 - 2014-05-16 18:06 - 00001276 _____ () C:\Users\FLOPPY\Desktop\Revo Uninstaller.lnk
2014-05-16 18:06 - 2014-05-16 18:06 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-16 18:05 - 2014-05-16 18:05 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\FLOPPY\Downloads\revosetup95.exe
2014-05-16 16:48 - 2014-05-16 16:48 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\DropboxMaster
2014-05-14 22:20 - 2014-05-14 22:21 - 00046504 _____ () C:\Users\FLOPPY\Downloads\Addition.txt
2014-05-14 22:19 - 2014-05-19 21:09 - 00023291 _____ () C:\Users\FLOPPY\Downloads\FRST.txt
2014-05-14 22:18 - 2014-05-19 21:09 - 00000000 ____D () C:\FRST
2014-05-14 22:17 - 2014-05-19 21:08 - 02067456 _____ (Farbar) C:\Users\FLOPPY\Downloads\FRST64.exe
2014-05-13 23:23 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-13 23:23 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-13 23:23 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-13 23:22 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-13 23:22 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-13 23:22 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-13 21:02 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-13 21:02 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-13 21:02 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-13 21:02 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 21:00 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-13 21:00 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-13 21:00 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-13 21:00 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-13 21:00 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-13 21:00 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-13 21:00 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-13 21:00 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-13 21:00 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-13 21:00 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-13 21:00 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-13 21:00 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-13 21:00 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-13 21:00 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-13 21:00 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-13 21:00 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-13 21:00 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-13 21:00 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-13 21:00 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-13 21:00 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-13 21:00 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 20:59 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-13 20:59 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-13 20:59 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-13 20:59 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-13 20:59 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-13 20:59 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-13 20:59 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-13 20:59 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-13 20:59 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-13 20:59 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-13 20:59 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-13 20:59 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-12 22:09 - 2014-05-12 22:09 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Lavasoft
2014-05-12 22:04 - 2014-05-12 22:04 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\LavasoftStatistics
2014-05-12 21:40 - 2014-05-19 20:49 - 00002317 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2014-05-12 21:40 - 2014-05-19 20:47 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection
2014-05-12 21:40 - 2014-05-12 21:40 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\adawarebp
2014-05-12 21:40 - 2014-05-12 21:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
2014-05-12 21:40 - 2014-05-12 21:40 - 00000000 ____D () C:\Program Files\Lavasoft
2014-05-12 21:39 - 2014-05-12 21:39 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2014-05-12 21:37 - 2014-05-12 21:37 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-05-12 21:36 - 2014-05-12 21:36 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-05-12 21:35 - 2014-05-12 21:35 - 01727624 _____ () C:\Users\FLOPPY\Downloads\Adaware_Installer_11.1.5354.exe
2014-05-12 21:33 - 2014-05-12 21:34 - 01325827 _____ () C:\Users\FLOPPY\Downloads\adwcleaner08.exe
2014-05-12 20:42 - 2014-05-12 20:42 - 00001171 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-12 20:42 - 2014-05-12 20:42 - 00001159 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-12 20:42 - 2014-05-12 20:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 20:41 - 2014-05-12 20:41 - 28852416 _____ (Mozilla) C:\Users\FLOPPY\Downloads\Firefox_Setup_de29.0.1.exe
2014-05-08 10:17 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-08 10:17 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-08 10:17 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-08 10:17 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-08 10:16 - 2014-05-14 22:05 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 10:16 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-08 10:16 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-08 10:16 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-08 10:16 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-08 10:16 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-08 10:16 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-08 10:16 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-08 10:16 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-08 10:16 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-08 10:16 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-08 10:16 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-08 10:16 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-08 10:16 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-08 10:16 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-08 10:16 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-08 10:16 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-08 10:16 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-08 10:16 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-08 10:16 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-08 10:16 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-08 10:16 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-08 10:16 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-08 10:16 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-08 10:16 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-08 10:16 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-08 10:16 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-08 10:16 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-08 10:16 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-08 10:16 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-08 10:16 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-08 10:16 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-08 10:16 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-08 10:16 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-08 10:16 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-08 10:16 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-08 10:16 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-08 10:16 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-08 10:16 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-08 10:16 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-08 10:16 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-06 19:57 - 2014-05-06 20:05 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\Windows Live
2014-05-06 19:53 - 2014-05-06 20:07 - 00000000 ____D () C:\Users\FLOPPY\Documents\06-05-2014
2014-04-29 23:42 - 2014-04-29 23:44 - 00000000 ____D () C:\Users\FLOPPY\Desktop\SOUND#33
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Gast
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-04-27 13:31 - 2014-05-19 20:22 - 00000000 ____D () C:\Program Files (x86)\sAve! net
2014-04-27 13:31 - 2014-05-19 19:56 - 00000000 ____D () C:\ProgramData\sAve! net
2014-04-27 13:31 - 2014-05-16 18:25 - 00000000 ____D () C:\ProgramData\fd55f1f9fbdbfd0a
2014-04-27 13:31 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-04-27 13:31 - 2014-04-27 13:31 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\Packages
2014-04-27 13:30 - 2014-04-27 13:32 - 00000000 ____D () C:\ProgramData\InstallMate
2014-04-25 23:49 - 2014-04-25 23:49 - 00001175 _____ () C:\Users\Public\Desktop\SoundCloud Downloader.lnk
2014-04-25 23:49 - 2014-04-25 23:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundCloud Downloader
2014-04-25 23:49 - 2014-04-25 23:49 - 00000000 ____D () C:\Program Files (x86)\SoundCloud Downloader
2014-04-25 23:48 - 2014-04-25 23:48 - 00929416 _____ (CNET Download.com) C:\Users\FLOPPY\Downloads\cbsidlm-cbsi188-SoundYum_SoundCloud_Downloader-BP-75992700.exe
2014-04-25 23:43 - 2014-04-25 23:43 - 00000000 ____D () C:\Users\FLOPPY\Documents\Verfügbarkeiten
2014-04-25 23:35 - 2014-04-25 23:35 - 01071360 _____ (Solid State Networks) C:\Users\FLOPPY\Downloads\install_flashplayer13x32axau_ltr5x64d_awc_aih(2).exe
2014-04-19 23:36 - 2014-04-19 23:38 - 01071360 _____ (Solid State Networks) C:\Users\FLOPPY\Downloads\install_flashplayer13x32axau_ltr5x64d_awc_aih(1).exe
2014-04-19 23:28 - 2014-05-12 20:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-19 17:19 - 2014-04-19 17:19 - 00001222 _____ () C:\Users\FLOPPY\Desktop\Chromecast.lnk
2014-04-19 17:18 - 2014-05-19 20:23 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002UA.job
2014-04-19 17:18 - 2014-05-16 17:23 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002Core.job
2014-04-19 17:18 - 2014-04-19 17:18 - 00884608 _____ (Google Inc.) C:\Users\FLOPPY\Downloads\chromecastinstaller.exe
2014-04-19 17:18 - 2014-04-19 17:18 - 00003884 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002UA
2014-04-19 17:18 - 2014-04-19 17:18 - 00003488 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002Core
2014-04-19 17:18 - 2014-04-19 17:18 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromecast
==================== One Month Modified Files and Folders =======
2014-05-19 21:09 - 2014-05-14 22:19 - 00023291 _____ () C:\Users\FLOPPY\Downloads\FRST.txt
2014-05-19 21:09 - 2014-05-14 22:18 - 00000000 ____D () C:\FRST
2014-05-19 21:08 - 2014-05-19 21:08 - 00000000 ____D () C:\Users\FLOPPY\Downloads\FRST-OlderVersion
2014-05-19 21:08 - 2014-05-14 22:17 - 02067456 _____ (Farbar) C:\Users\FLOPPY\Downloads\FRST64.exe
2014-05-19 21:04 - 2014-05-19 21:04 - 00001641 _____ () C:\Users\FLOPPY\Desktop\JRT.txt
2014-05-19 20:56 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-19 20:56 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-19 20:53 - 2014-05-19 20:53 - 00000000 ____D () C:\Windows\ERUNT
2014-05-19 20:50 - 2014-05-19 19:55 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-19 20:49 - 2014-05-12 21:40 - 00002317 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2014-05-19 20:49 - 2013-07-09 23:04 - 00000000 ___RD () C:\Users\FLOPPY\Dropbox
2014-05-19 20:49 - 2013-07-09 23:01 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Dropbox
2014-05-19 20:48 - 2013-04-17 22:51 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Spotify
2014-05-19 20:47 - 2014-05-12 21:40 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection
2014-05-19 20:47 - 2013-06-12 22:54 - 00000000 ____D () C:\ProgramData\Kodak
2014-05-19 20:46 - 2013-05-05 14:49 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-19 20:46 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-19 20:46 - 2009-07-14 06:51 - 00069450 _____ () C:\Windows\setupact.log
2014-05-19 20:45 - 2010-11-21 05:47 - 00199878 _____ () C:\Windows\PFRO.log
2014-05-19 20:44 - 2013-04-11 08:59 - 01460429 _____ () C:\Windows\WindowsUpdate.log
2014-05-19 20:43 - 2014-05-19 20:37 - 00000000 ____D () C:\AdwCleaner
2014-05-19 20:35 - 2014-05-19 20:35 - 00010691 _____ () C:\Users\FLOPPY\Desktop\mbam-scan-19-05-2014.txt
2014-05-19 20:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help
2014-05-19 20:23 - 2014-04-19 17:18 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002UA.job
2014-05-19 20:22 - 2014-04-27 13:31 - 00000000 ____D () C:\Program Files (x86)\sAve! net
2014-05-19 20:20 - 2013-05-05 14:49 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-19 20:19 - 2013-04-17 23:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-19 20:11 - 2014-05-19 20:11 - 01326389 _____ () C:\Users\FLOPPY\Downloads\adwcleaner_3.210.exe
2014-05-19 20:11 - 2014-05-19 20:11 - 01016261 _____ (Thisisu) C:\Users\FLOPPY\Downloads\JRT.exe
2014-05-19 19:56 - 2014-04-27 13:31 - 00000000 ____D () C:\ProgramData\sAve! net
2014-05-19 19:54 - 2014-05-19 19:54 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-19 19:54 - 2014-05-19 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-19 19:54 - 2014-05-19 19:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 19:54 - 2014-05-19 19:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-19 19:52 - 2014-05-19 19:52 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\FLOPPY\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-16 18:51 - 2014-05-16 18:51 - 00000000 __SHD () C:\Users\FLOPPY\AppData\Local\EmieUserList
2014-05-16 18:51 - 2014-05-16 18:51 - 00000000 __SHD () C:\Users\FLOPPY\AppData\Local\EmieSiteList
2014-05-16 18:47 - 2014-05-16 18:47 - 00033242 _____ () C:\ComboFix.txt
2014-05-16 18:47 - 2014-05-16 18:28 - 00000000 ____D () C:\Qoobox
2014-05-16 18:47 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-05-16 18:45 - 2014-05-16 18:28 - 00000000 ____D () C:\Windows\erdnt
2014-05-16 18:44 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-16 18:27 - 2014-05-16 18:27 - 05200990 ____R (Swearware) C:\Users\FLOPPY\Desktop\ComboFix.exe
2014-05-16 18:25 - 2014-04-27 13:31 - 00000000 ____D () C:\ProgramData\fd55f1f9fbdbfd0a
2014-05-16 18:17 - 2014-05-16 18:17 - 00000000 ____D () C:\Program Files (x86)\BiTSaver
2014-05-16 18:06 - 2014-05-16 18:06 - 00001276 _____ () C:\Users\FLOPPY\Desktop\Revo Uninstaller.lnk
2014-05-16 18:06 - 2014-05-16 18:06 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-16 18:05 - 2014-05-16 18:05 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\FLOPPY\Downloads\revosetup95.exe
2014-05-16 17:23 - 2014-04-19 17:18 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002Core.job
2014-05-16 16:50 - 2013-04-21 14:30 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-16 16:48 - 2014-05-16 16:48 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\DropboxMaster
2014-05-16 16:48 - 2013-07-09 23:04 - 00001033 _____ () C:\Users\FLOPPY\Desktop\Dropbox.lnk
2014-05-16 16:48 - 2013-07-09 23:03 - 00001024 _____ () C:\Windows\wininit.ini
2014-05-16 16:48 - 2013-07-09 23:02 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-16 16:48 - 2013-04-17 21:47 - 00000000 ___RD () C:\Users\FLOPPY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-14 22:21 - 2014-05-14 22:20 - 00046504 _____ () C:\Users\FLOPPY\Downloads\Addition.txt
2014-05-14 22:10 - 2013-04-17 21:47 - 00000000 ___RD () C:\Users\FLOPPY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 22:05 - 2014-05-08 10:16 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-13 23:22 - 2013-04-18 08:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-13 23:21 - 2013-09-25 17:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-13 23:19 - 2013-09-25 17:42 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 22:20 - 2013-04-17 23:29 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-13 22:20 - 2013-04-17 23:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 22:20 - 2012-03-29 16:55 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-13 21:20 - 2013-04-11 18:52 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-05-13 21:20 - 2013-04-11 18:52 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-05-13 21:20 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-12 22:09 - 2014-05-12 22:09 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Lavasoft
2014-05-12 22:04 - 2014-05-12 22:04 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\LavasoftStatistics
2014-05-12 21:40 - 2014-05-12 21:40 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\adawarebp
2014-05-12 21:40 - 2014-05-12 21:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
2014-05-12 21:40 - 2014-05-12 21:40 - 00000000 ____D () C:\Program Files\Lavasoft
2014-05-12 21:39 - 2014-05-12 21:39 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2014-05-12 21:37 - 2014-05-12 21:37 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-05-12 21:36 - 2014-05-12 21:36 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-05-12 21:35 - 2014-05-12 21:35 - 01727624 _____ () C:\Users\FLOPPY\Downloads\Adaware_Installer_11.1.5354.exe
2014-05-12 21:34 - 2014-05-12 21:33 - 01325827 _____ () C:\Users\FLOPPY\Downloads\adwcleaner08.exe
2014-05-12 20:43 - 2013-04-17 22:25 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Mozilla
2014-05-12 20:42 - 2014-05-12 20:42 - 00001171 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-12 20:42 - 2014-05-12 20:42 - 00001159 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-12 20:42 - 2014-05-12 20:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 20:42 - 2014-04-19 23:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-12 20:41 - 2014-05-12 20:41 - 28852416 _____ (Mozilla) C:\Users\FLOPPY\Downloads\Firefox_Setup_de29.0.1.exe
2014-05-12 20:31 - 2013-04-17 21:53 - 00000000 ____D () C:\Users\FLOPPY\Documents\On3On3On3
2014-05-09 08:14 - 2014-05-13 21:02 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-13 21:02 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 12:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-06 20:07 - 2014-05-06 19:53 - 00000000 ____D () C:\Users\FLOPPY\Documents\06-05-2014
2014-05-06 20:05 - 2014-05-06 19:57 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\Windows Live
2014-05-06 06:40 - 2014-05-13 23:23 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-13 23:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-13 23:22 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-13 23:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-13 23:23 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-13 23:23 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 22:16 - 2013-04-22 22:52 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Skype
2014-04-29 23:44 - 2014-04-29 23:42 - 00000000 ____D () C:\Users\FLOPPY\Desktop\SOUND#33
2014-04-28 09:08 - 2013-06-04 20:26 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\CrashDumps
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Gast
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-04-27 13:32 - 2014-04-27 13:31 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-04-27 13:32 - 2014-04-27 13:30 - 00000000 ____D () C:\ProgramData\InstallMate
2014-04-27 13:32 - 2013-05-05 14:49 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\Google
2014-04-27 13:31 - 2014-04-27 13:31 - 00000000 ____D () C:\Users\FLOPPY\AppData\Local\Packages
2014-04-27 13:31 - 2013-07-30 23:00 - 00000000 ____D () C:\Users\Administrator
2014-04-25 23:49 - 2014-04-25 23:49 - 00001175 _____ () C:\Users\Public\Desktop\SoundCloud Downloader.lnk
2014-04-25 23:49 - 2014-04-25 23:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundCloud Downloader
2014-04-25 23:49 - 2014-04-25 23:49 - 00000000 ____D () C:\Program Files (x86)\SoundCloud Downloader
2014-04-25 23:48 - 2014-04-25 23:48 - 00929416 _____ (CNET Download.com) C:\Users\FLOPPY\Downloads\cbsidlm-cbsi188-SoundYum_SoundCloud_Downloader-BP-75992700.exe
2014-04-25 23:43 - 2014-04-25 23:43 - 00000000 ____D () C:\Users\FLOPPY\Documents\Verfügbarkeiten
2014-04-25 23:35 - 2014-04-25 23:35 - 01071360 _____ (Solid State Networks) C:\Users\FLOPPY\Downloads\install_flashplayer13x32axau_ltr5x64d_awc_aih(2).exe
2014-04-25 10:07 - 2013-05-05 14:50 - 00002187 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-19 23:38 - 2014-04-19 23:36 - 01071360 _____ (Solid State Networks) C:\Users\FLOPPY\Downloads\install_flashplayer13x32axau_ltr5x64d_awc_aih(1).exe
2014-04-19 17:19 - 2014-04-19 17:19 - 00001222 _____ () C:\Users\FLOPPY\Desktop\Chromecast.lnk
2014-04-19 17:18 - 2014-04-19 17:18 - 00884608 _____ (Google Inc.) C:\Users\FLOPPY\Downloads\chromecastinstaller.exe
2014-04-19 17:18 - 2014-04-19 17:18 - 00003884 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002UA
2014-04-19 17:18 - 2014-04-19 17:18 - 00003488 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3435828442-162049101-3775305515-1002Core
2014-04-19 17:18 - 2014-04-19 17:18 - 00000000 ____D () C:\Users\FLOPPY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromecast
Some content of TEMP:
====================
C:\Users\FLOPPY\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpa_rsgb.dll
C:\Users\FLOPPY\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe
[2014-05-13 21:00] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-02 22:21
==================== End Of Log ============================ --- --- ---
--- --- --- |