Code:
# AdwCleaner v3.211 - Bericht erstellt am 05/06/2014 um 00:08:26
# Aktualisiert 26/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Peter - PETER-PC
# Gestartet von : C:\Users\Peter\Downloads\adwcleaner_3.211.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : IePluginServices
Dienst Gelöscht : vxlsnyaiet64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\IePluginServices
Ordner Gelöscht : C:\Program Files (x86)\Advanced System Protector
Ordner Gelöscht : C:\Program Files (x86)\PC Cleaner
Ordner Gelöscht : C:\Program Files (x86)\sizlsearch
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Program Files (x86)\Systweak Support Dock
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Program Files\003
Ordner Gelöscht : C:\Users\Peter\AppData\Local\Zoom_Downloader
Ordner Gelöscht : C:\Users\Peter\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Peter\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Peter\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Peter\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\System32\roboot64.exe
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Schlüssel Gelöscht : HKCU\Software\Ciuvo
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software
Schlüssel Gelöscht : HKLM\Software\qone8Software
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\suprasavings
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Google Chrome v
[ Datei : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [6967 octets] - [05/06/2014 00:07:25]
AdwCleaner[S0].txt - [5497 octets] - [05/06/2014 00:08:26]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5557 octets] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 05.06.2014
Suchlauf-Zeit: 00:15:28
Logdatei:
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.04.12
Rootkit Datenbank: v2014.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Peter
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 269076
Verstrichene Zeit: 9 Min, 39 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[cae8fb784e2d7bbbaa59e9817193f010]
Ordner: 0
(No malicious items detected)
Dateien: 22
PUP.Optional.AdPeak.A, C:\temp\InstallFilter64.msi, In Quarantäne, [e9c9fe755625ee488aeb61dc16ea7a86],
PUP.Optional.SupraSavings.A, C:\temp\t.msi, In Quarantäne, [981a0c6706751e186b69db7bd232ee12],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\nsd37A8.exe, In Quarantäne, [2e840a694d2e87afe5dd4241ec15b947],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\nsd553A.exe, In Quarantäne, [931f78fb8dee77bf774bc7bc17ea17e9],
PUP.Optional.SearchProtect.A, C:\Users\Peter\AppData\Local\Temp\nsdF28D.exe, In Quarantäne, [575b254ee19a6acc54ec8ba0c0419e62],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\nsj3509.exe, In Quarantäne, [476b690ad4a7a096d0f23e455ba607f9],
PUP.Optional.SearchProtect.A, C:\Users\Peter\AppData\Local\Temp\nsnF626.exe, In Quarantäne, [1999710274078ea891af83a8659c46ba],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\SPSetup.exe, In Quarantäne, [159d97dc730850e6f6cca0e36f92a858],
PUP.Optional.SearchProtect.A, C:\Users\Peter\AppData\Local\Temp\nss2E0A.exe, In Quarantäne, [d8daf380770454e2c37d9b90778a8779],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\nst528B.exe, In Quarantäne, [cae82b48b3c844f2c002d0b3df225aa6],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\nsu1128.exe, In Quarantäne, [1e94bbb8c6b52b0b437ffd8660a1aa56],
PUP.Optional.SearchProtect.A, C:\Users\Peter\AppData\Local\Temp\nsy3221.exe, In Quarantäne, [69491162700b0a2c340c1219c23f7d83],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\nsc675D\SpSetup.exe, In Quarantäne, [e1d1680be893211536facb5533cea957],
PUP.Optional.SkyTech.A, C:\Users\Peter\AppData\Local\Temp\2341060\2341060.zipDir\alilog.dll, In Quarantäne, [f9b99bd8473470c6f028939ff50ba060],
PUP.Optional.IePluginService.A, C:\Users\Peter\AppData\Local\Temp\2341060\2341060.zipDir\tmp\SupTab_Setup302.exe, In Quarantäne, [f9b9c7ac5f1c66d0fc3c4d0b1ce540c0],
PUP.Optional.Conduit.A, C:\Users\Peter\AppData\Local\Temp\nsyD2D\SpSetup.exe, In Quarantäne, [c0f2fe7582f9fc3aa71b2162639eba46],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsbFEEB.exe, In Quarantäne, [b7fbfe75d6a5e74fa41e0c77f9082dd3],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsi8098.exe, In Quarantäne, [377b0a695d1e68ce02c0721144bd44bc],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsl2BA6.exe, In Quarantäne, [1d950a69215ade5811b1740f38c98b75],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsyA92F.exe, In Quarantäne, [3c76abc87efd3105863c4f34d72a42be],
PUP.Optional.OptimumInstaller.A, C:\Users\Peter\Downloads\Setup (1).exe, In Quarantäne, [bdf57ff43a41e94da0f357f85ba6b54b],
PUP.Optional.OptimumInstaller.A, C:\Users\Peter\Downloads\Setup.exe, In Quarantäne, [4171d0a35e1d2c0aafe4c887cc355ea2],
Physische Sektoren: 0
(No malicious items detected)
(end)
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Peter (administrator) on PETER-PC on 05-06-2014 00:29:23
Running from C:\Users\Peter\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Peter\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10918504 2010-10-08] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] - "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe" "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware" [54072 2014-05-12] (Malwarebytes Corporation)
HKU\S-1-5-21-3303300667-2753219786-2939813476-1000\...\Run: [Google Update] => C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-09-24] (Google Inc.)
HKU\S-1-5-21-3303300667-2753219786-2939813476-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-09-24] (Google Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO-x32: Avira Savings Advisor BHO - {A18A516C-AA41-46A9-92DB-60208917E442} - C:\Program Files (x86)\avira\Internet Explorer\avira32.dll ()
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Peter\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Peter\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR HomePage: hxxp://www.google.de/
CHR StartupUrls: "hxxp://www.google.de/"
CHR Extension: (Google Docs) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-29]
CHR Extension: (Google Drive) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-29]
CHR Extension: (YouTube) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-29]
CHR Extension: (Avira Sparberater) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\cojnmaaohncijldefpkpkkakjonfmgeb [2014-05-29]
CHR Extension: (Google-Suche) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-29]
CHR Extension: (Google Wallet) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-21]
CHR Extension: (Google Mail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-29]
CHR HKLM-x32\...\Chrome\Extension: [cojnmaaohncijldefpkpkkakjonfmgeb] - C:\Program Files (x86)\avira\Chrome\avira-1.5.14.crx [2013-12-11]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-01-02] (BitRaider, LLC)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2014-01-14] (BitRaider)
S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [60320 2012-09-25] (G Data Software AG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-05] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
U0 uvih; C:\Windows\System32\drivers\qtjijdyv.sys [79064 2014-06-05] (Malwarebytes Corporation)
S3 RasPppoe; system32\DRIVERS\raspppoe.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-05 00:28 - 2014-06-05 00:29 - 00000000 ____D () C:\Users\Peter\Downloads\frst
2014-06-05 00:25 - 2014-06-05 00:25 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\qtjijdyv.sys
2014-06-05 00:12 - 2014-06-05 00:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 00:12 - 2014-06-05 00:12 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-05 00:11 - 2014-06-05 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-05 00:11 - 2014-06-05 00:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Peter\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-05 00:11 - 2014-06-05 00:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 00:11 - 2014-06-05 00:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-05 00:11 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-05 00:11 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-05 00:11 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-05 00:07 - 2014-06-05 00:08 - 00000000 ____D () C:\AdwCleaner
2014-06-05 00:07 - 2014-06-05 00:07 - 01327971 _____ () C:\Users\Peter\Downloads\adwcleaner_3.211.exe
2014-06-05 00:07 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-04 20:59 - 2014-06-05 00:29 - 00007694 _____ () C:\Users\Peter\Downloads\FRST.txt
2014-06-04 20:59 - 2014-06-05 00:29 - 00000000 ____D () C:\FRST
2014-06-04 20:56 - 2014-06-04 20:58 - 02068992 _____ (Farbar) C:\Users\Peter\Downloads\FRST64.exe
2014-06-02 17:52 - 2014-06-02 17:56 - 00000000 ____D () C:\Users\Peter\Desktop\Ina
2014-05-29 13:09 - 2014-05-29 13:09 - 00003158 _____ () C:\Windows\System32\Tasks\{7AFE5F64-B26A-481D-8D70-37A8F94C8FD7}
2014-05-29 13:05 - 2014-05-29 13:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2014-05-29 12:55 - 2014-05-29 13:07 - 00000000 ____D () C:\Program Files (x86)\Amazon
2014-05-29 12:41 - 2014-06-05 00:25 - 00000000 ____D () C:\temp
2014-05-29 12:40 - 2014-06-04 20:35 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-21 17:37 - 2014-05-21 17:37 - 00001485 _____ () C:\Users\Peter\Downloads\BAHN_Fahrplan_20140716.ics
2014-05-14 18:30 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 18:30 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 18:30 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 18:30 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 18:30 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 18:30 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 18:24 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 18:24 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 18:24 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 18:24 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 18:23 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 18:23 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 18:23 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 18:23 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 18:23 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 18:23 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 18:23 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 18:23 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 18:23 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 18:23 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 18:23 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 18:23 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 18:23 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 18:23 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 18:23 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 18:23 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 18:23 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 18:23 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 18:23 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 18:23 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 18:23 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 18:23 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 18:23 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 18:23 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 18:23 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 18:23 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 18:23 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 18:23 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 18:23 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 18:23 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-11 21:37 - 2014-05-11 21:37 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-05-11 21:37 - 2014-05-11 21:37 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-05-07 20:48 - 2014-05-07 20:48 - 13084896 _____ (Microsoft Corporation) C:\Users\Peter\Downloads\Silverlight_x64.exe
2014-05-07 20:48 - 2014-05-07 20:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-05-07 20:48 - 2014-05-07 20:48 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-05-07 20:48 - 2014-05-07 20:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-05-07 19:35 - 2014-05-07 19:37 - 00000000 ____D () C:\Users\Peter\AppData\Local\Microsoft Games
2014-05-07 19:17 - 2014-05-07 19:16 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-05-07 09:06 - 2014-05-07 09:06 - 00003408 _____ () C:\Windows\System32\Tasks\aviraSWU
2014-05-07 09:06 - 2014-05-07 09:06 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Avira
2014-05-07 09:03 - 2014-06-03 18:07 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-07 09:03 - 2014-06-03 18:07 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-07 09:03 - 2014-05-07 09:06 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-07 09:03 - 2014-05-07 09:03 - 00002074 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-05-07 09:03 - 2014-05-07 09:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-07 09:03 - 2014-05-07 09:03 - 00000000 ____D () C:\ProgramData\Avira
2014-05-07 09:03 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-05-06 21:44 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-06 21:44 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-06 21:44 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-06 21:44 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-06 21:44 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-06 21:44 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-06 21:44 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-06 21:44 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-06 21:44 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-06 21:44 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-06 21:44 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-06 21:44 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-06 21:44 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-06 21:44 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-06 21:44 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-06 21:44 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-06 21:44 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-06 21:44 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-06 21:44 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-06 21:44 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-06 21:44 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-06 21:44 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-06 21:44 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-06 21:44 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-06 21:44 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-06 21:44 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-06 21:44 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-06 21:44 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-06 21:44 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-06 21:44 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-06 21:44 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-06 21:44 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-06 21:44 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-06 21:44 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-06 21:44 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-06 21:44 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-06 21:44 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-06 21:44 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-06 21:44 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-06 21:44 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-06 21:44 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-06 21:44 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-06 21:44 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-06 21:44 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-06 21:43 - 2014-05-14 20:06 - 00000000 ___SD () C:\Windows\system32\CompatTel
==================== One Month Modified Files and Folders =======
2014-06-05 00:29 - 2014-06-05 00:28 - 00000000 ____D () C:\Users\Peter\Downloads\frst
2014-06-05 00:29 - 2014-06-04 20:59 - 00007694 _____ () C:\Users\Peter\Downloads\FRST.txt
2014-06-05 00:29 - 2014-06-04 20:59 - 00000000 ____D () C:\FRST
2014-06-05 00:29 - 2012-09-23 13:17 - 00000000 ____D () C:\Users\Peter\AppData\Local\Temp
2014-06-05 00:25 - 2014-06-05 00:25 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\qtjijdyv.sys
2014-06-05 00:25 - 2014-05-29 12:41 - 00000000 ____D () C:\temp
2014-06-05 00:25 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\Offline Web Pages
2014-06-05 00:17 - 2012-09-24 18:20 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3303300667-2753219786-2939813476-1000UA.job
2014-06-05 00:17 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-05 00:17 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-05 00:14 - 2010-05-12 10:18 - 00699150 _____ () C:\Windows\system32\perfh007.dat
2014-06-05 00:14 - 2010-05-12 10:18 - 00149290 _____ () C:\Windows\system32\perfc007.dat
2014-06-05 00:14 - 2009-07-14 07:13 - 01619528 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-05 00:13 - 2014-06-05 00:12 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 00:13 - 2012-09-23 12:52 - 01971280 _____ () C:\Windows\WindowsUpdate.log
2014-06-05 00:12 - 2014-06-05 00:12 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-05 00:12 - 2014-06-05 00:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-05 00:11 - 2014-06-05 00:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Peter\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-05 00:11 - 2014-06-05 00:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 00:11 - 2014-06-05 00:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-05 00:09 - 2012-09-24 20:04 - 00534578 _____ () C:\Windows\PFRO.log
2014-06-05 00:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-05 00:09 - 2009-07-14 06:51 - 00053374 _____ () C:\Windows\setupact.log
2014-06-05 00:08 - 2014-06-05 00:07 - 00000000 ____D () C:\AdwCleaner
2014-06-05 00:07 - 2014-06-05 00:07 - 01327971 _____ () C:\Users\Peter\Downloads\adwcleaner_3.211.exe
2014-06-04 21:22 - 2013-12-22 22:05 - 00000000 ____D () C:\ProgramData\Origin
2014-06-04 21:22 - 2013-12-22 22:05 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-04 20:58 - 2014-06-04 20:56 - 02068992 _____ (Farbar) C:\Users\Peter\Downloads\FRST64.exe
2014-06-04 20:53 - 2012-09-23 13:30 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-04 20:35 - 2014-05-29 12:40 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-06-03 18:07 - 2014-05-07 09:03 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-03 18:07 - 2014-05-07 09:03 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-02 17:56 - 2014-06-02 17:52 - 00000000 ____D () C:\Users\Peter\Desktop\Ina
2014-06-02 17:53 - 2012-09-24 20:59 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\TS3Client
2014-06-01 16:17 - 2012-09-24 18:20 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3303300667-2753219786-2939813476-1000Core.job
2014-05-29 19:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-29 13:19 - 2012-09-29 01:06 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\vlc
2014-05-29 13:10 - 2012-09-23 13:18 - 00001429 _____ () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-29 13:09 - 2014-05-29 13:09 - 00003158 _____ () C:\Windows\System32\Tasks\{7AFE5F64-B26A-481D-8D70-37A8F94C8FD7}
2014-05-29 13:07 - 2014-05-29 12:55 - 00000000 ____D () C:\Program Files (x86)\Amazon
2014-05-29 13:05 - 2014-05-29 13:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2014-05-29 13:05 - 2012-11-05 19:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-05-21 17:37 - 2014-05-21 17:37 - 00001485 _____ () C:\Users\Peter\Downloads\BAHN_Fahrplan_20140716.ics
2014-05-20 23:06 - 2013-12-22 22:10 - 00000000 ____D () C:\Users\Peter\Documents\SimCity
2014-05-20 22:56 - 2013-12-22 22:06 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Origin
2014-05-20 21:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-05-14 20:08 - 2012-09-23 13:18 - 00000000 ___RD () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-14 20:08 - 2012-09-23 13:18 - 00000000 ___RD () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 20:06 - 2014-05-06 21:43 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-14 18:30 - 2013-12-21 03:35 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 18:30 - 2012-11-05 19:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-14 18:29 - 2012-10-23 00:42 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 17:42 - 2012-09-23 13:20 - 00068328 _____ () C:\Users\Peter\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-13 17:41 - 2009-07-14 06:45 - 00311152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-12 07:26 - 2014-06-05 00:11 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-05 00:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-05 00:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 21:37 - 2014-05-11 21:37 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-05-11 21:37 - 2014-05-11 21:37 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-05-11 21:37 - 2012-11-05 19:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-05-09 08:14 - 2014-05-14 18:24 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-14 18:24 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-07 20:48 - 2014-05-07 20:48 - 13084896 _____ (Microsoft Corporation) C:\Users\Peter\Downloads\Silverlight_x64.exe
2014-05-07 20:48 - 2014-05-07 20:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-05-07 20:48 - 2014-05-07 20:48 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-05-07 20:48 - 2014-05-07 20:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-05-07 19:37 - 2014-05-07 19:35 - 00000000 ____D () C:\Users\Peter\AppData\Local\Microsoft Games
2014-05-07 19:16 - 2014-05-07 19:17 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-05-07 09:06 - 2014-05-07 09:06 - 00003408 _____ () C:\Windows\System32\Tasks\aviraSWU
2014-05-07 09:06 - 2014-05-07 09:06 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Avira
2014-05-07 09:06 - 2014-05-07 09:03 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-07 09:03 - 2014-05-07 09:03 - 00002074 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-05-07 09:03 - 2014-05-07 09:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-07 09:03 - 2014-05-07 09:03 - 00000000 ____D () C:\ProgramData\Avira
2014-05-07 08:56 - 2012-09-24 18:20 - 00000000 ____D () C:\Program Files (x86)\G Data
2014-05-07 08:55 - 2012-09-24 18:20 - 00000000 ____D () C:\ProgramData\G DATA
2014-05-07 08:55 - 2012-09-24 18:18 - 00000000 ____D () C:\Users\Peter\AppData\Local\Downloaded Installations
2014-05-07 08:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-06 16:12 - 2012-09-24 18:20 - 00004090 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3303300667-2753219786-2939813476-1000UA
2014-05-06 16:12 - 2012-09-24 18:20 - 00003694 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3303300667-2753219786-2939813476-1000Core
2014-05-06 06:40 - 2014-05-14 18:30 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-14 18:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-14 18:30 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-14 18:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-14 18:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-14 18:30 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
Some content of TEMP:
====================
C:\Users\Peter\AppData\Local\Temp\avgnt.exe
C:\Users\Peter\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Peter\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Peter\AppData\Local\Temp\nsp6D35.tmp.exe
C:\Users\Peter\AppData\Local\Temp\ose00000.exe
C:\Users\Peter\AppData\Local\Temp\Quarantine.exe
C:\Users\Peter\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Peter\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\Peter\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Peter\AppData\Local\Temp\System.Data.SQLite36586.dll
C:\Users\Peter\AppData\Local\Temp\Uninstaller-6752.exe
C:\Users\Peter\AppData\Local\Temp\_is52C1.exe
C:\Users\Peter\AppData\Local\Temp\_is52F0.exe
C:\Users\Peter\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-29 19:52
==================== End Of Log ============================ --- --- ---
--- --- --- |