ULTRA NOOB | 15.12.2014 22:58 | hier schonmal der mbam.txt Log Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 15.12.2014 21:48:47, SYSTEM, WIN-OZU160SVHRM, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 15.12.2014 21:48:47, SYSTEM, WIN-OZU160SVHRM, Manual, Rootkit Database, 2014.11.18.1, 2014.12.14.1,
Update, 15.12.2014 21:49:39, SYSTEM, WIN-OZU160SVHRM, Manual, Malware Database, 2014.11.20.6, 2014.12.15.5,
Scan, 15.12.2014 22:06:45, SYSTEM, WIN-OZU160SVHRM, Manual, Start: % 1 "% 2", Dauer: % 1 min 15 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 39-Malwareerkennung,
(end) Hier der Log vom AdwCleaner Code:
# AdwCleaner v4.105 - Bericht erstellt am 15/12/2014 um 22:26:25
# Aktualisiert 08/12/2014 von Xplode
# Database : 2014-12-13.4 [Live]
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Meister - WIN-OZU160SVHRM
# Gestartet von : C:\Users\Meister\Downloads\AdwCleaner_4.105.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : 51cdb72
***** [ Dateien / Ordner ] *****
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}
Schlüssel Gelöscht : HKLM\SOFTWARE\DeviceVM
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v33.1 (x86 de)
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [338 octets] - [20/11/2014 03:00:33]
AdwCleaner[R1].txt - [23736 octets] - [20/11/2014 03:03:10]
AdwCleaner[R2].txt - [2592 octets] - [29/11/2014 02:40:06]
AdwCleaner[R3].txt - [1280 octets] - [01/12/2014 01:34:56]
AdwCleaner[R4].txt - [1483 octets] - [15/12/2014 22:24:43]
AdwCleaner[S0].txt - [21539 octets] - [20/11/2014 03:07:06]
AdwCleaner[S1].txt - [2507 octets] - [29/11/2014 02:44:38]
AdwCleaner[S2].txt - [1341 octets] - [01/12/2014 01:38:28]
AdwCleaner[S3].txt - [1408 octets] - [15/12/2014 22:26:25]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1468 octets] ########## Junkware Log Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Professional x64
Ran by Meister on 15.12.2014 at 22:46:13,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611491169}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{edc9d0b1-7604-4d6b-8889-84fd79d1f4cb}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{edc9d0b1-7604-4d6b-8889-84fd79d1f4cb}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{edc9d0b1-7604-4d6b-8889-84fd79d1f4cb}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{edc9d0b1-7604-4d6b-8889-84fd79d1f4cb}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Meister\AppData\Roaming\mozilla\firefox\profiles\ph98kodk.default\minidumps [141 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.12.2014 at 22:51:32,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und der FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-12-2014 01
Ran by Meister (administrator) on WIN-OZU160SVHRM on 15-12-2014 22:56:23
Running from C:\Users\Meister\Downloads
Loaded Profile: Meister (Available profiles: user & Meister)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Hewlett-Packard) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(DeviceVM, Inc.) C:\Program Files (x86)\Dell\Reader 2.1\DVMExportService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
() C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(DeviceVM, Inc.) C:\Program Files (x86)\Dell\Reader 2.1\DellBtrEvent.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [FreeFallProtection] => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686744 2012-09-05] ()
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111488 2013-01-23] (Intel Corporation)
HKLM-x32\...\Run: [DellBtrEvent] => C:\Program Files (x86)\Dell\Reader 2.1\DellBtrEvent.exe [160768 2010-05-13] (DeviceVM, Inc.)
HKLM-x32\...\Run: [OrderReminder] => C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2005-03-18] (Hewlett-Packard)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5223016 2014-11-01] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
BootExecute: sasnative64autocheck autochk *
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1016316848-2073477898-3483257739-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:51821;https=127.0.0.1:51821
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com/?fr=hp-avast&type=avastbcl
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1016316848-2073477898-3483257739-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1016316848-2073477898-3483257739-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Meister\AppData\Roaming\Mozilla\Firefox\Profiles\ph98kodk.default
FF DefaultSearchUrl: https://de.search.yahoo.com/yhs/search
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Homepage: https://www.facebook.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKU\S-1-5-21-1016316848-2073477898-3483257739-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-1016316848-2073477898-3483257739-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-03-02]
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Users\Meister\Desktop\weil ich jetzt kurz internet brauch\congstar\Internet-Manager\Bin\addon
FF HKU\S-1-5-21-1016316848-2073477898-3483257739-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Meister\AppData\Roaming\Mozilla\Firefox\Profiles\ph98kodk.default\extensions\cliqz@cliqz.com
FF Extension: No Name - wrc@avast.com [Not Found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Meister\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-24]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-24] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [104416 2014-10-24] (AVAST Software)
R2 DvmMDES; C:\Program Files (x86)\Dell\Reader 2.1\DVMExportService.exe [327680 2010-05-04] (DeviceVM, Inc.) [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-08] ()
R2 QDLService2kHP; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe [330488 2009-10-01] (QUALCOMM, Inc.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2014-01-08] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-24] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-10-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-01] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [449936 2014-10-24] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-10-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-10-24] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-10-24] ()
R1 DVMIO; C:\Program Files (x86)\Dell\Reader 2.1\dvmio_x64.sys [20624 2010-05-04] (DeviceVM, Inc.)
U5 IntcDAud; C:\Windows\System32\Drivers\IntcDAud.sys [317440 2011-08-23] (Intel(R) Corporation)
S3 qcfilterhp2k; C:\Windows\System32\DRIVERS\qcfilterhp2k.sys [6400 2009-10-01] (QUALCOMM Incorporated)
S3 qcusbnethp2k; C:\Windows\System32\DRIVERS\qcusbnethp2k.sys [235008 2009-10-01] (QUALCOMM Incorporated)
S3 qcusbserhp2k; C:\Windows\System32\DRIVERS\qcusbserhp2k.sys [121216 2009-10-01] (QUALCOMM Incorporated)
S3 rismcx64; C:\Windows\System32\DRIVERS\rismcx64.sys [59008 2009-07-20] (RICOH Company, Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 HSPADataCardusbmdm; system32\DRIVERS\HSPADataCardusbmdm.sys [X]
S3 HSPADataCardusbnmea; system32\DRIVERS\HSPADataCardusbnmea.sys [X]
S3 HSPADataCardusbser; system32\DRIVERS\HSPADataCardusbser.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-15 22:55 - 2014-12-15 22:55 - 00000000 ____D () C:\Users\Meister\Downloads\FRST-OlderVersion
2014-12-15 22:51 - 2014-12-15 22:51 - 00001658 _____ () C:\Users\Meister\Desktop\JRT.txt
2014-12-15 22:45 - 2014-12-15 22:45 - 00000000 ____D () C:\Windows\ERUNT
2014-12-15 22:41 - 2014-12-15 22:41 - 01707646 _____ (Thisisu) C:\Users\Meister\Downloads\JRT.exe
2014-12-15 22:23 - 2014-12-15 22:24 - 02166272 _____ () C:\Users\Meister\Downloads\AdwCleaner_4.105.exe
2014-12-15 22:13 - 2014-12-15 22:13 - 00000578 _____ () C:\Users\Meister\Desktop\mbam.txt
2014-12-15 21:48 - 2014-12-15 22:15 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-15 21:48 - 2014-12-15 21:48 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-15 21:48 - 2014-12-15 21:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-15 21:48 - 2014-12-15 21:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-15 21:48 - 2014-12-15 21:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-15 21:48 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-15 21:48 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-15 21:48 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-15 21:44 - 2014-12-15 21:46 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Meister\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-15 00:39 - 2014-12-15 01:17 - 00000574 _____ () C:\Users\Meister\Desktop\maries weihnachten soll perfekt werden.txt
2014-12-11 05:19 - 2014-12-11 05:19 - 00000000 ____D () C:\Windows\system32\hotspot
2014-12-11 05:19 - 2014-12-11 05:19 - 00000000 ____D () C:\Users\Default\AppData\Roaming\AVAST Software
2014-12-11 05:19 - 2014-12-11 05:19 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\AVAST Software
2014-12-11 05:16 - 2014-12-11 05:16 - 00000000 ____D () C:\Users\Meister\AppData\Roaming\Intel
2014-12-11 05:15 - 2014-12-11 05:15 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
2014-12-11 05:14 - 2014-12-11 05:14 - 00000000 ____D () C:\ProgramData\Intel
2014-12-11 05:14 - 2014-12-11 05:14 - 00000000 ____D () C:\Program Files (x86)\Cisco
2014-12-11 05:09 - 2014-12-11 05:14 - 00000000 ____D () C:\Program Files\Intel
2014-12-11 05:08 - 2014-12-11 05:08 - 00000000 ____D () C:\ProgramData\IntelDLM
2014-12-11 05:02 - 2014-12-11 05:02 - 00000000 ____D () C:\Users\Meister\AppData\Local\Intel
2014-12-11 04:56 - 2014-12-11 04:56 - 00001170 _____ () C:\Users\Public\Desktop\Intel(R) Driver Update Utility 2.0.lnk
2014-12-11 04:56 - 2014-12-11 04:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility
2014-12-11 04:56 - 2014-12-11 04:56 - 00000000 ____D () C:\Program Files (x86)\Intel Driver Update Utility
2014-12-11 04:41 - 2014-12-11 05:12 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-11 04:40 - 2014-12-11 04:40 - 02333416 _____ (Intel) C:\Users\Meister\Downloads\Intel Driver Update Utility Installer.exe
2014-12-11 00:03 - 2014-12-11 00:03 - 00000000 ____D () C:\Users\Meister\Desktop\spastimus
2014-12-10 23:56 - 2014-12-10 23:56 - 00022499 _____ () C:\ComboFix.txt
2014-12-10 23:43 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-10 23:43 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-10 23:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-10 23:43 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-10 23:43 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-10 23:43 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-10 23:43 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-10 23:43 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-10 23:39 - 2014-12-10 23:56 - 00000000 ____D () C:\Qoobox
2014-12-10 23:39 - 2014-12-10 23:54 - 00000000 ____D () C:\Windows\erdnt
2014-12-10 23:37 - 2014-12-10 23:38 - 05600944 ____R (Swearware) C:\Users\Meister\Desktop\ComboFix.exe
2014-12-10 23:28 - 2014-12-10 23:28 - 00000749 _____ () C:\Users\Meister\Desktop\Revo Uninstaller.lnk
2014-12-10 23:26 - 2014-12-10 23:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Meister\Downloads\revosetup95.exe
2014-12-10 03:38 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-10 03:38 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-10 03:38 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-10 03:38 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-10 03:38 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-10 03:38 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-10 03:38 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-10 03:38 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-10 03:38 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 03:38 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-10 03:38 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-10 03:38 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 03:38 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 03:37 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-10 03:37 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-10 03:37 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-10 03:37 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-10 03:37 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-10 03:37 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-10 03:37 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-10 03:37 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-10 03:37 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-10 03:37 - 2014-11-22 03:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-10 03:37 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-10 03:37 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-10 03:37 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 03:37 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-10 03:37 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-10 03:37 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-10 03:37 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 03:37 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-10 03:37 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-10 03:37 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-10 03:37 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-10 03:37 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-10 03:37 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-10 03:37 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-10 03:37 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-10 03:37 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-10 03:37 - 2014-11-22 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-10 03:37 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-10 03:37 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-10 03:37 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-10 03:37 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-10 03:37 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-10 03:37 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-10 03:37 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-10 03:37 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-10 03:37 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-10 03:37 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-10 03:37 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-10 03:37 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-10 03:37 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-10 03:37 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-10 03:37 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-10 03:37 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-10 03:37 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-10 03:37 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-09 11:01 - 2014-12-11 00:00 - 00022499 _____ () C:\Users\Meister\Desktop\Neues Textdokument.txt
2014-12-09 10:48 - 2014-12-09 12:41 - 00000000 ____D () C:\Users\Meister\Desktop\bewerbung
2014-12-04 04:14 - 2014-12-08 14:40 - 00000913 _____ () C:\Users\Meister\Desktop\prakti.txt
2014-12-02 02:38 - 2014-12-02 02:41 - 00021232 _____ () C:\Users\Meister\Downloads\Addition.txt
2014-12-02 02:36 - 2014-12-15 22:56 - 00013201 _____ () C:\Users\Meister\Downloads\FRST.txt
2014-12-02 02:35 - 2014-12-15 22:56 - 00000000 ____D () C:\FRST
2014-12-02 02:35 - 2014-12-15 22:55 - 02119168 _____ (Farbar) C:\Users\Meister\Downloads\FRST64.exe
2014-11-21 14:33 - 2014-11-21 14:33 - 00000000 ____D () C:\Users\Meister\AppData\Roaming\dlg
2014-11-20 03:00 - 2014-12-15 22:26 - 00000000 ____D () C:\AdwCleaner
2014-11-20 02:45 - 2014-11-20 02:45 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-11-20 02:39 - 2014-11-20 02:40 - 00000848 _____ () C:\Windows\system32\Drivers\kgpcpy.cfg
2014-11-19 05:32 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 05:32 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 05:32 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 05:32 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-18 23:07 - 2014-11-18 23:07 - 00266288 _____ () C:\Windows\Minidump\111814-22292-01.dmp
2014-11-18 23:00 - 2014-11-18 23:07 - 394556837 _____ () C:\Windows\MEMORY.DMP
2014-11-18 23:00 - 2014-11-18 23:01 - 00262144 _____ () C:\Windows\Minidump\111814-22042-01.dmp
2014-11-18 03:04 - 2014-11-18 03:04 - 00288766 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2014-11-18 03:02 - 2014-11-18 03:03 - 00292262 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2014-11-18 03:02 - 2014-11-18 03:02 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-11-17 07:36 - 2014-11-17 08:07 - 00000016 _____ () C:\Windows\system32\config\software.szfi
2014-11-17 06:18 - 2014-11-17 06:20 - 00001632 _____ () C:\Windows\SysWOW64\Drivers\kgpfr2.cfg
2014-11-17 06:07 - 2014-11-17 06:07 - 00707664 _____ (iS3, Inc.) C:\Users\Meister\Downloads\SZSetup_AID10121_AV.exe
2014-11-17 06:03 - 2014-11-17 06:03 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-17 06:03 - 2014-11-17 06:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-17 06:03 - 2014-11-17 06:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-17 05:59 - 2014-11-17 06:02 - 36294704 _____ () C:\Users\Meister\Downloads\Firefox_Setup_de33.1.exe
2014-11-16 14:49 - 2014-11-16 14:49 - 00003468 _____ () C:\Windows\System32\Tasks\{6CADFB46-5998-4B5B-B917-E0079A6FAB8B}
2014-11-16 02:33 - 2014-12-15 22:29 - 00001694 _____ () C:\Windows\Tasks\TDJXRBNI.job
2014-11-16 02:33 - 2014-12-15 22:29 - 00001338 _____ () C:\Windows\Tasks\HH.job
2014-11-16 02:33 - 2014-11-16 02:33 - 01541024 _____ (enter) C:\Users\Meister\AppData\Roaming\HH.exe
2014-11-16 02:33 - 2014-11-16 02:33 - 00004738 _____ () C:\Windows\System32\Tasks\TDJXRBNI
2014-11-16 02:33 - 2014-11-16 02:33 - 00004382 _____ () C:\Windows\System32\Tasks\HH
2014-11-16 02:33 - 2014-11-16 02:33 - 00000000 __SHD () C:\Users\Meister\AppData\Local\EmieUserList
2014-11-16 02:33 - 2014-11-16 02:33 - 00000000 __SHD () C:\Users\Meister\AppData\Local\EmieSiteList
2014-11-16 02:33 - 2014-11-16 02:33 - 00000000 __SHD () C:\Users\Meister\AppData\Local\EmieBrowserModeList
2014-11-16 02:31 - 2014-12-15 22:29 - 00001344 _____ () C:\Windows\Tasks\VIIIJ.job
2014-11-16 02:31 - 2014-12-15 22:29 - 00001342 _____ () C:\Windows\Tasks\EUMM.job
2014-11-16 02:31 - 2014-11-16 02:31 - 01541024 _____ (app) C:\Users\Meister\AppData\Roaming\VIIIJ.exe
2014-11-16 02:31 - 2014-11-16 02:31 - 00004388 _____ () C:\Windows\System32\Tasks\VIIIJ
2014-11-16 02:31 - 2014-11-16 02:31 - 00004386 _____ () C:\Windows\System32\Tasks\EUMM
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-15 22:34 - 2014-03-02 16:32 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-12-15 22:27 - 2013-11-07 09:48 - 00540632 _____ () C:\Windows\PFRO.log
2014-12-15 22:27 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-15 22:27 - 2009-07-14 05:51 - 00054013 _____ () C:\Windows\setupact.log
2014-12-15 22:26 - 2013-10-18 13:36 - 01556232 _____ () C:\Windows\WindowsUpdate.log
2014-12-15 22:26 - 2009-07-14 05:45 - 00021952 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-15 22:26 - 2009-07-14 05:45 - 00021952 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-15 22:14 - 2013-11-10 11:37 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-15 22:08 - 2014-01-28 20:15 - 00000069 _____ () C:\dvmaccounts.ini
2014-12-15 17:56 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-15 01:19 - 2013-12-20 14:17 - 00000880 _____ () C:\Users\Meister\Desktop\PWs.txt
2014-12-14 06:04 - 2013-11-06 18:56 - 00000000 ____D () C:\Users\Meister\AppData\Roaming\Skype
2014-12-12 03:36 - 2014-06-11 10:06 - 01594892 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-12-12 03:36 - 2009-07-14 18:58 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-12-12 03:36 - 2009-07-14 18:58 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-12-12 03:36 - 2009-07-14 06:13 - 01594892 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-12 00:16 - 2013-11-10 11:37 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-12 00:15 - 2013-11-07 08:18 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-12 00:15 - 2013-11-07 08:18 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-11 05:16 - 2013-11-04 13:58 - 00000000 ____D () C:\Users\Meister
2014-12-11 05:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-11 05:14 - 2013-10-25 08:38 - 00000000 ____D () C:\Program Files\Common Files\Intel
2014-12-11 05:14 - 2013-10-25 08:03 - 00016096 _____ () C:\Windows\DPINST.LOG
2014-12-11 05:14 - 2013-10-25 07:44 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-12-11 03:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-11 03:05 - 2013-11-07 21:25 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-11 03:05 - 2013-11-07 21:25 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-10 23:52 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-12-10 23:37 - 2014-10-24 16:28 - 00000000 ____D () C:\Users\Meister\AppData\Roaming\0C1I1L1R1J0C1F1G1G1P1R2Z
2014-12-06 17:50 - 2014-10-24 16:49 - 00001974 _____ () C:\Users\Public\Desktop\Avast Internet Security.lnk
2014-12-06 17:50 - 2013-11-07 08:33 - 00001062 _____ () C:\Users\Public\Desktop\PDF-Viewer.lnk
2014-12-06 17:48 - 2014-06-13 08:53 - 00000000 ____D () C:\Users\Meister\Desktop\How to Facharbeit
2014-12-06 17:48 - 2013-12-02 14:11 - 00000000 ____D () C:\Users\Meister\Desktop\Schule
2014-11-18 23:07 - 2014-03-02 16:34 - 00000000 ____D () C:\Windows\Minidump
2014-11-17 05:22 - 2013-12-19 00:47 - 00000145 _____ () C:\Users\Meister\AppData\Roaming\WB.CFG
Some content of TEMP:
====================
C:\Users\Meister\AppData\Local\Temp\Quarantine.exe
C:\Users\Meister\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-06 05:19
==================== End Of Log ============================ --- --- ---
--- --- --- |