Barbarella_M | 28.05.2015 19:16 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.05.2015
Suchlauf-Zeit: 19:16:44
Logdatei: mbamlog.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.28.05
Rootkit Datenbank: v2015.05.24.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Barbarella
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 366252
Verstrichene Zeit: 21 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 1
PUP.Optional.Spigot.A, HKU\S-1-5-21-2482831953-4192449490-768695712-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{48BEB7AD-DBD6-433E-890C-BC3EA9A71D56}, In Quarantäne, [0005aeeb8802fb3b4119756ebc474ab6],
Registrierungswerte: 1
PUP.Optional.Spigot.A, HKU\S-1-5-21-2482831953-4192449490-768695712-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{48BEB7AD-DBD6-433E-890C-BC3EA9A71D56}|URL, https://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=523482&p={searchTerms}, In Quarantäne, [0005aeeb8802fb3b4119756ebc474ab6]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 6
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome\content, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
Dateien: 22
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\searchplugins\yahoo_ff.xml, In Quarantäne, [10f5d1c815751e1868c9fdf54bb8e51b],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome.manifest, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\icon.png, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\install.rdf, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome\content\config.json, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome\content\main.js, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome\content\prefs.txt, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome\content\savingsslider.js, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome\content\savingsslider.xul, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}\chrome\content\spigot.js, In Quarantäne, [2dd8cacf771356e0b0b79b3546bd8b75],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome.manifest, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\icon.png, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\install.rdf, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\config.json, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\main.js, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\main.xul, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\newtab.xul, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\prefs.txt, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\redirects.js, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\spigot.js, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7}\chrome\content\startpage.js, In Quarantäne, [7d88a8f18703043292d6953bcc37a35d],
PUP.Optional.Spigot.A, C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "https://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=523482&p=");), Ersetzt,[0500f0a9d1b99a9c52122d3ebf470df3]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Hallo, habe das mit dem Adv Cleaner versucht, es passiert was, aber er findet anscheinend nix. Der PC fährt weder herunter, noch geschieht sonst was. Habe vorsichtshalber den Bericht angefordert und füge ihn anbei.
VIELEN DANK Code:
# AdwCleaner v4.205 - Bericht erstellt 28/05/2015 um 19:50:26
# Aktualisiert 21/05/2015 von Xplode
# Datenbank : 2015-05-25.3 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : Barbarella - BARBARELLA-PC
# Gestarted von : C:\Users\Barbarella\Desktop\AdwCleaner_4.205.exe
# Option : Suchlauf
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
Ordner Gefunden : C:\Program Files\DriverToolkit
Ordner Gefunden : C:\Users\Barbarella\AppData\Local\DriverToolkit
Ordner Gefunden : C:\Users\Barbarella\Favorites\Links\radio
Ordner Gefunden : C:\Users\Barbarella\Favorites\Links\radio
***** [ Geplante Tasks ] *****
Task Gefunden : update-sys
Task Gefunden : update-S-1-5-21-2482831953-4192449490-768695712-1000
Task Gefunden : update-sys
Task Gefunden : update-S-1-5-21-2482831953-4192449490-768695712-1000
Task Gefunden : update-sys
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Daten Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
Schlüssel Gefunden : HKCU\Software\DriverToolkit
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17801
-\\ Mozilla Firefox v36.0.4 (x86 de)
[m7qhkk0m.default] - Zeile Gefunden : user_pref("startpage.ntsearch_url", "hxxps://de.search.yahoo.com/search?fr=spigot-nt-ff&ei=utf-8&ilc=12&type=523482&p={searchTerms}");
*************************
AdwCleaner[R0].txt - [1678 Bytes] - [28/05/2015 19:46:54]
AdwCleaner[R1].txt - [1599 Bytes] - [28/05/2015 19:50:26]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1658 Bytes] ########## Wie darf ich weiter machen?
Tschuldigung, war etwas übereifrig. Habe das mit dem Adv cleaner doch gefunden und wie gewünscht gemacht. Code:
# AdwCleaner v4.205 - Bericht erstellt 28/05/2015 um 20:00:27
# Aktualisiert 21/05/2015 von Xplode
# Datenbank : 2015-05-25.3 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : Barbarella - BARBARELLA-PC
# Gestarted von : C:\Users\Barbarella\Desktop\AdwCleaner_4.205.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Barbarella\Favorites\Links\radio
Ordner Gelöscht : C:\Program Files\DriverToolkit
Ordner Gelöscht : C:\Users\Barbarella\AppData\Local\DriverToolkit
Datei Gelöscht : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
***** [ Geplante Tasks ] *****
Task Gelöscht : update-sys
Task Gelöscht : update-S-1-5-21-2482831953-4192449490-768695712-1000
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\DriverToolkit
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17801
-\\ Mozilla Firefox v36.0.4 (x86 de)
[m7qhkk0m.default\prefs.js] - Zeile Gelöscht : user_pref("startpage.ntsearch_url", "hxxps://de.search.yahoo.com/search?fr=spigot-nt-ff&ei=utf-8&ilc=12&type=523482&p={searchTerms}");
*************************
AdwCleaner[R0].txt - [1678 Bytes] - [28/05/2015 19:46:54]
AdwCleaner[R1].txt - [1737 Bytes] - [28/05/2015 19:50:26]
AdwCleaner[R2].txt - [1796 Bytes] - [28/05/2015 19:56:17]
AdwCleaner[S0].txt - [1538 Bytes] - [28/05/2015 20:00:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1597 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.3 (05.28.2015:2)
OS: Windows 7 Home Premium x86
Ran by Barbarella on 28.05.2015 at 20:08:56,26
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Barbarella\AppData\Roaming\mozilla\firefox\profiles\m7qhkk0m.default\extensions\staged
Emptied folder: C:\Users\Barbarella\AppData\Roaming\mozilla\firefox\profiles\m7qhkk0m.default\minidumps [1 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.05.2015 at 20:15:19,13
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-05-2015
Ran by Barbarella (administrator) on BARBARELLA-PC on 28-05-2015 20:16:10
Running from C:\Users\Barbarella\Desktop\Trojaner
Loaded Profiles: Barbarella (Available Profiles: Barbarella & Mnet iphone)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Program Files\Canon\IJPLM\ijplmsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_17_0_0_169_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AVMWlanClient] => C:\Program Files\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [Lightshot] => C:\Program Files\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [V0770Mon.exe] => C:\Windows\V0770Mon.exe [32884 2012-06-01] (Creative Technology Ltd.)
HKLM\...\Run: [Live! Central 3] => C:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe [461312 2013-08-15] (Creative Technology Ltd)
HKLM\...\Run: [FastAccess Web Alert] => C:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe [2033648 2011-07-11] (Microsoft)
HKLM\...\Run: [CLMLServer_For_P2G9] => C:\Program Files\CyberLink\Power2Go9\CLMLSvc_P2G9.exe [110344 2014-07-08] (CyberLink)
HKLM\...\Run: [CanonQuickMenu] => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-2482831953-4192449490-768695712-1000\...\Run: [Power2GoExpress9] => NA
HKU\S-1-5-21-2482831953-4192449490-768695712-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2482831953-4192449490-768695712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2482831953-4192449490-768695712-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2482831953-4192449490-768695712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKU\S-1-5-21-2482831953-4192449490-768695712-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default
FF SelectedSearchEngine: Yahoo!
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1214154.dll [2014-11-26] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin: @canon.com/MycameraPlugin -> C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll [2008-10-15] (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC} [not found]
FF Extension: No Name - C:\Users\Barbarella\AppData\Roaming\Mozilla\Firefox\Profiles\m7qhkk0m.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7} [not found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
S2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) []
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [851456 2015-04-27] (Microsoft Corporation)
R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-22] (AVM Berlin) []
R3 CLVirtualBus01; C:\Windows\System32\DRIVERS\CLVirtualBus01.sys [78600 2014-03-12] (CyberLink)
R3 cmudax; C:\Windows\System32\drivers\cmudax.sys [1287296 2005-05-12] (C-Media Inc.)
R3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd6.sys [44032 2009-07-14] (VIA Technologies, Inc. )
S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [586752 2010-10-22] (AVM GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-28] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1311232 2009-07-14] (NXP Semiconductors)
R3 V0770Vid; C:\Windows\System32\DRIVERS\V0770Vid.sys [325376 2012-06-01] (Creative Technology Ltd.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\BARBAR~1\AppData\Local\Temp\catchme.sys [X]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-28 20:15 - 2015-05-28 20:15 - 00000869 _____ () C:\Users\Barbarella\Desktop\JRT.txt
2015-05-28 20:10 - 2015-05-28 20:10 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-BARBARELLA-PC-Windows-7-Home-Premium-(32-bit).dat
2015-05-28 20:09 - 2015-05-28 20:09 - 00000000 ____D () C:\RegBackup
2015-05-28 20:08 - 2015-05-28 20:08 - 02947193 _____ (Thisisu) C:\Users\Barbarella\Desktop\JRT.exe
2015-05-28 19:46 - 2015-05-28 20:00 - 00000000 ____D () C:\AdwCleaner
2015-05-28 19:44 - 2015-05-28 19:44 - 02222592 _____ () C:\Users\Barbarella\Desktop\AdwCleaner_4.205.exe
2015-05-28 19:16 - 2015-05-28 20:04 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-28 19:14 - 2015-05-28 19:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-28 19:14 - 2015-05-28 19:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-28 19:14 - 2015-05-28 19:14 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-05-28 19:14 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-28 19:14 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-28 19:14 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-27 20:40 - 2015-05-28 20:02 - 00001854 _____ () C:\Windows\PFRO.log
2015-05-27 20:36 - 2015-05-27 20:36 - 00000000 ____D () C:\Users\Mnet iphone\AppData\Roaming\Canon
2015-05-27 20:35 - 2015-05-27 20:37 - 00000000 ____D () C:\Users\Mnet iphone\AppData\Roaming\Apple Computer
2015-05-27 20:35 - 2015-05-27 20:35 - 00064416 _____ () C:\Users\Mnet iphone\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-27 20:35 - 2015-05-27 20:35 - 00000000 ____D () C:\Users\Mnet iphone\AppData\Roaming\Creative
2015-05-27 20:35 - 2015-05-27 20:35 - 00000000 ____D () C:\Users\Mnet iphone\AppData\Local\Power2Go9
2015-05-27 20:35 - 2015-05-27 20:35 - 00000000 ____D () C:\Users\Mnet iphone\AppData\Local\Apple Computer
2015-05-27 20:34 - 2015-05-27 20:36 - 00000000 ____D () C:\Users\Mnet iphone\AppData\Local\VirtualStore
2015-05-27 20:34 - 2015-05-27 20:35 - 00000000 ____D () C:\Users\Mnet iphone
2015-05-27 20:34 - 2015-05-27 20:34 - 00001413 _____ () C:\Users\Mnet iphone\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-27 20:34 - 2015-05-27 20:34 - 00000020 ___SH () C:\Users\Mnet iphone\ntuser.ini
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 _SHDL () C:\Users\Mnet iphone\Startmenü
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 _SHDL () C:\Users\Mnet iphone\Netzwerkumgebung
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 _SHDL () C:\Users\Mnet iphone\Druckumgebung
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 _SHDL () C:\Users\Mnet iphone\Documents\Eigene Musik
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 _SHDL () C:\Users\Mnet iphone\Documents\Eigene Bilder
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 _SHDL () C:\Users\Mnet iphone\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 _SHDL () C:\Users\Mnet iphone\AppData\Local\Verlauf
2015-05-27 20:34 - 2015-05-27 20:34 - 00000000 ____D () C:\Users\Mnet iphone\AppData\Roaming\Adobe
2015-05-27 20:34 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Mnet iphone\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-27 20:34 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Mnet iphone\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-27 12:47 - 2015-05-28 20:02 - 00001828 _____ () C:\Windows\setupact.log
2015-05-27 12:47 - 2015-05-27 12:47 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-27 10:09 - 2015-05-28 19:56 - 00000000 ____D () C:\Users\Barbarella\Desktop\Trojaner
2015-05-27 09:48 - 2015-05-27 09:48 - 00013138 _____ () C:\ComboFix.txt
2015-05-27 09:30 - 2015-05-27 09:48 - 00000000 ____D () C:\Qoobox
2015-05-27 09:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-05-27 09:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-05-27 09:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-05-27 09:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-05-27 09:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-05-27 09:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-05-27 09:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-05-27 09:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-05-27 09:29 - 2015-05-27 09:46 - 00000000 ____D () C:\Windows\erdnt
2015-05-27 09:28 - 2015-05-27 09:28 - 05628291 ____R (Swearware) C:\Users\Barbarella\Desktop\ComboFix.exe
2015-05-27 09:20 - 2015-05-27 09:20 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-05-27 09:14 - 2015-05-27 09:15 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Barbarella\Downloads\revosetup95.exe
2015-05-20 16:21 - 2015-05-28 20:16 - 00000000 ____D () C:\FRST
2015-05-15 20:05 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 11:43 - 2015-04-27 21:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-05-13 11:43 - 2015-04-27 21:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-13 11:43 - 2015-04-27 21:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-13 11:43 - 2015-04-27 21:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-13 11:43 - 2015-04-27 21:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-13 11:43 - 2015-04-27 21:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-13 11:43 - 2015-04-27 21:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 11:43 - 2015-04-27 21:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-13 11:43 - 2015-04-27 21:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-13 11:43 - 2015-04-27 21:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-13 11:43 - 2015-04-27 21:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-13 11:43 - 2015-04-27 21:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-13 11:43 - 2015-04-27 21:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-13 11:43 - 2015-04-27 21:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-13 11:43 - 2015-04-27 21:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-13 11:43 - 2015-04-27 21:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-13 11:43 - 2015-04-27 21:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-13 11:43 - 2015-04-27 21:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-13 11:43 - 2015-04-27 21:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-13 11:43 - 2015-04-27 21:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-13 11:43 - 2015-04-27 21:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-13 11:43 - 2015-04-27 21:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-13 11:43 - 2015-04-27 20:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-13 11:43 - 2015-04-27 20:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-13 11:43 - 2015-04-27 20:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 11:43 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 11:42 - 2015-05-05 03:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 11:42 - 2015-04-20 04:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 11:42 - 2015-04-20 04:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 11:42 - 2015-04-20 04:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 11:42 - 2015-04-18 04:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 11:42 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-13 11:42 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-13 11:42 - 2015-03-04 06:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-13 11:42 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 11:41 - 2015-04-22 03:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 11:41 - 2015-04-21 18:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-13 11:41 - 2015-04-21 18:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 11:41 - 2015-04-21 18:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 11:41 - 2015-04-21 18:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 11:41 - 2015-04-21 18:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-13 11:41 - 2015-04-21 18:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-13 11:41 - 2015-04-21 18:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 11:41 - 2015-04-21 18:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-13 11:41 - 2015-04-21 18:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 11:41 - 2015-04-21 18:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-13 11:41 - 2015-04-21 18:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-13 11:41 - 2015-04-21 18:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 11:41 - 2015-04-21 17:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 11:41 - 2015-04-21 17:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-13 11:41 - 2015-04-21 17:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-13 11:41 - 2015-04-21 17:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-13 11:41 - 2015-04-21 17:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 11:41 - 2015-04-21 17:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-13 11:41 - 2015-04-21 17:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 11:41 - 2015-04-21 17:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-13 11:41 - 2015-04-21 17:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 11:41 - 2015-04-21 17:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 11:41 - 2015-04-21 17:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 11:41 - 2015-04-21 17:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 11:41 - 2015-04-21 17:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 11:41 - 2015-04-21 17:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 11:41 - 2015-04-21 17:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-13 11:41 - 2015-04-21 17:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 11:41 - 2015-04-21 17:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 11:41 - 2015-04-21 16:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 11:41 - 2015-04-21 16:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 11:41 - 2015-04-13 05:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 11:41 - 2015-04-08 05:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-13 11:41 - 2015-04-08 05:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-13 11:41 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-11 16:19 - 2015-05-11 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-05-06 18:32 - 2015-05-06 18:32 - 00000000 ____D () C:\Users\Barbarella\AppData\Roaming\Update Manager
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-28 20:12 - 2014-12-12 20:10 - 02012033 _____ () C:\Windows\WindowsUpdate.log
2015-05-28 20:11 - 2009-07-14 06:34 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-28 20:11 - 2009-07-14 06:34 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-28 20:02 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-28 19:55 - 2014-12-12 22:21 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-28 19:06 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-27 20:37 - 2014-12-24 21:47 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2015-05-27 19:46 - 2010-11-20 23:01 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-27 10:00 - 2014-12-12 20:53 - 00002127 _____ () C:\Windows\epplauncher.mif
2015-05-27 09:48 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-05-27 09:48 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-05-27 09:45 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2015-05-24 15:11 - 2015-02-09 19:17 - 00000000 ____D () C:\Users\Barbarella\AppData\Roaming\FLV and Media Player
2015-05-20 20:01 - 2015-04-04 15:52 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-20 18:15 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-05-20 11:50 - 2014-12-12 23:00 - 00000000 ____D () C:\Users\Barbarella\AppData\Roaming\Skype
2015-05-15 20:45 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-15 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-05-15 20:09 - 2014-12-12 20:53 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-05-15 20:09 - 2014-12-12 20:52 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-05-15 20:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-15 19:22 - 2014-12-12 22:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-14 18:43 - 2009-07-14 06:33 - 00286712 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-14 18:26 - 2014-12-14 16:10 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-14 18:25 - 2014-12-14 16:10 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-13 20:01 - 2011-04-12 03:38 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-13 12:51 - 2014-12-14 15:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-13 12:45 - 2014-12-14 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-06 17:42 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories =======
2015-01-25 16:23 - 2015-02-24 17:25 - 0005632 _____ () C:\Users\Barbarella\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-12 22:57 - 2014-12-12 22:57 - 0000003 _____ () C:\Users\Barbarella\AppData\Local\updater.log
2014-12-12 22:57 - 2015-04-23 13:19 - 0000412 _____ () C:\Users\Barbarella\AppData\Local\UserProducts.xml
2014-12-14 12:22 - 2014-12-14 12:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Barbarella\AppData\Local\Temp\Quarantine.exe
C:\Users\Barbarella\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-27 12:43
==================== End of log ============================ Nun hoffe ich mal, das ich "Dummerle" alles richtig gemacht habe.... |