SPACY-TRACY | 24.08.2013 10:45 |
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-08-2013 01
Ran by Andrea Wähling (administrator) on 24-08-2013 11:32:08
Running from C:\Users\Andrea Wähling\Desktop\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Comodo Security Solutions Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AMD) C:\windows\system32\atiesrxx.exe
(Hewlett-Packard Company) C:\windows\system32\Hpservice.exe
(AMD) C:\windows\system32\atieclxx.exe
(Andrea Electronics Corporation) C:\windows\system32\AEADISRV.EXE
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
() C:\Program Files\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
() C:\windows\system32\PnkBstrA.exe
() C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cistray.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(ICQ, LLC.) C:\Program Files\ICQ7.7\ICQ.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\Andrea Wähling\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit_manager.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cis.exe
() C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IELowutil.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Farbar) C:\Users\Andrea Wähling\Desktop\Downloads\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [288312 2009-07-28] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [PDF Complete] - C:\Program Files\PDF Complete\pdfsty.exe [563736 2009-06-18] (PDF Complete Inc)
HKLM\...\Run: [WirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54576 2009-11-18] (Hewlett-Packard)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft IntelliPoint\ipoint.exe [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1464536 2013-07-08] (COMODO)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [gbrspcontrol] - C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [1851088 2013-05-30] (Comodo Security Solutions, Inc.)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-13] (Sonic Solutions)
Winlogon\Notify\WB: C:\Program Files\AlienGUIse\fastload.dll [X]
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.7\ICQ.exe [127040 2012-04-04] (ICQ, LLC.)
HKCU\...\Run: [Facebook Update] - C:\Users\Andrea Wähling\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.)
HKCU\...\Run: [Optimizer Pro] - C:\Program Files\Optimizer Pro\OptProLauncher.exe [135672 2013-06-21] (PC Utilities Pro)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Andrea Wähling\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-08-15] (Spotify Ltd)
HKU\space\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AlienwareDock.lnk
ShortcutTarget: AlienwareDock.lnk -> C:\Windows\Red Alienware Skin Pack\AlienwareDock\AlienwareDock.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\Comodo\GeekBuddy\launcher.exe (Comodo Security Solutions Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\YzShadow.lnk
ShortcutTarget: YzShadow.lnk -> C:\Windows\Red Alienware Skin Pack\YzShadow\YzShadow.exe (No File)
Startup: C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?babsrc=HP_ss_gin2g&mntrId=84960026C71A548B&affID=119820&tt=040713_rdrctful&tsp=4936
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10
URLSearchHook: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.yd.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=84960026C71A548B&affID=119820&tt=040713_rdrctful&tsp=4936
SearchScopes: HKCU - {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: WebSpy Reports Browser Helper Object - {C68F45EB-A501-46AB-8165-BC042CD27136} - C:\windows\system32\WsReportBho.dll (WebSpy Ltd)
BHO: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Common Files\Simple Adblock\SimpleAdblock.dll (Simple Adblock)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
Toolbar: HKLM - loadtbs - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Andrea Wähling\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -loadtbs - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Andrea Wähling\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\Profiles\1r400uwb.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Andrea Wähling\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Andrea Wähling\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Extension: No Name - C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: No Name - C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF Extension: No Name - C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\profiles\extensions\user.js
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM\...\Firefox\Extensions: [{8E9E3331-D360-4f87-8803-52DE43566502}] C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: hxxp://www.yd.delta-search.com/?babsrc=HP_ss&mntrId=84960026C71A548B&affID=119820&tt=040713_rdrctful&tsp=4936
CHR RestoreOnStartup: "hxxp://facebook.com/", "https://apps.facebook.com/detexas/?ex=16&state=4f7264a0060b8cf83189f221503fdeac&code=AQBCQ1GyLZBz4mwgkL53aILL36EtiMA2RP28gHVlBbrbndk-U792_2NWu9WR-oC5Su10Ow-uMc41zAXJ73ArUVWN6b5acjZGHGaWWV53LlONbP8X6Mbd3THwfk-jAexIkHjfX71bc0Pi4rCx7K7uSdd95Uc2AkGUvkjimb1kHwryB88OoDuqpuUZsTxcRm9w6YnFJklcf0QBHhsQTVNch6j8s3TlkKhfqXBAIETWykpeVImBXM9Pj-FmZMz8fIy_JwnitImIscgSqlPDwPsj2hdP2waOgBASZ3dFJaCJu8Lt7Rk41uimDj8DXkOGtII23mc#_=_"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Facebook Desktop) - C:\Users\Andrea W\u00E4hling\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll No File
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Andrea W\u00E4hling\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Extension: (Google Docs) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (WOT) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.13_0
CHR Extension: (YouTube) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Vimium) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbepggeogbaibhgnhhndojpepiihcmeb\1.43_0
CHR Extension: (Web Assistant) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.602_0
CHR Extension: (AdBlock) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.5_0
CHR Extension: (Sniper Team) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgbbaloijjnkpigapgmocdpoblnlec\1.0.2_0
CHR Extension: (Unofficial Walking Dead Theme) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncieondinlhgaapbkmbnmdmmamchoiin\7_0
CHR Extension: (Google Wallet Service) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.9_0
CHR Extension: (Battlefield Play4Free) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh\1.0.96.0_0
CHR Extension: (Gmail) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR Extension: (OneClickDownload) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.3_0
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx
CHR HKLM\...\Chrome\Extension: [onpejdpfebeopffobknkodakfphdelnh] - C:\Users\Andrea Wähling\AppData\Roaming\BabSolution\CR\Delta.crx
CHR HKLM\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files\1ClickDownload\oneclickdownloader10.crx
========================== Services (Whitelisted) =================
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2009-12-03] (LSI Corporation)
R2 CLPSLauncher; C:\Program Files\Common Files\COMODO\launcher_service.exe [70352 2013-07-24] (Comodo Security Solutions Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4801304 2013-07-08] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [127192 2013-06-18] (COMODO)
R2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2095808 2013-08-01] ()
R2 GeekBuddyRSP; C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [1851088 2013-05-30] (Comodo Security Solutions, Inc.)
R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [124928 2009-07-10] (Hewlett-Packard)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-06-18] (PDF Complete Inc)
R2 PnkBstrA; C:\windows\system32\PnkBstrA.exe [76888 2013-07-18] ()
R2 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-06-30] ()
R2 yksvc; C:\Windows\System32\yk62x86.dll [364544 2009-09-28] (Marvell)
==================== Drivers (Whitelisted) ====================
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [35064 2013-05-07] (Windows (R) Win 7 DDK provider)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20072 2013-06-18] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [582936 2013-07-08] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [43728 2013-06-18] (COMODO)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [85464 2013-06-18] (COMODO)
S3 KMWDFILTERx86; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [25088 2009-04-29] (Windows (R) Codename Longhorn DDK provider)
R1 mbmiodrvr; C:\windows\system32\mbmiodrvr.sys [2944 2004-04-10] (cansoft@livewiredev.com)
S3 MfeAVFK; C:\Windows\System32\drivers\MfeAVFK.sys [79816 2009-05-16] (McAfee, Inc.)
S3 MfeBOPK; C:\Windows\System32\drivers\MfeBOPK.sys [35272 2009-05-16] (McAfee, Inc.)
R1 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [214024 2009-05-16] (McAfee, Inc.)
S3 MfeRKDK; C:\Windows\System32\drivers\MfeRKDK.sys [34248 2009-05-16] (McAfee, Inc.)
R1 mfetdik; C:\Windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [21784 2011-08-01] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-06-03] ()
R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
S1 MpKsl3d730fed; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60CD6E9E-D442-4E4E-95B4-9FD318F81D2F}\MpKsl3d730fed.sys [x]
S3 XDva401; \??\C:\windows\system32\XDva401.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-23 21:36 - 2013-08-23 21:36 - 00309760 _____ C:\Users\Andrea Wähling\AppData\Roaming\execc.exe
2013-08-23 21:07 - 2013-08-23 21:07 - 00000000 ____D C:\FRST
2013-08-23 20:29 - 2013-08-23 20:29 - 00007372 _____ C:\Users\Andrea Wähling\Documents\noch mehr Log-files.htm
2013-08-23 20:03 - 2013-08-23 20:20 - 00066066 _____ C:\Users\Andrea Wähling\Documents\log Dateien.htm
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Obrkng
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kjryligtsmn
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ickjr
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Bjrs
2013-08-23 16:25 - 2013-08-23 23:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Lqflxavswp
2013-08-23 16:25 - 2013-08-23 23:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Depbvlq
2013-08-23 16:25 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Byxeph
2013-08-23 16:24 - 2013-08-24 11:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kgpowbde
2013-08-23 16:24 - 2013-08-24 11:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Havzwpj
2013-08-23 16:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ngicsmy
2013-08-19 11:18 - 2013-08-24 11:19 - 00000986 _____ C:\windows\setupact.log
2013-08-19 11:18 - 2013-08-19 11:18 - 00000000 _____ C:\windows\setuperr.log
2013-08-17 09:50 - 2013-08-17 09:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-15 17:32 - 2013-08-20 17:57 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Spotify
2013-08-15 17:32 - 2013-08-16 20:28 - 00002075 _____ C:\Users\Andrea Wähling\Desktop\Spotify.lnk
2013-08-15 17:32 - 2013-08-15 17:32 - 00001838 _____ C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2013-08-15 17:32 - 2013-08-15 17:32 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Spotify
2013-08-14 04:41 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-14 04:41 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-14 04:41 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-14 04:41 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-14 04:41 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-14 04:41 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-14 04:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-14 04:41 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-14 04:31 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2013-08-14 04:31 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2013-08-14 04:31 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-14 04:31 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-14 04:31 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-14 04:30 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-14 04:30 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-14 04:30 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2013-08-14 04:30 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-14 04:30 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-14 04:30 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-14 04:30 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2013-08-13 15:22 - 2013-08-14 14:34 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-08-13 01:51 - 2013-08-15 12:05 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\vlc
2013-08-13 01:49 - 2013-08-13 01:49 - 00000000 ____D C:\Program Files\VideoLAN
2013-07-31 15:36 - 2013-07-31 15:36 - 00001928 _____ C:\Users\Public\Desktop\SeaMonkey.lnk
2013-07-31 15:36 - 2013-07-31 15:36 - 00000000 ____D C:\Program Files\SeaMonkey
2013-07-29 15:40 - 2013-07-29 15:34 - 00002050 _____ C:\Users\Andrea Wähling\Documents\Heimlich & Co [K].lnk
2013-07-28 09:29 - 2013-07-30 12:58 - 00000000 ____D C:\Users\Andrea Wähling\Desktop\Hörspiele
2013-07-28 05:39 - 2013-07-28 05:39 - 00002170 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-07-26 17:40 - 2013-07-26 17:40 - 00000000 ____D C:\Program Files\Common Files\COMODO
2013-07-26 16:47 - 2013-08-14 04:50 - 00000000 ____D C:\windows\system32\MRT
==================== One Month Modified Files and Folders =======
2013-08-24 11:29 - 2012-05-22 21:21 - 01474832 _____ C:\windows\system32\Drivers\sfi.dat
2013-08-24 11:26 - 2009-07-14 06:34 - 00022480 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-24 11:26 - 2009-07-14 06:34 - 00022480 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-24 11:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kgpowbde
2013-08-24 11:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Havzwpj
2013-08-24 11:20 - 2012-04-04 00:35 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\ICQ
2013-08-24 11:19 - 2013-08-19 11:18 - 00000986 _____ C:\windows\setupact.log
2013-08-24 11:19 - 2012-08-18 01:56 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-24 11:19 - 2012-06-30 06:43 - 00065536 _____ C:\windows\system32\Ikeext.etl
2013-08-24 11:19 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-23 23:39 - 2012-11-18 17:36 - 01604216 _____ C:\windows\WindowsUpdate.log
2013-08-23 23:37 - 2012-08-18 01:56 - 00001114 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-23 23:23 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Lqflxavswp
2013-08-23 23:23 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Depbvlq
2013-08-23 22:18 - 2012-03-30 07:17 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-23 21:36 - 2013-08-23 21:36 - 00309760 _____ C:\Users\Andrea Wähling\AppData\Roaming\execc.exe
2013-08-23 21:28 - 2012-04-26 18:21 - 00001174 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1983455989-3255254433-2619224457-1001UA.job
2013-08-23 21:28 - 2012-04-26 18:21 - 00001152 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1983455989-3255254433-2619224457-1001Core.job
2013-08-23 21:07 - 2013-08-23 21:07 - 00000000 ____D C:\FRST
2013-08-23 20:29 - 2013-08-23 20:29 - 00007372 _____ C:\Users\Andrea Wähling\Documents\noch mehr Log-files.htm
2013-08-23 20:20 - 2013-08-23 20:03 - 00066066 _____ C:\Users\Andrea Wähling\Documents\log Dateien.htm
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Obrkng
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kjryligtsmn
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ickjr
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Bjrs
2013-08-23 16:25 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Byxeph
2013-08-23 16:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ngicsmy
2013-08-22 09:30 - 2013-07-18 16:03 - 00282104 _____ C:\windows\system32\PnkBstrB.xtr
2013-08-22 09:27 - 2013-07-18 15:00 - 00139424 _____ C:\windows\system32\Drivers\PnkBstrK.sys
2013-08-22 09:26 - 2013-07-18 15:00 - 00282104 _____ C:\windows\system32\PnkBstrB.exe
2013-08-22 09:26 - 2013-07-18 15:00 - 00282104 _____ C:\windows\system32\PnkBstrB.ex0
2013-08-21 20:43 - 2013-04-11 15:14 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-21 20:22 - 2009-07-14 04:37 - 00000000 ____D C:\windows\tracing
2013-08-20 17:57 - 2013-08-15 17:32 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Spotify
2013-08-20 12:48 - 2013-04-26 13:05 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Adobe
2013-08-20 12:46 - 2012-03-30 07:17 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2013-08-20 12:46 - 2012-03-30 07:17 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-19 11:18 - 2013-08-19 11:18 - 00000000 _____ C:\windows\setuperr.log
2013-08-18 11:21 - 2012-04-25 04:34 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-17 09:50 - 2013-08-17 09:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-16 20:34 - 2012-04-01 17:14 - 00000052 _____ C:\windows\system32\DOErrors.log
2013-08-16 20:33 - 2010-08-03 17:58 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\HpUpdate
2013-08-16 20:28 - 2013-08-15 17:32 - 00002075 _____ C:\Users\Andrea Wähling\Desktop\Spotify.lnk
2013-08-16 20:28 - 2010-01-09 02:25 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-15 18:22 - 2009-07-14 04:37 - 00000000 ____D C:\windows\rescache
2013-08-15 17:32 - 2013-08-15 17:32 - 00001838 _____ C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2013-08-15 17:32 - 2013-08-15 17:32 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Spotify
2013-08-15 16:50 - 2012-07-02 10:07 - 00000176 _____ C:\Users\Andrea Wähling\AppData\default.pls
2013-08-15 16:31 - 2012-09-20 20:06 - 00000000 ___RD C:\Users\Andrea Wähling\Desktop\Mukköö
2013-08-15 16:31 - 2012-07-27 08:49 - 00000000 ____D C:\Users\Andrea Wähling\Documents\Drakensang
2013-08-15 12:59 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-08-15 12:05 - 2013-08-13 01:51 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\vlc
2013-08-15 11:25 - 2012-11-16 20:44 - 00000000 ____D C:\windows\Minidump
2013-08-15 11:25 - 2009-07-27 10:31 - 00000000 ____D C:\windows\Panther
2013-08-14 14:34 - 2013-08-13 15:22 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-08-14 14:22 - 2012-03-31 10:45 - 00000000 ____D C:\Program Files\CCleaner
2013-08-14 13:58 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE
2013-08-14 04:50 - 2013-07-26 16:47 - 00000000 ____D C:\windows\system32\MRT
2013-08-14 04:46 - 2012-04-13 03:00 - 75778376 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-08-13 01:49 - 2013-08-13 01:49 - 00000000 ____D C:\Program Files\VideoLAN
2013-08-04 16:13 - 2012-03-30 12:10 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Skype
2013-08-02 10:30 - 2013-07-20 00:30 - 00048392 _____ (COMODO CA Limited) C:\windows\system32\certsentry.dll
2013-08-02 10:30 - 2012-05-22 20:59 - 00000000 ____D C:\Program Files\Comodo
2013-07-31 15:36 - 2013-07-31 15:36 - 00001928 _____ C:\Users\Public\Desktop\SeaMonkey.lnk
2013-07-31 15:36 - 2013-07-31 15:36 - 00000000 ____D C:\Program Files\SeaMonkey
2013-07-31 15:36 - 2012-03-29 21:55 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Mozilla
2013-07-31 15:36 - 2012-03-29 21:55 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Mozilla
2013-07-31 15:33 - 2012-03-29 21:54 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-30 12:58 - 2013-07-28 09:29 - 00000000 ____D C:\Users\Andrea Wähling\Desktop\Hörspiele
2013-07-30 10:01 - 2009-07-14 06:53 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-07-29 15:34 - 2013-07-29 15:40 - 00002050 _____ C:\Users\Andrea Wähling\Documents\Heimlich & Co [K].lnk
2013-07-28 22:46 - 2013-05-04 22:10 - 00000000 ___RD C:\Users\Andrea Wähling\Desktop\Daniel
2013-07-28 05:39 - 2013-07-28 05:39 - 00002170 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-07-28 05:39 - 2012-08-18 01:56 - 00000000 ____D C:\Program Files\Google
2013-07-27 01:43 - 2012-07-02 06:58 - 00000000 ____D C:\Program Files\Web Assistant
2013-07-26 17:40 - 2013-07-26 17:40 - 00000000 ____D C:\Program Files\Common Files\COMODO
2013-07-26 17:40 - 2012-10-06 00:42 - 00002013 _____ C:\Users\Public\Desktop\GeekBuddy.lnk
2013-07-26 05:13 - 2013-08-14 04:41 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-07-26 05:13 - 2013-08-14 04:41 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-07-26 05:13 - 2013-08-14 04:41 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-07-26 05:12 - 2013-08-14 04:41 - 14329344 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 02048512 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-07-26 05:11 - 2013-08-14 04:41 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-07-26 05:11 - 2013-08-14 04:41 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-07-26 04:49 - 2013-08-14 04:41 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-07-26 03:59 - 2013-08-14 04:41 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-07-25 10:57 - 2013-08-14 04:30 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
Files to move or delete:
====================
C:\Users\Andrea Wähling\Skin Pack Installer System X86 3.0.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-15 18:11
==================== End Of Log ============================ --- --- ---
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-08-2013 01
Ran by Andrea Wähling (administrator) on 24-08-2013 11:32:08
Running from C:\Users\Andrea Wähling\Desktop\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Comodo Security Solutions Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AMD) C:\windows\system32\atiesrxx.exe
(Hewlett-Packard Company) C:\windows\system32\Hpservice.exe
(AMD) C:\windows\system32\atieclxx.exe
(Andrea Electronics Corporation) C:\windows\system32\AEADISRV.EXE
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
() C:\Program Files\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
() C:\windows\system32\PnkBstrA.exe
() C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cistray.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(ICQ, LLC.) C:\Program Files\ICQ7.7\ICQ.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\Andrea Wähling\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit_manager.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cis.exe
() C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IELowutil.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Farbar) C:\Users\Andrea Wähling\Desktop\Downloads\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [288312 2009-07-28] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [PDF Complete] - C:\Program Files\PDF Complete\pdfsty.exe [563736 2009-06-18] (PDF Complete Inc)
HKLM\...\Run: [WirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54576 2009-11-18] (Hewlett-Packard)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft IntelliPoint\ipoint.exe [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1464536 2013-07-08] (COMODO)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [gbrspcontrol] - C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [1851088 2013-05-30] (Comodo Security Solutions, Inc.)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-13] (Sonic Solutions)
Winlogon\Notify\WB: C:\Program Files\AlienGUIse\fastload.dll [X]
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.7\ICQ.exe [127040 2012-04-04] (ICQ, LLC.)
HKCU\...\Run: [Facebook Update] - C:\Users\Andrea Wähling\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.)
HKCU\...\Run: [Optimizer Pro] - C:\Program Files\Optimizer Pro\OptProLauncher.exe [135672 2013-06-21] (PC Utilities Pro)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Andrea Wähling\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-08-15] (Spotify Ltd)
HKU\space\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2009-06-17] (Hewlett-Packard Company)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AlienwareDock.lnk
ShortcutTarget: AlienwareDock.lnk -> C:\Windows\Red Alienware Skin Pack\AlienwareDock\AlienwareDock.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\Comodo\GeekBuddy\launcher.exe (Comodo Security Solutions Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\YzShadow.lnk
ShortcutTarget: YzShadow.lnk -> C:\Windows\Red Alienware Skin Pack\YzShadow\YzShadow.exe (No File)
Startup: C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?babsrc=HP_ss_gin2g&mntrId=84960026C71A548B&affID=119820&tt=040713_rdrctful&tsp=4936
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10
URLSearchHook: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.yd.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=84960026C71A548B&affID=119820&tt=040713_rdrctful&tsp=4936
SearchScopes: HKCU - {44C658C5-0678-4FDF-A74C-C73634E58B27} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: WebSpy Reports Browser Helper Object - {C68F45EB-A501-46AB-8165-BC042CD27136} - C:\windows\system32\WsReportBho.dll (WebSpy Ltd)
BHO: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Common Files\Simple Adblock\SimpleAdblock.dll (Simple Adblock)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
Toolbar: HKLM - loadtbs - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Andrea Wähling\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -loadtbs - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Andrea Wähling\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\Profiles\1r400uwb.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Andrea Wähling\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Andrea Wähling\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Extension: No Name - C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: No Name - C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF Extension: No Name - C:\Users\Andrea Wähling\AppData\Roaming\Mozilla\Firefox\profiles\extensions\user.js
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKLM\...\Firefox\Extensions: [{8E9E3331-D360-4f87-8803-52DE43566502}] C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: hxxp://www.yd.delta-search.com/?babsrc=HP_ss&mntrId=84960026C71A548B&affID=119820&tt=040713_rdrctful&tsp=4936
CHR RestoreOnStartup: "hxxp://facebook.com/", "https://apps.facebook.com/detexas/?ex=16&state=4f7264a0060b8cf83189f221503fdeac&code=AQBCQ1GyLZBz4mwgkL53aILL36EtiMA2RP28gHVlBbrbndk-U792_2NWu9WR-oC5Su10Ow-uMc41zAXJ73ArUVWN6b5acjZGHGaWWV53LlONbP8X6Mbd3THwfk-jAexIkHjfX71bc0Pi4rCx7K7uSdd95Uc2AkGUvkjimb1kHwryB88OoDuqpuUZsTxcRm9w6YnFJklcf0QBHhsQTVNch6j8s3TlkKhfqXBAIETWykpeVImBXM9Pj-FmZMz8fIy_JwnitImIscgSqlPDwPsj2hdP2waOgBASZ3dFJaCJu8Lt7Rk41uimDj8DXkOGtII23mc#_=_"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Facebook Desktop) - C:\Users\Andrea W\u00E4hling\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll No File
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Andrea W\u00E4hling\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Extension: (Google Docs) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (WOT) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.13_0
CHR Extension: (YouTube) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Vimium) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbepggeogbaibhgnhhndojpepiihcmeb\1.43_0
CHR Extension: (Web Assistant) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.602_0
CHR Extension: (AdBlock) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.5_0
CHR Extension: (Sniper Team) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgbbaloijjnkpigapgmocdpoblnlec\1.0.2_0
CHR Extension: (Unofficial Walking Dead Theme) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncieondinlhgaapbkmbnmdmmamchoiin\7_0
CHR Extension: (Google Wallet Service) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.9_0
CHR Extension: (Battlefield Play4Free) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh\1.0.96.0_0
CHR Extension: (Gmail) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR Extension: (OneClickDownload) - C:\Users\ANDREA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.3_0
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx
CHR HKLM\...\Chrome\Extension: [onpejdpfebeopffobknkodakfphdelnh] - C:\Users\Andrea Wähling\AppData\Roaming\BabSolution\CR\Delta.crx
CHR HKLM\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files\1ClickDownload\oneclickdownloader10.crx
========================== Services (Whitelisted) =================
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2009-12-03] (LSI Corporation)
R2 CLPSLauncher; C:\Program Files\Common Files\COMODO\launcher_service.exe [70352 2013-07-24] (Comodo Security Solutions Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4801304 2013-07-08] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [127192 2013-06-18] (COMODO)
R2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2095808 2013-08-01] ()
R2 GeekBuddyRSP; C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [1851088 2013-05-30] (Comodo Security Solutions, Inc.)
R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [124928 2009-07-10] (Hewlett-Packard)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-06-18] (PDF Complete Inc)
R2 PnkBstrA; C:\windows\system32\PnkBstrA.exe [76888 2013-07-18] ()
R2 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-06-30] ()
R2 yksvc; C:\Windows\System32\yk62x86.dll [364544 2009-09-28] (Marvell)
==================== Drivers (Whitelisted) ====================
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [35064 2013-05-07] (Windows (R) Win 7 DDK provider)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20072 2013-06-18] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [582936 2013-07-08] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [43728 2013-06-18] (COMODO)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [85464 2013-06-18] (COMODO)
S3 KMWDFILTERx86; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [25088 2009-04-29] (Windows (R) Codename Longhorn DDK provider)
R1 mbmiodrvr; C:\windows\system32\mbmiodrvr.sys [2944 2004-04-10] (cansoft@livewiredev.com)
S3 MfeAVFK; C:\Windows\System32\drivers\MfeAVFK.sys [79816 2009-05-16] (McAfee, Inc.)
S3 MfeBOPK; C:\Windows\System32\drivers\MfeBOPK.sys [35272 2009-05-16] (McAfee, Inc.)
R1 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [214024 2009-05-16] (McAfee, Inc.)
S3 MfeRKDK; C:\Windows\System32\drivers\MfeRKDK.sys [34248 2009-05-16] (McAfee, Inc.)
R1 mfetdik; C:\Windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [21784 2011-08-01] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-06-03] ()
R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
S1 MpKsl3d730fed; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60CD6E9E-D442-4E4E-95B4-9FD318F81D2F}\MpKsl3d730fed.sys [x]
S3 XDva401; \??\C:\windows\system32\XDva401.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-23 21:36 - 2013-08-23 21:36 - 00309760 _____ C:\Users\Andrea Wähling\AppData\Roaming\execc.exe
2013-08-23 21:07 - 2013-08-23 21:07 - 00000000 ____D C:\FRST
2013-08-23 20:29 - 2013-08-23 20:29 - 00007372 _____ C:\Users\Andrea Wähling\Documents\noch mehr Log-files.htm
2013-08-23 20:03 - 2013-08-23 20:20 - 00066066 _____ C:\Users\Andrea Wähling\Documents\log Dateien.htm
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Obrkng
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kjryligtsmn
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ickjr
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Bjrs
2013-08-23 16:25 - 2013-08-23 23:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Lqflxavswp
2013-08-23 16:25 - 2013-08-23 23:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Depbvlq
2013-08-23 16:25 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Byxeph
2013-08-23 16:24 - 2013-08-24 11:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kgpowbde
2013-08-23 16:24 - 2013-08-24 11:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Havzwpj
2013-08-23 16:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ngicsmy
2013-08-19 11:18 - 2013-08-24 11:19 - 00000986 _____ C:\windows\setupact.log
2013-08-19 11:18 - 2013-08-19 11:18 - 00000000 _____ C:\windows\setuperr.log
2013-08-17 09:50 - 2013-08-17 09:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-15 17:32 - 2013-08-20 17:57 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Spotify
2013-08-15 17:32 - 2013-08-16 20:28 - 00002075 _____ C:\Users\Andrea Wähling\Desktop\Spotify.lnk
2013-08-15 17:32 - 2013-08-15 17:32 - 00001838 _____ C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2013-08-15 17:32 - 2013-08-15 17:32 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Spotify
2013-08-14 04:41 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-14 04:41 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-14 04:41 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-14 04:41 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-14 04:41 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-14 04:41 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-14 04:41 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-14 04:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-14 04:41 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-14 04:31 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2013-08-14 04:31 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2013-08-14 04:31 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-14 04:31 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-14 04:31 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-14 04:30 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-14 04:30 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-14 04:30 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2013-08-14 04:30 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-14 04:30 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-14 04:30 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-14 04:30 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2013-08-13 15:22 - 2013-08-14 14:34 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-08-13 01:51 - 2013-08-15 12:05 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\vlc
2013-08-13 01:49 - 2013-08-13 01:49 - 00000000 ____D C:\Program Files\VideoLAN
2013-07-31 15:36 - 2013-07-31 15:36 - 00001928 _____ C:\Users\Public\Desktop\SeaMonkey.lnk
2013-07-31 15:36 - 2013-07-31 15:36 - 00000000 ____D C:\Program Files\SeaMonkey
2013-07-29 15:40 - 2013-07-29 15:34 - 00002050 _____ C:\Users\Andrea Wähling\Documents\Heimlich & Co [K].lnk
2013-07-28 09:29 - 2013-07-30 12:58 - 00000000 ____D C:\Users\Andrea Wähling\Desktop\Hörspiele
2013-07-28 05:39 - 2013-07-28 05:39 - 00002170 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-07-26 17:40 - 2013-07-26 17:40 - 00000000 ____D C:\Program Files\Common Files\COMODO
2013-07-26 16:47 - 2013-08-14 04:50 - 00000000 ____D C:\windows\system32\MRT
==================== One Month Modified Files and Folders =======
2013-08-24 11:29 - 2012-05-22 21:21 - 01474832 _____ C:\windows\system32\Drivers\sfi.dat
2013-08-24 11:26 - 2009-07-14 06:34 - 00022480 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-24 11:26 - 2009-07-14 06:34 - 00022480 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-24 11:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kgpowbde
2013-08-24 11:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Havzwpj
2013-08-24 11:20 - 2012-04-04 00:35 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\ICQ
2013-08-24 11:19 - 2013-08-19 11:18 - 00000986 _____ C:\windows\setupact.log
2013-08-24 11:19 - 2012-08-18 01:56 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-24 11:19 - 2012-06-30 06:43 - 00065536 _____ C:\windows\system32\Ikeext.etl
2013-08-24 11:19 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-23 23:39 - 2012-11-18 17:36 - 01604216 _____ C:\windows\WindowsUpdate.log
2013-08-23 23:37 - 2012-08-18 01:56 - 00001114 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-23 23:23 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Lqflxavswp
2013-08-23 23:23 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Depbvlq
2013-08-23 22:18 - 2012-03-30 07:17 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-23 21:36 - 2013-08-23 21:36 - 00309760 _____ C:\Users\Andrea Wähling\AppData\Roaming\execc.exe
2013-08-23 21:28 - 2012-04-26 18:21 - 00001174 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1983455989-3255254433-2619224457-1001UA.job
2013-08-23 21:28 - 2012-04-26 18:21 - 00001152 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1983455989-3255254433-2619224457-1001Core.job
2013-08-23 21:07 - 2013-08-23 21:07 - 00000000 ____D C:\FRST
2013-08-23 20:29 - 2013-08-23 20:29 - 00007372 _____ C:\Users\Andrea Wähling\Documents\noch mehr Log-files.htm
2013-08-23 20:20 - 2013-08-23 20:03 - 00066066 _____ C:\Users\Andrea Wähling\Documents\log Dateien.htm
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Obrkng
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Kjryligtsmn
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ickjr
2013-08-23 19:23 - 2013-08-23 19:23 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Bjrs
2013-08-23 16:25 - 2013-08-23 16:25 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Byxeph
2013-08-23 16:24 - 2013-08-23 16:24 - 00000000 ___HD C:\Users\Andrea Wähling\AppData\Roaming\Ngicsmy
2013-08-22 09:30 - 2013-07-18 16:03 - 00282104 _____ C:\windows\system32\PnkBstrB.xtr
2013-08-22 09:27 - 2013-07-18 15:00 - 00139424 _____ C:\windows\system32\Drivers\PnkBstrK.sys
2013-08-22 09:26 - 2013-07-18 15:00 - 00282104 _____ C:\windows\system32\PnkBstrB.exe
2013-08-22 09:26 - 2013-07-18 15:00 - 00282104 _____ C:\windows\system32\PnkBstrB.ex0
2013-08-21 20:43 - 2013-04-11 15:14 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-21 20:22 - 2009-07-14 04:37 - 00000000 ____D C:\windows\tracing
2013-08-20 17:57 - 2013-08-15 17:32 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Spotify
2013-08-20 12:48 - 2013-04-26 13:05 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Adobe
2013-08-20 12:46 - 2012-03-30 07:17 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2013-08-20 12:46 - 2012-03-30 07:17 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-19 11:18 - 2013-08-19 11:18 - 00000000 _____ C:\windows\setuperr.log
2013-08-18 11:21 - 2012-04-25 04:34 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-17 09:50 - 2013-08-17 09:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-16 20:34 - 2012-04-01 17:14 - 00000052 _____ C:\windows\system32\DOErrors.log
2013-08-16 20:33 - 2010-08-03 17:58 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\HpUpdate
2013-08-16 20:28 - 2013-08-15 17:32 - 00002075 _____ C:\Users\Andrea Wähling\Desktop\Spotify.lnk
2013-08-16 20:28 - 2010-01-09 02:25 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-15 18:22 - 2009-07-14 04:37 - 00000000 ____D C:\windows\rescache
2013-08-15 17:32 - 2013-08-15 17:32 - 00001838 _____ C:\Users\Andrea Wähling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2013-08-15 17:32 - 2013-08-15 17:32 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Spotify
2013-08-15 16:50 - 2012-07-02 10:07 - 00000176 _____ C:\Users\Andrea Wähling\AppData\default.pls
2013-08-15 16:31 - 2012-09-20 20:06 - 00000000 ___RD C:\Users\Andrea Wähling\Desktop\Mukköö
2013-08-15 16:31 - 2012-07-27 08:49 - 00000000 ____D C:\Users\Andrea Wähling\Documents\Drakensang
2013-08-15 12:59 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-08-15 12:05 - 2013-08-13 01:51 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\vlc
2013-08-15 11:25 - 2012-11-16 20:44 - 00000000 ____D C:\windows\Minidump
2013-08-15 11:25 - 2009-07-27 10:31 - 00000000 ____D C:\windows\Panther
2013-08-14 14:34 - 2013-08-13 15:22 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-08-14 14:22 - 2012-03-31 10:45 - 00000000 ____D C:\Program Files\CCleaner
2013-08-14 13:58 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE
2013-08-14 04:50 - 2013-07-26 16:47 - 00000000 ____D C:\windows\system32\MRT
2013-08-14 04:46 - 2012-04-13 03:00 - 75778376 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-08-13 01:49 - 2013-08-13 01:49 - 00000000 ____D C:\Program Files\VideoLAN
2013-08-04 16:13 - 2012-03-30 12:10 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Skype
2013-08-02 10:30 - 2013-07-20 00:30 - 00048392 _____ (COMODO CA Limited) C:\windows\system32\certsentry.dll
2013-08-02 10:30 - 2012-05-22 20:59 - 00000000 ____D C:\Program Files\Comodo
2013-07-31 15:36 - 2013-07-31 15:36 - 00001928 _____ C:\Users\Public\Desktop\SeaMonkey.lnk
2013-07-31 15:36 - 2013-07-31 15:36 - 00000000 ____D C:\Program Files\SeaMonkey
2013-07-31 15:36 - 2012-03-29 21:55 - 00000000 ____D C:\Users\ANDREA~1\AppData\Local\Mozilla
2013-07-31 15:36 - 2012-03-29 21:55 - 00000000 ____D C:\Users\Andrea Wähling\AppData\Roaming\Mozilla
2013-07-31 15:33 - 2012-03-29 21:54 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-30 12:58 - 2013-07-28 09:29 - 00000000 ____D C:\Users\Andrea Wähling\Desktop\Hörspiele
2013-07-30 10:01 - 2009-07-14 06:53 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-07-29 15:34 - 2013-07-29 15:40 - 00002050 _____ C:\Users\Andrea Wähling\Documents\Heimlich & Co [K].lnk
2013-07-28 22:46 - 2013-05-04 22:10 - 00000000 ___RD C:\Users\Andrea Wähling\Desktop\Daniel
2013-07-28 05:39 - 2013-07-28 05:39 - 00002170 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-07-28 05:39 - 2012-08-18 01:56 - 00000000 ____D C:\Program Files\Google
2013-07-27 01:43 - 2012-07-02 06:58 - 00000000 ____D C:\Program Files\Web Assistant
2013-07-26 17:40 - 2013-07-26 17:40 - 00000000 ____D C:\Program Files\Common Files\COMODO
2013-07-26 17:40 - 2012-10-06 00:42 - 00002013 _____ C:\Users\Public\Desktop\GeekBuddy.lnk
2013-07-26 05:13 - 2013-08-14 04:41 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-07-26 05:13 - 2013-08-14 04:41 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-07-26 05:13 - 2013-08-14 04:41 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-07-26 05:12 - 2013-08-14 04:41 - 14329344 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 02048512 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-07-26 05:12 - 2013-08-14 04:41 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-07-26 05:11 - 2013-08-14 04:41 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-07-26 05:11 - 2013-08-14 04:41 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-07-26 04:49 - 2013-08-14 04:41 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-07-26 03:59 - 2013-08-14 04:41 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-07-25 10:57 - 2013-08-14 04:30 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
Files to move or delete:
====================
C:\Users\Andrea Wähling\Skin Pack Installer System X86 3.0.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-15 18:11
==================== End Of Log ============================ --- --- ---
Das sollte es ejtzt gewesen sein,Danke für die Mühe! |