| hilflos_ |  30.10.2013 15:11 |         Code:  
 Malwarebytes Anti-Malware 1.75.0.1300 
www.malwarebytes.org   
Datenbank Version: v2013.10.30.03   
Windows 7 Service Pack 1 x64 NTFS 
Internet Explorer 10.0.9200.16721 
chr :: CHR-VAIO [Administrator]   
30.10.2013 14:51:55 
mbam-log-2013-10-30 (14-51-55).txt   
Art des Suchlaufs: Quick-Scan 
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM 
Deaktivierte Suchlaufeinstellungen: P2P 
Durchsuchte Objekte: 232477 
Laufzeit: 4 Minute(n), 56 Sekunde(n)   
Infizierte Speicherprozesse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Speichermodule: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungsschlüssel: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungswerte: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateiobjekte der Registrierung: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Verzeichnisse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateien: 0 
(Keine bösartigen Objekte gefunden)   
(Ende)    Code:  
 # AdwCleaner v3.010 - Bericht erstellt am 30/10/2013 um 15:18:58 
# Updated 20/10/2013 von Xplode 
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) 
# Benutzername : chr - CHR-VAIO 
# Gestartet von : C:\Users\chr\Desktop\adwcleaner.exe 
# Option : Löschen   
***** [ Dienste ] *****     
***** [ Dateien / Ordner ] *****   
Ordner Gelöscht : C:\Program Files (x86)\Ask.com 
Ordner Gelöscht : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe} 
Ordner Gelöscht : C:\Users\chr\AppData\LocalLow\AskToolbar 
Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar   
***** [ Verknüpfungen ] *****     
***** [ Registrierungsdatenbank ] *****   
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS 
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} 
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} 
Schlüssel Gelöscht : HKCU\Software\APN 
Schlüssel Gelöscht : HKCU\Software\Ask.com 
Schlüssel Gelöscht : HKCU\Software\OCS 
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar 
Schlüssel Gelöscht : HKLM\Software\APN 
Schlüssel Gelöscht : HKLM\Software\AskToolbar 
Schlüssel Gelöscht : HKLM\Software\DeviceVM 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DeviceVM 
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF 
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF   
***** [ Browser ] *****   
-\\ Internet Explorer v10.0.9200.16720     
-\\ Mozilla Firefox v25.0 (de)   
[ Datei : C:\Users\chr\AppData\Roaming\Mozilla\Firefox\Profiles\or9fe8dg.default\prefs.js ]   
Zeile gelöscht : user_pref("browser.search.defaultengine", "Ask.com"); 
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Ask.com"); 
Zeile gelöscht : user_pref("browser.search.order.1", "Ask.com"); 
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Ask.com"); 
Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "");   
*************************   
AdwCleaner[R0].txt - [5401 octets] - [30/10/2013 15:18:13] 
AdwCleaner[S0].txt - [5170 octets] - [30/10/2013 15:18:58]   
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5230 octets] ##########    Code:  
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Junkware Removal Tool (JRT) by Thisisu 
Version: 6.0.7 (10.15.2013:3) 
OS: Windows 7 Home Premium x64 
Ran by chr on 30.10.2013 at 15:35:47,52 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~         
~~~ Services       
~~~ Registry Values   
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page 
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page 
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page 
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page 
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page 
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1834122880-2644262191-2915525390-1000\Software\Microsoft\Internet Explorer\Main\\Start Page       
~~~ Registry Keys   
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askToolbarInstaller-1_RASAPI32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askToolbarInstaller-1_RASMANCS 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\askToolbarInstaller-1_RASAPI32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\askToolbarInstaller-1_RASMANCS 
Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"       
~~~ Files       
~~~ Folders   
Successfully deleted: [Empty Folder] C:\Users\chr\appdata\local\{2D460EFE-79CD-4D14-BD11-85CED62922BD} 
Successfully deleted: [Empty Folder] C:\Users\chr\appdata\local\{CBB96BA3-BB65-4B71-9936-0951ED1CE4A8}       
~~~ Event Viewer Logs were cleared           
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Scan was completed on 30.10.2013 at 15:41:33,54 
End of JRT log 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~   
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-10-2013 
Ran by chr (administrator) on CHR-VAIO on 30-10-2013 15:53:30 
Running from C:\Users\chr\Desktop 
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard 
Internet Explorer Version 10 
Boot Mode: Normal   
==================== Processes (Whitelisted) =================   
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe 
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe 
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe 
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe 
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe 
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 
(McAfee, Inc.) C:\Windows\system32\mfevtps.exe 
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe 
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe 
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE 
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe 
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe 
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe 
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe 
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe 
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe 
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe 
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe 
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe 
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe 
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe 
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe 
(Dropbox, Inc.) C:\Users\chr\AppData\Roaming\Dropbox\bin\Dropbox.exe 
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe 
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 
(McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe 
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe 
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe 
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe 
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunes\iTunesHelper.exe 
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe 
(ALPS) C:\Program Files\Apoint\Apvfb.exe 
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe 
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe 
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe 
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe 
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe 
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe 
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe 
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe 
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe 
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe 
(Microsoft Corporation) C:\Windows\System32\vds.exe   
==================== Registry (Whitelisted) ==================   
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.) 
HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [790176 2011-03-31] (Atheros Communications) 
HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657056 2011-03-31] (Atheros Commnucations) 
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.) 
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-13] (Adobe Systems Incorporated) 
HKLM\...\Run: [AS2014] - C:\ProgramData\7sDniXVa\7sDniXVa.exe 
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation) 
HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\mcafee.com\agent\mcagent.exe [1675160 2011-11-22] (McAfee, Inc.) 
HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2757312 2011-02-15] (Sony Corporation) 
HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-26] (Sony Corporation) 
HKLM-x32\...\Run: [TrayServer] - C:\Program Files (x86)\MAGIX\Video_deluxe_MX_Plus\Trayserver_DE.exe [90112 2008-08-07] (MAGIX AG) 
HKLM-x32\...\Run: [] - [x] 
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) 
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-09-03] (Adobe Systems Incorporated) 
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) 
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.) 
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated) 
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) 
HKU\Gast\...\Run: [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 
HKU\Gast\...\Run: [msnmsgr] - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4240760 2010-11-10] (Microsoft Corporation) 
HKU\Gast\...\Run: [svchost] - "C:\Users\Gast\AppData\Roaming\Microsoft\Hostprozess für Windows-Dienste\2.9.5.3\svchost.exe" /bg 
HKU\Gast\...\Run: [AnyDVD] - D:\AnyDVD\AnyDVDtray.exe 
HKU\Gast\...\Run: [conhost] - C:\Users\Gast\AppData\Roaming\Microsoft\conhost.exe 
HKU\Gast\...\CurrentVersion\Windows: [Load] C:\Users\Gast\AppData\Local\Temp\csrss.exe <===== ATTENTION 
Startup: C:\Users\chr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 
ShortcutTarget: Dropbox.lnk -> C:\Users\chr\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)   
==================== Internet (Whitelisted) ====================   
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ 
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe 
BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File 
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) 
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120318211641.dll (McAfee, Inc.) 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) 
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) 
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) 
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) 
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) 
BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files\mcafee\msk\mskapbho.dll () 
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) 
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120318211641.dll (McAfee, Inc.) 
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) 
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) 
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) 
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) 
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) 
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) 
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) 
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) 
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) 
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab 
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) 
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) 
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File 
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) 
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) 
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) 
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) 
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) 
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1   
FireFox: 
======== 
FF ProfilePath: C:\Users\chr\AppData\Roaming\Mozilla\Firefox\Profiles\or9fe8dg.default 
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () 
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) 
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () 
FF Plugin: @microsoft.com/GENUINE - disabled No File 
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) 
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) 
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () 
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\iTunes\Mozilla Plugins\npitunes.dll () 
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) 
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\progra~2\mcafee\msc\npmcsn~1.dll () 
FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) 
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File 
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) 
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) 
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) 
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) 
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) 
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml 
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml 
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml 
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml 
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor 
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor 
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore 
FF Extension: McAfee ScriptScan for Firefox - C:\Program Files (x86)\Common Files\McAfee\SystemCore   
==================== Services (Whitelisted) =================   
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) 
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-03-31] (Atheros) 
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
S3 McAWFwk; c:\PROGRA~1\mcafee\msc\mcawfwk.exe [220528 2010-08-09] (McAfee, Inc.) 
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [502032 2011-10-18] (McAfee, Inc.) 
S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199272 2011-12-06] (McAfee, Inc.) 
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [208536 2011-12-06] (McAfee, Inc.) 
R2 mfevtp; C:\Windows\system32\mfevtps.exe [161168 2011-12-06] (McAfee, Inc.) 
R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) 
S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) 
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) 
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) 
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation) 
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation) 
S2 WinDefend; %ProgramFiles%\Windows Defender\mpsvc.dll [x]   
==================== Drivers (Whitelisted) ====================   
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) 
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65264 2011-10-15] (McAfee, Inc.) 
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [160280 2011-10-15] (McAfee, Inc.) 
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [229528 2011-10-15] (McAfee, Inc.) 
U3 mfeavfk01; No ImagePath 
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [481768 2011-10-15] (McAfee, Inc.) 
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [647080 2011-10-15] (McAfee, Inc.) 
R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75808 2011-10-15] (McAfee, Inc.) 
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100912 2011-10-15] (McAfee, Inc.) 
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [284648 2011-10-15] (McAfee, Inc.) 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) 
S3 catchme; \??\C:\ComboFix\catchme.sys [x]   
==================== NetSvcs (Whitelisted) ===================     
==================== One Month Created Files and Folders ========   
2013-10-30 15:52 - 2013-10-30 15:52 - 01956614 _____ (Farbar) C:\Users\chr\Desktop\FRST64.exe 
2013-10-30 15:48 - 2013-10-30 15:51 - 00000000 ____D C:\Users\chr\Desktop\Antiviren 
2013-10-30 15:41 - 2013-10-30 15:41 - 00002338 _____ C:\Users\chr\Desktop\JRT.txt 
2013-10-30 15:35 - 2013-10-30 15:35 - 00000000 ____D C:\Windows\ERUNT 
2013-10-30 15:18 - 2013-10-30 15:19 - 00000000 ____D C:\AdwCleaner 
2013-10-30 14:48 - 2013-10-30 14:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 
2013-10-30 14:48 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 
2013-10-30 14:43 - 2013-10-30 14:44 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\chr\Downloads\mbam-setup-1.75.0.1300.exe 
2013-10-30 14:35 - 2013-10-30 14:35 - 00000000 ____D C:\Users\chr\AppData\Local\Macromedia 
2013-10-30 14:34 - 2013-10-30 14:34 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 
2013-10-30 14:34 - 2013-10-30 14:34 - 00000000 ____D C:\Users\chr\AppData\Roaming\Mozilla 
2013-10-30 14:34 - 2013-10-30 14:34 - 00000000 ____D C:\Users\chr\AppData\Local\Mozilla 
2013-10-30 14:34 - 2013-10-30 14:34 - 00000000 ____D C:\ProgramData\Mozilla 
2013-10-30 14:33 - 2013-10-30 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 
2013-10-30 14:33 - 2013-10-30 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 
2013-10-30 14:32 - 2013-10-30 14:33 - 00283104 _____ (Mozilla) C:\Users\chr\Downloads\Firefox Setup Stub 25.0.exe 
2013-10-30 10:15 - 2013-10-30 10:17 - 22205064 _____ (Microsoft Corporation) C:\Users\chr\Downloads\Windows-KB890830-x64-V5.5.exe 
2013-10-29 15:54 - 2013-10-29 15:54 - 00037029 _____ C:\ComboFix.txt 
2013-10-29 15:38 - 2013-10-29 15:54 - 00000000 ____D C:\ComboFix 
2013-10-29 15:30 - 2013-10-29 15:46 - 00001116 _____ C:\Windows\PFRO.log 
2013-10-29 15:27 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 
2013-10-29 15:27 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 
2013-10-29 15:27 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 
2013-10-29 15:27 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 
2013-10-29 15:27 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 
2013-10-29 15:27 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 
2013-10-29 15:27 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 
2013-10-29 15:27 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 
2013-10-29 14:44 - 2013-10-30 15:30 - 00398704 _____ C:\Windows\WindowsUpdate.log 
2013-10-29 14:42 - 2013-10-30 15:20 - 00000672 _____ C:\Windows\setupact.log 
2013-10-29 14:42 - 2013-10-29 14:42 - 00000000 _____ C:\Windows\setuperr.log 
2013-10-29 14:40 - 2013-10-29 14:40 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 
2013-10-29 14:38 - 2013-10-29 15:54 - 00000000 ____D C:\Qoobox 
2013-10-29 14:37 - 2013-10-29 15:51 - 00000000 ____D C:\Windows\erdnt 
2013-10-28 14:43 - 2013-10-28 14:44 - 00028700 _____ C:\Users\chr\Desktop\Addition.txt 
2013-10-28 14:41 - 2013-10-28 14:41 - 00000000 ____D C:\FRST 
2013-10-23 22:59 - 2013-10-23 22:59 - 00000000 ____D C:\Windows\Sun 
2013-10-23 21:41 - 2013-10-23 21:41 - 00000000 ____D C:\Users\chr\AppData\Roaming\Malwarebytes 
2013-10-23 21:41 - 2013-10-23 21:41 - 00000000 ____D C:\ProgramData\Malwarebytes 
2013-10-23 21:38 - 2013-10-23 21:40 - 00000000 ____D C:\Users\chr\Downloads\mbam-chameleon-1.62.1.1000 
2013-10-23 21:37 - 2013-10-23 21:38 - 01440846 _____ C:\Users\chr\Downloads\mbam-chameleon-1.62.1.1000.zip 
2013-10-22 20:05 - 2013-10-23 20:41 - 00000000 ____D C:\Users\chr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Security Pro 
2013-10-22 18:05 - 2013-10-22 18:05 - 00000000 ____D C:\Program Files (x86)\Google 
2013-10-22 18:04 - 2013-10-22 18:04 - 00000000 ____D C:\Users\chr\AppData\Local\Google 
2013-10-22 09:03 - 2013-10-22 09:06 - 00000000 ____D C:\Users\chr\AppData\Roaming\Apple Computer 
2013-10-22 09:03 - 2013-10-22 09:03 - 00001884 _____ C:\Users\Public\Desktop\iTunes.lnk 
2013-10-22 09:03 - 2013-10-22 09:03 - 00000000 ____D C:\Users\chr\AppData\Local\Apple Computer 
2013-10-22 09:02 - 2012-08-21 12:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 
2013-10-22 09:01 - 2013-10-22 09:02 - 00000000 ____D C:\Program Files\iTunes 
2013-10-22 09:01 - 2013-10-22 09:01 - 00000000 ____D C:\ProgramData\Apple Computer 
2013-10-22 09:01 - 2013-10-22 09:01 - 00000000 ____D C:\Program Files\iPod 
2013-10-22 09:01 - 2013-10-22 09:01 - 00000000 ____D C:\Program Files (x86)\iTunes 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Users\chr\AppData\Local\Apple 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\ProgramData\Apple 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files\Common Files\Apple 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files\Bonjour 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files (x86)\Bonjour 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 
2013-10-22 08:56 - 2013-10-22 08:58 - 97206096 _____ (Apple Inc.) C:\Users\chr\Downloads\iTunes64Setup.exe 
2013-10-12 11:16 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 
2013-10-12 11:16 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 
2013-10-12 11:16 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 
2013-10-12 11:16 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 
2013-10-12 11:16 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 
2013-10-12 11:16 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 
2013-10-12 11:16 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 
2013-10-12 11:16 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 
2013-10-12 11:16 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 
2013-10-12 11:16 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 
2013-10-12 11:16 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 
2013-10-12 11:16 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 
2013-10-11 06:33 - 2013-10-11 06:33 - 00000165 ____H C:\Users\chr\Documents\~$Der Syndromansatz.pptx 
2013-10-10 17:28 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 
2013-10-10 17:28 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 
2013-10-10 17:28 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 
2013-10-10 17:28 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 
2013-10-10 17:28 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 
2013-10-10 17:28 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 
2013-10-10 17:28 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 
2013-10-10 17:28 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 
2013-10-10 17:28 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 
2013-10-10 17:28 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 
2013-10-10 17:28 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 
2013-10-10 17:28 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 
2013-10-10 17:28 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 
2013-10-10 17:28 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 
2013-10-10 17:28 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 
2013-10-10 17:28 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 
2013-10-10 17:28 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 
2013-10-10 17:28 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 
2013-10-10 17:28 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 
2013-10-10 17:28 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 
2013-10-10 17:28 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 
2013-10-10 17:28 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 
2013-10-10 17:28 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 
2013-10-10 17:28 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 
2013-10-10 17:28 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 
2013-10-10 17:28 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 
2013-10-10 17:28 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 
2013-10-10 17:27 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 
2013-10-10 17:27 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 
2013-10-10 17:27 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 
2013-10-10 17:27 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 
2013-10-10 17:27 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 
2013-10-10 17:27 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 
2013-10-10 17:27 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 
2013-10-10 17:27 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 
2013-10-10 17:27 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 
2013-10-10 17:27 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 
2013-10-10 17:27 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 
2013-10-10 17:27 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 
2013-10-10 17:27 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 
2013-10-10 17:27 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 
2013-10-10 17:27 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 
2013-10-10 17:27 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 
2013-10-10 17:27 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 
2013-10-10 17:27 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 
2013-10-10 17:27 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 
2013-10-03 20:13 - 2013-10-18 17:28 - 00678972 _____ C:\Users\chr\Documents\Der Syndromansatz.pptx 
2013-10-03 14:20 - 2013-10-03 14:25 - 00000000 ____D C:\Users\chr\Documents\WebCam Media 
2013-10-03 11:26 - 2013-10-03 11:26 - 00000000 ____D C:\Users\chr\AppData\Roaming\Cornelsen   
==================== One Month Modified Files and Folders =======   
2013-10-30 15:52 - 2013-10-30 15:52 - 01956614 _____ (Farbar) C:\Users\chr\Desktop\FRST64.exe 
2013-10-30 15:51 - 2013-10-30 15:48 - 00000000 ____D C:\Users\chr\Desktop\Antiviren 
2013-10-30 15:51 - 2013-03-31 13:20 - 00000000 ___RD C:\Users\chr\Dropbox 
2013-10-30 15:51 - 2013-03-31 13:16 - 00000000 ____D C:\Users\chr\AppData\Roaming\Dropbox 
2013-10-30 15:51 - 2011-12-24 22:41 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{652924D5-466E-4D99-8332-AA0B7322649C} 
2013-10-30 15:47 - 2012-03-31 06:01 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 
2013-10-30 15:41 - 2013-10-30 15:41 - 00002338 _____ C:\Users\chr\Desktop\JRT.txt 
2013-10-30 15:35 - 2013-10-30 15:35 - 00000000 ____D C:\Windows\ERUNT 
2013-10-30 15:30 - 2013-10-29 14:44 - 00398704 _____ C:\Windows\WindowsUpdate.log 
2013-10-30 15:28 - 2009-07-14 05:45 - 00020928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
2013-10-30 15:28 - 2009-07-14 05:45 - 00020928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
2013-10-30 15:26 - 2011-05-21 17:32 - 00696870 _____ C:\Windows\system32\perfh007.dat 
2013-10-30 15:26 - 2011-05-21 17:32 - 00148134 _____ C:\Windows\system32\perfc007.dat 
2013-10-30 15:26 - 2009-07-14 06:13 - 01612294 _____ C:\Windows\system32\PerfStringBackup.INI 
2013-10-30 15:24 - 2012-09-23 22:42 - 00001828 _____ C:\Users\Public\Desktop\McAfee Security Center.lnk 
2013-10-30 15:20 - 2013-10-29 14:42 - 00000672 _____ C:\Windows\setupact.log 
2013-10-30 15:20 - 2011-05-21 07:49 - 00000000 ____D C:\ProgramData\NVIDIA 
2013-10-30 15:20 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 
2013-10-30 15:19 - 2013-10-30 15:18 - 00000000 ____D C:\AdwCleaner 
2013-10-30 14:48 - 2013-10-30 14:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 
2013-10-30 14:44 - 2013-10-30 14:43 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\chr\Downloads\mbam-setup-1.75.0.1300.exe 
2013-10-30 14:35 - 2013-10-30 14:35 - 00000000 ____D C:\Users\chr\AppData\Local\Macromedia 
2013-10-30 14:34 - 2013-10-30 14:34 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 
2013-10-30 14:34 - 2013-10-30 14:34 - 00000000 ____D C:\Users\chr\AppData\Roaming\Mozilla 
2013-10-30 14:34 - 2013-10-30 14:34 - 00000000 ____D C:\Users\chr\AppData\Local\Mozilla 
2013-10-30 14:34 - 2013-10-30 14:34 - 00000000 ____D C:\ProgramData\Mozilla 
2013-10-30 14:34 - 2013-10-30 14:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 
2013-10-30 14:34 - 2013-10-30 14:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 
2013-10-30 14:33 - 2013-10-30 14:32 - 00283104 _____ (Mozilla) C:\Users\chr\Downloads\Firefox Setup Stub 25.0.exe 
2013-10-30 10:17 - 2013-10-30 10:15 - 22205064 _____ (Microsoft Corporation) C:\Users\chr\Downloads\Windows-KB890830-x64-V5.5.exe 
2013-10-29 15:54 - 2013-10-29 15:54 - 00037029 _____ C:\ComboFix.txt 
2013-10-29 15:54 - 2013-10-29 15:38 - 00000000 ____D C:\ComboFix 
2013-10-29 15:54 - 2013-10-29 14:38 - 00000000 ____D C:\Qoobox 
2013-10-29 15:54 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 
2013-10-29 15:51 - 2013-10-29 14:37 - 00000000 ____D C:\Windows\erdnt 
2013-10-29 15:47 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 
2013-10-29 15:46 - 2013-10-29 15:30 - 00001116 _____ C:\Windows\PFRO.log 
2013-10-29 15:36 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 
2013-10-29 14:42 - 2013-10-29 14:42 - 00000000 _____ C:\Windows\setuperr.log 
2013-10-29 14:40 - 2013-10-29 14:40 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 
2013-10-28 14:44 - 2013-10-28 14:43 - 00028700 _____ C:\Users\chr\Desktop\Addition.txt 
2013-10-28 14:41 - 2013-10-28 14:41 - 00000000 ____D C:\FRST 
2013-10-26 15:43 - 2011-12-24 23:34 - 00000000 ____D C:\Users\chr\AppData\Local\Adobe 
2013-10-23 22:59 - 2013-10-23 22:59 - 00000000 ____D C:\Windows\Sun 
2013-10-23 21:41 - 2013-10-23 21:41 - 00000000 ____D C:\Users\chr\AppData\Roaming\Malwarebytes 
2013-10-23 21:41 - 2013-10-23 21:41 - 00000000 ____D C:\ProgramData\Malwarebytes 
2013-10-23 21:40 - 2013-10-23 21:38 - 00000000 ____D C:\Users\chr\Downloads\mbam-chameleon-1.62.1.1000 
2013-10-23 21:38 - 2013-10-23 21:37 - 01440846 _____ C:\Users\chr\Downloads\mbam-chameleon-1.62.1.1000.zip 
2013-10-23 20:41 - 2013-10-22 20:05 - 00000000 ____D C:\Users\chr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Security Pro 
2013-10-22 18:59 - 2011-12-25 14:27 - 00000000 ____D C:\Users\chr\AppData\Local\CrashDumps 
2013-10-22 18:05 - 2013-10-22 18:05 - 00000000 ____D C:\Program Files (x86)\Google 
2013-10-22 18:04 - 2013-10-22 18:04 - 00000000 ____D C:\Users\chr\AppData\Local\Google 
2013-10-22 09:06 - 2013-10-22 09:03 - 00000000 ____D C:\Users\chr\AppData\Roaming\Apple Computer 
2013-10-22 09:03 - 2013-10-22 09:03 - 00001884 _____ C:\Users\Public\Desktop\iTunes.lnk 
2013-10-22 09:03 - 2013-10-22 09:03 - 00000000 ____D C:\Users\chr\AppData\Local\Apple Computer 
2013-10-22 09:02 - 2013-10-22 09:01 - 00000000 ____D C:\Program Files\iTunes 
2013-10-22 09:01 - 2013-10-22 09:01 - 00000000 ____D C:\ProgramData\Apple Computer 
2013-10-22 09:01 - 2013-10-22 09:01 - 00000000 ____D C:\Program Files\iPod 
2013-10-22 09:01 - 2013-10-22 09:01 - 00000000 ____D C:\Program Files (x86)\iTunes 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Users\chr\AppData\Local\Apple 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\ProgramData\Apple 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files\Common Files\Apple 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files\Bonjour 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files (x86)\Bonjour 
2013-10-22 09:00 - 2013-10-22 09:00 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 
2013-10-22 08:58 - 2013-10-22 08:56 - 97206096 _____ (Apple Inc.) C:\Users\chr\Downloads\iTunes64Setup.exe 
2013-10-22 08:50 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 
2013-10-18 17:28 - 2013-10-03 20:13 - 00678972 _____ C:\Users\chr\Documents\Der Syndromansatz.pptx 
2013-10-18 16:38 - 2012-10-05 14:46 - 00000000 ____D C:\Users\chr\AppData\Local\Microsoft Help 
2013-10-15 09:02 - 2011-12-24 22:24 - 00000000 ____D C:\Users\chr 
2013-10-15 08:33 - 2012-02-11 13:53 - 00000000 ____D C:\Users\chr\fut2 
2013-10-13 21:56 - 2011-12-24 22:33 - 00000000 ____D C:\Users\chr\AppData\Roaming\Adobe 
2013-10-12 20:06 - 2013-03-31 13:20 - 00001011 _____ C:\Users\chr\Desktop\Dropbox.lnk 
2013-10-12 20:06 - 2013-03-31 13:17 - 00000000 ____D C:\Users\chr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 
2013-10-12 20:06 - 2011-12-24 22:27 - 00000000 ___RD C:\Users\chr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 
2013-10-12 16:07 - 2009-07-14 05:45 - 05221792 _____ C:\Windows\system32\FNTCACHE.DAT 
2013-10-12 16:06 - 2013-03-13 22:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight 
2013-10-12 16:06 - 2013-03-13 22:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 
2013-10-12 16:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 
2013-10-12 11:47 - 2012-03-31 06:01 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 
2013-10-12 11:47 - 2012-03-31 06:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 
2013-10-12 11:47 - 2012-03-31 06:01 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 
2013-10-12 11:18 - 2012-10-05 14:46 - 00000000 ____D C:\ProgramData\Microsoft Help 
2013-10-12 11:14 - 2011-02-11 00:03 - 01590378 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 
2013-10-12 11:07 - 2013-08-09 20:19 - 00000000 ____D C:\Windows\system32\MRT 
2013-10-12 10:54 - 2011-12-24 22:31 - 00000000 ____D C:\Users\chr\Documents\Bluetooth Folder 
2013-10-11 06:33 - 2013-10-11 06:33 - 00000165 ____H C:\Users\chr\Documents\~$Der Syndromansatz.pptx 
2013-10-04 14:00 - 2011-05-21 07:53 - 00000000 ____D C:\Program Files (x86)\McAfee 
2013-10-03 14:25 - 2013-10-03 14:20 - 00000000 ____D C:\Users\chr\Documents\WebCam Media 
2013-10-03 14:21 - 2011-05-21 08:07 - 00000000 ___HD C:\ProgramData\ArcSoft 
2013-10-03 14:20 - 2012-03-30 20:04 - 00000000 ____D C:\Users\chr\AppData\Roaming\ArcSoft 
2013-10-03 11:26 - 2013-10-03 11:26 - 00000000 ____D C:\Users\chr\AppData\Roaming\Cornelsen 
2013-09-30 13:44 - 2013-09-29 12:58 - 00000000 ____D C:\Users\chr\HW_21   
Some content of TEMP: 
==================== 
C:\Users\chr\AppData\Local\Temp\Quarantine.exe     
==================== Bamital & volsnap Check =================   
C:\Windows\System32\winlogon.exe => MD5 is legit 
C:\Windows\System32\wininit.exe => MD5 is legit 
C:\Windows\SysWOW64\wininit.exe => MD5 is legit 
C:\Windows\explorer.exe => MD5 is legit 
C:\Windows\SysWOW64\explorer.exe => MD5 is legit 
C:\Windows\System32\svchost.exe => MD5 is legit 
C:\Windows\SysWOW64\svchost.exe => MD5 is legit 
C:\Windows\System32\services.exe => MD5 is legit 
C:\Windows\System32\User32.dll => MD5 is legit 
C:\Windows\SysWOW64\User32.dll => MD5 is legit 
C:\Windows\System32\userinit.exe => MD5 is legit 
C:\Windows\SysWOW64\userinit.exe => MD5 is legit 
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit     
LastRegBack: 2013-10-26 15:59   
==================== End Of Log ============================   --- --- ---     |