anja1988 | 28.01.2014 19:33 | antimalware nochmal: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.01.28.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Anja :: ANJA-PC2 [Administrator]
Schutz: Aktiviert
28.01.2014 18:32:28
mbam-log-2014-01-28 (18-32-28).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 219596
Laufzeit: 7 Minute(n), 7 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) adwcleaner: Code:
# AdwCleaner v3.018 - Bericht erstellt am 28/01/2014 um 19:03:34
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Anja - ANJA-PC2
# Gestartet von : D:\Eigene Dateien\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\DAEMON Tools Toolbar
Ordner Gelöscht : C:\Users\Anja\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\OCS
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\Conduit
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\SweetIMToolbarData
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Components\AskSearch.js
Datei Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\searchplugins\SweetIm.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader76279_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader76279_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_recuva_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_recuva_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7CD74AFF-3433-4E34-92E2-D98DFDB30754}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\prefs.js ]
Zeile gelöscht : user_pref("CT2463487.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gelöscht : user_pref("CT2463487.CTID", "CT2463487");
Zeile gelöscht : user_pref("CT2463487.CurrentServerDate", "11-5-2010");
Zeile gelöscht : user_pref("CT2463487.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2463487.DownloadReferralCookieData", "");
Zeile gelöscht : user_pref("CT2463487.EMailNotifierPollDate", "Tue May 11 2010 21:17:57 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.FirstServerDate", "11-5-2010");
Zeile gelöscht : user_pref("CT2463487.FirstTime", true);
Zeile gelöscht : user_pref("CT2463487.FirstTimeFF3", true);
Zeile gelöscht : user_pref("CT2463487.FirstTimeSettingsDone", true);
Zeile gelöscht : user_pref("CT2463487.FixPageNotFoundErrors", false);
Zeile gelöscht : user_pref("CT2463487.GroupingServerCheckInterval", 1440);
Zeile gelöscht : user_pref("CT2463487.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gelöscht : user_pref("CT2463487.Initialize", true);
Zeile gelöscht : user_pref("CT2463487.InitializeCommonPrefs", true);
Zeile gelöscht : user_pref("CT2463487.InstallationAndCookieDataSentCount", 1);
Zeile gelöscht : user_pref("CT2463487.InstalledDate", "Tue May 11 2010 21:17:39 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.InvalidateCache", false);
Zeile gelöscht : user_pref("CT2463487.IsGrouping", false);
Zeile gelöscht : user_pref("CT2463487.IsMulticommunity", false);
Zeile gelöscht : user_pref("CT2463487.IsOpenThankYouPage", true);
Zeile gelöscht : user_pref("CT2463487.IsOpenUninstallPage", true);
Zeile gelöscht : user_pref("CT2463487.LanguagePackLastCheckTime", "Tue May 11 2010 21:17:39 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.LanguagePackReloadIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2463487.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gelöscht : user_pref("CT2463487.LastLogin_2.6.0.15", "Tue May 11 2010 21:17:57 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.LatestVersion", "2.1.0.18");
Zeile gelöscht : user_pref("CT2463487.Locale", "en");
Zeile gelöscht : user_pref("CT2463487.LoginCache", 4);
Zeile gelöscht : user_pref("CT2463487.MCDetectTooltipHeight", "83");
Zeile gelöscht : user_pref("CT2463487.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gelöscht : user_pref("CT2463487.MCDetectTooltipWidth", "295");
Zeile gelöscht : user_pref("CT2463487.RadioIsPodcast", false);
Zeile gelöscht : user_pref("CT2463487.RadioLastCheckTime", "Tue May 11 2010 21:17:38 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.RadioLastUpdateIPServer", "3");
Zeile gelöscht : user_pref("CT2463487.RadioLastUpdateServer", "129042273303200000");
Zeile gelöscht : user_pref("CT2463487.RadioMediaID", "13027686");
Zeile gelöscht : user_pref("CT2463487.RadioMediaType", "Media Player");
Zeile gelöscht : user_pref("CT2463487.RadioMenuSelectedID", "EBRadioMenu_CT246348713027686");
Zeile gelöscht : user_pref("CT2463487.RadioStationName", "ckln.fm");
Zeile gelöscht : user_pref("CT2463487.RadioStationURL", "hxxp://141.117.225.9:8000");
Zeile gelöscht : user_pref("CT2463487.SHRINK_TOOLBAR", 1);
Zeile gelöscht : user_pref("CT2463487.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2463487&octid=EB_ORIGINAL_CTID&SearchSource=1");
Zeile gelöscht : user_pref("CT2463487.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("CT2463487.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2463487&q=");
Zeile gelöscht : user_pref("CT2463487.SearchInNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2463487.SearchInNewTabIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2463487.SearchInNewTabLastCheckTime", "Tue May 11 2010 21:17:58 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2463487.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2463487.SettingsCheckIntervalMin", 120);
Zeile gelöscht : user_pref("CT2463487.SettingsLastCheckTime", "Tue May 11 2010 21:17:36 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.SettingsLastUpdate", "1273549006");
Zeile gelöscht : user_pref("CT2463487.ThirdPartyComponentsInterval", 504);
Zeile gelöscht : user_pref("CT2463487.ThirdPartyComponentsLastCheck", "Tue May 11 2010 21:17:36 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.ThirdPartyComponentsLastUpdate", "1273549006");
Zeile gelöscht : user_pref("CT2463487.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Zeile gelöscht : user_pref("CT2463487.Uninstall", true);
Zeile gelöscht : user_pref("CT2463487.UserID", "UN32243536411522583");
Zeile gelöscht : user_pref("CT2463487.ValidationData_Toolbar", 2);
Zeile gelöscht : user_pref("CT2463487.WeatherNetwork", "");
Zeile gelöscht : user_pref("CT2463487.WeatherPollDate", "Tue May 11 2010 21:17:38 GMT+0200");
Zeile gelöscht : user_pref("CT2463487.WeatherUnit", "C");
Zeile gelöscht : user_pref("CT2463487.alertChannelId", "857155");
Zeile gelöscht : user_pref("CT2463487.clientLogIsEnabled", false);
Zeile gelöscht : user_pref("CT2463487.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2463487.myStuffEnabled", true);
Zeile gelöscht : user_pref("CT2463487.myStuffPublihserMinWidth", 400);
Zeile gelöscht : user_pref("CT2463487.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2463487.myStuffServiceIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2463487.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gelöscht : user_pref("CT2463487.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "CT2431245");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/DE", "\"0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/857155/852957/DE", "\"0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", "\"1300865807\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de-de", "L+tncv4eqt6Qm5T3dzChdA==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de-de", "poKjTfHs0NrVUIalKI8jyg==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de-de", "QmycQXJXVyFVAzIiNllWhQ==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de-de", "SuMy8xgBA7+FodOxmk9aiQ==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"634386539058500000\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634303635100000000");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2431245/CT2431245", "\"1303224677\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"634351849102130000\"");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwner", "");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerGuid", "");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerToolbarId", "");
Zeile gelöscht : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwner", "");
Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "");
Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "");
Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2463487");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2463487");
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Jun 08 2011 03:01:35 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.locale", "en");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jun 08 2011 03:01:35 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Zeile gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Zeile gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userId", "{17730671-c94c-4411-a5eb-e09421684e63}");
Zeile gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Tue May 11 2010 21:17:39 GMT+0200");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.sweetim.com/search.asp?src=2&q=");
Zeile gelöscht : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Zeile gelöscht : user_pref("sweetim.toolbar.mode.debug", "false");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "chrome://browser-region/locale/region.properties");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://www.google.de/|hxxp://www.t-online.de/");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", "chrome://browser-region/locale/region.properties");
Zeile gelöscht : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"[...]
Zeile gelöscht : user_pref("sweetim.toolbar.search.history.capacity", "10");
Zeile gelöscht : user_pref("sweetim.toolbar.simapp_id", "{B810AF13-4F7E-42F9-80C7-DEE76DF334FF}");
Zeile gelöscht : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com");
Zeile gelöscht : user_pref("sweetim.toolbar.version", "1.0.0.10");
*************************
AdwCleaner[R0].txt - [16864 octets] - [28/01/2014 19:01:18]
AdwCleaner[S0].txt - [16306 octets] - [28/01/2014 19:03:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16367 octets] ########## junkware removal tool: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Home Premium x64
Ran by Anja on 28.01.2014 at 19:17:36,19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3891313822-1426816455-2197276303-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ASKUpgrade_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ASKUpgrade_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ASKUpgrade_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ASKUpgrade_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0F8BAA37-548E-476A-B8BD-65FF02485269}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{233BA7DA-7443-4232-BEA9-46613F61F319}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0F8BAA37-548E-476A-B8BD-65FF02485269}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{233BA7DA-7443-4232-BEA9-46613F61F319}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{0E20E1A4-408F-4C64-95BF-8F782F8C7B86}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{0FCE0130-EB9E-4EC7-A14D-C67F0BC2AC80}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{12337F54-68C8-4529-AB44-F22AA3792363}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{1A98BAEF-F2DE-4C32-BB24-30B3589C7E00}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{1F148FA9-E6A9-4178-9E35-304B43FCACC6}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{21538725-73D8-4F78-BF6A-CE33D651568B}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{30056CC0-E5F4-4335-B586-045994E14441}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{31DA97D0-FFD0-44FD-98C5-8BF3579475F3}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{34B19636-86F7-4F5B-AB2A-B4A048CB5768}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{38290D6D-83E4-42B4-BCF4-E999F591224B}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{3A831B3D-F49F-4A42-A2C8-C7818AC97358}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{3CE916C1-F22B-4F61-B03B-158AD0C902BF}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{471F3A08-8DF9-465E-BA0C-2A396BD63A7A}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{51918160-3F80-4017-BDE3-D25FD6042D74}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{586F97E1-E803-4813-80BD-D2562F949D89}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{5CF03F18-A58C-4B5F-90D4-AB7B9D041404}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{644A53BC-EB8A-41FD-91F9-1E3F36C5EAD2}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{6551AB4A-4E5D-48B0-A96F-6D8EB93A6398}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{68664F1A-0BB4-43B4-8D99-190FD3602665}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{81D2FADA-F020-4D38-A8BD-0C53FC2B7C47}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{8AB34894-00B6-468E-8544-1AB2F8077F81}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{96299CC1-3315-4099-9BF1-0783E0352215}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{99B4948F-3D33-4371-9C13-5CC5809FE46D}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{A098D089-BA76-4CA8-A8C5-92EBBE4BCCA9}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{AAD60FDC-9BE7-40DA-B873-697A1869AE9A}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{AD52CFD2-769C-4F6F-A345-88857EB09E4B}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{B55B7A85-3554-48BA-BA56-C4CE5AD9437D}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{B5FB6645-7F5E-4E8B-B55B-4DD7F127F77C}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{BFA97D5B-C5D6-4EF0-87BC-610A0C148A83}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{C16EC6A6-721B-456A-8255-3EB4B3637A40}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{C2899F2E-701B-45B4-9E5E-FC3774643004}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{C70B4E81-B4F3-45BC-B5FA-F158E4EFC5A9}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{D145495C-C60B-4147-94AF-A6A4F4049B02}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{D666D0B9-31B7-487B-9081-1B8183494955}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{DAE8ED9A-8553-4403-AB4C-B87A0629B25B}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{DE5E425E-F13F-4F67-BB1A-CCAAC89BAC1B}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{F06EC220-A883-4072-BC2F-3057BAEBA89D}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{FC8A5962-C436-499A-8BF7-B38724B57463}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{FDDFCB68-4353-43E4-825D-6BD769452BAA}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{FDE930AC-499A-4FB9-BFD6-8E945E05667B}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{FE44AA8B-2588-49FB-AA08-EC740DA8B73E}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{FE572C5B-D214-4D3D-8070-AE802E7AAC3C}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{FF175169-2A53-4EB4-92E9-DCB0CAD222D1}
Successfully deleted: [Empty Folder] C:\Users\Anja\appdata\local\{FF25EDA9-24D0-4812-AD72-44E141F9E709}
~~~ FireFox
Emptied folder: C:\Users\Anja\AppData\Roaming\mozilla\firefox\profiles\n7ocq2kt.default\minidumps [36 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.01.2014 at 19:25:10,48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ neues FRST log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-01-2014 02
Ran by Anja (administrator) on ANJA-PC2 on 28-01-2014 19:27:28
Running from D:\Eigene Dateien\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe
(Hewlett-Packard) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(O&O Software GmbH) C:\Windows\System32\oodag.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqbam08.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqgpc01.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-15] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-22] (IDT, Inc.)
HKLM\...\Run: [SmartMenu] - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [610872 2009-07-21] ()
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HPCam_Menu] - c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-08-09] (InstallShield Software Corporation)
HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [Magic Desktop for HP notification] - C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-30] (Easybits)
HKCU\...\Run: [ISUSPM Startup] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-08-09] (InstallShield Software Corporation)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableChangePassword] 0
HKU\Default\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
HKU\Default\...\Policies\system: [WallpaperStyle] 2
HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
HKU\Default User\...\Policies\system: [WallpaperStyle] 2
==================== Internet (Whitelisted) ====================
ProxyServer: 192.168.1.200:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://studivz.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0F8BAA37-548E-476A-B8BD-65FF02485269} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKLM - {233BA7DA-7443-4232-BEA9-46613F61F319} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
SearchScopes: HKLM - {A97854E0-68A4-41B8-A2F0-CD1E9D76FA71} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
SearchScopes: HKLM-x32 - {A97854E0-68A4-41B8-A2F0-CD1E9D76FA71} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
SearchScopes: HKCU - {A97854E0-68A4-41B8-A2F0-CD1E9D76FA71} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/|hxxp://www.t-online.de/
FF NetworkProxy: "backup.ftp", "192.168.1.200"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.gopher", "192.168.1.200"
FF NetworkProxy: "backup.gopher_port", 8080
FF NetworkProxy: "backup.socks", "192.168.1.200"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "192.168.1.200"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "192.168.1.200"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "gopher", "192.168.1.200"
FF NetworkProxy: "gopher_port", 8080
FF NetworkProxy: "http", "192.168.1.200"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "no_proxies_on", "*.local"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "192.168.1.200"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "ssl", "192.168.1.200"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Windows\SysWOW64\npdeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-02-10]
FF Extension: iMacros for Firefox - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2013-12-29]
FF Extension: HP Detect - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\Extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2} [2012-01-04]
FF Extension: Personas Plus - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\Extensions\personas@christopher.beard.xpi [2012-07-01]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-22]
FF Extension: Adblock Plus - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\n7ocq2kt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-07-01]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-11-23]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013-11-23]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-09-01]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-09-01]
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [85096 2010-05-11] (Autodesk)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 O&O Defrag; C:\Windows\system32\oodag.exe [1967872 2009-02-25] (O&O Software GmbH)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [240128 2009-07-22] (IDT, Inc.)
R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x]
==================== Drivers (Whitelisted) ====================
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
S3 s1018bus; C:\Windows\System32\DRIVERS\s1018bus.sys [113704 2009-03-25] (MCCI Corporation)
S3 s1018mdfl; C:\Windows\System32\DRIVERS\s1018mdfl.sys [19496 2009-03-25] (MCCI Corporation)
S3 s1018mdm; C:\Windows\System32\DRIVERS\s1018mdm.sys [153128 2009-03-25] (MCCI Corporation)
S3 s1018mgmt; C:\Windows\System32\DRIVERS\s1018mgmt.sys [133160 2009-03-25] (MCCI Corporation)
S3 s1018nd5; C:\Windows\System32\DRIVERS\s1018nd5.sys [34856 2009-03-25] (MCCI Corporation)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [128552 2009-03-25] (MCCI Corporation)
S3 s1018unic; C:\Windows\System32\DRIVERS\s1018unic.sys [146472 2009-03-25] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2010-08-28] (Sony Ericsson Mobile Communications)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2009-12-29] (Duplex Secure Ltd.)
R1 vmm; C:\Windows\system32\Treiber\vmm.sys [294248 2010-08-09] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U4 eabfiltr;
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-28 19:25 - 2014-01-28 19:25 - 00006757 _____ C:\Users\Anja\Desktop\JRT.txt
2014-01-28 19:17 - 2014-01-28 19:17 - 00000000 ____D C:\Windows\ERUNT
2014-01-28 19:01 - 2014-01-28 19:03 - 00000000 ____D C:\AdwCleaner
2014-01-27 19:31 - 2014-01-27 19:31 - 00028487 _____ C:\ComboFix.txt
2014-01-27 19:04 - 2014-01-27 19:31 - 00000000 ____D C:\Qoobox
2014-01-27 19:04 - 2014-01-27 19:29 - 00000000 ____D C:\Windows\erdnt
2014-01-27 19:04 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-27 19:04 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-27 19:04 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-27 19:04 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-27 19:04 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-27 19:04 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-27 19:04 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-27 19:04 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-26 16:11 - 2014-01-26 16:11 - 00000000 ____D C:\FRST
2014-01-26 16:04 - 2014-01-26 16:04 - 00000020 _____ C:\Users\Anja\defogger_reenable
2014-01-25 19:51 - 2014-01-25 19:51 - 00000000 ____D C:\Users\Anja\Documents\PcSetup
2014-01-25 19:46 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-01-25 19:46 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-01-25 19:46 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-01-25 19:46 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-01-25 19:46 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-01-25 19:46 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-01-25 19:46 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-01-25 19:46 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-01-25 19:46 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-01-25 19:46 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-01-25 19:46 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-01-25 19:46 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-01-25 19:46 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-01-25 19:46 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-01-25 19:46 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-01-25 19:46 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-01-25 19:46 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-01-25 19:46 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-01-25 19:45 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-01-25 19:45 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-01-25 19:45 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-01-25 19:45 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-01-25 19:45 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-01-25 19:45 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-01-25 19:45 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-01-25 19:45 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-01-25 19:45 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-01-25 19:45 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-01-25 19:45 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-01-25 19:45 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-01-25 19:45 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-01-25 18:44 - 2014-01-25 18:44 - 00003232 _____ C:\Windows\System32\Tasks\{4A1AAD81-86C2-4565-9557-AF43F2E7CA0B}
2014-01-25 18:28 - 2013-11-23 11:31 - 00873384 _____ (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2014-01-25 18:28 - 2013-11-23 11:31 - 00796072 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2014-01-25 15:35 - 2014-01-25 15:35 - 00000000 ____D C:\Users\Anja\AppData\Roaming\Malwarebytes
2014-01-25 15:34 - 2014-01-25 15:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-25 15:34 - 2014-01-25 15:34 - 00001075 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-25 15:34 - 2014-01-25 15:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-25 15:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-15 20:00 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 20:00 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 20:00 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 20:00 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 20:00 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 20:00 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 20:00 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 20:00 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 20:00 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-30 09:14 - 2013-12-30 09:20 - 00000000 ____D C:\ProgramData\Easybits Magic Desktop for HP
2013-12-29 13:10 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-29 13:10 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-29 13:10 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-29 13:10 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-29 13:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-29 13:03 - 2013-12-29 13:03 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-29 13:03 - 2013-12-29 13:03 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-29 13:02 - 2013-12-29 13:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-29 13:02 - 2013-12-29 13:02 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-29 13:02 - 2013-12-29 13:02 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-29 13:02 - 2013-12-29 13:02 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-29 13:02 - 2013-12-29 13:02 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-29 13:02 - 2013-12-29 13:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-29 13:00 - 2013-12-29 13:09 - 00011157 _____ C:\Windows\IE11_main.log
==================== One Month Modified Files and Folders =======
2014-01-28 19:25 - 2014-01-28 19:25 - 00006757 _____ C:\Users\Anja\Desktop\JRT.txt
2014-01-28 19:17 - 2014-01-28 19:17 - 00000000 ____D C:\Windows\ERUNT
2014-01-28 19:17 - 2009-07-14 05:51 - 00138065 _____ C:\Windows\setupact.log
2014-01-28 19:16 - 2009-11-25 00:23 - 02026688 _____ C:\Windows\WindowsUpdate.log
2014-01-28 19:12 - 2009-07-14 05:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-28 19:12 - 2009-07-14 05:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-28 19:11 - 2010-02-05 12:43 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-28 19:05 - 2009-12-30 11:09 - 00232800 _____ C:\Windows\system32\OODBS.lor
2014-01-28 19:05 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-28 19:03 - 2014-01-28 19:01 - 00000000 ____D C:\AdwCleaner
2014-01-28 18:42 - 2010-02-05 12:43 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-28 18:29 - 2012-11-17 14:48 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-27 19:31 - 2014-01-27 19:31 - 00028487 _____ C:\ComboFix.txt
2014-01-27 19:31 - 2014-01-27 19:04 - 00000000 ____D C:\Qoobox
2014-01-27 19:31 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2014-01-27 19:29 - 2014-01-27 19:04 - 00000000 ____D C:\Windows\erdnt
2014-01-27 19:25 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-27 19:24 - 2009-11-25 00:41 - 00374082 _____ C:\Windows\PFRO.log
2014-01-27 19:24 - 2009-07-14 03:34 - 24641536 _____ C:\Windows\system32\config\SYSTEM.bak
2014-01-27 19:24 - 2009-07-14 03:34 - 104333312 _____ C:\Windows\system32\config\SOFTWARE.bak
2014-01-27 19:24 - 2009-07-14 03:34 - 00524288 _____ C:\Windows\system32\config\DEFAULT.bak
2014-01-27 19:24 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak
2014-01-27 19:24 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\SAM.bak
2014-01-26 18:32 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2014-01-26 16:11 - 2014-01-26 16:11 - 00000000 ____D C:\FRST
2014-01-26 16:04 - 2014-01-26 16:04 - 00000020 _____ C:\Users\Anja\defogger_reenable
2014-01-26 16:04 - 2009-12-29 18:27 - 00000000 ____D C:\Users\Anja
2014-01-25 20:12 - 2009-08-25 19:08 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-25 20:09 - 2009-08-26 03:42 - 00704894 _____ C:\Windows\system32\perfh007.dat
2014-01-25 20:09 - 2009-08-26 03:42 - 00151542 _____ C:\Windows\system32\perfc007.dat
2014-01-25 20:09 - 2009-07-14 06:13 - 01629348 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-25 20:00 - 2009-07-14 05:45 - 03407800 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-25 19:52 - 2011-01-25 20:21 - 01600224 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-25 19:51 - 2014-01-25 19:51 - 00000000 ____D C:\Users\Anja\Documents\PcSetup
2014-01-25 19:51 - 2012-12-30 15:38 - 00000033 _____ C:\Users\Anja\AppData\Roaming\pcouffin.log
2014-01-25 19:51 - 2012-12-30 15:37 - 00099384 _____ C:\Users\Anja\AppData\Roaming\inst.exe
2014-01-25 19:51 - 2012-12-30 15:37 - 00082816 _____ (VSO Software) C:\Users\Anja\AppData\Roaming\pcouffin.sys
2014-01-25 19:51 - 2012-12-30 15:37 - 00007859 _____ C:\Users\Anja\AppData\Roaming\pcouffin.cat
2014-01-25 19:51 - 2012-12-30 15:37 - 00000000 ____D C:\Users\Anja\AppData\Roaming\Vso
2014-01-25 19:50 - 2010-06-13 19:21 - 00020462 _____ C:\ProgramData\hpzinstall.log
2014-01-25 19:45 - 2013-08-27 20:46 - 00000000 ____D C:\Windows\system32\MRT
2014-01-25 19:42 - 2009-12-30 09:16 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-25 19:24 - 2009-08-25 17:56 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2014-01-25 19:24 - 2009-08-25 17:53 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2014-01-25 19:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help
2014-01-25 19:17 - 2012-11-17 14:48 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-25 19:17 - 2012-09-01 14:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-25 19:17 - 2011-05-20 12:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-25 19:17 - 2010-01-09 16:44 - 00000000 ____D C:\Users\Anja\AppData\Local\Adobe
2014-01-25 18:55 - 2012-05-05 11:22 - 00000600 _____ C:\Users\Anja\AppData\Roaming\winscp.rnd
2014-01-25 18:54 - 2013-11-02 21:58 - 00000000 ____D C:\Windows\WindowsMobile
2014-01-25 18:53 - 2009-08-25 17:58 - 00000000 ____D C:\Program Files (x86)\Windows Live
2014-01-25 18:46 - 2010-08-28 17:40 - 00000000 ____D C:\Users\Anja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Ericsson
2014-01-25 18:46 - 2010-08-28 17:38 - 00000000 ____D C:\Program Files (x86)\Sony Ericsson
2014-01-25 18:45 - 2010-04-13 12:25 - 00007053 _____ C:\Windows\citamis.str
2014-01-25 18:44 - 2014-01-25 18:44 - 00003232 _____ C:\Windows\System32\Tasks\{4A1AAD81-86C2-4565-9557-AF43F2E7CA0B}
2014-01-25 18:44 - 2010-04-13 12:27 - 00000000 ____D C:\Program Files (x86)\Siemens
2014-01-25 18:42 - 2009-07-14 05:45 - 00000000 ____D C:\Windows\Setup
2014-01-25 18:31 - 2009-08-25 18:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2014-01-25 18:28 - 2009-08-25 20:15 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-25 18:24 - 2012-05-28 20:28 - 00000000 ____D C:\Program Files\gs
2014-01-25 18:22 - 2009-12-29 20:41 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2014-01-25 18:22 - 2009-12-29 20:40 - 00000000 ____D C:\Program Files (x86)\SlySoft
2014-01-25 18:20 - 2010-01-09 16:44 - 00000000 ____D C:\Users\Anja\AppData\Local\Autodesk
2014-01-25 18:20 - 2009-12-29 22:56 - 00000000 ____D C:\ProgramData\Autodesk
2014-01-25 18:20 - 2009-12-29 22:56 - 00000000 ____D C:\Program Files (x86)\AutoCAD 2004
2014-01-25 15:35 - 2014-01-25 15:35 - 00000000 ____D C:\Users\Anja\AppData\Roaming\Malwarebytes
2014-01-25 15:35 - 2014-01-25 15:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-25 15:34 - 2014-01-25 15:34 - 00001075 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-25 15:34 - 2014-01-25 15:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-25 10:52 - 2009-12-29 20:38 - 00000414 _____ C:\Windows\Tasks\1-Klick-Wartung.job
2014-01-19 08:33 - 2009-12-29 18:42 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-18 12:31 - 2010-11-14 18:51 - 00000000 ____D C:\Users\Anja\AppData\Roaming\vlc
2014-01-18 11:03 - 2010-03-28 20:29 - 00000000 ____D C:\Users\Anja\AppData\Roaming\dvdcss
2014-01-16 17:42 - 2012-03-23 08:26 - 00000000 ____D C:\Users\Anja\Documents\Eigene Scans
2013-12-30 09:20 - 2013-12-30 09:14 - 00000000 ____D C:\ProgramData\Easybits Magic Desktop for HP
2013-12-30 09:15 - 2010-01-09 16:44 - 00001427 _____ C:\Users\Anja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-30 09:14 - 2009-08-25 20:02 - 00009988 _____ C:\Windows\SysWOW64\ezdigsgn.dat
2013-12-30 09:12 - 2012-07-01 16:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-30 09:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-29 13:09 - 2013-12-29 13:00 - 00011157 _____ C:\Windows\IE11_main.log
2013-12-29 13:03 - 2013-12-29 13:03 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-29 13:03 - 2013-12-29 13:03 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-29 13:02 - 2013-12-29 13:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-29 13:02 - 2013-12-29 13:02 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-29 13:02 - 2013-12-29 13:02 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-29 13:02 - 2013-12-29 13:02 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-29 13:02 - 2013-12-29 13:02 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-29 13:02 - 2013-12-29 13:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-29 13:02 - 2013-12-29 13:02 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-29 13:02 - 2013-12-29 13:02 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-29 12:46 - 2013-11-23 11:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
Some content of TEMP:
====================
C:\Users\Anja\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-23 00:04
==================== End Of Log ============================ --- --- --- |