troJanina | 20.07.2014 19:45 | als <code></code>? Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 20.07.2014
Suchlauf-Zeit: 18:33:59
Logdatei: suchlauf_verlaufsprotokoll.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.20.04
Rootkit Datenbank: v2014.07.17.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Admin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 302657
Verstrichene Zeit: 3 Min, 44 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 20
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [d9eb1d84d5a6bc7a0e731e9ba9597e82],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [d9eb1d84d5a6bc7a0e731e9ba9597e82],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\UI, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [487c237edaa178be1dd865562bd7cd33],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [487c237edaa178be1dd865562bd7cd33],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [487c237edaa178be1dd865562bd7cd33],
PUP.Optional.FreeSoftwareToday.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy, In Quarantäne, [7b49d2cf98e39b9b0e1219a350b2e818],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\x64, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\x86, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89\Download, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89\fst_de_89, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89\fst_de_89\1.10, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Program Files (x86)\fst_de_89, In Quarantäne, [6c581a876219231359b8d2eb8c76f808],
Dateien: 27
PUP.Optional.Trovi.A, C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\z8c3id95.default\searchplugins\trovi-search.xml, In Quarantäne, [863e7c25740765d1ab22fed4ea189f61],
PUP.Optional.SweetPage.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml, In Quarantäne, [6064dcc5c3b826102369a86d12f2f20e],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [d9eb1d84d5a6bc7a0e731e9ba9597e82],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\SearchProtect\CRASH_DUMP_P6540_T2624_D2014_07_09_T17_07_39.dmp, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\SearchProtect\CRASH_REPORT_P6540_T2624_D2014_07_09_T17_07_39.txt, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.SearchProtect.A, C:\Users\Admin\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [43818c15f68592a4a6dc8b2ec2402cd4],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-07-09[16-39-08-596].log, In Quarantäne, [487c237edaa178be1dd865562bd7cd33],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [487c237edaa178be1dd865562bd7cd33],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\175.crx, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\175.dat, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\175.xpi, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\a.db, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\b.db, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\di0BlockAndSurfyv175.bin, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\di0BlockAndSurfyv175.exe, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\di6BlockAndSurfM.exe, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\Sqlite3.dll, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\x64\TandemRunner.exe, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\di4BlockAndSurf\x86\TandemRunner.exe, In Quarantäne, [0fb5534e3f3cfa3c7f392597679b2cd4],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89\upfst_de_89.cyl, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89\upfst_de_89.exe, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89\user_profil.cyp, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Users\Admin\AppData\Local\fst_de_89\fst_de_89\1.10\cnf.cyl, In Quarantäne, [fec6178ab4c7dc5aa56b5c618a7826da],
PUP.Optional.FreeSoftToday.A, C:\Program Files (x86)\fst_de_89\unins000.dat, In Quarantäne, [6c581a876219231359b8d2eb8c76f808],
PUP.Optional.FreeSoftToday.A, C:\Program Files (x86)\fst_de_89\unins000.msg, In Quarantäne, [6c581a876219231359b8d2eb8c76f808],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.216 - Bericht erstellt am 20/07/2014 um 19:26:30
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Admin - ADMIN-PC
# Gestartet von : C:\Users\Admin\Downloads\adwcleaner_3.216.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\AnyProtectEx
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\sweet-page
Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
Datei Gelöscht : C:\Users\Admin\AppData\Roaming\aps.scan.quick.results
Datei Gelöscht : C:\Users\Admin\AppData\Roaming\aps.scan.results
Datei Gelöscht : C:\Users\Admin\AppData\Roaming\aps.uninstall.scan.results
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKCU\Software\OCS
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\z8c3id95.default\prefs.js ]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322196&octid=EB_ORIGINAL_CTID&ISID=MA1B62CB1-5364-43EE-B9DD-ED2D9A7D585D&SearchSource=58&CUI=&UM=6&UP=SP7DD54E2A-E878-4BF3-8857-B931A5991ECF&q={searchTerms}&SSPV=
Gelöscht [Extension] : bopakagnckmlgajfccecajhnimjiiedh
*************************
AdwCleaner[R0].txt - [1903 octets] - [20/07/2014 19:10:56]
AdwCleaner[S0].txt - [1778 octets] - [20/07/2014 19:26:30]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1838 octets] ########## JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Admin on 20.07.2014 at 19:33:53,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\z8c3id95.default\minidumps [104 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.07.2014 at 19:39:47,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
und das FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by Admin (administrator) on ADMIN-PC on 20-07-2014 20:04:22
Running from C:\Users\Admin\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(FSL) C:\Program Files (x86)\FSL\SuperFinder\SuperFinder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [36352 2013-01-31] (Intel Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291128 2013-03-06] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe_ID0EYTHM] => C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe [1884160 2007-03-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-06-27] (AVAST Software)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2099200 2014-04-13] (Dominik Reichl)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Super Finder XT.lnk
ShortcutTarget: Super Finder XT.lnk -> C:\Program Files (x86)\FSL\SuperFinder\SuperFinder.exe (FSL)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com?fr=hp-avast&type=avastbcl
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com?fr=hp-avast&type=avastbcl
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = https://de.yahoo.com?fr=hp-avast&type=avastbcl
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKCU - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: No Name -> {074C1DC5-9320-4A9A-947D-C042949C6216} -> No File
BHO-x32: No Name -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll No File
Toolbar: HKLM-x32 - No Name - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\z8c3id95.default
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Homepage: https://www.google.de/
FF Keyword.URL: https://de.search.yahoo.com/yhs/search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll No File
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\z8c3id95.default\searchplugins\yahoo-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: KeeFox - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\z8c3id95.default\Extensions\keefox@chris.tomlinson [2014-06-27]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-27]
FF HKCU\...\Firefox\Extensions: [{b9aa91db-385d-4c69-8a2f-96790aa9405b}] - c:\program files (x86)\copernic\desktopsearch4\firefoxconnector
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: https://de.yahoo.com?fr=hp-avast&type=avastbcl
CHR StartupUrls: "https://de.yahoo.com?fr=hp-avast&type=avastbcl"
CHR DefaultSearchKeyword: www.yahoo.com
CHR DefaultSearchProvider: Yahoo! (Avast)
CHR DefaultSearchURL: https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-11]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-11]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-11]
CHR Extension: (Google-Suche) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-11]
CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-11]
CHR Extension: (Google Mail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-11]
CHR HKCU\...\Chrome\Extension: [cnnbdaahphjgdgfhliignpepgnbnfomp] - c:\program files (x86)\copernic\desktopsearch4\ChromeConnector\ChromeConnector.crx [2014-05-11]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-27] (AVAST Software)
R2 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2014-05-30] (Macrovision Europe Ltd.) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129848 2013-02-22] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-02-22] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-27] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-27] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-06-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-06-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-06-27] ()
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [496400 2013-02-27] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-01-31] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-20 20:03 - 2014-07-20 20:02 - 02089984 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2014-07-20 19:39 - 2014-07-20 19:39 - 00001014 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-07-20 19:33 - 2014-07-20 19:33 - 00000000 ____D () C:\Windows\ERUNT
2014-07-20 19:31 - 2014-07-20 19:31 - 01016261 _____ (Thisisu) C:\Users\Admin\Desktop\JRT.exe
2014-07-20 19:11 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-20 19:05 - 2014-07-20 19:26 - 00000000 ____D () C:\AdwCleaner
2014-07-20 19:05 - 2014-07-20 19:05 - 01354223 _____ () C:\Users\Admin\Downloads\adwcleaner_3.216.exe
2014-07-20 19:04 - 2014-07-20 19:04 - 00001642 _____ () C:\Users\Admin\Desktop\schutz-protokoll.txt
2014-07-20 19:03 - 2014-07-20 19:03 - 00007634 _____ () C:\Users\Admin\Desktop\suchlauf_verlaufsprotokoll.txt
2014-07-20 18:29 - 2014-07-20 19:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-20 18:29 - 2014-07-20 18:29 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-20 18:29 - 2014-07-20 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-20 18:29 - 2014-07-20 18:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-20 18:29 - 2014-07-20 18:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-20 18:29 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-20 18:29 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-20 18:29 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-19 12:21 - 2014-07-20 19:27 - 00013508 _____ () C:\Windows\PFRO.log
2014-07-19 00:32 - 2014-07-19 00:32 - 00027296 _____ () C:\ComboFix.txt
2014-07-19 00:25 - 2014-07-20 20:04 - 00003364 _____ () C:\Users\Admin\Desktop\win.txt
2014-07-19 00:23 - 2014-07-19 00:23 - 00001459 _____ () C:\Users\Admin\Desktop\ComboFix.exe - Verknüpfung.lnk
2014-07-19 00:13 - 2014-07-19 00:13 - 00031486 _____ () C:\ComboFix_.txt
2014-07-19 00:08 - 2014-07-19 00:32 - 00000000 ____D () C:\Qoobox
2014-07-19 00:08 - 2014-07-19 00:12 - 00000000 ____D () C:\Windows\erdnt
2014-07-19 00:08 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-19 00:08 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-19 00:08 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-19 00:08 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-19 00:08 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-19 00:08 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-19 00:08 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-19 00:08 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-19 00:07 - 2014-07-19 00:07 - 05221938 ____R (Swearware) C:\Users\Admin\Downloads\ComboFix.exe
2014-07-18 23:53 - 2014-07-18 23:53 - 00001304 _____ () C:\Users\Admin\Desktop\Notepad.lnk
2014-07-18 16:35 - 2014-07-18 16:35 - 02439631 _____ () C:\Users\Admin\Downloads\FireShot_0.98.56.zip
2014-07-18 16:35 - 2014-07-18 16:35 - 00000000 ____D () C:\Users\Admin\Downloads\FireShot_0.98.56
2014-07-18 16:33 - 2014-07-18 16:33 - 00961360 _____ (Chip Digital GmbH) C:\Users\Admin\Downloads\FireShot_0.98.56 - CHIP-Installer.exe
2014-07-18 16:31 - 2014-07-18 16:31 - 00961360 _____ (Chip Digital GmbH) C:\Users\Admin\Downloads\fireshot_ie_install-0.98.4 - CHIP-Installer.exe
2014-07-17 15:48 - 2014-07-17 15:48 - 00022276 _____ () C:\Users\Admin\Desktop\Addition.txt
2014-07-17 15:41 - 2014-07-20 20:04 - 00015095 _____ () C:\Users\Admin\Desktop\FRST.txt
2014-07-17 15:24 - 2014-07-17 15:24 - 00057937 _____ () C:\Users\Admin\Downloads\FRST.txt
2014-07-17 15:24 - 2014-07-17 15:24 - 00022276 _____ () C:\Users\Admin\Downloads\Addition.txt
2014-07-17 15:23 - 2014-07-20 20:04 - 00000000 ____D () C:\FRST
2014-07-17 15:23 - 2014-07-20 20:02 - 02089984 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2014-07-17 10:38 - 2014-07-17 10:38 - 00004220 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-17 10:38 - 2014-07-17 10:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-17 10:17 - 2014-07-20 19:27 - 00001120 _____ () C:\Windows\setupact.log
2014-07-17 10:17 - 2014-07-17 10:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-16 16:18 - 2014-07-20 18:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-16 12:25 - 2014-07-16 12:44 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\XnView
2014-07-16 12:24 - 2014-07-16 12:25 - 00000919 _____ () C:\Users\Admin\Desktop\XnView.lnk
2014-07-16 12:24 - 2014-07-16 12:24 - 04868432 _____ (Gougelet Pierre-e ) C:\Users\Admin\Downloads\XnView-win.exe
2014-07-16 12:24 - 2014-07-16 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
2014-07-16 12:24 - 2014-07-16 12:24 - 00000000 ____D () C:\Program Files (x86)\XnView
2014-07-10 17:23 - 2014-07-10 17:23 - 00000000 ____D () C:\Windows\pss
2014-07-10 17:20 - 2014-07-10 17:20 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-07-10 17:20 - 2014-07-10 17:20 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-10 17:18 - 2014-07-10 17:18 - 03736040 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup415_slim.exe
2014-07-10 17:11 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-10 17:11 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-10 17:11 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 17:11 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 17:11 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 17:11 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 17:11 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 17:11 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 17:10 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 17:10 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 17:10 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 17:10 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 17:10 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 17:10 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 17:10 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 17:10 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 17:10 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 17:10 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 17:10 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 17:10 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 17:10 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 17:10 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 17:10 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 17:10 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 17:10 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 17:10 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 17:10 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 17:10 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 17:10 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 17:10 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 17:10 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 17:10 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 17:10 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 17:10 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 17:10 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 17:10 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 17:10 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 17:10 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 17:10 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 17:10 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 17:10 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 17:10 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 17:10 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 17:10 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 17:10 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 17:10 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 17:10 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 17:10 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 17:10 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 17:10 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 17:10 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 17:10 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 17:10 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 17:10 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 17:10 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 17:10 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 17:10 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 17:10 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 17:10 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 17:10 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-10 17:10 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-10 17:10 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-10 17:10 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-10 17:10 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-10 17:10 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-10 17:10 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-10 17:09 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 17:09 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 17:09 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-10 11:42 - 2014-07-10 11:42 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-07-10 11:25 - 2014-07-07 17:04 - 00057528 _____ (Corsica) C:\Windows\system32\Drivers\webinstr.sys
2014-07-09 17:04 - 2014-07-10 17:20 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-09 16:28 - 2014-07-10 11:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-09 16:28 - 2014-07-10 11:33 - 00000000 ____D () C:\Program Files (x86)\Audiograbber
2014-07-09 16:27 - 2014-07-10 11:33 - 00000000 ____D () C:\Program Files (x86)\Security Guard
2014-07-09 10:35 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 10:35 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 10:35 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 10:35 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 10:35 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 10:35 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 10:35 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 10:35 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 10:35 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 10:35 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 10:35 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 10:35 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-02 15:09 - 2014-07-02 15:09 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-01 14:34 - 2014-07-01 14:34 - 00001133 _____ () C:\Users\Admin\Desktop\Super Finder XT.lnk
2014-07-01 14:34 - 2014-07-01 14:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FSL
2014-07-01 14:34 - 2014-07-01 14:34 - 00000000 ____D () C:\Program Files (x86)\FSL
2014-07-01 14:33 - 2014-07-01 14:33 - 00000000 ____D () C:\Users\Admin\Downloads\everything12
2014-07-01 14:31 - 2014-07-01 14:31 - 05184839 _____ (FSL - FreeSoftLand ) C:\Users\Admin\Downloads\super-finder-xt_20431.exe
2014-06-27 16:47 - 2014-06-27 16:47 - 00000000 ____D () C:\Users\Admin\AppData\Local\KeePass
2014-06-27 14:39 - 2014-07-17 16:16 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\KeePass
2014-06-27 14:37 - 2014-06-27 14:38 - 00000000 ____D () C:\Users\Admin\Downloads\Neuer Ordner
2014-06-27 14:31 - 2014-06-27 16:31 - 00000000 ____D () C:\Program Files (x86)\KeePass Password Safe 2
2014-06-27 14:31 - 2014-06-27 14:31 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk
2014-06-27 14:31 - 2014-06-27 14:31 - 00001105 _____ () C:\Users\Admin\Desktop\KeePass 2.lnk
2014-06-27 14:27 - 2014-06-27 14:27 - 02545000 _____ (Dominik Reichl ) C:\Users\Admin\Downloads\KeePass-2.26-Setup.exe
2014-06-27 13:43 - 2014-07-20 19:27 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-27 13:43 - 2014-07-10 11:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-27 13:43 - 2014-07-04 10:56 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-27 13:43 - 2014-06-27 13:43 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-27 13:43 - 2014-06-27 13:43 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-06-27 13:43 - 2014-06-27 13:43 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software
2014-06-27 13:43 - 2014-06-27 13:43 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-27 13:42 - 2014-06-27 13:43 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-27 13:38 - 2014-06-27 13:39 - 91906368 _____ (AVAST Software) C:\Users\Admin\Downloads\avast_free_antivirus_setup_9.0.2021.exe
2014-06-24 17:42 - 2014-06-24 17:42 - 00000000 ____D () C:\ProgramData\CanonIJ
2014-06-24 16:10 - 2014-06-24 16:10 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2014-06-24 16:10 - 2014-06-24 16:10 - 00000000 _____ () C:\Users\Admin\Sti_Trace.log
2014-06-24 13:23 - 2014-06-24 16:10 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Canon
2014-06-24 12:55 - 2014-06-24 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CanoScan LiDE 210
2014-06-24 12:46 - 2014-06-24 12:46 - 00000000 ___HD () C:\ProgramData\CanonIJSolutionMenuEX
2014-06-24 12:44 - 2014-06-24 12:44 - 00000000 ___HD () C:\ProgramData\CanonIJEGV
2014-06-24 12:43 - 2014-07-18 17:26 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-06-24 12:43 - 2014-06-24 12:43 - 00002075 _____ () C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
2014-06-24 12:43 - 2014-06-24 12:43 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-06-24 12:43 - 2014-06-24 12:43 - 00000000 ____D () C:\Program Files\Common Files\CANON
2014-06-24 12:42 - 2014-06-24 12:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-06-24 12:42 - 2014-06-24 12:42 - 00002372 _____ () C:\Users\Public\Desktop\Canon CanoScan LiDE 210 Online-Handbuch.lnk
2014-06-24 12:41 - 2014-06-24 12:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon CanoScan LiDE 210 Manual
2014-06-24 12:41 - 2014-06-24 12:41 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-06-24 12:41 - 2012-07-04 11:55 - 01354240 _____ (CANON INC.) C:\Windows\system32\CNQ4809C.dll
2014-06-24 12:41 - 2012-07-04 11:55 - 00112128 _____ (CANON INC.) C:\Windows\system32\CNQ4809I.dll
2014-06-24 12:41 - 2012-07-04 11:29 - 00106496 _____ (CANON INC.) C:\Windows\SysWOW64\CNQ4809U.dll
2014-06-24 12:41 - 2012-04-18 15:24 - 00103424 _____ (Canon Inc.) C:\Windows\system32\CNQ4809O.dll
2014-06-24 12:41 - 2010-12-17 14:47 - 00515584 _____ (CANON INC.) C:\Windows\system32\CNQ4809L.dll
2014-06-24 12:41 - 2010-03-11 10:57 - 00248320 _____ (CANON INC.) C:\Windows\system32\CNQ4809Y.dll
2014-06-24 12:39 - 2014-06-24 12:42 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-06-24 12:38 - 2014-06-24 12:38 - 00000355 _____ () C:\Users\Admin\Desktop\Computer - Verknüpfung.lnk
2014-06-24 12:36 - 2014-06-24 12:36 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2014-06-24 12:36 - 2010-12-17 14:47 - 00438272 _____ (CANON INC.) C:\Windows\SysWOW64\CNQ4809L.dll
2014-06-24 12:36 - 2010-03-19 13:55 - 00393256 _____ () C:\Windows\SysWOW64\CNQ4809N.DAT
2014-06-24 12:36 - 2010-03-19 13:55 - 00393256 _____ () C:\Windows\system32\CNQ4809N.DAT
2014-06-24 12:36 - 2008-08-25 18:02 - 00017920 _____ (CANON INC.) C:\Windows\system32\CNHMCA6.dll
2014-06-24 12:36 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2014-06-21 18:06 - 2000-06-29 10:00 - 00036864 _____ (Agfa-Gevaert N.V.) C:\Windows\SysWOW64\agusbsti.dll
2014-06-21 15:04 - 2014-06-21 15:04 - 00000000 ____D () C:\ProgramData\McAfee
==================== One Month Modified Files and Folders =======
2014-07-20 20:04 - 2014-07-19 00:25 - 00003364 _____ () C:\Users\Admin\Desktop\win.txt
2014-07-20 20:04 - 2014-07-17 15:41 - 00015095 _____ () C:\Users\Admin\Desktop\FRST.txt
2014-07-20 20:04 - 2014-07-17 15:23 - 00000000 ____D () C:\FRST
2014-07-20 20:02 - 2014-07-20 20:03 - 02089984 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2014-07-20 20:02 - 2014-07-17 15:23 - 02089984 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2014-07-20 19:39 - 2014-07-20 19:39 - 00001014 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-07-20 19:35 - 2009-07-14 06:45 - 00025328 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-20 19:35 - 2009-07-14 06:45 - 00025328 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-20 19:33 - 2014-07-20 19:33 - 00000000 ____D () C:\Windows\ERUNT
2014-07-20 19:33 - 2011-04-12 09:43 - 00699726 _____ () C:\Windows\system32\perfh007.dat
2014-07-20 19:33 - 2011-04-12 09:43 - 00149364 _____ () C:\Windows\system32\perfc007.dat
2014-07-20 19:33 - 2009-07-14 07:13 - 01621742 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-20 19:31 - 2014-07-20 19:31 - 01016261 _____ (Thisisu) C:\Users\Admin\Desktop\JRT.exe
2014-07-20 19:28 - 2014-07-20 18:29 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-20 19:27 - 2014-07-19 12:21 - 00013508 _____ () C:\Windows\PFRO.log
2014-07-20 19:27 - 2014-07-17 10:17 - 00001120 _____ () C:\Windows\setupact.log
2014-07-20 19:27 - 2014-06-27 13:43 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-07-20 19:27 - 2014-05-11 14:51 - 01943692 _____ () C:\Windows\WindowsUpdate.log
2014-07-20 19:27 - 2014-05-11 11:09 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-20 19:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-20 19:26 - 2014-07-20 19:05 - 00000000 ____D () C:\AdwCleaner
2014-07-20 19:20 - 2014-05-20 15:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-20 19:20 - 2014-05-11 11:09 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-20 19:05 - 2014-07-20 19:05 - 01354223 _____ () C:\Users\Admin\Downloads\adwcleaner_3.216.exe
2014-07-20 19:04 - 2014-07-20 19:04 - 00001642 _____ () C:\Users\Admin\Desktop\schutz-protokoll.txt
2014-07-20 19:03 - 2014-07-20 19:03 - 00007634 _____ () C:\Users\Admin\Desktop\suchlauf_verlaufsprotokoll.txt
2014-07-20 18:29 - 2014-07-20 18:29 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-20 18:29 - 2014-07-20 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-20 18:29 - 2014-07-20 18:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-20 18:29 - 2014-07-20 18:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-20 18:28 - 2014-07-16 16:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-20 17:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-20 13:53 - 2014-05-29 14:54 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{F773CA57-B648-47F7-B599-0236F79381D3}
2014-07-19 12:50 - 2014-05-31 18:49 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\TV-Browser
2014-07-19 00:32 - 2014-07-19 00:32 - 00027296 _____ () C:\ComboFix.txt
2014-07-19 00:32 - 2014-07-19 00:08 - 00000000 ____D () C:\Qoobox
2014-07-19 00:31 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-19 00:23 - 2014-07-19 00:23 - 00001459 _____ () C:\Users\Admin\Desktop\ComboFix.exe - Verknüpfung.lnk
2014-07-19 00:13 - 2014-07-19 00:13 - 00031486 _____ () C:\ComboFix_.txt
2014-07-19 00:13 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-07-19 00:12 - 2014-07-19 00:08 - 00000000 ____D () C:\Windows\erdnt
2014-07-19 00:07 - 2014-07-19 00:07 - 05221938 ____R (Swearware) C:\Users\Admin\Downloads\ComboFix.exe
2014-07-18 23:53 - 2014-07-18 23:53 - 00001304 _____ () C:\Users\Admin\Desktop\Notepad.lnk
2014-07-18 17:26 - 2014-06-24 12:43 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-07-18 16:55 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-07-18 16:35 - 2014-07-18 16:35 - 02439631 _____ () C:\Users\Admin\Downloads\FireShot_0.98.56.zip
2014-07-18 16:35 - 2014-07-18 16:35 - 00000000 ____D () C:\Users\Admin\Downloads\FireShot_0.98.56
2014-07-18 16:33 - 2014-07-18 16:33 - 00961360 _____ (Chip Digital GmbH) C:\Users\Admin\Downloads\FireShot_0.98.56 - CHIP-Installer.exe
2014-07-18 16:31 - 2014-07-18 16:31 - 00961360 _____ (Chip Digital GmbH) C:\Users\Admin\Downloads\fireshot_ie_install-0.98.4 - CHIP-Installer.exe
2014-07-18 15:22 - 2014-05-11 11:11 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-18 02:18 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-17 16:16 - 2014-06-27 14:39 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\KeePass
2014-07-17 15:48 - 2014-07-17 15:48 - 00022276 _____ () C:\Users\Admin\Desktop\Addition.txt
2014-07-17 15:24 - 2014-07-17 15:24 - 00057937 _____ () C:\Users\Admin\Downloads\FRST.txt
2014-07-17 15:24 - 2014-07-17 15:24 - 00022276 _____ () C:\Users\Admin\Downloads\Addition.txt
2014-07-17 10:38 - 2014-07-17 10:38 - 00004220 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-17 10:38 - 2014-07-17 10:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-17 10:38 - 2014-05-31 18:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-17 10:38 - 2014-05-31 18:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-17 10:17 - 2014-07-17 10:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-17 02:49 - 2014-05-11 15:47 - 00000000 ____D () C:\Windows\Panther
2014-07-16 12:44 - 2014-07-16 12:25 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\XnView
2014-07-16 12:25 - 2014-07-16 12:24 - 00000919 _____ () C:\Users\Admin\Desktop\XnView.lnk
2014-07-16 12:24 - 2014-07-16 12:24 - 04868432 _____ (Gougelet Pierre-e ) C:\Users\Admin\Downloads\XnView-win.exe
2014-07-16 12:24 - 2014-07-16 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
2014-07-16 12:24 - 2014-07-16 12:24 - 00000000 ____D () C:\Program Files (x86)\XnView
2014-07-16 12:20 - 2014-05-27 17:05 - 00000000 ____D () C:\Users\Admin\Desktop\toolz
2014-07-11 22:39 - 2014-05-11 11:15 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-07-11 08:44 - 2009-07-14 06:45 - 02236160 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-11 08:43 - 2014-05-11 10:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-11 08:43 - 2011-04-12 09:55 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-11 08:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-11 08:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-11 03:02 - 2014-05-31 18:48 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-11 02:56 - 2014-05-31 18:48 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-11 02:56 - 2014-05-31 18:48 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-11 02:55 - 2014-05-31 18:48 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-10 17:38 - 2014-05-11 10:01 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-10 17:38 - 2014-05-11 10:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 17:23 - 2014-07-10 17:23 - 00000000 ____D () C:\Windows\pss
2014-07-10 17:20 - 2014-07-10 17:20 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-07-10 17:20 - 2014-07-10 17:20 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-10 17:20 - 2014-07-09 17:04 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-10 17:18 - 2014-07-10 17:18 - 03736040 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup415_slim.exe
2014-07-10 12:20 - 2014-05-20 15:04 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-10 12:20 - 2014-05-20 15:04 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-10 12:20 - 2014-05-20 15:04 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-10 11:42 - 2014-07-10 11:42 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-07-10 11:42 - 2014-05-11 14:52 - 00000000 ____D () C:\Users\Admin
2014-07-10 11:41 - 2014-06-27 13:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-07-10 11:41 - 2014-05-30 15:12 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-07-10 11:41 - 2014-05-20 15:04 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-07-10 11:41 - 2014-05-20 15:04 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-10 11:41 - 2011-04-12 09:55 - 00000000 ____D () C:\Windows\ShellNew
2014-07-10 11:41 - 2009-07-14 05:20 - 00000000 __RSD () C:\Windows\Media
2014-07-10 11:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-07-10 11:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-10 11:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-07-10 11:33 - 2014-07-09 16:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-10 11:33 - 2014-07-09 16:28 - 00000000 ____D () C:\Program Files (x86)\Audiograbber
2014-07-10 11:33 - 2014-07-09 16:27 - 00000000 ____D () C:\Program Files (x86)\Security Guard
2014-07-10 11:33 - 2011-04-12 09:54 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-07-10 11:33 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-07-10 11:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-07-10 11:25 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-07-07 17:04 - 2014-07-10 11:25 - 00057528 _____ (Corsica) C:\Windows\system32\Drivers\webinstr.sys
2014-07-04 13:26 - 2014-06-18 11:03 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2014-07-04 10:56 - 2014-06-27 13:43 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-02 15:10 - 2014-05-27 17:05 - 00000000 ____D () C:\Program Files (x86)\Everything
2014-07-02 15:09 - 2014-07-02 15:09 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-01 14:34 - 2014-07-01 14:34 - 00001133 _____ () C:\Users\Admin\Desktop\Super Finder XT.lnk
2014-07-01 14:34 - 2014-07-01 14:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FSL
2014-07-01 14:34 - 2014-07-01 14:34 - 00000000 ____D () C:\Program Files (x86)\FSL
2014-07-01 14:33 - 2014-07-01 14:33 - 00000000 ____D () C:\Users\Admin\Downloads\everything12
2014-07-01 14:31 - 2014-07-01 14:31 - 05184839 _____ (FSL - FreeSoftLand ) C:\Users\Admin\Downloads\super-finder-xt_20431.exe
2014-06-30 04:09 - 2014-07-10 17:11 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-10 17:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-28 04:13 - 2014-05-20 15:00 - 00001135 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-28 04:13 - 2014-05-20 15:00 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-27 16:47 - 2014-06-27 16:47 - 00000000 ____D () C:\Users\Admin\AppData\Local\KeePass
2014-06-27 16:31 - 2014-06-27 14:31 - 00000000 ____D () C:\Program Files (x86)\KeePass Password Safe 2
2014-06-27 14:38 - 2014-06-27 14:37 - 00000000 ____D () C:\Users\Admin\Downloads\Neuer Ordner
2014-06-27 14:35 - 2014-05-11 10:58 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Adobe
2014-06-27 14:31 - 2014-06-27 14:31 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk
2014-06-27 14:31 - 2014-06-27 14:31 - 00001105 _____ () C:\Users\Admin\Desktop\KeePass 2.lnk
2014-06-27 14:27 - 2014-06-27 14:27 - 02545000 _____ (Dominik Reichl ) C:\Users\Admin\Downloads\KeePass-2.26-Setup.exe
2014-06-27 13:43 - 2014-06-27 13:43 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-27 13:43 - 2014-06-27 13:43 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-27 13:43 - 2014-06-27 13:43 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-27 13:43 - 2014-06-27 13:43 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-06-27 13:43 - 2014-06-27 13:43 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software
2014-06-27 13:43 - 2014-06-27 13:43 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-27 13:43 - 2014-06-27 13:42 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-27 13:39 - 2014-06-27 13:38 - 91906368 _____ (AVAST Software) C:\Users\Admin\Downloads\avast_free_antivirus_setup_9.0.2021.exe
2014-06-27 10:30 - 2014-05-11 11:15 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-06-27 10:29 - 2014-05-11 11:14 - 00000000 ____D () C:\ProgramData\Adobe
2014-06-26 14:33 - 2014-06-17 17:13 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\PDF Architect 2
2014-06-24 17:42 - 2014-06-24 17:42 - 00000000 ____D () C:\ProgramData\CanonIJ
2014-06-24 16:10 - 2014-06-24 16:10 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2014-06-24 16:10 - 2014-06-24 16:10 - 00000000 _____ () C:\Users\Admin\Sti_Trace.log
2014-06-24 16:10 - 2014-06-24 13:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Canon
2014-06-24 12:55 - 2014-06-24 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CanoScan LiDE 210
2014-06-24 12:46 - 2014-06-24 12:46 - 00000000 ___HD () C:\ProgramData\CanonIJSolutionMenuEX
2014-06-24 12:44 - 2014-06-24 12:44 - 00000000 ___HD () C:\ProgramData\CanonIJEGV
2014-06-24 12:43 - 2014-06-24 12:43 - 00002075 _____ () C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
2014-06-24 12:43 - 2014-06-24 12:43 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-06-24 12:43 - 2014-06-24 12:43 - 00000000 ____D () C:\Program Files\Common Files\CANON
2014-06-24 12:43 - 2014-06-24 12:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-06-24 12:42 - 2014-06-24 12:42 - 00002372 _____ () C:\Users\Public\Desktop\Canon CanoScan LiDE 210 Online-Handbuch.lnk
2014-06-24 12:42 - 2014-06-24 12:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon CanoScan LiDE 210 Manual
2014-06-24 12:42 - 2014-06-24 12:39 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-06-24 12:41 - 2014-06-24 12:41 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-06-24 12:38 - 2014-06-24 12:38 - 00000355 _____ () C:\Users\Admin\Desktop\Computer - Verknüpfung.lnk
2014-06-24 12:36 - 2014-06-24 12:36 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2014-06-21 18:07 - 2014-05-11 14:52 - 00000000 ____D () C:\Users\Admin\AppData\Local\VirtualStore
2014-06-21 15:04 - 2014-06-21 15:04 - 00000000 ____D () C:\ProgramData\McAfee
2014-06-20 22:14 - 2014-07-10 17:10 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-20 21:39 - 2014-07-09 10:35 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-20 16:58
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- --- |