Hier die Scans...
mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.10.2014
Suchlauf-Zeit: 19:29:44
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.10.28.05
Rootkit Datenbank: v2014.10.22.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: f
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 331545
Verstrichene Zeit: 17 Min, 51 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 2
Trojan.Agent.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\blood_glucose_measurement, In Quarantäne, [f322e23888f454e29c2166720cf5da26],
Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\how_to_video, In Quarantäne, [30e51a00196362d46060d6016c9530d0],
Registrierungswerte: 4
Trojan.Agent.ED, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|unit_price, C:\ProgramData\Adobe\ARM\Reader_11.0.01\16103\file_system\mail_filter.exe, In Quarantäne, [ac6963b734487eb88838597fdc25867a]
Trojan.Agent.ED, HKU\S-1-5-21-3525988650-49406593-731613899-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|unit_price, C:\ProgramData\Adobe\ARM\Reader_11.0.01\16103\file_system\mail_filter.exe, Löschen bei Neustart, [ac6963b734487eb88838597fdc25867a]
Trojan.FakeMS, HKU\S-1-5-21-3525988650-49406593-731613899-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|explorer64, C:\Users\f\AppData\Roaming\Explorer64\explorer64.exe, Löschen bei Neustart, [92835ebc9ddff83ebeb36173827fd52b]
Trojan.Agent.ED, HKU\S-1-5-21-3525988650-49406593-731613899-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|contrast, C:\ProgramData\Adobe\ARM\Reader_11.0.01\12797\reading_list\handwriting_panel.exe, Löschen bei Neustart, [19fce7339ddff14569511cbbd130847c]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 0
(Keine schädliche Elemente erkannt)
Dateien: 6
Trojan.Agent.ED, C:\ProgramData\Adobe\ARM\Reader_11.0.01\16103\file_system\mail_filter.exe, In Quarantäne, [ac6963b734487eb88838597fdc25867a],
Trojan.FakeMS, C:\Users\f\AppData\Roaming\Explorer64\explorer64.exe, In Quarantäne, [92835ebc9ddff83ebeb36173827fd52b],
Trojan.Agent.ED, C:\ProgramData\Adobe\ARM\Reader_11.0.01\12797\reading_list\handwriting_panel.exe, In Quarantäne, [19fce7339ddff14569511cbbd130847c],
Trojan.Agent.ED, C:\Windows\assembly\GAC_32\Microsoft.Interop.Security.AzRoles\2.0.0.0__31bf3856ad364e35\sound_recorder\document.exe, In Quarantäne, [f322e23888f454e29c2166720cf5da26],
Trojan.Agent, C:\Windows\assembly\GAC_32\Microsoft.Interop.Security.AzRoles\2.0.0.0__31bf3856ad364e35\sound_recorder\production_schedule.exe, In Quarantäne, [30e51a00196362d46060d6016c9530d0],
PUP.Optional.InstalLCore, C:\Users\f\AppData\Local\Temp\is765589038\52614A36_stp.EXE, In Quarantäne, [38dd5bbf215bea4c333d58b8996cb050],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) ADW: Code:
# AdwCleaner v4.002 - Bericht erstellt am 28/10/2014 um 20:03:38
# DB v2014-10-26.6
# Aktualisiert 27/10/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : f - F-PC
# Gestartet von : C:\Users\f\Downloads\adwcleaner_4.002.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17344
-\\ Mozilla Firefox v33.0 (x86 de)
*************************
AdwCleaner[R0].txt - [6205 octets] - [22/10/2014 08:35:33]
AdwCleaner[R1].txt - [879 octets] - [24/10/2014 08:57:23]
AdwCleaner[R2].txt - [997 octets] - [25/10/2014 16:06:11]
AdwCleaner[R3].txt - [1237 octets] - [28/10/2014 20:00:28]
AdwCleaner[S0].txt - [6212 octets] - [22/10/2014 08:40:06]
AdwCleaner[S1].txt - [931 octets] - [24/10/2014 09:00:49]
AdwCleaner[S2].txt - [1049 octets] - [25/10/2014 16:22:51]
AdwCleaner[S3].txt - [1151 octets] - [28/10/2014 20:03:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1211 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.21.2014:1)
OS: Windows 7 Home Premium x64
Ran by f on 28.10.2014 at 20:10:22,28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\f\AppData\Roaming\mozilla\firefox\profiles\lr8dg9f4.default-1414058758463\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.10.2014 at 20:12:44,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-10-2014
Ran by f (administrator) on F-PC on 28-10-2014 20:17:26
Running from C:\Users\f\Downloads
Loaded Profile: f (Available profiles: f)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LoadFUJ02E3] => C:\Program Files\Fujitsu\FUJ02E3\fuj02e3.exe [76104 2011-11-24] (FUJITSU LIMITED)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [PSUTility] => C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [169368 2012-06-30] (FUJITSU LIMITED)
HKLM\...\Run: [LoadFujitsuQuickTouch] => C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [158024 2011-10-01] (FUJITSU LIMITED)
HKLM\...\Run: [LoadBtnHnd] => C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [23368 2011-10-01] (FUJITSU LIMITED)
HKLM-x32\...\Run: [IndicatorUtility] => C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-30] (FUJITSU LIMITED)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [255208 2012-03-21] (CyberLink Corp.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-09-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3525988650-49406593-731613899-1000\...\Run: [wxaszman] => C:\Users\f\AppData\Local\Ietuumwae\ibyamiszman.exe [109568 2014-10-27] ()
HKU\S-1-5-21-3525988650-49406593-731613899-1000\...\Winlogon: [Shell] C:\Program Files\Common Files\Microsoft Shared\ink\fr-FR\firmware\combine.exe,explorer.exe <==== ATTENTION
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk
ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk
ShortcutTarget: newreminderdialog.lnk -> C:\Program Files\Fujitsu\FujitsuRecovery\NewReminderDialog.exe (Fujitsu Technology Solutions)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk
ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk
ShortcutTarget: newreminderdialog.lnk -> C:\Program Files\Fujitsu\FujitsuRecovery\NewReminderDialog.exe (Fujitsu Technology Solutions)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {5DD6BB4B-C18D-4DA3-951A-1E9EB26E68BE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MAFSJS
SearchScopes: HKLM-x32 - {5DD6BB4B-C18D-4DA3-951A-1E9EB26E68BE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MAFSJS
SearchScopes: HKCU - {5DD6BB4B-C18D-4DA3-951A-1E9EB26E68BE} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\f\AppData\Roaming\Mozilla\Firefox\Profiles\lr8dg9f4.default-1414058758463
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\f\AppData\Roaming\Mozilla\Firefox\Profiles\lr8dg9f4.default-1414058758463\Extensions\trash [2014-10-23]
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-09-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-09-24] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc)
R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2011-11-24] (FUJITSU LIMITED)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-04-18] ()
R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED) [File not signed]
R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [51608 2012-06-30] (FUJITSU LIMITED)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2671376 2012-04-18] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2013-01-16] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-09-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-09-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-09-24] (Avira Operations GmbH & Co. KG)
R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED)
R3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED)
R3 FUJ02E3; C:\Windows\system32\drivers\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1812608 2011-12-28] ()
S3 TASCAM_US122144; C:\Windows\System32\Drivers\tascusb2.sys [409664 2010-06-18] (TASCAM)
S3 TASCAM_US122L_MIDI; C:\Windows\System32\drivers\tscusb2m.sys [31296 2010-06-18] (TASCAM)
S3 TASCAM_US122L_WDM; C:\Windows\System32\drivers\tscusb2a.sys [50240 2010-06-18] (TASCAM)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-28 20:12 - 2014-10-28 20:12 - 00000762 _____ () C:\Users\f\Desktop\JRT.txt
2014-10-28 20:10 - 2014-10-28 20:10 - 00000000 ____D () C:\Windows\ERUNT
2014-10-28 20:09 - 2014-10-28 20:09 - 01706144 _____ (Thisisu) C:\Users\f\Desktop\JRT.exe
2014-10-28 20:03 - 2014-10-28 20:03 - 00001291 _____ () C:\Users\f\Desktop\AdwCleaner[S3].txt
2014-10-28 20:00 - 2014-10-28 20:00 - 01998336 _____ () C:\Users\f\Downloads\adwcleaner_4.002.exe
2014-10-28 19:57 - 2014-10-28 19:58 - 00003365 _____ () C:\Users\f\Desktop\mbam.txt
2014-10-28 19:28 - 2014-10-28 20:06 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-28 19:27 - 2014-10-28 19:27 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-28 19:27 - 2014-10-28 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-28 19:27 - 2014-10-28 19:27 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-28 19:27 - 2014-10-28 19:27 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-28 19:27 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-28 19:27 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-28 19:27 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-28 19:26 - 2014-10-28 19:27 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\f\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-28 19:26 - 2014-10-28 19:26 - 00001113 _____ () C:\Users\f\Desktop\Continue File Opener Installation.lnk
2014-10-28 16:19 - 2014-10-28 16:20 - 76360088 _____ (Adobe Systems Incorporated) C:\Users\f\Downloads\AdbeRdr11009_de_DE.exe
2014-10-27 21:55 - 2014-10-27 21:55 - 00020624 _____ () C:\ComboFix.txt
2014-10-27 21:40 - 2014-10-27 21:55 - 00000000 ____D () C:\Qoobox
2014-10-27 21:40 - 2014-10-27 21:54 - 00000000 ____D () C:\Windows\erdnt
2014-10-27 21:40 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-27 21:40 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-27 21:40 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-27 21:40 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-27 21:40 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-27 21:40 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-27 21:40 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-27 21:40 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-27 21:38 - 2014-10-27 21:39 - 05591695 ____R (Swearware) C:\Users\f\Desktop\ComboFix.exe
2014-10-27 20:56 - 2014-10-27 20:54 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-27 20:55 - 2014-10-27 21:00 - 00001143 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-27 20:54 - 2014-10-27 21:00 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-27 20:54 - 2014-10-27 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-27 20:54 - 2014-10-27 20:54 - 00002068 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-10-27 20:54 - 2014-10-27 20:54 - 00000000 ____D () C:\Users\f\AppData\Roaming\Avira
2014-10-27 20:53 - 2014-10-27 20:55 - 00000000 ____D () C:\ProgramData\Avira
2014-10-27 20:53 - 2014-09-24 12:44 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-27 20:53 - 2014-09-24 12:44 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-10-27 20:53 - 2014-09-24 12:44 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-10-27 10:56 - 2014-10-27 10:56 - 00008981 _____ () C:\Users\f\Desktop\Gmer.txt
2014-10-27 10:43 - 2014-10-27 10:43 - 00284848 _____ () C:\Windows\Minidump\102714-20202-01.dmp
2014-10-27 10:28 - 2014-10-27 10:28 - 00380416 _____ () C:\Users\f\Downloads\1sn7jh7l.exe
2014-10-27 10:27 - 2014-10-27 10:28 - 00020165 _____ () C:\Users\f\Downloads\Addition.txt
2014-10-27 10:26 - 2014-10-28 20:17 - 00013377 _____ () C:\Users\f\Downloads\FRST.txt
2014-10-27 10:26 - 2014-10-28 20:17 - 00000000 ____D () C:\FRST
2014-10-27 10:25 - 2014-10-27 10:25 - 02113024 _____ (Farbar) C:\Users\f\Downloads\FRST64.exe
2014-10-27 10:24 - 2014-10-27 10:24 - 00000464 _____ () C:\Users\f\Downloads\defogger_disable.log
2014-10-27 10:24 - 2014-10-27 10:24 - 00000000 _____ () C:\Users\f\defogger_reenable
2014-10-27 10:23 - 2014-10-27 10:23 - 00050477 _____ () C:\Users\f\Downloads\Defogger.exe
2014-10-27 09:58 - 2014-10-27 09:58 - 00000000 ___HD () C:\Users\f\AppData\Local\Ietuumwae
2014-10-25 16:04 - 2014-10-25 16:04 - 00854448 _____ () C:\Users\f\Downloads\SecurityCheck.exe
2014-10-25 14:53 - 2014-10-25 14:54 - 00284792 _____ () C:\Windows\Minidump\102514-20498-01.dmp
2014-10-25 11:26 - 2014-10-25 11:26 - 02347384 _____ (ESET) C:\Users\f\Downloads\esetsmartinstaller_deu.exe
2014-10-25 11:10 - 2014-10-25 11:10 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-10-25 11:10 - 2014-10-25 11:10 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-10-25 11:09 - 2014-10-25 11:09 - 00244408 _____ () C:\Users\f\Downloads\Firefox Setup Stub 33.0.exe
2014-10-23 11:06 - 2014-10-23 11:06 - 00000000 ____D () C:\Users\f\Desktop\Alte Firefox-Daten
2014-10-23 10:41 - 2014-10-23 10:41 - 00218987 _____ () C:\Users\f\Desktop\bookmarks-2014-10-23.json
2014-10-23 09:58 - 2014-10-25 11:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-22 11:51 - 2014-10-23 07:59 - 00000000 ___HD () C:\Users\f\AppData\Local\Explorer32
2014-10-22 08:35 - 2014-10-28 20:09 - 00000000 ____D () C:\AdwCleaner
2014-10-21 22:20 - 2014-10-28 19:50 - 00000000 ___HD () C:\Users\f\AppData\Roaming\Explorer64
2014-10-21 21:20 - 2014-10-24 09:47 - 00000000 ___HD () C:\Users\f\AppData\Local\Ygxovf
2014-10-21 21:09 - 2014-10-24 08:34 - 00000000 ___HD () C:\Users\f\AppData\Local\Update
2014-10-21 20:56 - 2014-10-21 21:20 - 00000000 ___HD () C:\Users\f\AppData\Local\Fvhfn
2014-10-21 15:34 - 2014-10-24 10:21 - 00000000 ____D () C:\ProgramData\nwwqude
2014-10-21 15:03 - 2014-10-24 08:51 - 00000000 ___HD () C:\Users\f\AppData\Roaming\Explorer32
2014-10-21 13:59 - 2014-10-27 21:00 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-21 13:54 - 2014-10-21 13:56 - 150010760 _____ () C:\Users\f\Downloads\avira_free_antivirus_de.exe
2014-10-18 22:32 - 2014-10-18 22:32 - 00000000 ____D () C:\Users\f\Desktop\Mtume (Kawaida (1973)
2014-10-16 10:44 - 2014-10-28 16:11 - 00000000 ____D () C:\Users\f\Desktop\boogieboot_boogiebüdchen
2014-10-16 09:15 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-16 09:14 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 22:45 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 22:44 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 22:44 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 22:44 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 22:44 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 22:44 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 22:44 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 22:44 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 22:44 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 22:44 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 22:44 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 22:44 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 22:44 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 22:44 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 22:44 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 22:44 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 22:44 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 22:44 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 22:44 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 22:44 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 22:44 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 22:44 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 22:44 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 22:44 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 22:44 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 22:44 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 22:44 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 22:44 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 22:44 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 22:44 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 22:44 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 22:44 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 22:44 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 22:44 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 22:44 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 22:44 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 22:44 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 22:44 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 22:44 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 22:44 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 22:44 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 22:44 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 22:44 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 22:44 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 22:44 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 22:44 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 22:44 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 22:44 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 22:44 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 22:44 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 22:44 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 22:44 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 22:44 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 22:44 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 22:44 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 22:44 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 22:44 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 22:44 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 22:44 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 22:44 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 22:44 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 22:44 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 22:44 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 22:43 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 22:43 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 22:43 - 2014-07-17 03:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 22:43 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-15 22:43 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 22:43 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 22:43 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 22:43 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 22:43 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 22:43 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 22:43 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 22:43 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-15 22:43 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-10-15 22:43 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-10-15 22:43 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 22:43 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 22:43 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 22:43 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-15 22:43 - 2014-05-30 09:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-10-15 22:43 - 2014-05-30 09:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-10-15 22:43 - 2014-05-30 09:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-10-15 22:43 - 2014-05-30 09:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-10-15 22:43 - 2014-05-30 08:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-10-15 22:43 - 2014-05-30 08:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-10-15 22:43 - 2014-05-30 08:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-10-15 22:43 - 2014-05-30 08:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-10-15 10:26 - 2014-10-15 17:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-10-11 12:16 - 2014-10-11 12:16 - 00000000 ____D () C:\Users\f\Desktop\(Ad)ventures
2014-10-11 11:51 - 2014-10-11 11:52 - 00000000 ____D () C:\Users\f\Desktop\IZotope.Ozone.VST.DX.RTAS.HTDM.v4.03.Incl.Keygen-AiR
2014-10-11 11:51 - 2014-10-11 11:51 - 00000000 ____D () C:\Users\f\Desktop\Edirol
2014-10-09 10:27 - 2014-10-23 09:58 - 00000000 ____D () C:\Users\f\Desktop\HA_Fotografie
2014-10-07 14:59 - 2014-10-07 14:59 - 00000098 _____ () C:\Users\f\Downloads\100% Pure Poison.rar
2014-10-03 12:19 - 2014-10-03 12:19 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-03 12:19 - 2014-10-03 12:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-28 20:13 - 2009-07-14 05:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-28 20:13 - 2009-07-14 05:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-28 20:10 - 2013-01-16 19:37 - 00696870 _____ () C:\Windows\system32\perfh007.dat
2014-10-28 20:10 - 2013-01-16 19:37 - 00148134 _____ () C:\Windows\system32\perfc007.dat
2014-10-28 20:10 - 2009-07-14 06:13 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-28 20:07 - 2014-05-28 08:43 - 00000000 ____D () C:\Users\f\Documents\Youcam
2014-10-28 20:04 - 2010-11-21 04:47 - 00320346 _____ () C:\Windows\PFRO.log
2014-10-28 20:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-28 20:04 - 2009-07-14 05:51 - 00083063 _____ () C:\Windows\setupact.log
2014-10-28 20:03 - 2014-05-28 08:32 - 02013323 _____ () C:\Windows\WindowsUpdate.log
2014-10-28 19:52 - 2014-05-30 11:02 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-28 19:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Registration
2014-10-28 16:22 - 2014-05-30 09:47 - 00000000 ____D () C:\Users\f\AppData\Roaming\Adobe
2014-10-28 16:20 - 2013-02-28 18:30 - 00000000 ____D () C:\ProgramData\Adobe
2014-10-27 21:55 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-10-27 21:51 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-27 15:28 - 2014-08-26 14:33 - 00000000 ____D () C:\Users\f\AppData\Roaming\Skype
2014-10-27 10:43 - 2014-06-03 15:19 - 00000000 ____D () C:\Windows\Minidump
2014-10-27 10:24 - 2014-05-28 08:33 - 00000000 ____D () C:\Users\f
2014-10-25 11:17 - 2014-07-23 18:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-24 12:38 - 2014-05-28 08:42 - 00000000 ____D () C:\ProgramData\McAfee
2014-10-22 21:58 - 2014-07-28 14:58 - 00000000 ____D () C:\Users\f\AppData\Roaming\vlc
2014-10-18 14:39 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-10-17 18:37 - 2014-07-28 17:18 - 00000000 ____D () C:\Users\f\AppData\Roaming\Audacity
2014-10-16 17:59 - 2009-07-14 05:45 - 00301744 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-16 09:16 - 2014-08-26 21:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-16 09:13 - 2014-08-26 21:56 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-15 12:01 - 2014-08-21 16:58 - 00000000 ____D () C:\Users\f\Desktop\ebay
2014-10-03 12:19 - 2014-08-26 14:33 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-10-03 12:19 - 2014-08-26 14:33 - 00000000 ____D () C:\ProgramData\Skype
2014-10-02 14:53 - 2010-11-21 04:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-30 10:10 - 2014-08-25 11:56 - 00000000 ____D () C:\Users\f\Desktop\kleiderkreisel
2014-09-29 10:00 - 2013-02-28 18:30 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
Some content of TEMP:
====================
C:\Users\f\AppData\Local\Temp\avgnt.exe
C:\Users\f\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe
C:\Users\f\AppData\Local\Temp\Quarantine.exe
C:\Users\f\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-26 12:48
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
viele grüße,
fabjels
Ich weiß nicht wo wir stehen, will auch nicht vorgreifen, aber vielleicht ist es hilfreich für Dich
zu wissen, dass Avira - auch nach den vier Scans oben - nach Neustart des Rechners immer noch folgenden Virus findet:Objekt: ibyamiszman.exe Fund: TR/Matsnu.A.264.
Soll ich dies ignorieren oder in Quarantäne verschieben lassen? |