EddyEast | 13.12.2014 10:06 | Code:
Von der MBAM hab ich keine brauchbare txt gefunden da ich vorher einen scan abgebrochen hab, hat aber 4 search protect dateien gefunden die ich gelöscht hab
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 13.12.2014 09:04:39, SYSTEM, EVOT-PC, Manual, Rootkit Database, 2014.11.18.1, 2014.12.8.3,
Update, 13.12.2014 09:04:39, SYSTEM, EVOT-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Error, 13.12.2014 09:05:14, SYSTEM, EVOT-PC, Manual, 0,
Error, 13.12.2014 09:05:14, SYSTEM, EVOT-PC, Manual, 0,
Scan, 13.12.2014 09:05:44, SYSTEM, EVOT-PC, Manual, Start: % 1 "% 2", Dauer: % 1 min 0 Sekunden, Bedrohungs-Suchlauf, Abgebrochen, 0 Malwareerkennung, 0-Malwareerkennung,
Update, 13.12.2014 09:06:08, SYSTEM, EVOT-PC, Manual, Malware Database, 2014.11.20.6, 2014.12.13.2,
Scan, 13.12.2014 09:22:11, SYSTEM, EVOT-PC, Manual, Start: % 1 "% 2", Dauer: % 1 min 15 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 8-Malwareerkennung,
(end) Code:
# AdwCleaner v4.105 - Bericht erstellt am 13/12/2014 um 09:38:46
# Aktualisiert 08/12/2014 von Xplode
# Database : 2014-12-12.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : evot - EVOT-PC
# Gestartet von : C:\Users\evot\Downloads\AdwCleaner_4.105.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : c2cautoupdatesvc
Dienst Gelöscht : c2cpnrsvc
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\evot\AppData\Roaming\DesktopIconForAmazon
***** [ Tasks ] *****
Task Gelöscht : LaunchSignup
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\OCS
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v34.0 (x86 de)
*************************
AdwCleaner[R0].txt - [1827 octets] - [13/12/2014 09:36:06]
AdwCleaner[S0].txt - [1694 octets] - [13/12/2014 09:38:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1754 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Home Premium x64
Ran by evot on 13.12.2014 at 9:45:23,44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\evot\AppData\Roaming\mozilla\firefox\profiles\0tavtfcq.default-1418379616975\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.12.2014 at 9:51:20,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-12-2014 03
Ran by evot (administrator) on EVOT-PC on 13-12-2014 09:59:42
Running from C:\Users\evot\Desktop
Loaded Profile: evot (Available profiles: evot)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11855976 2011-05-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-22] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKU\S-1-5-21-3311255235-3397216843-2718031111-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3311255235-3397216843-2718031111-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3311255235-3397216843-2718031111-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\evot\AppData\Roaming\Mozilla\Firefox\Profiles\0tavtfcq.default-1418379616975
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-10]
FF HKU\S-1-5-21-3311255235-3397216843-2718031111-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\evot\AppData\Roaming\Mozilla\Firefox\Profiles\kc3jsgcx.default\extensions\cliqz@cliqz.com
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-05-24] (Advanced Micro Devices, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-13 09:59 - 2014-12-13 10:00 - 00006676 _____ () C:\Users\evot\Desktop\FRST.txt
2014-12-13 09:51 - 2014-12-13 09:51 - 00000768 _____ () C:\Users\evot\Desktop\JRT.txt
2014-12-13 09:42 - 2014-12-13 09:42 - 00000833 _____ () C:\Users\evot\Desktop\mbam.txt
2014-12-13 09:38 - 2014-12-13 09:38 - 00001842 _____ () C:\Users\evot\Desktop\AdwCleaner[S0].txt
2014-12-13 09:36 - 2014-12-13 09:44 - 00000000 ____D () C:\AdwCleaner
2014-12-13 09:35 - 2014-12-13 09:35 - 02166272 _____ () C:\Users\evot\Desktop\AdwCleaner_4.105.exe
2014-12-13 09:04 - 2014-12-13 09:41 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-13 09:04 - 2014-12-13 09:04 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-13 09:04 - 2014-12-13 09:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-13 09:04 - 2014-12-13 09:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-13 09:04 - 2014-12-13 09:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-13 09:04 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-13 09:04 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-13 09:04 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-13 09:03 - 2014-12-13 09:03 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\evot\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-12 10:10 - 2014-12-12 10:10 - 00017756 _____ () C:\ComboFix.txt
2014-12-12 09:53 - 2014-12-12 10:10 - 00000000 ____D () C:\Qoobox
2014-12-12 09:53 - 2014-12-12 10:08 - 00000000 ____D () C:\Windows\erdnt
2014-12-12 09:53 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-12 09:53 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-12 09:53 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-12 09:53 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-12 09:53 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-12 09:53 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-12 09:53 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-12 09:53 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-12 09:49 - 2014-12-12 09:50 - 05600944 ____R (Swearware) C:\Users\evot\Desktop\ComboFix.exe
2014-12-12 09:41 - 2014-12-12 09:41 - 00001268 _____ () C:\Users\evot\Desktop\Revo Uninstaller.lnk
2014-12-12 09:41 - 2014-12-12 09:41 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-12-12 09:40 - 2014-12-12 09:40 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\evot\Downloads\revosetup95.exe
2014-12-12 09:33 - 2014-12-12 09:33 - 442094430 _____ () C:\Windows\MEMORY.DMP
2014-12-12 09:33 - 2014-12-12 09:33 - 00455648 _____ () C:\Windows\Minidump\121214-39452-01.dmp
2014-12-12 09:33 - 2014-12-12 09:33 - 00000000 ____D () C:\Windows\Minidump
2014-12-12 09:18 - 2014-12-12 09:18 - 00000081 _____ () C:\Users\evot\Desktop\Neues Textdokument (2).txt
2014-12-12 08:42 - 2014-12-12 08:42 - 00380416 _____ () C:\Users\evot\Desktop\Gmer-19357.exe
2014-12-12 08:38 - 2014-12-13 09:59 - 00000000 ____D () C:\FRST
2014-12-12 08:38 - 2014-12-12 08:38 - 02119680 _____ (Farbar) C:\Users\evot\Desktop\FRST64.exe
2014-12-12 08:37 - 2014-12-12 08:37 - 00000000 _____ () C:\Users\evot\defogger_reenable
2014-12-12 08:35 - 2014-12-12 08:35 - 00050477 _____ () C:\Users\evot\Downloads\Defogger.exe
2014-12-11 19:14 - 2014-12-11 19:14 - 00000000 ____D () C:\Windows\ERUNT
2014-12-11 19:06 - 2014-12-11 19:06 - 01707646 _____ (Thisisu) C:\Users\evot\Desktop\JRT.exe
2014-12-11 05:31 - 2014-12-11 05:33 - 154051656 _____ () C:\Users\evot\Downloads\avira_free_antivirus468_de.exe
2014-12-11 05:31 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-11 05:31 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-11 05:31 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-11 05:31 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-11 05:31 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-11 05:31 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-11 05:31 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 05:31 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-11 05:31 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-11 05:31 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-11 05:31 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-11 05:31 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-11 05:31 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-11 05:31 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-11 05:31 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-11 05:31 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 05:31 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-11 05:30 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-11 05:30 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-11 05:30 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 05:30 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-11 05:30 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-11 05:30 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-11 05:30 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-11 05:30 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-11 05:30 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-11 05:30 - 2014-11-22 03:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-11 05:30 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-11 05:30 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-11 05:30 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 05:30 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-11 05:30 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-11 05:30 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-11 05:30 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-11 05:30 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-11 05:30 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-11 05:30 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-11 05:30 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-11 05:30 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-11 05:30 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-11 05:30 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-11 05:30 - 2014-11-22 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-11 05:30 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-11 05:30 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-11 05:30 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-11 05:30 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-11 05:30 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-11 05:30 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-11 05:30 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-11 05:30 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-11 05:30 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-11 05:30 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-11 05:30 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-11 05:30 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-11 05:30 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-11 05:30 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-11 05:30 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-11 05:30 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-10 16:05 - 2014-12-10 16:05 - 00035699 _____ () C:\Users\evot\Desktop\JOBBÖRSE - Stellenangebot - Maschinenführer_in Extrusion (Extruderführer_in).htm
2014-12-10 16:05 - 2014-12-10 16:05 - 00000000 ____D () C:\Users\evot\Desktop\JOBBÖRSE - Stellenangebot - Maschinenführer_in Extrusion (Extruderführer_in)-Dateien
2014-12-10 15:32 - 2014-12-10 15:32 - 00037555 _____ () C:\Users\evot\Desktop\JOBBÖRSE - Stellenangebot - Verfahrensmech.-Kunststoff-_Kautschuktechnik (m. Schwerp.).htm
2014-12-10 15:32 - 2014-12-10 15:32 - 00000000 ____D () C:\Users\evot\Desktop\JOBBÖRSE - Stellenangebot - Verfahrensmech.-Kunststoff-_Kautschuktechnik (m. Schwerp.)-Dateien
2014-12-10 02:54 - 2014-12-10 02:55 - 00000151 _____ () C:\Users\evot\Desktop\yahoo.url
2014-12-09 22:15 - 2014-12-09 22:15 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-12-09 22:15 - 2014-12-09 22:15 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-12-09 15:17 - 2014-12-10 02:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-12-09 15:17 - 2014-12-09 15:17 - 00002795 _____ () C:\Users\evot\Desktop\Microsoft Office Outlook 2007.lnk
2014-12-09 15:17 - 2014-12-09 15:17 - 00002697 _____ () C:\Users\evot\Desktop\Microsoft Office Word 2007.lnk
2014-12-09 15:15 - 2014-12-09 15:21 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-12-09 15:14 - 2014-12-09 15:14 - 00000000 ____D () C:\Windows\PCHEALTH
2014-12-09 15:14 - 2014-12-09 15:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2014-12-09 15:11 - 2014-12-09 15:11 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-12-09 15:11 - 2014-12-09 15:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-12-09 15:10 - 2014-12-12 08:41 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-09 15:10 - 2014-12-09 15:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-12-09 15:10 - 2014-12-09 15:10 - 00000000 ___RD () C:\MSOCache
2014-12-09 15:10 - 2014-12-09 15:10 - 00000000 ____D () C:\Users\evot\AppData\Local\Microsoft Help
2014-12-09 14:57 - 2014-12-11 07:44 - 00000000 ____D () C:\Users\evot\Desktop\Bewerbung
2014-12-09 14:38 - 2014-12-09 14:38 - 01682512 _____ (BitTorrent Inc.) C:\Users\evot\Downloads\uTorrent_3.4.2b36802.exe
2014-12-09 14:27 - 2014-12-09 14:27 - 00792912 _____ ( ) C:\Users\evot\Downloads\microsoft_word.exe
2014-12-08 01:19 - 2014-12-08 01:36 - 00000449 _____ () C:\Users\evot\Desktop\dr dean ornish.txt
2014-11-19 23:49 - 2014-11-19 23:49 - 00000000 ____D () C:\Users\evot\AppData\Local\PDF24
2014-11-19 23:48 - 2014-11-19 23:48 - 16343840 _____ (Geek Software GmbH ) C:\Users\evot\Downloads\pdf24-creator-6.9.1.exe
2014-11-19 23:22 - 2014-11-19 23:22 - 00000979 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\VueScan x64.lnk
2014-11-19 23:22 - 2014-11-19 23:22 - 00000973 _____ () C:\Users\Public\Desktop\VueScan x64.lnk
2014-11-19 23:22 - 2014-11-19 23:22 - 00000000 ____D () C:\Program Files\VueScan
2014-11-19 23:21 - 2014-11-19 23:22 - 00000000 ____D () C:\Users\evot\Downloads\Vue9451
2014-11-19 23:21 - 2014-11-19 23:21 - 17292917 _____ () C:\Users\evot\Downloads\Vue9451.zip
2014-11-19 23:20 - 2014-11-19 23:21 - 01125200 _____ () C:\Users\evot\Downloads\VueScan - CHIP-Installer.exe
2014-11-19 23:17 - 2014-12-12 08:22 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-11-19 23:17 - 2014-11-19 23:17 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-11-19 23:17 - 2014-11-19 23:17 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-11-19 23:16 - 2014-11-19 23:19 - 00000000 ____D () C:\ProgramData\Adobe
2014-11-19 23:09 - 2014-11-19 23:12 - 00000000 ____D () C:\Users\evot\AppData\Roaming\Scan2PDF
2014-11-19 23:09 - 2014-11-19 23:09 - 00000000 ____D () C:\Users\evot\AppData\Roaming\Canon
2014-11-19 23:09 - 2014-11-19 23:09 - 00000000 _____ () C:\Users\evot\Sti_Trace.log
2014-11-19 23:06 - 2014-11-19 23:06 - 01125200 _____ () C:\Users\evot\Downloads\Scan2PDF - CHIP-Installer.exe
2014-11-19 07:50 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 07:50 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 07:50 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 07:50 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-18 14:56 - 2014-11-18 14:56 - 01202848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FM20.DLL
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-13 09:46 - 2009-07-14 05:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-13 09:46 - 2009-07-14 05:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-13 09:44 - 2014-09-09 16:44 - 01155975 _____ () C:\Windows\WindowsUpdate.log
2014-12-13 09:44 - 2011-04-12 08:43 - 00643866 _____ () C:\Windows\system32\perfh007.dat
2014-12-13 09:44 - 2011-04-12 08:43 - 00126394 _____ () C:\Windows\system32\perfc007.dat
2014-12-13 09:44 - 2009-07-14 06:13 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-13 09:39 - 2010-11-21 04:47 - 00054438 _____ () C:\Windows\PFRO.log
2014-12-13 09:39 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-13 09:39 - 2009-07-14 05:51 - 00035978 _____ () C:\Windows\setupact.log
2014-12-13 09:03 - 2014-09-14 20:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-13 08:37 - 2014-09-10 15:07 - 00000000 ____D () C:\Users\evot\AppData\Roaming\Skype
2014-12-12 20:17 - 2014-09-09 17:53 - 00000915 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-12-12 20:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-12 14:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 11:23 - 2014-09-14 20:17 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-12-12 10:10 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-12 10:05 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-12-12 10:04 - 2009-07-14 03:34 - 60555264 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-12-12 10:04 - 2009-07-14 03:34 - 15204352 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-12-12 10:04 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-12-12 10:04 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-12-12 10:04 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-12-12 09:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-12 08:37 - 2014-09-09 16:52 - 00000000 ____D () C:\Users\evot
2014-12-11 05:37 - 2014-09-09 17:51 - 00108840 _____ () C:\Users\evot\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-10 02:46 - 2014-09-09 23:19 - 00000000 ____D () C:\Users\evot\AppData\Roaming\uTorrent
2014-12-10 02:24 - 2014-09-09 17:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-10 02:24 - 2009-07-14 05:45 - 00409832 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-09 22:15 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini
2014-12-09 20:03 - 2014-09-14 20:17 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-09 20:03 - 2014-09-14 20:17 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-09 20:03 - 2014-09-14 20:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-09 15:14 - 2011-04-12 08:54 - 00000000 ____D () C:\Windows\ShellNew
2014-12-09 15:14 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-12-09 15:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-12-07 22:26 - 2014-11-10 20:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-01 15:47 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-27 13:02 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-19 23:23 - 2014-09-09 17:21 - 00009410 _____ () C:\Windows\DPINST.LOG
2014-11-19 23:18 - 2014-09-14 20:18 - 00000000 ____D () C:\Users\evot\AppData\Roaming\Adobe
2014-11-19 23:18 - 2014-09-14 20:15 - 00000000 ____D () C:\Users\evot\AppData\Local\Adobe
2014-11-19 07:42 - 2014-09-28 14:57 - 00000552 _____ () C:\Users\evot\Desktop\Neues Textdokument.txt
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-05 15:52
==================== End Of Log ============================ --- --- --- |