Sunwalk3r | 24.06.2013 09:02 | Code:
# AdwCleaner v2.303 - Datei am 23/06/2013 um 19:09:03 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzer : *** - ARBEITSZIMMER
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\***\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\49hb8co1.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\49hb8co1.default\bprotector_prefs.js
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\49hb8co1.default\searchplugins\delta.xml
Gelöscht mit Neustart : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\ProgramData\APN
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\InstallMate
Ordner Gelöscht : C:\Users\***\AppData\Local\AVG Secure Search
Ordner Gelöscht : C:\Users\***\AppData\LocalLow\AVG Secure Search
Ordner Gelöscht : C:\Users\***\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\***\AppData\Roaming\DataMgr
Ordner Gelöscht : C:\Users\***\AppData\Roaming\Delta
Ordner Gelöscht : C:\Users\***\AppData\Roaming\HMN
Ordner Gelöscht : C:\Users\***\AppData\Roaming\SDIV 2.0
Ordner Gelöscht : C:\Users\****\AppData\Local\AVG Secure Search
Ordner Gelöscht : C:\Users\****\AppData\LocalLow\AskToolbar
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\XingHaoLyrics
Schlüssel Gelöscht : HKCU\Software\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\delta LTD
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\5f28adee73bea47
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\BabylonToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FBDownloader.DownloadPhoto
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FBDownloader.DownloadPhoto.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\InstallIQ
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_winrar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_winrar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{553318DA-D010-469E-84B1-496563CAE1BF}
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\5f28adee73bea47
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{14F35FFC-522A-4DD1-A07E-6B8B65C6891E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{553318DA-D010-469E-84B1-496563CAE1BF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{598B7D72-2C44-4351-BBC8-3DACE2A10CB6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{553318DA-D010-469E-84B1-496563CAE1BF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Protector]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16611
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v21.0 (de)
Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\49hb8co1.default\prefs.js
C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\49hb8co1.default\user.js ... Gelöscht !
Gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.fbdownloader.com/search.php?channel=sfde203fbd[...]
Gelöscht : user_pref("extensions.51b70bbef2a20.scode", "(function(){try{if('aol.com,mail.google.com,premiumrepo[...]
Datei : C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\o17y33x6.default\prefs.js
Gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "");
-\\ Google Chrome v27.0.1453.116
Datei : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Preferences
Gelöscht [l.28] : icon_url = "hxxp://search.fbdownloader.com/favicon.ico",
Gelöscht [l.31] : keyword = "fbdownloader_search",
Gelöscht [l.35] : search_url = "hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q={searchTerms[...]
Gelöscht [l.2239] : homepage = "hxxp://search.fbdownloader.com/?channel=sfde203fbdgy21",
*************************
AdwCleaner[R1].txt - [8810 octets] - [23/06/2013 19:08:07]
AdwCleaner[S1].txt - [344 octets] - [23/06/2013 19:07:57]
AdwCleaner[S2].txt - [8583 octets] - [23/06/2013 19:09:03]
########## EOF - C:\AdwCleaner[S2].txt - [8643 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Professional x64
Ran by *** on 23.06.2013 at 19:15:57,23
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E7749801-E9C3-407A-A20F-B68C008EF0B5}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\49hb8co1.default\minidumps [120 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.06.2013 at 19:20:12,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=f271daecb1492b4eae35ac84c6206f53
# engine=14135
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-24 12:41:54
# local_time=2013-06-24 02:41:54 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1043 16777213 100 87 46733 59168498 0 0
# compatibility_mode=5893 16776574 100 94 18256164 123664364 0 0
# scanned=1267328
# found=2
# cleaned=0
# scan_time=26244
sh=B5EF372772365F2F02C9F9CFAF0BE4E7027F49C5 ft=1 fh=da5297ae5b2a6ce6 vn="Win32/TrojanDownloader.FakeAlert.ARD trojan" ac=I fn="D:\unzipe\mp3\Mediafire.Newsong.-.the.Christmas.shoes.mp3.52007.exe"
sh=E82C1C38E9CA3080447DE2AA45CA160200D3272D ft=1 fh=65ac5f93de6be24b vn="probably a variant of Win32/Agent.NXGDQBH trojan" ac=I fn="D:\Users\Burkhard\AppData\Local\Temp\loop.exe" Code:
Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10 ``````````````Antivirus/Firewall Check:``````````````
AVG AntiVirus Free Edition 2013
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Spybot - Search & Destroy
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 25
Java version out of Date!
Adobe Flash Player 9 Flash Player out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (21.0)
Mozilla Thunderbird (17.0.2)
Google Chrome 27.0.1453.110
Google Chrome 27.0.1453.116 ````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
AVG avgwdsvc.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2013
Ran by *** (administrator) on 24-06-2013 09:56:16
Running from C:\Users\***\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
(Dropbox, Inc.) C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Adobe Systems Inc.) D:\Programme\Acrobat 8.0\Acrobat\acrotray.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Macrovision Europe Ltd.) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems Incorporated) D:\ProgrammeWin7\Photoshop Elements 11\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BCSSync] "D:\ProgrammeWin7\Office14\BCSSync.exe" /DelayServices [x]
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [446392 2012-04-04] (Adobe Systems Incorporated)
HKCU\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3673728 2012-11-06] (DT Soft Ltd)
HKCU\...\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [3713032 2012-11-13] (Safer-Networking Ltd.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [642728 2012-09-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "D:\Programme\Acrobat 8.0\Acrobat\Acrotray.exe" [x]
HKLM-x32\...\Run: [Adobe_ID0EYTHM] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [1884160 2007-03-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [FreePDF Assistant] "C:\Program Files (x86)\FreePDF_XP\fpassist.exe" [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~4\Office14\GROOVEEX.DLL No File
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\PROGRA~4\Office14\URLREDIR.DLL No File
BHO-x32: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Programme\/Adobe Contribute CS3/contributeieplugin.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Programme\Acrobat 8.0\Acrobat\AcroIEFavClient.dll No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Programme\Acrobat 8.0\Acrobat\AcroIEFavClient.dll No File
Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Programme\/Adobe Contribute CS3/contributeieplugin.dll No File
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\PROGRA~4\Office14\GROOVEEX.DLL No File [ ]
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\49hb8co1.default
FF Homepage: hxxp://www.sueddeutsche.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @ilok.com/iLokHelper,version=3.1.0.7 - C:\Program Files (x86)\PACE Anti-Piracy\iLok\NPPaceILok.dll ( PACE Anti-Piracy, Inc)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: No Name - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\49hb8co1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchURL: (FBDownloader Search) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR DefaultSuggestURL: (FBDownloader Search) - "suggest_url": ""
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (PACE Client Helper Plugin) - C:\Program Files (x86)\PACE Anti-Piracy\iLok\NPPaceILok.dll ( PACE Anti-Piracy, Inc)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (iTunes Application Detector) - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Extension: (Google Docs) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Gmail) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor11.0; D:\ProgrammeWin7\Photoshop Elements 11\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-23] (Adobe Systems Incorporated)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)
S3 Microsoft SharePoint Workspace Audit Service; D:\ProgrammeWin7\Office14\GROOVE.EXE [50899608 2012-09-20] (Microsoft Corporation)
R2 vToolbarUpdater15.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [1015984 2013-05-21] (AVG Secure Search)
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [60288 2009-07-14] (Microsoft Corporation)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-05-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-11-19] (DT Soft Ltd)
S3 iLokDrvr; C:\Windows\System32\DRIVERS\iLokDrvr.sys [24728 2012-11-17] ()
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation)
S3 ZOOM_R16MTR; C:\Windows\System32\Drivers\zmr16usbaudio.sys [96768 2012-04-12] (Zoom Corporation.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-24 09:56 - 2013-06-24 09:56 - 00000041 ____A C:\Users\***\Desktop\checkup.txt
2013-06-24 09:55 - 2013-06-24 09:55 - 00890839 ____A C:\Users\***\Desktop\SecurityCheck.exe
2013-06-23 19:22 - 2013-06-23 19:22 - 02347384 ____A (ESET) C:\Users\***\Desktop\esetsmartinstaller_enu.exe
2013-06-23 19:22 - 2013-06-23 19:22 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-23 19:20 - 2013-06-23 19:21 - 00000901 ____A C:\Users\***\Desktop\JRT.txt
2013-06-23 19:15 - 2013-06-23 19:15 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\***\Desktop\JRT.exe
2013-06-23 19:15 - 2013-06-23 19:15 - 00000000 ____D C:\Windows\ERUNT
2013-06-23 19:15 - 2013-06-23 19:15 - 00000000 ____D C:\JRT
2013-06-23 19:13 - 2013-06-23 19:13 - 00008609 ____A C:\Users\***\Desktop\AdwCleaner[S2].txt
2013-06-23 19:09 - 2013-06-23 19:09 - 00008700 ____A C:\AdwCleaner[S2].txt
2013-06-23 19:09 - 2013-06-23 19:09 - 00000121 ____A C:\Windows\DeleteOnReboot.bat
2013-06-23 19:08 - 2013-06-23 19:08 - 00008810 ____A C:\AdwCleaner[R1].txt
2013-06-23 19:07 - 2013-06-23 19:07 - 00000344 ____A C:\AdwCleaner[S1].txt
2013-06-23 19:06 - 2013-06-23 19:07 - 00648201 ____A C:\Users\***\Desktop\adwcleaner.exe
2013-06-23 13:38 - 2013-06-23 13:38 - 00448512 ____A (OldTimer Tools) C:\Users\***\Desktop\TFC.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-23 13:28 - 2013-06-23 13:28 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-23 13:15 - 2013-06-23 13:15 - 00000000 ____D C:\Program Files\eLicenser
2013-06-23 13:06 - 2013-06-23 13:06 - 00000000 ____D C:\Users\***\AppData\Local\eLicenser
2013-06-23 12:42 - 2013-06-23 12:27 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20130623-124219.backup
2013-06-23 12:30 - 2013-06-23 12:30 - 00022491 ____A C:\ComboFix.txt
2013-06-23 12:18 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-06-23 12:18 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-06-23 12:18 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-06-23 12:18 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-06-23 12:18 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-06-23 12:18 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-06-23 12:18 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-06-23 12:18 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-06-23 12:16 - 2013-06-23 12:30 - 00000000 ____D C:\Qoobox
2013-06-23 12:16 - 2013-06-23 12:28 - 00000000 ____D C:\Windows\erdnt
2013-06-23 12:15 - 2013-06-23 12:15 - 05082201 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe
2013-06-22 23:23 - 2013-06-22 23:27 - 00023788 ____A C:\Users\***\Desktop\Addition.txt
2013-06-22 23:23 - 2013-06-22 23:23 - 00000000 ____D C:\FRST
2013-06-22 23:22 - 2013-06-22 23:22 - 01931364 ____A (Farbar) C:\Users\***\Desktop\FRST64.exe
2013-06-22 13:09 - 2013-06-22 18:03 - 00000000 ____D C:\Users\***\AppData\Roaming\vlc
2013-06-22 13:08 - 2013-06-22 13:08 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-06-21 21:09 - 2013-06-21 21:09 - 00000000 ____D C:\Users\***\AppData\Roaming\Malwarebytes
2013-06-21 21:09 - 2013-06-21 21:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-21 21:09 - 2013-06-21 21:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-21 21:09 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-21 20:25 - 2013-06-23 19:11 - 00001301 ____A C:\Windows\setupact.log
2013-06-20 09:41 - 2001-09-16 17:39 - 00001024 ____A C:\b4
2013-06-20 09:41 - 1997-02-01 18:10 - 00011910 ____A C:\Windows\SysWOW64\Genmidi.dll
2013-06-20 09:41 - 1997-02-01 18:10 - 00011910 ____A C:\Windows\Genmidi.dll
2013-06-20 09:38 - 2003-09-10 18:00 - 00163840 ____A () C:\Windows\SysWOW64\ArtFfct.dll
2013-06-18 03:01 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-18 03:01 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-18 03:01 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-18 03:01 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-18 03:01 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-18 03:01 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-18 03:01 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-18 03:01 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-18 03:01 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-18 03:01 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-18 03:01 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-18 03:01 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-17 18:05 - 2013-06-17 18:05 - 00001731 ____A C:\Users\Public\Desktop\EZmix.lnk
2013-06-17 15:02 - 2013-06-17 15:02 - 00001971 ____A C:\Users\Public\Desktop\EZkeys.lnk
2013-06-17 15:02 - 2013-06-17 15:02 - 00000000 ____D C:\Program Files (x86)\Toontrack
2013-06-17 10:02 - 2013-06-17 10:02 - 00000000 ____D C:\Program Files (x86)\Vstplugins
2013-06-13 03:02 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-13 03:02 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-13 03:02 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-13 03:02 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-13 03:02 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-13 03:02 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-13 03:02 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-13 03:02 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-13 03:02 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-13 03:02 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-13 03:02 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-13 03:02 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-13 03:02 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-13 03:02 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-13 03:02 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-13 03:02 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-13 03:02 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-13 03:02 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-13 03:02 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 11:23 - 2013-06-12 11:23 - 00000554 ____A C:\Users\Public\Desktop\ElectraX standalone.lnk
2013-06-12 09:34 - 2013-06-12 10:12 - 00000560 ____A C:\Users\Public\Desktop\ElectraX64 standalone.lnk
2013-06-12 09:12 - 2013-06-12 09:12 - 00000000 ____D C:\Users\***\AppData\Roaming\AVG
2013-06-12 09:11 - 2013-06-17 10:09 - 00000000 ____D C:\ProgramData\AVG
2013-06-12 09:11 - 2013-06-12 09:11 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-06-12 09:02 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 09:02 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 09:02 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 09:02 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 09:02 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 09:02 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 09:02 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 09:02 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 09:02 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 09:02 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 09:02 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 09:02 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 09:02 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 09:02 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 09:02 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 09:02 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 09:02 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 09:02 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 09:02 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-12 08:59 - 2013-06-12 08:59 - 00000000 ____D C:\Users\***\AppData\Roaming\EZDownloader
2013-06-11 12:49 - 2013-06-17 10:10 - 00000000 ____D C:\Program Files (x86)\EZDownloader
2013-06-11 12:49 - 2013-06-11 12:49 - 00001953 ____A C:\Users\Public\Desktop\EZDownloader.lnk
2013-06-11 12:49 - 2013-06-11 12:49 - 00000000 ____D C:\ProgramData\StarApp
2013-05-30 21:49 - 2013-05-30 21:49 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-05-30 21:49 - 2013-05-30 21:49 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-05-26 12:10 - 2013-05-26 12:10 - 00000000 ____D C:\Users\****\AppData\Local\Apple
==================== One Month Modified Files and Folders =======
2013-06-24 09:56 - 2013-06-24 09:56 - 00000041 ____A C:\Users\***\Desktop\checkup.txt
2013-06-24 09:55 - 2013-06-24 09:55 - 00890839 ____A C:\Users\***\Desktop\SecurityCheck.exe
2013-06-24 09:52 - 2013-04-02 10:33 - 00001114 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-24 09:52 - 2012-11-19 13:40 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-24 04:27 - 2012-11-18 19:12 - 01821668 ____A C:\Windows\WindowsUpdate.log
2013-06-24 02:00 - 2012-11-19 14:47 - 00000000 ____D C:\Users\***\AppData\Local\Adobe
2013-06-23 19:22 - 2013-06-23 19:22 - 02347384 ____A (ESET) C:\Users\***\Desktop\esetsmartinstaller_enu.exe
2013-06-23 19:22 - 2013-06-23 19:22 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-23 19:21 - 2013-06-23 19:20 - 00000901 ____A C:\Users\***\Desktop\JRT.txt
2013-06-23 19:18 - 2009-07-14 06:45 - 00020304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-23 19:18 - 2009-07-14 06:45 - 00020304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-23 19:15 - 2013-06-23 19:15 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\***\Desktop\JRT.exe
2013-06-23 19:15 - 2013-06-23 19:15 - 00000000 ____D C:\Windows\ERUNT
2013-06-23 19:15 - 2013-06-23 19:15 - 00000000 ____D C:\JRT
2013-06-23 19:13 - 2013-06-23 19:13 - 00008609 ____A C:\Users\***\Desktop\AdwCleaner[S2].txt
2013-06-23 19:12 - 2012-11-22 10:09 - 00000000 ___RD C:\Users\***\Dropbox
2013-06-23 19:12 - 2012-11-22 10:02 - 00000000 ____D C:\Users\***\AppData\Roaming\Dropbox
2013-06-23 19:11 - 2013-06-21 20:25 - 00001301 ____A C:\Windows\setupact.log
2013-06-23 19:11 - 2013-05-14 18:50 - 00000000 ____D C:\Users\***\AppData\Local\FreePDF_XP
2013-06-23 19:11 - 2013-04-02 10:33 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-23 19:11 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-23 19:09 - 2013-06-23 19:09 - 00008700 ____A C:\AdwCleaner[S2].txt
2013-06-23 19:09 - 2013-06-23 19:09 - 00000121 ____A C:\Windows\DeleteOnReboot.bat
2013-06-23 19:08 - 2013-06-23 19:08 - 00008810 ____A C:\AdwCleaner[R1].txt
2013-06-23 19:07 - 2013-06-23 19:07 - 00000344 ____A C:\AdwCleaner[S1].txt
2013-06-23 19:07 - 2013-06-23 19:06 - 00648201 ____A C:\Users\***\Desktop\adwcleaner.exe
2013-06-23 14:23 - 2013-04-12 11:51 - 00000000 ____D C:\Users\***\Documents\Cubase LE AI Elements Projects
2013-06-23 13:42 - 2012-11-18 20:09 - 00000000 ____D C:\ProgramData\MFAData
2013-06-23 13:38 - 2013-06-23 13:38 - 00448512 ____A (OldTimer Tools) C:\Users\***\Desktop\TFC.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-23 13:28 - 2013-06-23 13:28 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-23 13:28 - 2013-06-23 13:28 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-23 13:28 - 2012-11-26 10:05 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-23 13:28 - 2012-11-26 10:05 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-23 13:15 - 2013-06-23 13:15 - 00000000 ____D C:\Program Files\eLicenser
2013-06-23 13:15 - 2013-04-12 11:43 - 00000051 ____A C:\Windows\SysWOW64\SYNSOPOS.exe.cfg
2013-06-23 13:15 - 2013-04-12 11:43 - 00000000 ____D C:\ProgramData\eLicenser
2013-06-23 13:15 - 2013-04-12 11:43 - 00000000 ____D C:\Program Files (x86)\eLicenser
2013-06-23 13:15 - 2012-11-19 13:21 - 00019532 ____A C:\Windows\DPINST.LOG
2013-06-23 13:06 - 2013-06-23 13:06 - 00000000 ____D C:\Users\***\AppData\Local\eLicenser
2013-06-23 12:35 - 2012-11-19 15:29 - 00017612 ____A C:\Windows\PFRO.log
2013-06-23 12:30 - 2013-06-23 12:30 - 00022491 ____A C:\ComboFix.txt
2013-06-23 12:30 - 2013-06-23 12:16 - 00000000 ____D C:\Qoobox
2013-06-23 12:28 - 2013-06-23 12:16 - 00000000 ____D C:\Windows\erdnt
2013-06-23 12:27 - 2013-06-23 12:42 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20130623-124219.backup
2013-06-23 12:27 - 2009-07-14 04:34 - 00000234 ____A C:\Windows\system.ini
2013-06-23 12:18 - 2012-12-30 15:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-06-23 12:15 - 2013-06-23 12:15 - 05082201 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe
2013-06-22 23:27 - 2013-06-22 23:23 - 00023788 ____A C:\Users\***\Desktop\Addition.txt
2013-06-22 23:23 - 2013-06-22 23:23 - 00000000 ____D C:\FRST
2013-06-22 23:22 - 2013-06-22 23:22 - 01931364 ____A (Farbar) C:\Users\***\Desktop\FRST64.exe
2013-06-22 18:03 - 2013-06-22 13:09 - 00000000 ____D C:\Users\***\AppData\Roaming\vlc
2013-06-22 13:08 - 2013-06-22 13:08 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-06-22 12:56 - 2009-07-14 19:58 - 00653928 ____A C:\Windows\System32\perfh007.dat
2013-06-22 12:56 - 2009-07-14 19:58 - 00129800 ____A C:\Windows\System32\perfc007.dat
2013-06-22 12:56 - 2009-07-14 07:13 - 01498506 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-21 21:09 - 2013-06-21 21:09 - 00000000 ____D C:\Users\***\AppData\Roaming\Malwarebytes
2013-06-21 21:09 - 2013-06-21 21:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-21 21:09 - 2013-06-21 21:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-21 20:45 - 2012-11-18 20:12 - 00000000 ____D C:\Program Files (x86)\AVG
2013-06-21 15:53 - 2012-11-23 16:15 - 00088448 ____A C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-20 09:57 - 2012-11-18 19:57 - 00088448 ____A C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-20 09:57 - 2009-07-14 06:45 - 06843440 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-19 11:47 - 2012-11-19 10:43 - 00000000 ____D C:\Users\***\Documents\Native Instruments
2013-06-19 11:47 - 2012-11-19 10:43 - 00000000 ____D C:\Users\***\AppData\Local\Native Instruments
2013-06-17 18:05 - 2013-06-17 18:05 - 00001731 ____A C:\Users\Public\Desktop\EZmix.lnk
2013-06-17 15:02 - 2013-06-17 15:02 - 00001971 ____A C:\Users\Public\Desktop\EZkeys.lnk
2013-06-17 15:02 - 2013-06-17 15:02 - 00000000 ____D C:\Program Files (x86)\Toontrack
2013-06-17 10:10 - 2013-06-11 12:49 - 00000000 ____D C:\Program Files (x86)\EZDownloader
2013-06-17 10:10 - 2013-02-04 15:45 - 00000000 ____D C:\Program Files\Toontrack
2013-06-17 10:10 - 2012-11-23 16:14 - 00000000 ____D C:\users\****
2013-06-17 10:10 - 2012-11-19 15:17 - 00000000 ____D C:\ProgramData\FLEXnet
2013-06-17 10:10 - 2009-07-14 20:18 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-06-17 10:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-17 10:09 - 2013-06-12 09:11 - 00000000 ____D C:\ProgramData\AVG
2013-06-17 10:02 - 2013-06-17 10:02 - 00000000 ____D C:\Program Files (x86)\Vstplugins
2013-06-17 09:21 - 2012-11-18 19:22 - 00000000 ____D C:\users\***
2013-06-13 17:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-13 03:03 - 2012-11-20 21:05 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 15:43 - 2012-11-19 13:40 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 15:43 - 2012-11-19 13:40 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 11:23 - 2013-06-12 11:23 - 00000554 ____A C:\Users\Public\Desktop\ElectraX standalone.lnk
2013-06-12 10:12 - 2013-06-12 09:34 - 00000560 ____A C:\Users\Public\Desktop\ElectraX64 standalone.lnk
2013-06-12 10:04 - 2013-02-17 14:45 - 00000000 ____D C:\Users\***\AppData\Roaming\Amazon
2013-06-12 10:04 - 2013-02-17 14:41 - 00000000 ____D C:\Program Files (x86)\Amazon
2013-06-12 09:12 - 2013-06-12 09:12 - 00000000 ____D C:\Users\***\AppData\Roaming\AVG
2013-06-12 09:11 - 2013-06-12 09:11 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-06-12 08:59 - 2013-06-12 08:59 - 00000000 ____D C:\Users\***\AppData\Roaming\EZDownloader
2013-06-11 12:49 - 2013-06-11 12:49 - 00001953 ____A C:\Users\Public\Desktop\EZDownloader.lnk
2013-06-11 12:49 - 2013-06-11 12:49 - 00000000 ____D C:\ProgramData\StarApp
2013-06-11 09:58 - 2012-11-19 11:08 - 00000000 ____D C:\Users\***\AppData\Roaming\Adobe
2013-06-08 16:08 - 2013-06-18 03:01 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-18 03:01 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-18 03:01 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-18 03:01 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-18 03:01 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-18 03:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-18 03:01 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-18 03:01 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-18 03:01 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-18 03:01 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-18 03:01 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-18 03:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-08 11:09 - 2012-11-22 10:09 - 00001031 ____A C:\Users\***\Desktop\Dropbox.lnk
2013-06-05 13:02 - 2012-12-18 11:25 - 00000000 ____D C:\Users\***\AppData\Local\Apple Computer
2013-05-30 21:49 - 2013-05-30 21:49 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-05-30 21:49 - 2013-05-30 21:49 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-05-26 12:10 - 2013-05-26 12:10 - 00000000 ____D C:\Users\****\AppData\Local\Apple
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-24 03:04
==================== End Of Log ============================ --- --- ---
Keine Probleme mehr! :) Vielen Dank schon mal für die Hilfe. |