nobody123 | 23.08.2013 06:35 | Code:
# AdwCleaner v3.000 - Report created 23/08/2013 at 07:08:28
# Updated 20/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Tim - Tim-PC
# Running from : C:\Users\Tim\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Users\Tim\AppData\Roaming\Babylon
File Deleted : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\bkp2s34p.default\searchplugins\Babylon.xml
File Deleted : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\bkp2s34p.default\user.js
File Deleted : C:\Windows\System32\Tasks\Dealply
File Deleted : C:\Windows\System32\Tasks\DealPlyUpdate
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\SOFTWARE\a6dd88bc6aea43
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\BabSolution
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\FoxyDeal
Key Deleted : HKLM\Software\Delta
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\bkp2s34p.default\prefs.js ]
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "de");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "a03a8f6200000000000074f06d1a81c7");
Line Deleted : user_pref("extensions.delta.instlDay", "15928");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.22.0");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.22.022:06:46");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.22.0");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119523&tt=070813_wt4&tsp=4971");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
-\\ Google Chrome v29.0.1547.57
[ File : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : homepage
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [4457 octets] - [23/08/2013 07:07:03]
AdwCleaner[S0].txt - [3658 octets] - [23/08/2013 07:08:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3718 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.4 (08.22.2013:1)
OS: Windows 7 Home Premium x86
Ran by Tim on 23.08.2013 at 7:18:47,16
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dsiteproducts
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\Users\Tim\AppData\Roaming\mozilla\firefox\profiles\bkp2s34p.default\invalidprefs.js
Emptied folder: C:\Users\Tim\AppData\Roaming\mozilla\firefox\profiles\bkp2s34p.default\minidumps [10 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.08.2013 at 7:20:23,23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-08-2013 02
Ran by Tim (administrator) on 23-08-2013 07:26:26
Running from C:\Users\Tim\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Realtek) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtWlan.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Electronic Arts) C:\Program Files\Origin\Origin.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Farbar) C:\Users\Tim\Downloads\FRST(2).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-04-06] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-06] (Realtek Semiconductor)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [947152 2013-01-27] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKCU\...\Run: [EADM] - C:\Program Files\Origin\Origin.exe [3497552 2013-05-19] (Electronic Arts)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {1B349F1D-EAC2-4825-A0D1-AB44B87F56AB} URL = hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKCU - {FEC19396-EE58-4F28-B179-8060C46869A8} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll No File
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} hxxp://cdn.scan.onecare.live.com/resource/download/scanner/de-de/wlscctrl2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{914F0FAE-A51C-4BBC-A0E5-9445B0F62A3F}: [NameServer]192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\bkp2s34p.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Shuu2lqk7OSV - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\bkp2s34p.default\Extensions\Shuu2lqk7OSV@NTO066xN6gxohjuS.com.xpi
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========================== Services (Whitelisted) =================
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [20456 2013-01-27] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295232 2013-01-27] (Microsoft Corporation)
R2 Realtek11nSU; C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek)
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe" [x]
==================== Drivers (Whitelisted) ====================
R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [11832 2009-07-07] (Advanced Micro Devices Inc.)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Tim\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-23 07:20 - 2013-08-23 07:20 - 00001170 _____ C:\Users\Tim\Desktop\JRT.txt
2013-08-23 07:17 - 2013-08-23 07:17 - 01021434 _____ (Thisisu) C:\Users\Tim\Downloads\JRT(1).exe
2013-08-23 07:06 - 2013-08-23 07:08 - 00000000 ____D C:\AdwCleaner
2013-08-23 07:04 - 2013-08-23 07:06 - 00000000 ____D C:\Users\Tim\Desktop\Fotos
2013-08-23 07:04 - 2013-08-23 07:05 - 00975858 _____ C:\Users\Tim\Desktop\adwcleaner.exe
2013-08-19 08:58 - 2013-08-19 08:58 - 00030234 _____ C:\Users\Tim\Desktop\user_1.jpeg
2013-08-19 08:58 - 2013-08-19 08:58 - 00029067 _____ C:\Users\Tim\Desktop\0.jpeg
2013-08-19 08:39 - 2013-08-19 08:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-19 08:01 - 2013-08-19 08:01 - 00017989 _____ C:\ComboFix.txt
2013-08-18 15:02 - 2013-08-18 15:04 - 05105231 ____R (Swearware) C:\Users\Tim\Desktop\ComboFix.exe
2013-08-16 09:43 - 2013-08-16 09:43 - 61079552 _____ C:\Users\Tim\Desktop\iTunes64.msi
2013-08-16 09:43 - 2013-08-16 09:43 - 00077136 _____ (Apple Inc.) C:\Users\Tim\Desktop\SetupAdmin.exe
2013-08-16 08:37 - 2013-08-16 08:37 - 21538816 _____ C:\Users\Tim\Desktop\AppleApplicationSupport.msi
2013-08-14 10:06 - 2013-08-14 10:08 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 10:02 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 10:02 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 10:02 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 10:02 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 10:02 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 10:02 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 10:02 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 10:02 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 10:02 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 08:45 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 08:45 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 08:45 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 08:45 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 08:45 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 08:44 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-14 08:44 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 08:44 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 08:44 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 08:43 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 08:38 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 08:38 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-11 22:54 - 2013-08-11 22:55 - 00000000 ____D C:\Users\Tim\Desktop\Bilder August
2013-08-11 22:01 - 2013-08-11 22:02 - 01066136 _____ C:\Users\Tim\Downloads\setup.exe
2013-08-03 00:30 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-03 00:30 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-03 00:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-03 00:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-03 00:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-03 00:30 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-03 00:30 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-03 00:30 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-03 00:20 - 2013-08-19 08:01 - 00000000 ____D C:\Qoobox
2013-08-03 00:19 - 2013-08-19 07:55 - 00000000 ____D C:\Windows\erdnt
2013-08-03 00:14 - 2013-08-13 21:52 - 05103833 _____ (Swearware) C:\Users\Tim\Downloads\ComboFix.exe
2013-07-31 08:14 - 2013-07-31 08:15 - 00013610 _____ C:\Users\Tim\Downloads\Addition.txt
2013-07-31 08:12 - 2013-07-31 08:12 - 00000000 ____D C:\FRST
2013-07-31 08:09 - 2013-07-31 08:10 - 01222064 _____ (Farbar) C:\Users\Tim\Downloads\FRST(1).exe
2013-07-31 08:08 - 2013-07-31 08:09 - 01222064 _____ (Farbar) C:\Users\Tim\Downloads\FRST.exe
2013-07-30 19:39 - 2013-07-30 19:40 - 02347384 _____ (ESET) C:\Users\Tim\Downloads\esetsmartinstaller_deu.exe
2013-07-28 18:47 - 2013-07-28 18:47 - 00000000 ____D C:\Windows\ERUNT
2013-07-28 18:46 - 2013-07-28 18:47 - 00561198 _____ (Oleg N. Scherbakov) C:\Users\Tim\Downloads\JRT.exe
2013-07-27 10:59 - 2013-07-27 11:00 - 00891062 _____ C:\Users\Tim\Downloads\SecurityCheck.exe
2013-07-27 08:39 - 2013-07-27 08:39 - 02347384 _____ (ESET) C:\Users\Tim\Downloads\esetsmartinstaller_enu.exe
2013-07-26 21:53 - 2013-07-26 21:53 - 00001075 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-26 21:53 - 2013-07-26 21:53 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Malwarebytes
2013-07-26 21:53 - 2013-07-26 21:53 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-26 21:53 - 2013-07-26 21:53 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-26 21:53 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-07-26 21:49 - 2013-07-26 21:52 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tim\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-26 21:38 - 2013-07-26 21:38 - 00700783 ____R (Swearware) C:\Users\Tim\Downloads\dds+.exe
2013-07-26 21:22 - 2013-07-26 21:23 - 00000171 _____ C:\Windows\DeleteOnReboot.bat
2013-07-26 21:21 - 2013-07-26 21:23 - 00001190 _____ C:\AdwCleaner[S2].txt
2013-07-26 21:21 - 2013-07-26 21:22 - 00002044 _____ C:\AdwCleaner[S1].txt
2013-07-26 21:02 - 2013-07-26 21:04 - 00666633 _____ C:\Users\Tim\Downloads\adwcleaner06.exe
2013-07-26 20:01 - 2013-07-26 20:01 - 00000005 _____ C:\Users\Tim\AppData\Roaming\WBPU-TTL.DAT
2013-07-26 12:00 - 2013-07-26 12:00 - 00793536 _____ C:\Users\Tim\Downloads\ZipOpenerSetup.exe
2013-07-25 20:37 - 2013-07-25 20:45 - 17165244 _____ C:\Users\Tim\Downloads\FSK18_mi116(1).AVI
==================== One Month Modified Files and Folders =======
2013-08-23 07:25 - 2013-08-23 07:25 - 01070315 _____ (Farbar) C:\Users\Tim\Downloads\FRST(2).exe
2013-08-23 07:20 - 2013-08-23 07:20 - 00001170 _____ C:\Users\Tim\Desktop\JRT.txt
2013-08-23 07:17 - 2013-08-23 07:17 - 01021434 _____ (Thisisu) C:\Users\Tim\Downloads\JRT(1).exe
2013-08-23 07:17 - 2009-07-14 06:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-23 07:17 - 2009-07-14 06:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-23 07:11 - 2013-05-19 17:00 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Skype
2013-08-23 07:10 - 2013-02-03 11:50 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-23 07:10 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-23 07:10 - 2009-07-14 06:39 - 00117967 _____ C:\Windows\setupact.log
2013-08-23 07:08 - 2013-08-23 07:06 - 00000000 ____D C:\AdwCleaner
2013-08-23 07:08 - 2010-08-05 18:44 - 01167319 _____ C:\Windows\WindowsUpdate.log
2013-08-23 07:06 - 2013-08-23 07:04 - 00000000 ____D C:\Users\Tim\Desktop\Fotos
2013-08-23 07:05 - 2013-08-23 07:04 - 00975858 _____ C:\Users\Tim\Desktop\adwcleaner.exe
2013-08-23 06:56 - 2013-02-03 11:50 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-23 06:39 - 2013-01-01 21:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-23 04:03 - 2013-02-03 11:51 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-22 23:45 - 2013-06-24 04:29 - 00000000 ____D C:\Users\Tim\Desktop\Kalifornien 2013
2013-08-22 23:35 - 2013-02-03 16:12 - 00000000 ____D C:\Users\Tim\Desktop\ebay
2013-08-22 22:50 - 2013-01-01 21:14 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-08-22 22:50 - 2013-01-01 21:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-08-22 21:56 - 2013-01-18 11:58 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-19 08:58 - 2013-08-19 08:58 - 00030234 _____ C:\Users\Tim\Desktop\user_1.jpeg
2013-08-19 08:58 - 2013-08-19 08:58 - 00029067 _____ C:\Users\Tim\Desktop\0.jpeg
2013-08-19 08:40 - 2013-08-19 08:39 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-19 08:01 - 2013-08-19 08:01 - 00017989 _____ C:\ComboFix.txt
2013-08-19 08:01 - 2013-08-03 00:20 - 00000000 ____D C:\Qoobox
2013-08-19 07:57 - 2010-01-26 18:04 - 00119792 _____ C:\Windows\PFRO.log
2013-08-19 07:57 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-08-19 07:56 - 2009-07-14 04:03 - 53477376 _____ C:\Windows\system32\config\software.bak
2013-08-19 07:56 - 2009-07-14 04:03 - 20185088 _____ C:\Windows\system32\config\system.bak
2013-08-19 07:56 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-08-19 07:56 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-08-19 07:56 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\default.bak
2013-08-19 07:55 - 2013-08-03 00:19 - 00000000 ____D C:\Windows\erdnt
2013-08-18 15:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-08-18 15:04 - 2013-08-18 15:02 - 05105231 ____R (Swearware) C:\Users\Tim\Desktop\ComboFix.exe
2013-08-16 19:47 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-16 19:26 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-16 09:43 - 2013-08-16 09:43 - 61079552 _____ C:\Users\Tim\Desktop\iTunes64.msi
2013-08-16 09:43 - 2013-08-16 09:43 - 00077136 _____ (Apple Inc.) C:\Users\Tim\Desktop\SetupAdmin.exe
2013-08-16 08:37 - 2013-08-16 08:37 - 21538816 _____ C:\Users\Tim\Desktop\AppleApplicationSupport.msi
2013-08-14 10:08 - 2013-08-14 10:06 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 10:06 - 2010-01-28 15:03 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-14 10:06 - 2010-01-26 16:42 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 10:04 - 2010-01-26 16:21 - 01633792 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-13 21:52 - 2013-08-03 00:14 - 05103833 _____ (Swearware) C:\Users\Tim\Downloads\ComboFix.exe
2013-08-11 22:55 - 2013-08-11 22:54 - 00000000 ____D C:\Users\Tim\Desktop\Bilder August
2013-08-11 22:02 - 2013-08-11 22:01 - 01066136 _____ C:\Users\Tim\Downloads\setup.exe
2013-08-11 01:11 - 2013-01-03 20:27 - 00000000 ____D C:\ProgramData\Comodo
2013-08-11 01:11 - 2013-01-03 20:26 - 00000000 ____D C:\Program Files\Comodo
2013-08-04 22:01 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-08-03 07:00 - 2009-07-14 06:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-03 00:43 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2013-08-03 00:43 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-07-31 08:15 - 2013-07-31 08:14 - 00013610 _____ C:\Users\Tim\Downloads\Addition.txt
2013-07-31 08:12 - 2013-07-31 08:12 - 00000000 ____D C:\FRST
2013-07-31 08:10 - 2013-07-31 08:09 - 01222064 _____ (Farbar) C:\Users\Tim\Downloads\FRST(1).exe
2013-07-31 08:09 - 2013-07-31 08:08 - 01222064 _____ (Farbar) C:\Users\Tim\Downloads\FRST.exe
2013-07-30 19:40 - 2013-07-30 19:39 - 02347384 _____ (ESET) C:\Users\Tim\Downloads\esetsmartinstaller_deu.exe
2013-07-28 18:47 - 2013-07-28 18:47 - 00000000 ____D C:\Windows\ERUNT
2013-07-28 18:47 - 2013-07-28 18:46 - 00561198 _____ (Oleg N. Scherbakov) C:\Users\Tim\Downloads\JRT.exe
2013-07-27 11:00 - 2013-07-27 10:59 - 00891062 _____ C:\Users\Tim\Downloads\SecurityCheck.exe
2013-07-27 08:39 - 2013-07-27 08:39 - 02347384 _____ (ESET) C:\Users\Tim\Downloads\esetsmartinstaller_enu.exe
2013-07-27 08:37 - 2013-01-03 20:30 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
2013-07-27 08:17 - 2009-07-14 10:57 - 00000000 ____D C:\Windows\ShellNew
2013-07-27 08:13 - 2012-11-20 22:52 - 00000000 ____D C:\Users\Tim\Desktop\Neuer Ordner
2013-07-26 21:53 - 2013-07-26 21:53 - 00001075 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-26 21:53 - 2013-07-26 21:53 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Malwarebytes
2013-07-26 21:53 - 2013-07-26 21:53 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-26 21:53 - 2013-07-26 21:53 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-26 21:52 - 2013-07-26 21:49 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tim\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-26 21:38 - 2013-07-26 21:38 - 00700783 ____R (Swearware) C:\Users\Tim\Downloads\dds+.exe
2013-07-26 21:23 - 2013-07-26 21:22 - 00000171 _____ C:\Windows\DeleteOnReboot.bat
2013-07-26 21:23 - 2013-07-26 21:21 - 00001190 _____ C:\AdwCleaner[S2].txt
2013-07-26 21:22 - 2013-07-26 21:21 - 00002044 _____ C:\AdwCleaner[S1].txt
2013-07-26 21:04 - 2013-07-26 21:02 - 00666633 _____ C:\Users\Tim\Downloads\adwcleaner06.exe
2013-07-26 20:01 - 2013-07-26 20:01 - 00000005 _____ C:\Users\Tim\AppData\Roaming\WBPU-TTL.DAT
2013-07-26 12:00 - 2013-07-26 12:00 - 00793536 _____ C:\Users\Tim\Downloads\ZipOpenerSetup.exe
2013-07-26 05:13 - 2013-08-14 10:02 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 05:13 - 2013-08-14 10:02 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 05:13 - 2013-08-14 10:02 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 05:12 - 2013-08-14 10:02 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 05:12 - 2013-08-14 10:02 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 05:11 - 2013-08-14 10:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 05:11 - 2013-08-14 10:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-26 04:49 - 2013-08-14 10:02 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-26 03:59 - 2013-08-14 10:02 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-25 20:45 - 2013-07-25 20:37 - 17165244 _____ C:\Users\Tim\Downloads\FSK18_mi116(1).AVI
2013-07-25 10:57 - 2013-08-14 08:43 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-23 00:55
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Erledigt - was muss ich als nächstes machen? :pfeiff:
Danke vielmals nochmal! |