Lukas1234 | 30.07.2013 12:29 | So, hier alle 5 logs Code:
ComboFix 13-02-21.02 - Mietke 21.02.2013 18:13:14.1.4 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.4094.2026 [GMT 1:00]
ausgeführt von:: c:\users\Mietke\Desktop\ComboFix.exe
AV: McAfee Anti-Virus und Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus und Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\IMinent Toolbar\tbHElper.dll
c:\program files (x86)\kikin
c:\program files (x86)\kikin\default_settings.xml
c:\program files (x86)\kikin\file_list.txt
c:\program files (x86)\kikin\ie_kikin.dll
c:\program files (x86)\kikin\ie_kikin.dll.old
c:\program files (x86)\kikin\kikin.ico
c:\program files (x86)\kikin\kikin_updater_2.0.0.11.exe
c:\program files (x86)\kikin\KikinBroker.exe
c:\program files (x86)\kikin\KikinCrashReporter.exe
c:\program files (x86)\kikin\uninst.exe
c:\programdata\0d5af0ae-d4e7-4b12-ba04-658f5165b97e.ico
c:\users\Mietke\AppData\Local\assembly\tmp
c:\users\Mietke\AppData\Roaming\AcroIEHelpe.txt
c:\users\Mietke\AppData\Roaming\Amnaro
c:\users\Mietke\AppData\Roaming\Amnaro\ketuf.cat
c:\users\Mietke\AppData\Roaming\Cayt
c:\users\Mietke\AppData\Roaming\Cayt\daluo.efl
c:\users\Mietke\AppData\Roaming\Cigo
c:\users\Mietke\AppData\Roaming\Cigo\idur.buq
c:\users\Mietke\AppData\Roaming\Ezqy
c:\users\Mietke\AppData\Roaming\Ezqy\hiluo.sou
c:\users\Mietke\AppData\Roaming\Help\coredb\storage
c:\users\Mietke\AppData\Roaming\kikin
c:\users\Mietke\AppData\Roaming\kikin\ff_kkes.xml
c:\users\Mietke\AppData\Roaming\kikin\ie_configuration.xml
c:\users\Mietke\AppData\Roaming\kikin\ie_kkes.xml
c:\users\Mietke\AppData\Roaming\kikin\ie_settings.xml
c:\users\Mietke\AppData\Roaming\Nedem
c:\users\Mietke\AppData\Roaming\Nedem\geil.aty
c:\users\Mietke\AppData\Roaming\Oqel
c:\users\Mietke\AppData\Roaming\Oqel\udesu.nyv
c:\users\Mietke\AppData\Roaming\Otovu
c:\users\Mietke\AppData\Roaming\Otovu\axre.zuy
c:\users\Mietke\AppData\Roaming\srvblck2.tmp
c:\users\Mietke\AppData\Roaming\Tyseh
c:\users\Mietke\AppData\Roaming\Tyseh\kyer.xig
c:\users\Mietke\AppData\Roaming\Usicc
c:\users\Mietke\AppData\Roaming\Usicc\igtey.yta
c:\users\Mietke\AppData\Roaming\Utbeiz
c:\users\Mietke\AppData\Roaming\Utbeiz\icla.lio
c:\users\Mietke\AppData\Roaming\Vihea
c:\users\Mietke\AppData\Roaming\Vihea\alse.ryc
c:\windows\IsUn0407.exe
c:\windows\SysWow64\URTTemp
c:\windows\SysWow64\URTTemp\regtlib.exe
D:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-01-21 bis 2013-02-21 ))))))))))))))))))))))))))))))
.
.
2013-02-21 17:25 . 2013-02-21 17:25 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-02-21 17:25 . 2013-02-21 17:25 -------- d-----w- c:\users\UpdatusUser.Mietke-PC\AppData\Local\temp
2013-02-21 17:25 . 2013-02-21 17:25 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-21 16:50 . 2013-02-21 17:11 -------- d-----w- C:\32788R22FWJFW
2013-02-21 16:10 . 2013-02-21 16:10 -------- d-----w- C:\_OTL
2013-02-19 11:50 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8FBC0AD9-5BA6-4E17-BDC8-5D16BE44A60E}\mpengine.dll
2013-02-13 19:48 . 2013-01-02 11:08 1027584 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-02-13 19:48 . 2013-01-02 07:37 759296 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll
2013-02-13 19:48 . 2013-01-04 11:31 1423720 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-13 19:48 . 2013-01-04 01:59 2773504 ----a-w- c:\windows\system32\win32k.sys
2013-02-13 19:48 . 2013-01-05 13:44 9331200 ----a-w- c:\windows\system32\mshtml.dll
2013-02-13 19:48 . 2013-01-05 13:42 2356736 ----a-w- c:\windows\system32\iertutil.dll
2013-02-13 19:48 . 2013-01-05 13:42 12509184 ----a-w- c:\windows\system32\ieframe.dll
2013-02-02 18:23 . 2013-02-02 18:23 -------- d-----w- c:\users\Mietke\AppData\Local\Red 5 Studios
2013-02-02 16:41 . 2013-02-02 16:41 -------- d-----w- c:\program files (x86)\Xiph.Org
2013-01-30 13:00 . 2013-01-30 13:00 -------- d-----w- c:\program files\iPod
2013-01-30 13:00 . 2013-01-30 13:01 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-01-30 13:00 . 2013-01-30 13:01 -------- d-----w- c:\program files\iTunes
2013-01-30 13:00 . 2013-01-30 13:01 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-20 17:27 . 2010-05-23 10:03 270240 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-02-20 17:27 . 2009-12-06 14:03 270240 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-02-13 20:52 . 2006-11-02 12:35 70004024 ----a-w- c:\windows\system32\mrt.exe
2013-02-09 19:29 . 2012-05-30 10:09 697712 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-02-09 19:29 . 2012-05-30 10:09 74096 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-17 00:28 . 2011-04-22 19:44 273840 ------w- c:\windows\system32\MpSigStub.exe
2012-12-26 19:48 . 2010-05-23 10:03 270240 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-16 13:31 . 2012-12-22 02:00 48128 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 13:12 . 2012-12-22 02:00 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-16 11:08 . 2012-12-22 02:00 368128 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 10:50 . 2012-12-22 02:00 293376 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-14 15:49 . 2013-01-09 18:54 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
2010-07-02 07:54 2607872 ----a-w- c:\program files (x86)\IMinent Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files (x86)\IMinent Toolbar\tbcore3.dll" [2010-07-02 2607872]
.
[HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\Mietke\AppData\Local\Akamai\netsession_win.exe" [2012-10-09 4441920]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-09 39408]
"FreeCT"="c:\program files (x86)\FreeCountdownTimer\FreeCountdownTimer.exe" [2012-04-22 2053456]
"TBPanel"="c:\program files (x86)\Vtune\TBPanel.exe" [2011-08-02 2248704]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2011-02-23 371200]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Z1"="c:\users\Mietke\Desktop\mbar\mbar.exe" [2013-02-05 1363528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2008-01-21 27648]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2009-01-19 334344]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 71009799
*Deregistered* - 71009799
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-02 16:26 1607120 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-02-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-30 19:29]
.
2013-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-03 16:54]
.
2013-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-03 16:54]
.
2013-02-20 c:\windows\Tasks\User_Feed_Synchronization-{38A14B28-3686-4261-A0BB-BA949EC18DBC}.job
- c:\windows\system32\msfeedssync.exe [2013-02-13 08:45]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RAVCpl64.exe" [2008-07-16 6440480]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-20 178712]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.iminent.com/?appId=86A427A2-1952-45A7-86C7-EAF17CD51250
mLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files (x86)\kikin\ie_kikin.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.web.de
FF - prefs.js: keyword.URL - hxxp://mystart.incredibar.com/mb155/?loc=IB_DS&a=6OyGIMUR6v&&i=26&search=
FF - ExtSQL: !HIDDEN! 2009-06-24 11:10; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2009-11-28 22:36; {800b5000-a755-47e1-992b-48a1c1357f07}; c:\program files (x86)\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - ExtSQL: !HIDDEN! 2011-01-04 12:03; {ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}; c:\users\Mietke\AppData\Roaming\5006
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyGIMUR6v&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 442cdc36000000000000001ee5e1a5d7
FF - user.js: extensions.incredibar_i.instlDay - 15523
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1415:24
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6OyGIMUR6v
FF - user.js: extensions.incredibar_i.upn2n - 92261686095990951
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10657
FF - user.js: extensions.incredibar_i.ppd -
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files (x86)\kikin\ie_kikin.dll
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Free Audio CD Burner_is1 - c:\program files (x86)\DVDVideoSoft\Free Audio CD Burner\unins000.exe
AddRemove-Free YouTube to iPod Converter_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\Uninstall.exe
AddRemove-Free YouTube to MP3 Converter_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\Uninstall.exe
AddRemove-MobMap_is1 - c:\program files (x86)\MobMapUpdater\unins000.exe
AddRemove-Neffy - c:\program files (x86)\Neffy\uninst.exe
AddRemove-Pflanzen gegen Zombies - c:\program files (x86)\PopCap Games\Pflanzen gegen Zombies\PopUninstall.exe
AddRemove-The Secret World_is1 - d:\program files (x86)\The Secret World\The Secret World\unins000.exe
AddRemove-{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF001} - d:\program files (x86)\Global Agenda\HiRezGamesDiagAndSupport.exe
AddRemove-{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC} - d:\program files (x86)\Global Agenda\HiRezGamesDiagAndSupport.exe
AddRemove-{BC3051A7-1021-4B57-A3DA-AAC24566FAE7}_is1 - c:\users\Mietke\Documents\The War Z\unins000.exe
AddRemove-{E4A71A41-BCC8-480a-9E69-0DA29CBA7ECA} - c:\program files (x86)\kikin\uninst.exe
AddRemove-NCsoft-AionEU - c:\program files (x86)\NCSoft\Launcher\NCLauncher.exe
AddRemove-NCsoft-GuildWars - c:\program files (x86)\NCSoft\Launcher\NCLauncher.exe
AddRemove-Planetside 2 - d:\program files (x86)\Planetside 2\Uninstaller.exe
AddRemove-soe-PlanetSide 2 PSG - d:\program files (x86)\Planetside 2\Uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_ce5ba24.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\X6va002]
"ImagePath"="\??\c:\users\Mietke\AppData\Local\Temp\002A95A.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\X6va005]
"ImagePath"="\??\c:\users\Mietke\AppData\Local\Temp\005FA6B.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1126053746-1709790084-1523483457-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:38,0c,9e,88,c5,7a,26,9f,85,ae,8b,25,4d,80,92,06,c2,9a,f6,ae,41,2f,51,
cd,18,36,f9,a4,81,c6,09,73,dd,50,9c,ec,9a,e3,07,4f,cb,82,5d,5a,f7,ef,c2,d1,\
"??"=hex:69,6f,5c,46,6a,89,f9,ee,2d,48,e0,10,87,42,1e,12
.
[HKEY_USERS\S-1-5-21-1126053746-1709790084-1523483457-1000\Software\SecuROM\License information*]
"datasecu"=hex:69,14,a1,3b,98,0f,ee,be,42,4e,4c,4a,7a,7e,e3,3a,ca,53,f1,ce,ea,
c7,0b,4a,6f,90,4f,35,d4,b1,1f,dc,7a,2a,06,b4,ed,88,4f,2d,4f,96,06,37,2e,be,\
"rkeysecu"=hex:29,ca,2a,2e,ea,ce,8d,fe,d0,5a,6b,1e,81,4f,b2,13
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2013-02-21 18:28:36
ComboFix-quarantined-files.txt 2013-02-21 17:28
.
Vor Suchlauf: 28 Verzeichnis(se), 20.304.850.944 Bytes frei
Nach Suchlauf: 34 Verzeichnis(se), 22.944.645.120 Bytes frei
.
- - End Of File - - CFC99D2FE85849AB6CA602529834553A Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.07.29.01
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 8.0.6001.19443
Mietke :: MIETKE-PC [Administrator]
30.07.2013 11:31:06
mbam-log-2013-07-30 (11-31-06).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|H:\|I:\|J:\|K:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 523671
Laufzeit: 1 Stunde(n), 34 Minute(n), 50 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) Code:
# AdwCleaner v2.306 - Datei am 30/07/2013 um 13:10:26 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Benutzer : Mietke - MIETKE-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Mietke\Downloads\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\searchplugins\softonic.xml
Gelöscht mit Neustart : C:\Program Files (x86)\Softonic
Gelöscht mit Neustart : C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Gelöscht mit Neustart : C:\Users\Mietke\AppData\Roaming\Softonic
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SoftonicApp.appCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SoftonicApp.appCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{0C58B7D1-D415-492B-A149-E976156BD3B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{5018CFD2-804D-4C99-9F81-25EAEA2769DE}]
***** [Internet Browser] *****
-\\ Internet Explorer v8.0.6001.19443
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.softonic.com/MOY00009/tb_v1?SearchSource=10&cc=&mi=442cdc36000000000000001ee5e1a5d7 --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.softonic.com/MOY00009/tb_v1/?SearchSource=15&cc=&mi=442cdc36000000000000001ee5e1a5d7 --> hxxp://www.google.com
-\\ Mozilla Firefox v22.0 (de)
Datei : C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\prefs.js
C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\user.js ... Gelöscht !
Gelöscht : user_pref("extensions.Softonic.admin", false);
Gelöscht : user_pref("extensions.Softonic.aflt", "SD");
Gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
Gelöscht : user_pref("extensions.Softonic.autoRvrt", "false");
Gelöscht : user_pref("extensions.Softonic.dfltLng", "es");
Gelöscht : user_pref("extensions.Softonic.dfltSrch", true);
Gelöscht : user_pref("extensions.Softonic.dnsErr", true);
Gelöscht : user_pref("extensions.Softonic.excTlbr", false);
Gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false);
Gelöscht : user_pref("extensions.Softonic.hmpg", true);
Gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00009/tb_v1?SearchSource=13&[...]
Gelöscht : user_pref("extensions.Softonic.hpOld0", "www.web.de");
Gelöscht : user_pref("extensions.Softonic.id", "442cdc36000000000000001ee5e1a5d7");
Gelöscht : user_pref("extensions.Softonic.instlDay", "15896");
Gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00009");
Gelöscht : user_pref("extensions.Softonic.kw_url", "hxxp://search.softonic.com/MOY00009/tb_v1?SearchSource=2&cc[...]
Gelöscht : user_pref("extensions.Softonic.newTab", true);
Gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00009/tb_v1/?SearchSource=[...]
Gelöscht : user_pref("extensions.Softonic.prdct", "Softonic");
Gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic");
Gelöscht : user_pref("extensions.Softonic.rvrt", "false");
Gelöscht : user_pref("extensions.Softonic.smplGrp", "none");
Gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Gelöscht : user_pref("extensions.Softonic.tlbrId", "BASEirobinhoodActive");
Gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00009/tb_v1?SearchSource[...]
Gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.19.3");
Gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.19.318:51:52");
Gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.19.3");
-\\ Google Chrome v28.0.1500.72
Datei : C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [34875 octets] - [25/02/2013 19:33:36]
AdwCleaner[S2].txt - [1220 octets] - [25/02/2013 20:32:11]
AdwCleaner[S3].txt - [347 octets] - [30/07/2013 13:09:33]
AdwCleaner[S4].txt - [9237 octets] - [30/07/2013 13:10:26]
########## EOF - C:\AdwCleaner[S4].txt - [9297 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.8 (07.29.2013:2)
OS: Windows (TM) Vista Home Premium x64
Ran by Mietke on 30.07.2013 at 13:17:05,57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2624E793-ECBA-45DD-ACFB-19A7C3C58F79}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\big fish games"
Successfully deleted: [Folder] "C:\Program Files (x86)\advanced pc tweaker"
Successfully deleted: [Folder] "C:\Program Files (x86)\softonic"
~~~ FireFox
Emptied folder: C:\Users\Mietke\AppData\Roaming\mozilla\firefox\profiles\kz08tl84.default\minidumps [68 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.07.2013 at 13:24:46,31
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013
Ran by Mietke (administrator) on 30-07-2013 13:25:41
Running from C:\Users\Mietke\Downloads
Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hi-Rez Studios) D:\Program Files (x86)\Global Agenda\HiPatchService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
() C:\Program Files (x86)\Vtune\TBPANEL.exe
(fabi.me) C:\Users\Mietke\Desktop\SpeedAutoClicker.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RAVCpl64.exe [6440480 2008-07-16] (Realtek Semiconductor)
HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-04-20] (Intel Corporation)
HKCU\...\Run: [TBPanel] - C:\Program Files (x86)\Vtune\TBPanel.exe [2248704 2011-08-02] ()
HKCU\...\Run: [Speed AutoClicker] - C:\Users\Mietke\Desktop\SpeedAutoClicker.exe [174080 2012-05-15] (fabi.me)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
HKU\UpdatusUser.Mietke-PC\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SparweltGutscheinAlarm.Sparwelt_Gutschein_Tool - {10945114-b19f-4614-8450-b25e444a1020} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: HKLM-x32 {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.31.0.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default
FF NewTab: user_pref("browser.newtab.url", "");
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: www.web.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\searchplugins\searchplugins-backup
FF Extension: No Name - C:\Users\Mietke\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
FF Extension: No Name - C:\Users\Mietke\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Battlefield Heroes Updater - C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\Extensions\battlefieldheroespatcher@ea.com
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: groovesharkUnlocker - C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\Extensions\groovesharkUnlocker@overlord1337.xpi
FF Extension: No Name - C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\Profiles\kz08tl84.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: No Name - C:\Users\Mietke\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM-x32\...\Firefox\Extensions: [{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}] C:\Users\Mietke\AppData\Roaming\5006
FF Extension: Java String Helper - C:\Users\Mietke\AppData\Roaming\5006
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKCU\...\Firefox\Extensions: [{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}] C:\Users\Mietke\AppData\Roaming\5006
FF Extension: Java String Helper - C:\Users\Mietke\AppData\Roaming\5006
Chrome:
=======
CHR Extension: (Docs) - C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Guild Wars 2 Divinity's Garden Theme) - C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogkbacblabnljjogoaaadkcpjnamonfc\1_0
CHR Extension: (Gmail) - C:\Users\Mietke\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-05-09] (AVAST Software)
S2 gupdate1ca743942b03ae0; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-12-03] (Google Inc.)
R2 HiPatchService; D:\Program Files (x86)\Global Agenda\HiPatchService.exe [8704 2012-06-24] (Hi-Rez Studios)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [3453712 2009-12-16] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-06-07] ()
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
==================== Drivers (Whitelisted) ====================
S3 1394hub; C:\Windows\System32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
S3 1394hub; C:\Windows\SysWow64\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2011-02-23] (ALWIL Software)
R0 aswNdis2; C:\Windows\System32\Drivers\aswNdis2.sys [270824 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [59144 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] ()
S3 Cardex; C:\Windows\SysWOW64\drivers\TBPANELX64.SYS [15648 2007-03-16] (Windows (R) Server 2003 DDK provider)
S3 Cardex; C:\Windows\SysWOW64\drivers\TBPANELX64.SYS [15648 2007-03-16] (Windows (R) Server 2003 DDK provider)
R3 L1E; C:\Windows\System32\DRIVERS\L1E60x64.sys [56320 2008-07-22] (Atheros Communications, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [40904 2009-09-16] (McAfee, Inc.)
S3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [49480 2009-09-16] (McAfee, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-02] ()
S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2004-12-30] (INCA Internet Co., Ltd.)
S1 Beep; No ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 dump_wmimmc; \??\C:\Program Files (x86)\Dragonica\Release\GameGuard\dump_wmimmc.sys [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
S3 TBPanel; No ImagePath
S3 TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [x]
S3 X6va002; \??\C:\Users\Mietke\AppData\Local\Temp\002A95A.tmp [x]
S3 X6va005; \??\C:\Users\Mietke\AppData\Local\Temp\005FA6B.tmp [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-30 13:16 - 2013-07-30 13:16 - 00009330 _____ C:\Users\Mietke\Desktop\AdwCleaner[S4].txt
2013-07-30 13:10 - 2013-07-30 13:10 - 00009330 _____ C:\AdwCleaner[S4].txt
2013-07-30 13:10 - 2013-07-30 13:10 - 00000276 _____ C:\Windows\DeleteOnReboot.bat
2013-07-30 13:09 - 2013-07-30 13:09 - 00000347 _____ C:\AdwCleaner[S3].txt
2013-07-30 13:08 - 2013-07-30 13:08 - 00022799 _____ C:\Users\Mietke\Desktop\ComboFix2.txt
2013-07-30 11:30 - 2013-07-30 11:30 - 00562042 _____ (Oleg N. Scherbakov) C:\Users\Mietke\Downloads\JRT.exe
2013-07-30 11:28 - 2013-07-30 11:28 - 00666633 _____ C:\Users\Mietke\Downloads\adwcleaner.exe
2013-07-29 17:05 - 2013-07-29 17:05 - 00013207 _____ C:\ComboFix.txt
2013-07-29 16:47 - 2013-07-29 16:47 - 05095176 ____R (Swearware) C:\Users\Mietke\Downloads\ComboFix.exe
2013-07-29 12:28 - 2013-07-29 12:32 - 00025376 _____ C:\Users\Mietke\Downloads\Addition.txt
2013-07-29 12:25 - 2013-07-29 12:25 - 00000000 ____D C:\FRST
2013-07-29 12:23 - 2013-07-29 12:24 - 01780547 _____ (Farbar) C:\Users\Mietke\Downloads\FRST64.exe
2013-07-25 23:37 - 2013-07-25 23:37 - 00512825 _____ () C:\Users\Mietke\Downloads\FTB_Launcher.exe
2013-07-25 23:35 - 2013-07-25 23:35 - 00480057 _____ C:\Users\Mietke\Downloads\FTB_Launcher.jar
2013-07-25 23:16 - 2013-07-25 23:16 - 00512825 _____ () C:\Users\Mietke\Desktop\FTB_Launcher.exe
2013-07-23 21:50 - 2013-07-23 21:50 - 00000000 _____ C:\Users\Mietke\Desktop\server.log
2013-07-23 21:47 - 2013-07-23 21:47 - 02028089 _____ C:\Users\Mietke\Downloads\mcpatcher-4.1.0_04.exe
2013-07-23 21:41 - 2013-07-23 21:41 - 00000000 _____ C:\Users\Mietke\Downloads\server.log
2013-07-23 21:37 - 2013-07-23 21:40 - 00000000 ____D C:\Users\Mietke\AppData\Roaming\ftblauncher
2013-07-12 01:05 - 2013-07-12 01:05 - 00000000 ____D C:\Windows\PCHEALTH
2013-07-11 22:44 - 2013-06-01 06:19 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 22:44 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 22:44 - 2013-04-17 14:32 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-11 22:44 - 2013-04-17 14:32 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-11 22:44 - 2013-04-17 14:32 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-11 22:44 - 2013-04-17 14:32 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-11 22:44 - 2013-04-17 13:29 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-11 22:44 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-07-11 22:44 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-07-11 22:44 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-07-11 22:44 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-07-11 22:44 - 2013-04-17 13:27 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-11 22:44 - 2013-04-17 13:02 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-11 22:44 - 2013-04-17 12:58 - 01556480 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 22:44 - 2013-04-17 12:58 - 01149440 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-07-11 22:44 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-07-11 22:44 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-07-11 22:44 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-07-11 22:44 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 22:43 - 2013-06-04 04:03 - 02775040 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 22:43 - 2013-05-29 13:30 - 01212928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-11 22:43 - 2013-05-29 13:30 - 00916480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-11 22:43 - 2013-05-29 13:30 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-07-11 22:43 - 2013-05-29 13:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-07-11 22:43 - 2013-05-29 13:26 - 06016000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-11 22:43 - 2013-05-29 13:26 - 00611840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2013-07-11 22:43 - 2013-05-29 13:26 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-07-11 22:43 - 2013-05-29 13:25 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-11 22:43 - 2013-05-29 13:25 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-07-11 22:43 - 2013-05-29 13:25 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-07-11 22:43 - 2013-05-29 13:25 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 11111424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 02004992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 01469440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-07-11 22:43 - 2013-05-29 13:24 - 00387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-11 22:43 - 2013-05-29 13:24 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-11 22:43 - 2013-05-29 11:47 - 00385024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-07-11 22:43 - 2013-05-29 10:07 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-07-11 22:43 - 2013-05-29 10:06 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2013-07-11 22:43 - 2013-05-29 10:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-07-11 22:43 - 2013-05-29 10:04 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 22:43 - 2013-05-29 09:12 - 01489408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 22:43 - 2013-05-29 09:12 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 22:43 - 2013-05-29 09:12 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-11 22:43 - 2013-05-29 09:10 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-07-11 22:43 - 2013-05-29 09:09 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-07-11 22:43 - 2013-05-29 09:08 - 09339904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 22:43 - 2013-05-29 09:08 - 00742912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 22:43 - 2013-05-29 09:08 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-11 22:43 - 2013-05-29 09:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-07-11 22:43 - 2013-05-29 09:08 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-07-11 22:43 - 2013-05-29 09:08 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 12509184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 02356736 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 01538560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-11 22:43 - 2013-05-29 09:07 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-11 22:43 - 2013-05-29 09:07 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-11 22:43 - 2013-05-29 07:59 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-07-11 22:43 - 2013-05-29 06:27 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-11 22:43 - 2013-05-29 06:26 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-11 22:43 - 2013-05-29 06:24 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-07-11 22:43 - 2013-05-29 06:23 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 22:43 - 2013-05-08 06:18 - 01706496 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 22:43 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-10 23:29 - 2013-07-10 23:29 - 00000000 ___HD C:\Users\Mietke\Desktop\.updtmp
2013-07-10 20:11 - 2012-05-15 21:32 - 00174080 _____ (fabi.me) C:\Users\Mietke\Desktop\SpeedAutoClicker.exe
2013-07-10 18:59 - 2013-07-10 20:13 - 00000000 ____D C:\Users\Mietke\AppData\Local\fabi.me
2013-07-10 18:59 - 2013-07-10 18:59 - 00002026 _____ C:\Users\Public\Desktop\AutoClicker.exe.lnk
2013-07-10 18:59 - 2013-07-10 18:59 - 00000000 ____D C:\ProgramData\Macrovision
2013-07-10 18:59 - 2013-07-10 18:59 - 00000000 ____D C:\Program Files (x86)\Shark Software
2013-07-10 18:57 - 2013-07-10 18:57 - 08904974 _____ (Shark Software ) C:\Users\Mietke\Downloads\setup.exe
2013-07-08 17:15 - 2013-07-11 22:08 - 00000016 _____ C:\Users\Mietke\Desktop\Neues Textdokument.txt
2013-07-07 02:08 - 2013-07-07 02:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
111
==================== One Month Modified Files and Folders =======
2013-07-30 13:24 - 2013-07-30 13:24 - 00001124 _____ C:\Users\Mietke\Desktop\JRT.txt
2013-07-30 13:24 - 2013-01-09 20:44 - 00000440 ____H C:\Windows\Tasks\User_Feed_Synchronization-{38A14B28-3686-4261-A0BB-BA949EC18DBC}.job
2013-07-30 13:18 - 2008-01-21 03:53 - 01221480 _____ C:\Windows\WindowsUpdate.log
2013-07-30 13:16 - 2013-07-30 13:16 - 00009330 _____ C:\Users\Mietke\Desktop\AdwCleaner[S4].txt
2013-07-30 13:13 - 2012-07-09 13:25 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-07-30 13:13 - 2010-04-27 19:54 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2013-07-30 13:13 - 2009-12-03 19:01 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-30 13:13 - 2009-04-30 17:09 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-30 13:13 - 2006-11-02 17:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-30 13:13 - 2006-11-02 17:22 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-30 13:13 - 2006-11-02 17:22 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-30 13:11 - 2006-11-02 17:42 - 00032578 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-30 13:10 - 2013-07-30 13:10 - 00009330 _____ C:\AdwCleaner[S4].txt
2013-07-30 13:10 - 2013-07-30 13:10 - 00000276 _____ C:\Windows\DeleteOnReboot.bat
2013-07-30 13:09 - 2013-07-30 13:09 - 00000347 _____ C:\AdwCleaner[S3].txt
2013-07-30 13:08 - 2013-07-30 13:08 - 00022799 _____ C:\Users\Mietke\Desktop\ComboFix2.txt
2013-07-30 13:02 - 2013-02-25 18:48 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-30 12:52 - 2009-12-03 19:01 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-30 11:30 - 2013-07-30 11:30 - 00562042 _____ (Oleg N. Scherbakov) C:\Users\Mietke\Downloads\JRT.exe
2013-07-30 11:28 - 2013-07-30 11:28 - 00666633 _____ C:\Users\Mietke\Downloads\adwcleaner.exe
2013-07-30 11:15 - 2011-04-29 14:40 - 00031016 _____ C:\Windows\system32\spsys.log
2013-07-30 11:14 - 2013-02-25 19:35 - 00013166 _____ C:\Windows\PFRO.log
2013-07-29 18:39 - 2006-11-02 15:34 - 00000000 ____D C:\Windows\tracing
2013-07-29 17:05 - 2013-07-29 17:05 - 00013207 _____ C:\ComboFix.txt
2013-07-29 17:05 - 2013-02-21 18:51 - 00000000 ____D C:\Qoobox
2013-07-29 17:02 - 2006-11-02 14:34 - 00000215 _____ C:\Windows\system.ini
2013-07-29 16:49 - 2013-02-21 18:50 - 00000000 ____D C:\32788R22FWJFW
2013-07-29 16:47 - 2013-07-29 16:47 - 05095176 ____R (Swearware) C:\Users\Mietke\Downloads\ComboFix.exe
2013-07-29 12:32 - 2013-07-29 12:28 - 00025376 _____ C:\Users\Mietke\Downloads\Addition.txt
2013-07-29 12:25 - 2013-07-29 12:25 - 00000000 ____D C:\FRST
2013-07-29 12:24 - 2013-07-29 12:23 - 01780547 _____ (Farbar) C:\Users\Mietke\Downloads\FRST64.exe
2013-07-29 11:18 - 2010-11-15 18:23 - 00000000 ____D C:\Games
2013-07-28 21:55 - 2010-10-01 22:36 - 00000000 ____D C:\Users\Mietke\AppData\Roaming\TS3Client
2013-07-28 14:24 - 2012-10-05 16:21 - 00010246 _____ C:\Users\Mietke\Desktop\Gw2 Handelstabelle.ods
2013-07-27 11:04 - 2008-01-21 13:10 - 01474544 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-27 11:04 - 2008-01-21 13:09 - 00639210 _____ C:\Windows\system32\perfh007.dat
2013-07-27 11:04 - 2008-01-21 13:09 - 00131250 _____ C:\Windows\system32\perfc007.dat
2013-07-25 23:37 - 2013-07-25 23:37 - 00512825 _____ () C:\Users\Mietke\Downloads\FTB_Launcher.exe
2013-07-25 23:35 - 2013-07-25 23:35 - 00480057 _____ C:\Users\Mietke\Downloads\FTB_Launcher.jar
2013-07-25 23:16 - 2013-07-25 23:16 - 00512825 _____ () C:\Users\Mietke\Desktop\FTB_Launcher.exe
2013-07-23 21:50 - 2013-07-23 21:50 - 00000000 _____ C:\Users\Mietke\Desktop\server.log
2013-07-23 21:47 - 2013-07-23 21:47 - 02028089 _____ C:\Users\Mietke\Downloads\mcpatcher-4.1.0_04.exe
2013-07-23 21:41 - 2013-07-23 21:41 - 00000000 _____ C:\Users\Mietke\Downloads\server.log
2013-07-23 21:40 - 2013-07-23 21:37 - 00000000 ____D C:\Users\Mietke\AppData\Roaming\ftblauncher
2013-07-23 12:21 - 2013-02-25 18:48 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-23 12:21 - 2013-02-25 18:48 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-23 12:21 - 2013-02-25 18:48 - 00003736 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-23 12:21 - 2011-03-05 12:21 - 00000000 ____D C:\Users\Mietke\AppData\Local\Adobe
2013-07-19 14:22 - 2011-03-18 15:05 - 00000000 ____D C:\Users\Mietke\AppData\Roaming\.minecraft
2013-07-17 12:46 - 2013-03-03 15:28 - 00002388 _____ C:\Windows\setupact.log
2013-07-13 12:50 - 2013-03-09 19:33 - 00002025 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-13 01:40 - 2009-12-03 19:01 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-13 01:40 - 2009-12-03 19:01 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-12 10:15 - 2006-11-02 17:21 - 04815240 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-12 10:13 - 2006-11-02 17:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2013-07-12 01:12 - 2006-11-02 14:35 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-07-12 01:05 - 2013-07-12 01:05 - 00000000 ____D C:\Windows\PCHEALTH
2013-07-11 22:08 - 2013-07-08 17:15 - 00000016 _____ C:\Users\Mietke\Desktop\Neues Textdokument.txt
2013-07-10 23:29 - 2013-07-10 23:29 - 00000000 ___HD C:\Users\Mietke\Desktop\.updtmp
2013-07-10 20:13 - 2013-07-10 18:59 - 00000000 ____D C:\Users\Mietke\AppData\Local\fabi.me
2013-07-10 18:59 - 2013-07-10 18:59 - 00002026 _____ C:\Users\Public\Desktop\AutoClicker.exe.lnk
2013-07-10 18:59 - 2013-07-10 18:59 - 00000000 ____D C:\ProgramData\Macrovision
2013-07-10 18:59 - 2013-07-10 18:59 - 00000000 ____D C:\Program Files (x86)\Shark Software
2013-07-10 18:57 - 2013-07-10 18:57 - 08904974 _____ (Shark Software ) C:\Users\Mietke\Downloads\setup.exe
2013-07-10 08:26 - 2009-04-28 18:55 - 00000000 ____D C:\Users\Mietke
2013-07-08 11:16 - 2012-05-28 22:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-07 02:09 - 2013-07-07 02:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-30 13:20
==================== End Of Log ============================ --- --- --- |