Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   http://www_getwindowinfo/ und TBUpdater.dll nervern seit einiger Zeit, wie bekomme ich die vom Rechner? (https://www.trojaner-board.de/139724-http-www_getwindowinfo-tbupdater-dll-nervern-seit-einiger-zeit-bekomme-rechner.html)

baby-lissa 12.08.2013 18:22

http://www_getwindowinfo/ und TBUpdater.dll nervern seit einiger Zeit, wie bekomme ich die vom Rechner?
 
Mion mion, seit einiger Zeit habe ich den Internet explorer mit volgender Seite hxxp://www_getwindowinfo/ der immer aktiv ist, und als ich adwcleaner06 Installiert habe zum beseitigen kam das Nächszt Problem, der TBUpader.dll der immer starten will aber die Datei nicht findet, zudem kommt noch eine Fehlermeldung Server ausgelastet.
Wie bekomme ich den ganzen mist wieder vom PC? ADWClearner06 und ad aware habe nicht geholfen.
Kann mir hier jemande helfe?
Ich bin kein PC Spezialist also bitte alles in einfachen Worten und Programmen.
Danke im Vorraus

markusg 12.08.2013 18:23

Hi, gleich folgt eine Anweisung zu FRST, beachte bitte die Infos die ich in der Additions.txt für die Software liste möchte.
1.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


2.

Empfehlungen fürs Deinstallieren
Bitte kopiere die Liste der installierten Programme aus der additions.txt hier in deinen Thread. Notiere mir bitte
hinter jede Zeile, ob folgendes Kategorie zutrifft: Unbekannt, Nötig, Unnötig

baby-lissa 12.08.2013 18:35


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013 02
Ran by Lissi1 (administrator) on 12-08-2013 19:31:57
Running from C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TTDT2QBV
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(CrypKey (Canada) Ltd.) C:\Windows\system32\crypserv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe
(Lavasoft Limited) C:\PROGRA~2\AD-AWA~1\AdAware.exe
(Dropbox, Inc.) C:\Users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Windows Net) C:\Users\Lissi1\AppData\Roaming\Windows Net Data\net.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TTDT2QBV\FRST64 (1).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [Monitor] - C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [IntelliType Pro] - c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung)
HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.)
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5622512 2013-05-15] (SUPERAntiSpyware.com)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [542632 2013-01-31] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-08-05] (Avira Operations GmbH & Co. KG)
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Scanner Finder.lnk
ShortcutTarget: Scanner Finder.lnk -> C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled ()
Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Lissi1\AppData\Roaming\Windows Net Data\net.exe (Windows Net)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {00B6DEF0-C572-45D3-AF51-CD416F2DA9C0} URL = hxxp://www.bing.com/search?FORM=BDT3DF&PC=BDT3&dt=080613&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKCU - 63D76E6EC6B04284B071A585DCBE8EA6 URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=53E641BF-D5D6-4646-8077-EE58703B9D12&apn_sauid=45E38BAC-10B5-487C-BE1B-F389560F4295
BHO-x32: No Name - {120A8821-2BEE-4C29-BCDA-62C577781992} -  No File
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Deaktivierungs-Add-on für Browser von Google Analytics - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll (Google, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} -  No File
BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} -  No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
Toolbar: HKLM-x32 - No Name - !{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} -  No File
Toolbar: HKLM-x32 - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} -  No File
Toolbar: HKLM-x32 - HomeTab - {ba696155-d96e-4281-b467-0367a0456474} -  No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -  No File
Toolbar: HKCU - No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} -  No File
Toolbar: HKCU - No Name - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} -  No File
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage:                "homepage":        "",
CHR RestoreOnStartup: "hxxp://www.msn.com/?pc=BDT3&ocid=BDT3DHP&dt=080613"
CHR Extension: (Plus-HD-2.4) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.23.29_0
CHR Extension: (Skype Click to Call) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.0.0_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-02-14] (Lavasoft Limited)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-05] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-08-05] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [45056 2006-12-14] (Sony Corporation)
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [57344 2006-12-14] ()
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
S3 SonicStage Back-End Service; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe [112184 2007-02-05] (Sony Corporation)
S3 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [69632 2006-12-14] (Sony Corporation)
S3 SSScsiSV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe [75320 2007-02-05] (Sony Corporation)
R2 Crypkey License; crypserv.exe [x]

==================== Drivers (Whitelisted) ====================

S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-05] (Avira Operations GmbH & Co. KG)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-02-22] (GFI Software)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] ()
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-12 15:59 - 2013-08-12 15:59 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{87BB76C1-82E0-437C-A37C-0433E34C4B33}
2013-08-12 11:03 - 2013-08-12 11:03 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-12 10:59 - 2013-08-12 13:25 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-12 07:17 - 2013-08-12 15:17 - 00000512 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b4eb2f77-0b34-4a31-8e76-89b6cbcecc1b.job
2013-08-12 07:17 - 2013-08-12 13:24 - 00000512 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 33915243-1829-4197-b765-f2f614375d1b.job
2013-08-12 07:17 - 2013-08-12 07:17 - 00003590 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 33915243-1829-4197-b765-f2f614375d1b
2013-08-12 07:17 - 2013-08-12 07:17 - 00003516 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task b4eb2f77-0b34-4a31-8e76-89b6cbcecc1b
2013-08-12 07:17 - 2013-08-12 07:17 - 00001812 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-08-12 06:44 - 2013-08-12 06:44 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-12 06:44 - 2013-08-12 06:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-12 06:44 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-11 20:06 - 2013-08-12 06:33 - 00000000 ____D C:\Program Files (x86)\Eusing Free Registry Cleaner
2013-08-11 19:02 - 2013-08-12 19:02 - 00000468 _____ C:\Windows\Tasks\Wise Registry Cleaner Schedule Task.job
2013-08-11 19:02 - 2013-08-11 19:52 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Wise Registry Cleaner
2013-08-11 19:02 - 2013-08-11 19:03 - 00003340 _____ C:\Windows\System32\Tasks\Wise Registry Cleaner Schedule Task
2013-08-11 19:00 - 2013-08-11 19:00 - 00000000 ____D C:\Program Files (x86)\Wise
2013-08-11 18:22 - 2013-08-11 18:22 - 00002676 _____ C:\AdwCleaner[S12].txt
2013-08-11 18:22 - 2013-08-11 18:22 - 00002613 _____ C:\AdwCleaner[R19].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015178 _____ C:\AdwCleaner[R18].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015091 _____ C:\AdwCleaner[S11].txt
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 __SHD C:\found.000
2013-08-10 22:13 - 2013-08-10 22:13 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{FF9A8822-4474-4304-9014-9D112D469C43}
2013-08-09 19:38 - 2013-08-09 19:44 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-09 19:38 - 2013-08-09 19:39 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{776DAD39-B110-4BB8-8E5D-C94A0562B076}
2013-08-08 11:07 - 2013-08-08 11:07 - 00000085 _____ C:\Windows\wininit.ini
2013-08-07 20:00 - 2013-08-12 18:15 - 00001290 _____ C:\Windows\Tasks\Plus-HD-2.4-updater.job
2013-08-07 20:00 - 2013-08-07 20:00 - 00004320 _____ C:\Windows\System32\Tasks\Plus-HD-2.4-updater
2013-08-07 19:59 - 2013-08-12 18:15 - 00001202 _____ C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job
2013-08-07 19:59 - 2013-08-12 18:15 - 00001100 _____ C:\Windows\Tasks\Plus-HD-2.4-enabler.job
2013-08-07 19:59 - 2013-08-07 19:59 - 00004232 _____ C:\Windows\System32\Tasks\Plus-HD-2.4-codedownloader
2013-08-07 19:59 - 2013-08-07 19:59 - 00004130 _____ C:\Windows\System32\Tasks\Plus-HD-2.4-enabler
2013-08-07 19:58 - 2013-08-12 18:15 - 00001910 _____ C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job
2013-08-07 19:58 - 2013-08-11 16:06 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4
2013-08-07 18:29 - 2013-08-07 18:29 - 00002180 _____ C:\AdwCleaner[S10].txt
2013-08-07 18:28 - 2013-08-07 18:28 - 00002117 _____ C:\AdwCleaner[R17].txt
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 10:31 - 2013-08-07 10:31 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-07 10:30 - 2013-08-07 11:35 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:27 - 2013-08-07 10:27 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Lissi1\Downloads\SpyHunter-Installer.exe
2013-08-07 10:23 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-08-07 10:23 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-08-07 10:14 - 2013-08-07 10:14 - 00000000 ____D C:\FRST
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-06 18:55 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-08-06 18:55 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-08-06 18:20 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-08-06 18:20 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-08-06 18:20 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2013-08-06 18:20 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-08-06 18:20 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-08-06 18:20 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-08-06 18:20 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-08-06 18:20 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-08-06 18:20 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-08-06 18:20 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-08-06 18:20 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-08-06 18:20 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-08-06 18:20 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-08-06 18:20 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-08-06 18:20 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-08-06 18:18 - 2013-08-06 18:20 - 00000000 ____D C:\Windows\system32\MRT
2013-08-06 18:13 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMAW.DLL
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:06 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 18:00 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-08-06 18:00 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-08-06 18:00 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-08-06 18:00 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-08-06 18:00 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:35 - 2013-08-06 14:44 - 00010360 _____ C:\Windows\IE10_main.log
2013-08-06 11:59 - 2013-08-06 11:59 - 00002055 _____ C:\AdwCleaner[R14].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001994 _____ C:\AdwCleaner[R13].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001933 _____ C:\AdwCleaner[R12].txt
2013-08-06 11:48 - 2013-08-06 11:48 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{E669DA13-D1D7-4467-8C6E-03285C19EF68}
2013-08-06 10:56 - 2013-05-29 08:15 - 17829376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-06 10:56 - 2013-05-29 07:50 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-06 10:56 - 2013-05-29 07:43 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-06 10:56 - 2013-05-29 07:36 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-06 10:56 - 2013-05-29 07:35 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-06 10:56 - 2013-05-29 07:34 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-06 10:56 - 2013-05-29 07:33 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-06 10:56 - 2013-05-29 07:31 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-06 10:56 - 2013-05-29 07:27 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-06 10:56 - 2013-05-29 07:27 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-06 10:56 - 2013-05-29 07:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-06 10:56 - 2013-05-29 07:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-06 10:56 - 2013-05-29 07:18 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-06 10:56 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-06 10:56 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-06 10:56 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-06 10:56 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-06 10:56 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-06 10:56 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-06 10:56 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-06 10:56 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-06 10:56 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-06 10:56 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-08-06 10:56 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-06 10:56 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-06 10:56 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-06 10:56 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-06 10:56 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-06 10:56 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-06 10:54 - 2013-05-08 08:39 - 01910632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-06 10:54 - 2013-04-10 08:01 - 00983400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-08-06 10:54 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-08-06 10:54 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-08-06 10:54 - 2013-02-27 07:52 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-08-06 10:54 - 2013-02-27 07:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-08-06 10:54 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-08-06 10:54 - 2013-01-03 08:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-08-06 10:54 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-08-06 10:53 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-08-06 10:53 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-08-06 10:53 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-06 10:53 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-06 10:53 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-08-06 10:53 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-08-06 10:53 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-08-06 10:53 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-08-06 10:53 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023x.sys
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-08-06 10:53 - 2013-01-04 07:46 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-08-06 10:53 - 2013-01-04 06:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-06 10:53 - 2013-01-04 04:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-06 10:53 - 2013-01-04 04:47 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-06 10:53 - 2013-01-04 04:47 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-06 10:53 - 2013-01-04 04:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-06 10:52 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-08-06 10:52 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-08-06 10:52 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-08-06 10:52 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-08-06 10:51 - 2013-05-13 07:51 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-06 10:51 - 2013-05-13 07:51 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-06 10:51 - 2013-05-13 07:51 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-06 10:51 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-06 10:51 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-08-06 10:50 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-08-06 10:50 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-08-06 10:50 - 2013-03-19 08:04 - 05550424 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-06 10:50 - 2013-03-19 07:46 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-08-06 10:50 - 2013-03-19 07:04 - 03968856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-06 10:50 - 2013-03-19 07:04 - 03913560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-06 10:50 - 2013-03-19 06:47 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-08-06 10:50 - 2013-03-19 05:06 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-08-06 10:33 - 2013-08-06 10:33 - 00024422 _____ C:\ComboFix.txt
2013-08-06 10:18 - 2013-08-06 10:33 - 00000000 ____D C:\Qoobox
2013-08-06 10:18 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-06 10:18 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-06 10:18 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-06 10:17 - 2013-08-06 10:32 - 00000000 ____D C:\Windows\erdnt
2013-08-06 10:10 - 2013-08-06 10:10 - 00001872 _____ C:\AdwCleaner[R11].txt
2013-08-06 10:08 - 2013-08-06 10:08 - 00001811 _____ C:\AdwCleaner[R10].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00002038 _____ C:\AdwCleaner[S7].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00001976 _____ C:\AdwCleaner[R9].txt
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 12:26 - 2013-08-07 00:09 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 12:26 - 2013-08-05 12:26 - 00001714 _____ C:\AdwCleaner[R8].txt
2013-08-05 12:21 - 2013-08-05 12:21 - 00001654 _____ C:\AdwCleaner[R7].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001596 _____ C:\AdwCleaner[S6].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001534 _____ C:\AdwCleaner[R6].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001726 _____ C:\AdwCleaner[S5].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001664 _____ C:\AdwCleaner[R5].txt
2013-08-05 12:01 - 2013-08-05 12:01 - 00666633 _____ C:\Users\Lissi1\Desktop\adwcleaner06.exe
2013-08-05 11:53 - 2013-08-05 11:53 - 00078778 _____ C:\AdwCleaner[R4].txt
2013-08-05 11:53 - 2013-08-05 11:53 - 00033765 _____ C:\AdwCleaner[S4].txt
2013-08-05 11:51 - 2013-08-05 11:51 - 00078717 _____ C:\AdwCleaner[R3].txt
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:42 - 2013-08-05 11:43 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:42 - 2013-08-05 11:35 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-27 01:17 - 2013-07-28 13:18 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{FAF84326-4611-466D-B67A-0E297DF11DC0}
2013-07-26 13:22 - 2013-07-26 19:59 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-07-26 13:16 - 2013-07-26 13:16 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{2D21CAF1-E27F-424F-9F6A-3C2B7F8E8FE5}
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:34 - 2013-07-25 19:34 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{79D351A7-86AB-4734-97E9-C42B3C381CD0}
2013-07-25 19:22 - 2013-07-26 13:19 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-07-25 16:48 - 2013-07-25 19:12 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-23 18:47 - 2013-07-23 18:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 18:20 - 2013-08-09 12:00 - 00003874 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-07-23 18:20 - 2013-08-01 03:08 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-23 18:20 - 2013-07-29 18:44 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-23 14:55 - 2013-07-23 14:55 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{8B102F25-1113-48D3-9381-DA6E4B9A6BA8}
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 16:53 - 2013-07-22 17:03 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-22 14:42 - 2013-07-22 14:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{8EF11119-F58F-43BF-BC83-8F60387DADED}
2013-07-22 14:41 - 2013-07-14 19:47 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430 - Kopie.mov
2013-07-20 12:08 - 2013-07-20 12:08 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{A2FDA827-159E-4898-9016-E6A1408AFA4C}
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 16:37 - 2013-07-17 17:49 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 16:37 - 2013-07-17 17:49 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-14 18:38 - 2013-07-14 19:47 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430.mov

==================== One Month Modified Files and Folders =======

2013-08-12 19:27 - 2013-05-08 20:36 - 190989312 _____ C:\Users\Lissi1\Outlooklissa.pst
2013-08-12 19:16 - 2013-08-12 19:16 - 00065536 ___HT C:\Users\Lissi1\~Outlooklissa.pst.tmp
2013-08-12 19:16 - 2012-02-04 18:48 - 00000000 ____D C:\Users\Lissi1
2013-08-12 19:02 - 2013-08-11 19:02 - 00000468 _____ C:\Windows\Tasks\Wise Registry Cleaner Schedule Task.job
2013-08-12 18:55 - 2012-05-01 10:51 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-12 18:44 - 2012-02-04 18:44 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-12 18:23 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-12 18:23 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-12 18:19 - 2012-12-24 23:53 - 00004086 _____ C:\Windows\System32\Tasks\Software Updater Ui
2013-08-12 18:19 - 2012-12-24 23:51 - 00004122 _____ C:\Windows\System32\Tasks\Software Updater
2013-08-12 18:17 - 2012-10-23 16:44 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Dropbox
2013-08-12 18:16 - 2012-04-13 16:05 - 03431936 ___SH C:\Users\Lissi1\Desktop\Thumbs.db
2013-08-12 18:15 - 2013-08-07 20:00 - 00001290 _____ C:\Windows\Tasks\Plus-HD-2.4-updater.job
2013-08-12 18:15 - 2013-08-07 19:59 - 00001202 _____ C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job
2013-08-12 18:15 - 2013-08-07 19:59 - 00001100 _____ C:\Windows\Tasks\Plus-HD-2.4-enabler.job
2013-08-12 18:15 - 2013-08-07 19:58 - 00001910 _____ C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job
2013-08-12 18:15 - 2013-04-04 12:45 - 00009681 _____ C:\Windows\setupact.log
2013-08-12 18:15 - 2013-03-05 20:06 - 00007936 _____ C:\Windows\error.log
2013-08-12 18:15 - 2012-10-23 16:46 - 00000000 ___RD C:\Users\Lissi1\Dropbox
2013-08-12 18:15 - 2012-02-04 18:44 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-12 18:15 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-12 18:14 - 2013-03-05 20:05 - 00003165 _____ C:\Windows\errord.log
2013-08-12 16:15 - 2012-02-04 18:43 - 01513589 _____ C:\Windows\WindowsUpdate.log
2013-08-12 15:59 - 2013-08-12 15:59 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{87BB76C1-82E0-437C-A37C-0433E34C4B33}
2013-08-12 15:17 - 2013-08-12 07:17 - 00000512 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b4eb2f77-0b34-4a31-8e76-89b6cbcecc1b.job
2013-08-12 13:25 - 2013-08-12 10:59 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-12 13:24 - 2013-08-12 07:17 - 00000512 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 33915243-1829-4197-b765-f2f614375d1b.job
2013-08-12 13:24 - 2012-11-13 07:22 - 00125256 _____ C:\Windows\PFRO.log
2013-08-12 11:03 - 2013-08-12 11:03 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-12 07:17 - 2013-08-12 07:17 - 00003590 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 33915243-1829-4197-b765-f2f614375d1b
2013-08-12 07:17 - 2013-08-12 07:17 - 00003516 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task b4eb2f77-0b34-4a31-8e76-89b6cbcecc1b
2013-08-12 07:17 - 2013-08-12 07:17 - 00001812 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-08-12 06:44 - 2013-08-12 06:44 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-12 06:44 - 2013-08-12 06:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-12 06:33 - 2013-08-11 20:06 - 00000000 ____D C:\Program Files (x86)\Eusing Free Registry Cleaner
2013-08-11 20:54 - 2012-09-20 17:48 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Skype
2013-08-11 19:57 - 2012-12-24 23:48 - 00000000 ____D C:\Program Files (x86)\SelfUpdater
2013-08-11 19:52 - 2013-08-11 19:02 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Wise Registry Cleaner
2013-08-11 19:03 - 2013-08-11 19:02 - 00003340 _____ C:\Windows\System32\Tasks\Wise Registry Cleaner Schedule Task
2013-08-11 19:00 - 2013-08-11 19:00 - 00000000 ____D C:\Program Files (x86)\Wise
2013-08-11 18:22 - 2013-08-11 18:22 - 00002676 _____ C:\AdwCleaner[S12].txt
2013-08-11 18:22 - 2013-08-11 18:22 - 00002613 _____ C:\AdwCleaner[R19].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015178 _____ C:\AdwCleaner[R18].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015091 _____ C:\AdwCleaner[S11].txt
2013-08-11 17:11 - 2012-05-09 15:14 - 00000000 ____D C:\Program Files (x86)\Free FLV Converter
2013-08-11 16:44 - 2013-03-10 20:20 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\MyPhoneExplorer
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 __SHD C:\found.000
2013-08-11 16:06 - 2013-08-07 19:58 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4
2013-08-10 22:13 - 2013-08-10 22:13 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{FF9A8822-4474-4304-9014-9D112D469C43}
2013-08-10 18:26 - 2013-03-10 20:25 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-08-10 18:25 - 2013-03-10 21:04 - 00002065 _____ C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2013-08-10 18:25 - 2013-03-10 21:04 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2013-08-09 19:44 - 2013-08-09 19:38 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-09 19:39 - 2013-08-09 19:38 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{776DAD39-B110-4BB8-8E5D-C94A0562B076}
2013-08-09 12:00 - 2013-07-23 18:20 - 00003874 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-08-08 11:07 - 2013-08-08 11:07 - 00000085 _____ C:\Windows\wininit.ini
2013-08-07 20:07 - 2012-05-09 15:16 - 00002592 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-07 20:00 - 2013-08-07 20:00 - 00004320 _____ C:\Windows\System32\Tasks\Plus-HD-2.4-updater
2013-08-07 19:59 - 2013-08-07 19:59 - 00004232 _____ C:\Windows\System32\Tasks\Plus-HD-2.4-codedownloader
2013-08-07 19:59 - 2013-08-07 19:59 - 00004130 _____ C:\Windows\System32\Tasks\Plus-HD-2.4-enabler
2013-08-07 18:29 - 2013-08-07 18:29 - 00002180 _____ C:\AdwCleaner[S10].txt
2013-08-07 18:28 - 2013-08-07 18:28 - 00002117 _____ C:\AdwCleaner[R17].txt
2013-08-07 18:26 - 2011-07-18 23:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-07 11:35 - 2013-08-07 10:30 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 10:31 - 2013-08-07 10:31 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-07 10:27 - 2013-08-07 10:27 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Lissi1\Downloads\SpyHunter-Installer.exe
2013-08-07 10:14 - 2013-08-07 10:14 - 00000000 ____D C:\FRST
2013-08-07 01:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-07 00:09 - 2013-08-05 12:26 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-06 18:38 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-06 18:38 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-06 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-08-06 18:33 - 2011-04-12 10:28 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-08-06 18:20 - 2013-08-06 18:18 - 00000000 ____D C:\Windows\system32\MRT
2013-08-06 18:12 - 2011-05-16 16:04 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-08-06 18:12 - 2011-05-16 16:04 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-08-06 18:12 - 2009-07-14 07:13 - 01519624 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:07 - 2013-08-06 18:06 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 17:43 - 2011-07-18 22:54 - 00000000 ____D C:\Windows\Panther
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sl-SI
2013-08-06 14:51 - 2012-02-04 19:29 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-06 14:44 - 2013-08-06 14:35 - 00010360 _____ C:\Windows\IE10_main.log
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 11:59 - 2013-08-06 11:59 - 00002055 _____ C:\AdwCleaner[R14].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001994 _____ C:\AdwCleaner[R13].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001933 _____ C:\AdwCleaner[R12].txt
2013-08-06 11:48 - 2013-08-06 11:48 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{E669DA13-D1D7-4467-8C6E-03285C19EF68}
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-08-06 10:33 - 2013-08-06 10:33 - 00024422 _____ C:\ComboFix.txt
2013-08-06 10:33 - 2013-08-06 10:18 - 00000000 ____D C:\Qoobox
2013-08-06 10:33 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-06 10:32 - 2013-08-06 10:17 - 00000000 ____D C:\Windows\erdnt
2013-08-06 10:28 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-06 10:10 - 2013-08-06 10:10 - 00001872 _____ C:\AdwCleaner[R11].txt
2013-08-06 10:08 - 2013-08-06 10:08 - 00001811 _____ C:\AdwCleaner[R10].txt
2013-08-05 22:44 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-05 19:23 - 2013-08-05 19:23 - 00002038 _____ C:\AdwCleaner[S7].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00001976 _____ C:\AdwCleaner[R9].txt
2013-08-05 16:22 - 2013-05-11 14:02 - 00000000 ____D C:\ProgramData\Avery
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 12:26 - 2013-08-05 12:26 - 00001714 _____ C:\AdwCleaner[R8].txt
2013-08-05 12:21 - 2013-08-05 12:21 - 00001654 _____ C:\AdwCleaner[R7].txt
2013-08-05 12:09 - 2012-02-04 23:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\CheckPoint
2013-08-05 12:08 - 2013-08-05 12:08 - 00001596 _____ C:\AdwCleaner[S6].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001534 _____ C:\AdwCleaner[R6].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001726 _____ C:\AdwCleaner[S5].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001664 _____ C:\AdwCleaner[R5].txt
2013-08-05 12:01 - 2013-08-05 12:01 - 00666633 _____ C:\Users\Lissi1\Desktop\adwcleaner06.exe
2013-08-05 11:53 - 2013-08-05 11:53 - 00078778 _____ C:\AdwCleaner[R4].txt
2013-08-05 11:53 - 2013-08-05 11:53 - 00033765 _____ C:\AdwCleaner[S4].txt
2013-08-05 11:51 - 2013-08-05 11:51 - 00078717 _____ C:\AdwCleaner[R3].txt
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:43 - 2013-08-05 11:42 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:35 - 2013-08-05 11:42 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-01 03:08 - 2013-07-23 18:20 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-29 18:44 - 2013-07-23 18:20 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-28 13:18 - 2013-07-27 01:17 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{FAF84326-4611-466D-B67A-0E297DF11DC0}
2013-07-26 19:59 - 2013-07-26 13:22 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-07-26 13:19 - 2013-07-25 19:22 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-07-26 13:16 - 2013-07-26 13:16 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{2D21CAF1-E27F-424F-9F6A-3C2B7F8E8FE5}
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:34 - 2013-07-25 19:34 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{79D351A7-86AB-4734-97E9-C42B3C381CD0}
2013-07-25 19:12 - 2013-07-25 16:48 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-23 18:47 - 2013-07-23 18:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-23 14:55 - 2013-07-23 14:55 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{8B102F25-1113-48D3-9381-DA6E4B9A6BA8}
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 17:03 - 2013-07-22 16:53 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-22 14:43 - 2013-07-22 14:42 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{8EF11119-F58F-43BF-BC83-8F60387DADED}
2013-07-20 12:08 - 2013-07-20 12:08 - 00000000 ____D C:\Users\Lissi1\AppData\Local\{A2FDA827-159E-4898-9016-E6A1408AFA4C}
2013-07-18 20:44 - 2012-12-27 12:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\BOM
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 18:43 - 2012-09-17 16:53 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Apps\2.0
2013-07-17 18:34 - 2013-02-09 17:40 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus
2013-07-17 18:34 - 2012-05-09 15:14 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\FreeFLVConverter
2013-07-17 18:34 - 2012-02-04 21:31 - 00000000 ____D C:\Program Files (x86)\ScanWizard 5
2013-07-17 18:34 - 2011-07-18 23:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-17 18:21 - 2011-04-12 10:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-07-17 18:13 - 2013-02-09 17:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Ad-Aware Antivirus
2013-07-17 17:49 - 2013-07-17 16:37 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 17:49 - 2013-07-17 16:37 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-17 09:24 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files\Google
2013-07-16 08:43 - 2012-02-04 19:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Google
2013-07-16 08:43 - 2012-02-04 18:44 - 00000000 ____D C:\ProgramData\Google
2013-07-16 08:25 - 2012-05-01 10:51 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-16 08:25 - 2012-05-01 10:51 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-16 08:25 - 2011-10-14 14:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-14 19:47 - 2013-07-22 14:41 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430 - Kopie.mov
2013-07-14 19:47 - 2013-07-14 18:38 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430.mov

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-12 05:58

==================== End Of Log ============================

--- --- ---

Additions.txtFRST Additions Logfile:
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02
Ran by Lissi1 at 2013-08-12 19:34:11
Running from C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TTDT2QBV
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

 
Ad-Aware Antivirus (x32 Version: 10.5.0.4339)
Adobe AIR (x32 Version: 3.1.0.4880)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Adobe Shockwave Player 11.6 (x32 Version: 11.6.5.635)
Alamandi (x32)
AMD APP SDK Runtime (Version: 2.5.793.1)
AMD AVIVO64 Codecs (Version: 11.7.0.11013)
AMD Catalyst Install Manager (Version: 3.0.851.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.61013.1636)
Angry Birds Star Wars (x32 Version: 1.0.0)
Apple Application Support (x32 Version: 2.3)
Apple Software Update (x32 Version: 2.1.3.127)
AVIConverter 5.1.6 (x32 Version: 5.1.6)
Avira Free Antivirus (x32 Version: 13.0.0.3885)
AVS Update Manager 1.0 (x32)
AVS Video Converter 8 (x32)
AVS4YOU Software Navigator 1.4 (x32)
Biet-O-Matic v2.14.8 (x32 Version: Biet-O-Matic v2.14.8)
Canon Easy-PhotoPrint EX (x32)
Canon iP4900 series Benutzerregistrierung (x32)
Canon iP4900 series On-screen Manual (x32)
Canon iP4900 series Printer Driver
Canon My Printer (x32)
Catalyst Control Center (x32 Version: 2011.1013.1702.28713)
Catalyst Control Center InstallProxy (x32 Version: 2011.1013.1702.28713)
Catalyst Control Center Localization All (x32 Version: 2011.1013.1702.28713)
CCC Help Danish (x32 Version: 2011.1013.1701.28713)
CCC Help Dutch (x32 Version: 2011.1013.1701.28713)
CCC Help English (x32 Version: 2011.1013.1701.28713)
CCC Help Finnish (x32 Version: 2011.1013.1701.28713)
CCC Help French (x32 Version: 2011.1013.1701.28713)
CCC Help German (x32 Version: 2011.1013.1701.28713)
CCC Help Italian (x32 Version: 2011.1013.1701.28713)
CCC Help Japanese (x32 Version: 2011.1013.1701.28713)
CCC Help Norwegian (x32 Version: 2011.1013.1701.28713)
CCC Help Spanish (x32 Version: 2011.1013.1701.28713)
CCC Help Swedish (x32 Version: 2011.1013.1701.28713)
ccc-utility64 (Version: 2011.1013.1702.28713)
CD-LabelPrint (x32)
Color!It 1.5 Professional-E (x32)
ContentHD (x32 Version: 1.00.0002)
Contents (x32 Version: 1.6.0.367)
Contents (x32 Version: 1.6.1.137)
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2)
Corel Painter Photo Essentials 4 (x32 Version: 4.1)
Corel Painter Photo Essentials 4 (x32)
Corel PaintShop Photo Pro X3 (x32 Version: 1.00.0000)
Corel PaintShop Photo Pro X3 (x32 Version: 1.6.1.137)
Corel VideoStudio Pro X3 (x32 Version: 1.6.0.367)
CyberLink LabelPrint (x32 Version: 2.5.3624)
CyberLink Power2Go (x32 Version: 7.0.0.1327)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306)
CyberLink PowerRecover (x32 Version: 5.5.4125)
CyberLink WaveEditor (x32 Version: 1.0.1.2821)
D3DX10 (x32 Version: 15.4.2368.0902)
Deaktivierungs-Add-on für Browser von Google Analytics (x32 Version: 0.9.2.0)
Der wunderbare Zauberer von Oz (x32)
DeviceIO (x32 Version: 1.6.0.367)
DeviceIO (x32 Version: 1.6.1.137)
Die Sage von Kolossus (x32)
Dropbox (HKCU Version: 2.0.22)
DVD Shrink 3.2 (x32)
FarmFrenzy (x32)
FLV Media Player version 1.3 (x32 Version: 1.3)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922)
Free Video to MP3 Converter version 5.0.24.430 (x32 Version: 5.0.24.430)
Free YouTube Download version 3.2.2.430 (x32 Version: 3.2.2.430)
Free YouTube to MP3 Converter version 3.12.0.128 (x32 Version: 3.12.0.128)
Freez FLV to AVI/MPEG/WMV Converter (x32 Version: 1.6)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Google Chrome (x32 Version: 28.0.1500.95)
Google Update Helper (x32 Version: 1.3.21.153)
ICA (x32 Version: 1.6.0.367)
ICA (x32 Version: 1.6.1.137)
Intel(R) Rapid Storage Technology (x32 Version: 10.6.0.1002)
IPM_PSP_Pro (x32 Version: 1.00.0000)
IPM_VS_Pro (x32 Version: 13.0)
Java 7 Update 21 (64-bit) (Version: 7.0.210)
Java 7 Update 21 (x32 Version: 7.0.210)
Java Auto Updater (x32 Version: 2.1.9.5)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Kaufland Foto (x32 Version: 5.0.1)
Kernel for Outlook PST Repair Evaluation ver 13.02.01 (x32)
Klett Lernsoftware Mathematik - mathe live 5 BA (x32)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (x32 Version: 15.4.5722.2)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Medion Home Cinema (x32 Version: 8.0.3216)
Memeo Instant Backup (x32 Version: 4.60.0.7943)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Microsoft-Maus- und Tastatur-Center (Version: 2.0.162.0)
Microtek FineReader OCR Engine (x32)
MLE (x32 Version: 1.0.0.23)
MSVC80_x64_v2 (Version: 1.0.3.0)
MSVC80_x86_v2 (x32 Version: 1.0.3.0)
MSVC90_x64 (Version: 1.0.1.2)
MSVC90_x86 (x32 Version: 1.0.1.2)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MyFreeCodec (HKCU)
MyPhoneExplorer (x32 Version: 1.8.4)
OpenMG Limited Patch 4.7-07-14-05-01 (x32)
OpenMG Secure Module (x32 Version: 4.7.00.12140)
OpenMG Secure Module 4.7.00 (x32 Version: 4.7.00.12140)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
Pošta Windows Live (x32 Version: 15.4.3502.0922)
PSPH10Pro (x32 Version: 1.00.0000)
PSPPContent (x32 Version: 1.00.0000)
PSPPRO_DCRAW (x32 Version: 13.0.0)
PureHD (x32 Version: 1.6.0.367)
PureHD (x32 Version: 1.6.1.137)
QuickShare (x32 Version: 1.6.1.714)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6438)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.25.0)
rosoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Samsung Kies (x32 Version: 2.3.2.12064_9)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.16.0)
ScanWizard 5 (x32)
Setup (x32 Version: 1.6.0.367)
Setup (x32 Version: 1.6.1.137)
Share (x32 Version: 1.6.0.367)
Share (x32 Version: 1.6.1.137)
Share64 (Version: 1.6.0.367)
Share64 (Version: 1.6.1.137)
Skype Click to Call (x32 Version: 6.3.11079)
Skype™ 6.5 (x32 Version: 6.5.158)
SmartSound Common Data (x32 Version: 1.1.0)
SmartSound Quicktracks 5 (x32 Version: 5.1.5)
SonicStage 4.3 (x32 Version: 4.3)
Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0)
Stellar Phoenix Outlook PST Repair (x32 Version: 4.5.0.0)
SUPERAntiSpyware (Version: 5.6.1020)
swMSM (x32 Version: 12.0.0.1)
TeamSpeak 3 Client (Version: 3.0.10)
TeamViewer 7 (x32 Version: 7.0.13852)
Uniblue DriverScanner (x32 Version: 4.0.9.10)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2)
VC 9.0 Runtime (x32 Version: 1.0.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Versandhelfer (x32 Version: 0.9.511)
VIO (x32 Version: 1.6.0.367)
VIO (x32 Version: 1.6.1.137)
VSClassic (x32 Version: 1.6.0.367)
VSPro (x32 Version: 1.6.0.367)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922)
Windows Live Fotótár (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Media Encoder 9 Series (x32 Version: 9.00.2980)
Windows Media Encoder 9 Series (x32)
Windows Utils (x32)
WinRAR 4.10 (64-Bit) (Version: 4.10.0)
Wise Registry Cleaner 7.82 (x32 Version: 7.82)
WISO Steuer-Sparbuch 2012 (x32 Version: 19.00.7303)
WISO Steuer-Sparbuch 2013 (x32 Version: 20.00.8137)
Yahoo! Messenger (x32)
Yahoo! Software Update (x32)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922)

==================== Restore Points  =========================

07-08-2013 08:30:52 Installed SpyHunter
07-08-2013 09:32:53 Removed SpyHunter
07-08-2013 09:32:54 Windows Update
07-08-2013 16:25:12 Free System Utilities
07-08-2013 16:26:51 Entfernt PC Inspector File Recovery
07-08-2013 17:57:21 Free System Utilities
07-08-2013 18:07:52 Free System Utilities 07.08.2013 20:07:51
08-08-2013 13:43:01 Free System Utilities 08.08.2013 15:41:50
08-08-2013 14:49:10 Free System Utilities 08.08.2013 16:49:10
09-08-2013 10:50:16 Free System Utilities 09.08.2013 12:50:10
09-08-2013 15:06:55 Free System Utilities 09.08.2013 17:06:54
11-08-2013 15:07:57 Free System Utilities
11-08-2013 16:31:08 Wiederherstellungsvorgang
11-08-2013 17:00:31 Windows-Sicherung

==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-08-06 10:26 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {046FA198-336F-4B8F-A05D-B074ED8CAC06} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4060780361-2962197505-3855748707-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe No File
Task: {08AE6839-3B32-478C-9D97-C7ABF7DBB35D} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4060780361-2962197505-3855748707-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe No File
Task: {16009711-3FBE-4DBF-99F2-8AD1D74B2922} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files (x86)\HomeTab\ProtectedSearch.exe No File
Task: {1D57B99B-8AB2-4AC9-BE59-EEB8DF2B3D50} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {1FD084E7-0FD9-4836-94DB-B0DFFF45DBA7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-16] (Adobe Systems Incorporated)
Task: {20B670F8-D495-43B4-B66F-6576E798D397} - System32\Tasks\DealPlyUpdate => C:\Program Files (x86)\DealPly\DealPlyUpdate.exe No File
Task: {2FB4A20B-1195-4F6F-98A9-B71131340E69} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {3438A74F-D30D-4DAE-AABD-8E4687FB1D39} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4060780361-2962197505-3855748707-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe No File
Task: {38490776-1286-491D-ABF7-4EF8E1016596} - System32\Tasks\Hoolapp Init => C:\Users\Lissi1\AppData\Roaming\HOOLAP~1\Hoolapp.exe No File
Task: {3A322291-9708-4AC4-BDA9-28080B9131D4} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4060780361-2962197505-3855748707-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe No File
Task: {3AA39623-4C26-4352-881B-32950C8DC3DC} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-4060780361-2962197505-3855748707-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe No File
Task: {3EA0857D-4881-4604-B1DD-D0141F5D725A} - System32\Tasks\Browser Updater\Browser Updater => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {41F95C5D-50D6-4CAD-BE33-AAA9619969EE} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe No File
Task: {4294D513-D50C-4121-9732-0675460C6D57} - System32\Tasks\Plus-HD-2.4-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-chromeinstaller.exe No File
Task: {43F0A8BC-3F41-4656-B2EE-CC75C64FABA2} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation)
Task: {45DAED8B-06FE-48E8-B603-79B9796F4EF7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04] (Google Inc.)
Task: {491EEB26-98AA-40E3-AF52-D1DD16938513} - System32\Tasks\Plus-HD-2.4-enabler => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-enabler.exe No File
Task: {4AA0C1DA-4F0B-4B12-BCF9-D46D829AC8EF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04] (Google Inc.)
Task: {5FF3B954-CCE0-4AEC-BDFC-43073F0D0DD0} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SelfUpdater\SoftwareUpdater.Ui.exe [2013-07-17] ()
Task: {66700F3D-2ABE-4082-87B8-8D546CAE53C0} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {69AD682C-3980-4A53-AAEF-CD4D2636270D} - System32\Tasks\Wise Registry Cleaner Schedule Task => C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe [2013-07-19] (WiseCleaner.com)
Task: {759FB95A-54DA-4844-A13C-E32642F2E977} - System32\Tasks\Plus-HD-2.4-updater => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-updater.exe No File
Task: {81E6757E-5936-461A-8C17-008E67EEF5B6} - System32\Tasks\DealPly => C:\Users\Lissi1\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE No File
Task: {86C19865-1960-4B4F-90EF-F356C010C886} - System32\Tasks\Software Updater => C:\Program Files (x86)\SelfUpdater\SoftwareUpdater.Bootstrapper.exe [2013-07-06] ()
Task: {8BC70FDF-C6CF-421C-9767-ACF6CE5E9963} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-21] (Microsoft Corporation)
Task: {8EACA554-38B1-446E-96DA-237BADAF8C14} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4060780361-2962197505-3855748707-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe No File
Task: {900ADC48-B10E-458D-BCD8-941E98E5B974} - System32\Tasks\Freemium1ClickMaint => C:\Program Files (x86)\Covus Freemium\Free System Utilities\1Click.exe No File
Task: {90DB39C7-E1DE-4F1B-9AAA-9F0CE40B6EBC} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2012-11-02] (Microsoft Corporation)
Task: {9144BDC4-7FBD-4921-A320-DF00D2A8E251} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2012-11-02] (Microsoft)
Task: {9CE62795-67B5-4A69-9724-9B8D0C043D46} - System32\Tasks\Plus-HD-2.4-codedownloader => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-codedownloader.exe No File
Task: {AD703A90-8D87-444F-A712-45B4ABC66271} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2012-11-02] (Microsoft Corporation)
Task: {ADEB3839-1313-431B-9387-D0B711B9B657} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BF0DAFDB-2D29-4DC0-883A-6449CDD05DD5} - System32\Tasks\SUPERAntiSpyware Scheduled Task b4eb2f77-0b34-4a31-8e76-89b6cbcecc1b => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com)
Task: {C3365C9E-CE3C-4414-89A8-558B613878AA} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation)
Task: {C86F2E05-0E17-4A66-88AB-FDA0560B733E} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe [2013-02-14] (Lavasoft Limited)
Task: {CDDF991A-9628-4933-BB0C-DA7D9E740C2F} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4060780361-2962197505-3855748707-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe No File
Task: {E2088BC0-2227-4FBB-8943-761C3507FF09} - System32\Tasks\SUPERAntiSpyware Scheduled Task 33915243-1829-4197-b765-f2f614375d1b => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com)
Task: {EE6C8F1E-50BA-409C-9705-B4AAA515AC87} - System32\Tasks\Hoolapp for Android => C:\Users\Lissi1\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE No File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-chromeinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-codedownloader.exe
Task: C:\Windows\Tasks\Plus-HD-2.4-enabler.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-enabler.exe
Task: C:\Windows\Tasks\Plus-HD-2.4-updater.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-updater.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 33915243-1829-4197-b765-f2f614375d1b.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b4eb2f77-0b34-4a31-8e76-89b6cbcecc1b.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\Wise Registry Cleaner Schedule Task.job => C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe

==================== Faulty Device Manager Devices =============

Name: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Description: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek Semiconductor Corp.
Service: RTL8192su
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/12/2013 06:15:15 PM) (Source: MemeoBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (08/12/2013 03:54:54 PM) (Source: MemeoBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (08/12/2013 01:24:42 PM) (Source: MemeoBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (08/12/2013 08:17:44 AM) (Source: MsiInstaller) (User: NT-AUTORITÄT)
Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (08/11/2013 08:16:23 PM) (Source: MemeoBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (08/11/2013 06:47:03 PM) (Source: System Restore) (User: )
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Windows-Sicherung). Zusätzliche Informationen: 0x8000ffff.

Error: (08/11/2013 06:45:35 PM) (Source: MemeoBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (08/11/2013 06:36:58 PM) (Source: System Restore) (User: )
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Windows-Sicherung). Zusätzliche Informationen: 0x8000ffff.

Error: (08/11/2013 06:36:12 PM) (Source: MemeoBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (08/11/2013 05:04:46 PM) (Source: System Restore) (User: )
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Windows-Sicherung). Zusätzliche Informationen: 0x8000ffff.


System errors:
=============
Error: (08/12/2013 06:18:46 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{42036434-BD32-45B5-89BB-BED2AEAA9F2C}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (08/12/2013 04:33:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (08/12/2013 04:33:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (08/12/2013 04:33:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (08/12/2013 04:33:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (08/12/2013 04:33:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (08/12/2013 04:33:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (08/12/2013 04:32:58 PM) (Source: DCOM) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (08/12/2013 04:32:58 PM) (Source: DCOM) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (08/12/2013 04:32:56 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068


Microsoft Office Sessions:
=========================
Error: (07/23/2013 06:51:30 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: LISSI1-PC, Application Version: LISSI1-PC, Microsoft Office Version: 12.0.6612.1000. This session lasted LISSI1-PC seconds with 0 seconds of active time.  This session ended with a crash.

Error: (07/23/2013 06:50:57 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2013-08-06 10:26:37.912
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-08-06 10:26:37.881
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-08-05 16:09:11.869
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-05 14:22:39.572
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-05 12:49:07.294
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-05 12:36:28.451
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-05 12:21:33.053
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-05 11:30:50.054
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-05 11:11:14.377
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-05 11:06:07.710
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 63%
Total physical RAM: 4023.11 MB
Available physical RAM: 1484.23 MB
Total Pagefile: 8044.41 MB
Available Pagefile: 4637.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (Boot) (Fixed) (Total:1346.17 GB) (Free:1272.22 GB) NTFS (Disk=0 Partition=2)
Drive d: (Recover) (Fixed) (Total:50 GB) (Free:31.19 GB) NTFS (Disk=0 Partition=3)
Drive j: (Volume) (Fixed) (Total:1863.01 GB) (Free:195.27 GB) NTFS (Disk=1 Partition=1)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 1397 GB) (Disk ID: C0F66F80)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=-753589551104) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: BC49D5D0)
Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS)

==================== End Of Log ============================

--- --- ---

markusg 12.08.2013 18:39

Die beschriftungen in der Additions.txt fehlen

baby-lissa 12.08.2013 19:04

d-Aware Antivirus (x32 Version: 10.5.0.4339) nötig
Adobe AIR (x32 Version: 3.1.0.4880) unbekannt
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94) nötig
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) vermutlich nötig
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) nötig
Adobe Shockwave Player 11.6 (x32 Version: 11.6.5.635) nötig
Alamandi (x32) unnötig
AMD APP SDK Runtime (Version: 2.5.793.1) vermutlich nötig
AMD AVIVO64 Codecs (Version: 11.7.0.11013) vermutlich nötig
AMD Catalyst Install Manager (Version: 3.0.851.0) nötig
AMD Drag and Drop Transcoding (Version: 2.00.0000) vermutlich nötig
AMD Media Foundation Decoders (Version: 1.0.61013.1636) vermutlich nötig
Angry Birds Star Wars (x32 Version: 1.0.0) unnötig
Apple Application Support (x32 Version: 2.3) unbekannt
Apple Software Update (x32 Version: 2.1.3.127) unbekannt
AVIConverter 5.1.6 (x32 Version: 5.1.6) nötig
Avira Free Antivirus (x32 Version: 13.0.0.3885) nötig
AVS Update Manager 1.0 (x32) unnötig
AVS Video Converter 8 (x32) unnötig
AVS4YOU Software Navigator 1.4 (x32) unnötig
Biet-O-Matic v2.14.8 (x32 Version: Biet-O-Matic v2.14.8) unnötig
Canon Easy-PhotoPrint EX (x32) nötig
Canon iP4900 series Benutzerregistrierung (x32) nötig
Canon iP4900 series On-screen Manual (x32) nötig
Canon iP4900 series Printer Driver nötig
Canon My Printer (x32) nötig
Catalyst Control Center (x32 Version: 2011.1013.1702.28713) vermutlich nötig
Catalyst Control Center InstallProxy (x32 Version: 2011.1013.1702.28713) vermutlich nötig
Catalyst Control Center Localization All (x32 Version: 2011.1013.1702.28713) vermutlich nötig
CCC Help Danish (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help Dutch (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help English (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help Finnish (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help French (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help German (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help Italian (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help Japanese (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help Norwegian (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help Spanish (x32 Version: 2011.1013.1701.28713) unbekannt
CCC Help Swedish (x32 Version: 2011.1013.1701.28713) unbekannt
ccc-utility64 (Version: 2011.1013.1702.28713) unbekannt
CD-LabelPrint (x32) nötig
Color!It 1.5 Professional-E (x32) nötig
ContentHD (x32 Version: 1.00.0002) unbekannt
Contents (x32 Version: 1.6.0.367) unbekannt
Contents (x32 Version: 1.6.1.137) unbekannt
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2) unbekannt
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2) unbekannt
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2) unbekannt
Corel Painter Photo Essentials 4 (x32 Version: 4.1) nötig
Corel Painter Photo Essentials 4 (x32) nötig
Corel PaintShop Photo Pro X3 (x32 Version: 1.00.0000) nötig
Corel PaintShop Photo Pro X3 (x32 Version: 1.6.1.137) nötig
Corel VideoStudio Pro X3 (x32 Version: 1.6.0.367) nötig
CyberLink LabelPrint (x32 Version: 2.5.3624) nötig
CyberLink Power2Go (x32 Version: 7.0.0.1327) nötig
CyberLink PowerDVD Copy (x32 Version: 1.5.1306) nötig
CyberLink PowerRecover (x32 Version: 5.5.4125) nötig
CyberLink WaveEditor (x32 Version: 1.0.1.2821) nötig
D3DX10 (x32 Version: 15.4.2368.0902) unbekannt
Deaktivierungs-Add-on für Browser von Google Analytics (x32 Version: 0.9.2.0) unbekannt
Der wunderbare Zauberer von Oz (x32) nötig
DeviceIO (x32 Version: 1.6.0.367) unbekannt
DeviceIO (x32 Version: 1.6.1.137) unbekannt
Die Sage von Kolossus (x32) nötig
Dropbox (HKCU Version: 2.0.22) nötig
DVD Shrink 3.2 (x32) nötig
FarmFrenzy (x32) nötig
FLV Media Player version 1.3 (x32 Version: 1.3) nötig
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2) unbekannt
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922) unbekannt
Free Video to MP3 Converter version 5.0.24.430 (x32 Version: 5.0.24.430)unnötig
Free YouTube Download version 3.2.2.430 (x32 Version: 3.2.2.430)unnötig
Free YouTube to MP3 Converter version 3.12.0.128 (x32 Version: 3.12.0.128)unnötig
Freez FLV to AVI/MPEG/WMV Converter (x32 Version: 1.6) unnötig
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)unbekannt
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922) unbekannt
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922) unbekannt
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922) unbekannt
Google Chrome (x32 Version: 28.0.1500.95) unnötig
Google Update Helper (x32 Version: 1.3.21.153) unbekannt
ICA (x32 Version: 1.6.0.367) unbekannt
ICA (x32 Version: 1.6.1.137) unbekannt
Intel(R) Rapid Storage Technology (x32 Version: 10.6.0.1002) unbekannt
IPM_PSP_Pro (x32 Version: 1.00.0000) unbekannt
IPM_VS_Pro (x32 Version: 13.0) unbekannt
Java 7 Update 21 (64-bit) (Version: 7.0.210) nötig
Java 7 Update 21 (x32 Version: 7.0.210) unnötig
Java Auto Updater (x32 Version: 2.1.9.5) unbekannt
Junk Mail filter update (x32 Version: 15.4.3502.0922) unbekannt
Kaufland Foto (x32 Version: 5.0.1) nötig
Kernel for Outlook PST Repair Evaluation ver 13.02.01 (x32) nötig
Klett Lernsoftware Mathematik - mathe live 5 BA (x32) nötig
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (x32 Version: 15.4.5722.2) unbekannt
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) nötig
Medion Home Cinema (x32 Version: 8.0.3216) nötig
Memeo Instant Backup (x32 Version: 4.60.0.7943) unbekannt
Mesh Runtime (x32 Version: 15.4.5722.2) unbekannt
Microsoft Application Error Reporting (Version: 12.0.6015.5000) unbekannt
Microsoft Office 2007 Service Pack 3 (SP3) (x32) nötig
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) nötig
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) vermutlich nötig
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlivh nötig
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) vermutlich nötig
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) vermutlich nötig
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) vermutlich nötig
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) vermutlich nötig
Microsoft Silverlight (Version: 5.1.20513.0) unbekannt
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) unbekannt
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) unbekannt
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) unbekannt
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) unbekannt
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) unbekannt
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) unbekannt
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) unbekannt
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) unbekannt
Microsoft-Maus- und Tastatur-Center (Version: 2.0.162.0) nötig
Microtek FineReader OCR Engine (x32) unbekannt
MLE (x32 Version: 1.0.0.23) unbekannt
MSVC80_x64_v2 (Version: 1.0.3.0) unbekannt
MSVC80_x86_v2 (x32 Version: 1.0.3.0) unbekannt
MSVC90_x64 (Version: 1.0.1.2) unbekannt
MSVC90_x86 (x32 Version: 1.0.1.2) unbekannt
MSVCRT (x32 Version: 15.4.2862.0708) unbekannt
MSVCRT_amd64 (x32 Version: 15.4.2862.0708) unbekannt
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) unbekannt
MyFreeCodec (HKCU) unbekannt
MyPhoneExplorer (x32 Version: 1.8.4) nötig
OpenMG Limited Patch 4.7-07-14-05-01 (x32) unbekannt
OpenMG Secure Module (x32 Version: 4.7.00.12140) unbekannt
OpenMG Secure Module 4.7.00 (x32 Version: 4.7.00.12140) unbekannt
PlayReady PC Runtime amd64 (Version: 1.3.0) unbekannt
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922) unbekannt
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922) unbekannt
Pošta Windows Live (x32 Version: 15.4.3502.0922) unbekannt
PSPH10Pro (x32 Version: 1.00.0000) unbekannt
PSPPContent (x32 Version: 1.00.0000) unbekannt
PSPPRO_DCRAW (x32 Version: 13.0.0) unbekannt
PureHD (x32 Version: 1.6.0.367) unbekannt
PureHD (x32 Version: 1.6.1.137) unbekannt
QuickShare (x32 Version: 1.6.1.714) unbekannt
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922) unbekannt
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6438) nötig
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.25.0) vermutlich nötig
rosoft .NET Framework 4 Client Profile (Version: 4.0.30320) unbekannt
Samsung Kies (x32 Version: 2.3.2.12064_9) nötig
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.16.0) nötig
ScanWizard 5 (x32) nötig
Setup (x32 Version: 1.6.0.367) unbekannt
Setup (x32 Version: 1.6.1.137) unbekannt
Share (x32 Version: 1.6.0.367) unbekannt
Share (x32 Version: 1.6.1.137) unbekannt
Share64 (Version: 1.6.0.367) unbekannt
Share64 (Version: 1.6.1.137) unbekannt
Skype Click to Call (x32 Version: 6.3.11079) nötig
Skype™ 6.5 (x32 Version: 6.5.158) nötig
SmartSound Common Data (x32 Version: 1.1.0) unbekannt
SmartSound Quicktracks 5 (x32 Version: 5.1.5) unbekannt
SonicStage 4.3 (x32 Version: 4.3) unbekannt
Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0) unbekannt
Stellar Phoenix Outlook PST Repair (x32 Version: 4.5.0.0) nötig
SUPERAntiSpyware (Version: 5.6.1020) vermutlich nötig
swMSM (x32 Version: 12.0.0.1) unbekannt
TeamSpeak 3 Client (Version: 3.0.10) nötig
TeamViewer 7 (x32 Version: 7.0.13852) nötig
Uniblue DriverScanner (x32 Version: 4.0.9.10) unbekannt
Update for 2007 Microsoft Office System (KB967642) (x32) unbekannt
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) unbekannt
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) unbekannt
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) unbekannt
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) unbekannt
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) unbekannt
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) unbekannt
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32) unbekannt
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) unbekannt
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) unbekannt
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) unbekannt
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) unbekannt
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32) unbekannt
Update für Microsoft Office Excel 2007 Help (KB963678) (x32) unbekannt
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) unbekannt
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) unbekannt
Update für Microsoft Office Word 2007 Help (KB963665) (x32) unbekannt
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2) unbekannt
VC 9.0 Runtime (x32 Version: 1.0.0) unbekannt
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) unbekannt
Versandhelfer (x32 Version: 0.9.511) unnötig
VIO (x32 Version: 1.6.0.367) unbekannt
VIO (x32 Version: 1.6.1.137) unbekannt
VSClassic (x32 Version: 1.6.0.367) unbekannt
VSPro (x32 Version: 1.6.0.367) unbekannt
Windows Live Communications Platform (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Essentials (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Essentials (x32 Version: 15.4.3555.0308) unbekannt
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Fotótár (x32 Version: 15.4.3502.0922) unbekannt
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) unbekannt
Windows Live Installer (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Language Selector (Version: 15.4.3555.0308) unbekannt
Windows Live Mail (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2) unbekannt
Windows Live Mesh (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) unbekannt
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2) unbekannt
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2) unbekannt
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2) unbekannt
Windows Live Messenger (x32 Version: 15.4.3538.0513) unnötig
Windows Live MIME IFilter (Version: 15.4.3502.0922) unbekannt
Windows Live Movie Maker (x32 Version: 15.4.3502.0922) nötig
Windows Live Photo Common (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) unbekannt
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) unbekannt
Windows Live Remote Client (Version: 15.4.5722.2) unbekannt
Windows Live Remote Client Resources (Version: 15.4.5722.2) unbekannt
Windows Live Remote Service (Version: 15.4.5722.2) unbekannt
Windows Live Remote Service Resources (Version: 15.4.5722.2) unbekannt
Windows Live SOXE (x32 Version: 15.4.3502.0922) unbekannt
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922) unbekannt
Windows Live UX Platform (x32 Version: 15.4.3502.0922) unbekannt
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) unbekannt
Windows Live Writer (x32 Version: 15.4.3502.0922) unbekannt
Windows Live Writer Resources (x32 Version: 15.4.3502.0922) unbekannt
Windows Media Encoder 9 Series (x32 Version: 9.00.2980) unbekannt
Windows Media Encoder 9 Series (x32) unbekannt
Windows Utils (x32) unbekannt
WinRAR 4.10 (64-Bit) (Version: 4.10.0) nötig
Wise Registry Cleaner 7.82 (x32 Version: 7.82) unnötig
WISO Steuer-Sparbuch 2012 (x32 Version: 19.00.7303) nötig
WISO Steuer-Sparbuch 2013 (x32 Version: 20.00.8137) nötig
Yahoo! Messenger (x32) nötig
Yahoo! Software Update (x32) unbekannt
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922) unbekannt

sorry habe ich nachgeleifert

markusg 12.08.2013 19:15

Hi,
es sind 2 Logs zu erstellen, möglichst gleichzeitig posten.
1.
deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden, instalieren.
adobe reader:
bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
Sicherheit (erweitert)
Erweiterte Sicherheit anhaken
und alle Dateien auswählen.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok

deinstaliere:
Alamandi
Angry
AVS: alle
Biet-O
Free : alle
Freez
Google Chrome
Java 7 : beide
downloade Java jre:
Java-Downloads für alle Betriebssysteme
klicke:
Download der Java-Software für Windows Offline
laden, und instalieren
deinstaliere:
Spelling
SUPERAntiSpyware : weg damit, findet meist nur kookies. behalte malwarebytes, ist sinnvoller.
TeamViewer : würd ich nur bei Bedarf instalieren, wenns drauf bleiben soll, Upgrade auf Version8
Uniblue
Versandhelfer
Wise Registry : finger weg von registry cleanern, sie können dem System schaden.

starte neu.
2.
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


3.
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

baby-lissa 12.08.2013 19:28

was ist uniblue???

markusg 12.08.2013 19:39

driver scanner, sollte entweder in der systemsteuerung, programme deinstalieren oder in rewo stehen

baby-lissa 12.08.2013 20:05

Combofix Logfile:
Code:

ComboFix 13-08-12.01 - Lissi1 12.08.2013  20:53:39.2.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4023.1851 [GMT 2:00]
ausgeführt von:: c:\users\Lissi1\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
 * Im Speicher befindliches AV aktiv.
.
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Lissi1\~Outlooklissa.pst.tmp
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-07-12 bis 2013-08-12  ))))))))))))))))))))))))))))))
.
.
2013-08-12 19:01 . 2013-08-12 19:01        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-08-12 18:41 . 2013-08-12 18:41        312232        ----a-w-        c:\windows\system32\javaws.exe
2013-08-12 18:41 . 2013-08-12 18:41        189352        ----a-w-        c:\windows\system32\javaw.exe
2013-08-12 18:41 . 2013-08-12 18:41        188840        ----a-w-        c:\windows\system32\java.exe
2013-08-12 18:41 . 2013-08-12 18:41        108968        ----a-w-        c:\windows\system32\WindowsAccessBridge-64.dll
2013-08-12 18:41 . 2013-08-12 18:41        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-12 18:41 . 2013-08-12 18:41        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-12 09:03 . 2013-08-12 18:39        --------        d-----w-        c:\users\Lissi1\AppData\Local\Adobe
2013-08-12 08:59 . 2013-08-12 11:25        --------        d-----w-        c:\users\Lissi1\AppData\Local\adawarebp
2013-08-12 05:17 . 2013-08-12 05:17        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-12 04:44 . 2013-08-12 04:44        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-12 04:44 . 2013-04-04 12:50        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-08-11 18:06 . 2013-08-12 04:33        --------        d-----w-        c:\program files (x86)\Eusing Free Registry Cleaner
2013-08-11 14:37 . 2013-08-11 14:37        --------        d-----w-        C:\found.000
2013-08-07 17:58 . 2013-08-11 14:06        --------        d-----w-        c:\program files (x86)\Plus-HD-2.4
2013-08-07 08:31 . 2013-08-07 08:31        --------        d-----w-        c:\program files\Enigma Software Group
2013-08-07 08:30 . 2013-08-07 09:35        --------        d-----w-        c:\windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 08:30 . 2013-08-07 08:30        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-07 08:23 . 2013-04-17 07:02        1230336        ----a-w-        c:\windows\SysWow64\WindowsCodecs.dll
2013-08-07 08:23 . 2013-04-17 06:24        1424384        ----a-w-        c:\windows\system32\WindowsCodecs.dll
2013-08-07 08:14 . 2013-08-07 08:14        --------        d-----w-        C:\FRST
2013-08-06 16:55 . 2013-04-02 22:51        1643520        ----a-w-        c:\windows\system32\DWrite.dll
2013-08-06 16:55 . 2013-04-09 23:34        1247744        ----a-w-        c:\windows\SysWow64\DWrite.dll
2013-08-06 16:13 . 2012-03-14 03:00        385024        ----a-w-        c:\windows\system32\CNMLMAW.DLL
2013-08-06 16:00 . 2012-08-24 18:05        340992        ----a-w-        c:\windows\system32\schannel.dll
2013-08-06 16:00 . 2012-08-24 16:57        247808        ----a-w-        c:\windows\SysWow64\schannel.dll
2013-08-06 16:00 . 2012-08-24 18:13        154480        ----a-w-        c:\windows\system32\drivers\ksecpkg.sys
2013-08-06 16:00 . 2012-08-24 18:09        458712        ----a-w-        c:\windows\system32\drivers\cng.sys
2013-08-06 16:00 . 2012-08-24 18:03        1448448        ----a-w-        c:\windows\system32\lsasrv.dll
2013-08-06 16:00 . 2012-08-24 16:57        22016        ----a-w-        c:\windows\SysWow64\secur32.dll
2013-08-06 16:00 . 2012-08-24 16:53        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll
2013-08-06 12:38 . 2013-08-06 12:38        9728        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 08:54 . 2013-04-10 06:01        265064        ----a-w-        c:\windows\system32\drivers\dxgmms1.sys
2013-08-06 08:54 . 2013-04-10 06:01        983400        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys
2013-08-06 08:54 . 2011-02-03 11:25        144384        ----a-w-        c:\windows\system32\cdd.dll
2013-08-06 08:54 . 2013-05-08 06:39        1910632        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-08-06 08:54 . 2013-01-03 06:00        288088        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2013-08-06 08:54 . 2013-02-27 05:52        14172672        ----a-w-        c:\windows\system32\shell32.dll
2013-08-06 08:54 . 2013-02-27 05:52        197120        ----a-w-        c:\windows\system32\shdocvw.dll
2013-08-06 08:54 . 2013-02-27 05:48        1930752        ----a-w-        c:\windows\system32\authui.dll
2013-08-06 08:54 . 2013-02-27 06:02        111448        ----a-w-        c:\windows\system32\consent.exe
2013-08-06 08:54 . 2013-02-27 05:47        70144        ----a-w-        c:\windows\system32\appinfo.dll
2013-08-06 08:54 . 2013-02-27 04:49        1796096        ----a-w-        c:\windows\SysWow64\authui.dll
2013-08-06 08:52 . 2013-06-05 03:34        3153920        ----a-w-        c:\windows\system32\win32k.sys
2013-08-06 08:52 . 2013-05-10 05:49        30720        ----a-w-        c:\windows\system32\cryptdlg.dll
2013-08-06 08:52 . 2013-05-10 03:20        24576        ----a-w-        c:\windows\SysWow64\cryptdlg.dll
2013-08-06 08:52 . 2013-04-10 05:48        1732608        ----a-w-        c:\program files\Windows Journal\NBDoc.DLL
2013-08-06 08:52 . 2013-04-10 05:46        1367040        ----a-w-        c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-08-06 08:52 . 2013-04-10 05:46        1402880        ----a-w-        c:\program files\Windows Journal\JNWDRV.dll
2013-08-06 08:52 . 2013-04-10 05:46        1393152        ----a-w-        c:\program files\Windows Journal\JNTFiltr.dll
2013-08-06 08:52 . 2013-04-10 05:03        936448        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-08-06 08:52 . 2013-01-24 06:01        223752        ----a-w-        c:\windows\system32\drivers\fvevol.sys
2013-08-06 08:51 . 2013-05-13 05:51        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2013-08-06 08:51 . 2013-05-13 05:51        1464320        ----a-w-        c:\windows\system32\crypt32.dll
2013-08-06 08:51 . 2013-05-13 04:45        1160192        ----a-w-        c:\windows\SysWow64\crypt32.dll
2013-08-06 08:51 . 2013-05-13 03:43        1192448        ----a-w-        c:\windows\system32\certutil.exe
2013-08-06 08:51 . 2013-05-13 03:08        903168        ----a-w-        c:\windows\SysWow64\certutil.exe
2013-08-06 08:51 . 2013-05-13 05:51        139776        ----a-w-        c:\windows\system32\cryptnet.dll
2013-08-06 08:51 . 2013-05-13 05:50        52224        ----a-w-        c:\windows\system32\certenc.dll
2013-08-06 08:51 . 2013-05-13 04:45        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2013-08-06 08:51 . 2013-05-13 04:45        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2013-08-06 08:51 . 2013-05-13 03:08        43008        ----a-w-        c:\windows\SysWow64\certenc.dll
2013-08-06 08:50 . 2013-03-19 06:04        5550424        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-08-06 08:50 . 2013-03-19 05:04        3968856        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2013-08-06 08:50 . 2013-03-19 05:04        3913560        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2013-08-06 08:50 . 2013-03-19 03:06        112640        ----a-w-        c:\windows\system32\smss.exe
2013-08-06 08:50 . 2013-03-19 05:46        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2013-08-06 08:50 . 2013-03-19 04:47        6656        ----a-w-        c:\windows\SysWow64\apisetschema.dll
2013-08-06 08:50 . 2013-04-25 23:30        1505280        ----a-w-        c:\windows\SysWow64\d3d11.dll
2013-08-06 08:50 . 2013-03-31 22:52        1887232        ----a-w-        c:\windows\system32\d3d11.dll
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\programdata\Malwarebytes
2013-08-05 10:26 . 2013-08-06 22:09        --------        d-----w-        c:\program files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 09:49 . 2013-08-05 09:49        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Avira
2013-08-05 09:44 . 2013-08-05 09:44        83672        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
2013-08-05 09:42 . 2013-08-05 09:35        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-08-05 09:42 . 2013-08-05 09:35        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-08-05 09:42 . 2013-08-05 09:35        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-08-05 09:42 . 2013-08-05 09:43        --------        d-----w-        c:\programdata\Avira
2013-08-05 09:42 . 2013-08-05 09:42        --------        d-----w-        c:\program files (x86)\Avira
2013-07-23 16:47 . 2013-07-23 16:47        --------        d-----w-        c:\users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 16:20 . 2013-07-29 16:44        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 16:20 . 2013-08-01 01:08        32328        ----a-w-        c:\windows\Launcher.exe
2013-07-17 16:43 . 2013-07-17 16:43        --------        d-----w-        c:\users\Lissi1\AppData\Local\Deployment
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-12 18:41 . 2012-12-16 15:13        1093032        ----a-w-        c:\windows\system32\npDeployJava1.dll
2013-08-12 18:41 . 2011-07-18 21:14        972712        ----a-w-        c:\windows\system32\deployJava1.dll
2013-06-23 22:57 . 2011-07-18 20:31        78277128        ----a-w-        c:\windows\system32\MRT.exe
2013-05-15 06:13 . 2011-03-29 01:36        22240        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-12-20 844296]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-14 343168]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-01-31 542632]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-08-05 345144]
.
c:\users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
net.lnk - c:\users\Lissi1\AppData\Roaming\Windows Net Data\net.exe [2013-7-23 709120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Scanner Finder.lnk - c:\program files (x86)\ScanWizard 5\ScannerFinder.exe [2012-2-4 344064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled\
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe [2013-5-17 1393744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS;c:\windows\SYSNATIVE\DRIVERS\PFC027.SYS [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [x]
S2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 50864556
*Deregistered* - 50864556
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-12 18:41]
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 12673128]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944]
"IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - eBay - eine der größten deutschen Shopping-Websites
IE: {{92808042-fb78-4fa0-bb4f-c9a95e0e9c10} - {ba696155-d96e-4281-b467-0367a0456474} -
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)
WebBrowser-{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - (no file)
WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - (no file)
AddRemove-Adobe Flash Player ActiveX - c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
AddRemove-_{707EB912-C597-49D8-9460-46CC9AB03EBE} - c:\program files (x86)\Corel\Corel Painter Photo Essentials 4\MSILauncher {707EB912-C597-49D8-9460-46CC9AB03EBE}
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ba696155-d96e-4281-b467-0367a0456474}]
@Denied: (A 2) (Administrators)
@Denied: (A 2) (S-1-5-21-4060780361-2962197505-3855748707-1000)
"Flags"=dword:00000400
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32]
@DACL=(02 0000)
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-12  21:03:01
ComboFix-quarantined-files.txt  2013-08-12 19:03
ComboFix2.txt  2013-08-06 08:33
.
Vor Suchlauf: 15 Verzeichnis(se), 1.376.416.366.592 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 1.376.293.629.952 Bytes frei
.
- - End Of File - - 75C97ADD0078F14CDF79A6EE2965772D

--- --- ---
D41D8CD98F00B204E9800998ECF8427E

soll jetzt ein Neustart gemacht werden oder erst TDSKiller laufen lassen?
WAS ist drivescanner? habe ich nicht in der Systemsteuerung

markusg 12.08.2013 20:06

Hi, warum wurde combofix schon mal ausgeführt?
poste mal noch die
ComboFix-quarantined-files.txt

baby-lissa 12.08.2013 20:14

ich habe combfix noch nie ausgefürt und das ist kleider alles was ich posten konnte

combofix hat nur die eine txt aufgemacht sonnst nichts

21:09:34.0661 3700 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:09:34.0880 3700 ============================================================
21:09:34.0880 3700 Current date / time: 2013/08/12 21:09:34.0880
21:09:34.0880 3700 SystemInfo:
21:09:34.0880 3700
21:09:34.0880 3700 OS Version: 6.1.7601 ServicePack: 1.0
21:09:34.0880 3700 Product type: Workstation
21:09:34.0880 3700 ComputerName: LISSI1-PC
21:09:34.0880 3700 UserName: Lissi1
21:09:34.0880 3700 Windows directory: C:\Windows
21:09:34.0880 3700 System windows directory: C:\Windows
21:09:34.0880 3700 Running under WOW64
21:09:34.0880 3700 Processor architecture: Intel x64
21:09:34.0880 3700 Number of processors: 4
21:09:34.0880 3700 Page size: 0x1000
21:09:34.0880 3700 Boot type: Normal boot
21:09:34.0880 3700 ============================================================
21:09:35.0270 3700 Drive \Device\Harddisk0\DR0 - Size: 0x15D50F66000 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:09:35.0270 3700 Drive \Device\Harddisk1\DR1 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:09:35.0301 3700 ============================================================
21:09:35.0301 3700 \Device\Harddisk0\DR0:
21:09:35.0301 3700 MBR partitions:
21:09:35.0301 3700 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
21:09:35.0301 3700 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xA8454800
21:09:35.0301 3700 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xA8487000, BlocksNum 0x6400000
21:09:35.0301 3700 \Device\Harddisk1\DR1:
21:09:35.0301 3700 MBR partitions:
21:09:35.0301 3700 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800
21:09:35.0301 3700 ============================================================
21:09:35.0316 3700 C: <-> \Device\Harddisk0\DR0\Partition2
21:09:35.0363 3700 D: <-> \Device\Harddisk0\DR0\Partition3
21:09:35.0394 3700 J: <-> \Device\Harddisk1\DR1\Partition1
21:09:35.0394 3700 ============================================================
21:09:35.0394 3700 Initialize success
21:09:35.0394 3700 ============================================================
21:09:37.0968 2112 ============================================================
21:09:37.0968 2112 Scan started
21:09:37.0968 2112 Mode: Manual;
21:09:37.0968 2112 ============================================================
21:09:38.0499 2112 ================ Scan system memory ========================
21:09:38.0499 2112 System memory - ok
21:09:38.0499 2112 ================ Scan services =============================
21:09:38.0609 2112 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
21:09:38.0609 2112 1394ohci - ok
21:09:38.0640 2112 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
21:09:38.0640 2112 ACPI - ok
21:09:38.0687 2112 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
21:09:38.0687 2112 AcpiPmi - ok
21:09:38.0765 2112 [ 3F59267F038747E89BA97CD11388748D ] Ad-Aware Service C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
21:09:38.0765 2112 Ad-Aware Service - ok
21:09:38.0827 2112 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:09:38.0827 2112 AdobeARMservice - ok
21:09:38.0999 2112 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:09:38.0999 2112 AdobeFlashPlayerUpdateSvc - ok
21:09:39.0030 2112 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
21:09:39.0046 2112 adp94xx - ok
21:09:39.0077 2112 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
21:09:39.0077 2112 adpahci - ok
21:09:39.0108 2112 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
21:09:39.0108 2112 adpu320 - ok
21:09:39.0139 2112 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:09:39.0139 2112 AeLookupSvc - ok
21:09:39.0155 2112 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
21:09:39.0171 2112 AFD - ok
21:09:39.0186 2112 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
21:09:39.0202 2112 agp440 - ok
21:09:39.0202 2112 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
21:09:39.0202 2112 ALG - ok
21:09:39.0233 2112 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
21:09:39.0233 2112 aliide - ok
21:09:39.0264 2112 [ C08ADE825268D291AFE06EDA71415C7D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:09:39.0264 2112 AMD External Events Utility - ok
21:09:39.0280 2112 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
21:09:39.0295 2112 amdide - okr

21:09:34.0661 3700 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:09:34.0880 3700 ============================================================
21:09:34.0880 3700 Current date / time: 2013/08/12 21:09:34.0880
21:09:34.0880 3700 SystemInfo:
21:09:34.0880 3700
21:09:34.0880 3700 OS Version: 6.1.7601 ServicePack: 1.0
21:09:34.0880 3700 Product type: Workstation
21:09:34.0880 3700 ComputerName: LISSI1-PC
21:09:34.0880 3700 UserName: Lissi1
21:09:34.0880 3700 Windows directory: C:\Windows
21:09:34.0880 3700 System windows directory: C:\Windows
21:09:34.0880 3700 Running under WOW64
21:09:34.0880 3700 Processor architecture: Intel x64
21:09:34.0880 3700 Number of processors: 4
21:09:34.0880 3700 Page size: 0x1000
21:09:34.0880 3700 Boot type: Normal boot
21:09:34.0880 3700 ============================================================
21:09:35.0270 3700 Drive \Device\Harddisk0\DR0 - Size: 0x15D50F66000 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:09:35.0270 3700 Drive \Device\Harddisk1\DR1 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:09:35.0301 3700 ============================================================
21:09:35.0301 3700 \Device\Harddisk0\DR0:
21:09:35.0301 3700 MBR partitions:
21:09:35.0301 3700 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
21:09:35.0301 3700 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xA8454800
21:09:35.0301 3700 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xA8487000, BlocksNum 0x6400000
21:09:35.0301 3700 \Device\Harddisk1\DR1:
21:09:35.0301 3700 MBR partitions:
21:09:35.0301 3700 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800
21:09:35.0301 3700 ============================================================
21:09:35.0316 3700 C: <-> \Device\Harddisk0\DR0\Partition2
21:09:35.0363 3700 D: <-> \Device\Harddisk0\DR0\Partition3
21:09:35.0394 3700 J: <-> \Device\Harddisk1\DR1\Partition1
21:09:35.0394 3700 ============================================================
21:09:35.0394 3700 Initialize success
21:09:35.0394 3700 ============================================================
21:09:37.0968 2112 ============================================================
21:09:37.0968 2112 Scan started
21:09:37.0968 2112 Mode: Manual;
21:09:37.0968 2112 ============================================================
21:09:38.0499 2112 ================ Scan system memory ========================
21:09:38.0499 2112 System memory - ok
21:09:38.0499 2112 ================ Scan services =============================
21:09:38.0609 2112 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
21:09:38.0609 2112 1394ohci - ok
21:09:38.0640 2112 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
21:09:38.0640 2112 ACPI - ok
21:09:38.0687 2112 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
21:09:38.0687 2112 AcpiPmi - ok
21:09:38.0765 2112 [ 3F59267F038747E89BA97CD11388748D ] Ad-Aware Service C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
21:09:38.0765 2112 Ad-Aware Service - ok
21:09:38.0827 2112 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:09:38.0827 2112 AdobeARMservice - ok
21:09:38.0999 2112 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:09:38.0999 2112 AdobeFlashPlayerUpdateSvc - ok
21:09:39.0030 2112 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
21:09:39.0046 2112 adp94xx - ok
21:09:39.0077 2112 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
21:09:39.0077 2112 adpahci - ok
21:09:39.0108 2112 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
21:09:39.0108 2112 adpu320 - ok
21:09:39.0139 2112 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:09:39.0139 2112 AeLookupSvc - ok
21:09:39.0155 2112 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
21:09:39.0171 2112 AFD - ok
21:09:39.0186 2112 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
21:09:39.0202 2112 agp440 - ok
21:09:39.0202 2112 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
21:09:39.0202 2112 ALG - ok
21:09:39.0233 2112 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
21:09:39.0233 2112 aliide - ok
21:09:39.0264 2112 [ C08ADE825268D291AFE06EDA71415C7D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:09:39.0264 2112 AMD External Events Utility - ok
21:09:39.0280 2112 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
21:09:39.0295 2112 amdide - ok

markusg 12.08.2013 20:16

Hi, combofix wurde bereits ausgeführt, und zwar am 08.06
navigiere bitte auf c: und poste mir die C:\ComboFix.txt
adwcleaner wurde auch schon ausgeführt
C:\AdwCleaner(nummer)txt benöitge ich auch
außerdem TDSS Killer nach anleitung konfigurieren, Log posten

baby-lissa 12.08.2013 20:27

Combofix Logfile:
Code:

ComboFix 13-08-12.01 - Lissi1 12.08.2013  20:53:39.2.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4023.1851 [GMT 2:00]
ausgeführt von:: c:\users\Lissi1\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
 * Im Speicher befindliches AV aktiv.
.
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Lissi1\~Outlooklissa.pst.tmp
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-07-12 bis 2013-08-12  ))))))))))))))))))))))))))))))
.
.
2013-08-12 19:01 . 2013-08-12 19:01        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-08-12 18:41 . 2013-08-12 18:41        312232        ----a-w-        c:\windows\system32\javaws.exe
2013-08-12 18:41 . 2013-08-12 18:41        189352        ----a-w-        c:\windows\system32\javaw.exe
2013-08-12 18:41 . 2013-08-12 18:41        188840        ----a-w-        c:\windows\system32\java.exe
2013-08-12 18:41 . 2013-08-12 18:41        108968        ----a-w-        c:\windows\system32\WindowsAccessBridge-64.dll
2013-08-12 18:41 . 2013-08-12 18:41        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-12 18:41 . 2013-08-12 18:41        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-12 09:03 . 2013-08-12 18:39        --------        d-----w-        c:\users\Lissi1\AppData\Local\Adobe
2013-08-12 08:59 . 2013-08-12 11:25        --------        d-----w-        c:\users\Lissi1\AppData\Local\adawarebp
2013-08-12 05:17 . 2013-08-12 05:17        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-12 04:44 . 2013-08-12 04:44        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-12 04:44 . 2013-04-04 12:50        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-08-11 18:06 . 2013-08-12 04:33        --------        d-----w-        c:\program files (x86)\Eusing Free Registry Cleaner
2013-08-11 14:37 . 2013-08-11 14:37        --------        d-----w-        C:\found.000
2013-08-07 17:58 . 2013-08-11 14:06        --------        d-----w-        c:\program files (x86)\Plus-HD-2.4
2013-08-07 08:31 . 2013-08-07 08:31        --------        d-----w-        c:\program files\Enigma Software Group
2013-08-07 08:30 . 2013-08-07 09:35        --------        d-----w-        c:\windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 08:30 . 2013-08-07 08:30        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-07 08:23 . 2013-04-17 07:02        1230336        ----a-w-        c:\windows\SysWow64\WindowsCodecs.dll
2013-08-07 08:23 . 2013-04-17 06:24        1424384        ----a-w-        c:\windows\system32\WindowsCodecs.dll
2013-08-07 08:14 . 2013-08-07 08:14        --------        d-----w-        C:\FRST
2013-08-06 16:55 . 2013-04-02 22:51        1643520        ----a-w-        c:\windows\system32\DWrite.dll
2013-08-06 16:55 . 2013-04-09 23:34        1247744        ----a-w-        c:\windows\SysWow64\DWrite.dll
2013-08-06 16:13 . 2012-03-14 03:00        385024        ----a-w-        c:\windows\system32\CNMLMAW.DLL
2013-08-06 16:00 . 2012-08-24 18:05        340992        ----a-w-        c:\windows\system32\schannel.dll
2013-08-06 16:00 . 2012-08-24 16:57        247808        ----a-w-        c:\windows\SysWow64\schannel.dll
2013-08-06 16:00 . 2012-08-24 18:13        154480        ----a-w-        c:\windows\system32\drivers\ksecpkg.sys
2013-08-06 16:00 . 2012-08-24 18:09        458712        ----a-w-        c:\windows\system32\drivers\cng.sys
2013-08-06 16:00 . 2012-08-24 18:03        1448448        ----a-w-        c:\windows\system32\lsasrv.dll
2013-08-06 16:00 . 2012-08-24 16:57        22016        ----a-w-        c:\windows\SysWow64\secur32.dll
2013-08-06 16:00 . 2012-08-24 16:53        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll
2013-08-06 12:38 . 2013-08-06 12:38        9728        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 08:54 . 2013-04-10 06:01        265064        ----a-w-        c:\windows\system32\drivers\dxgmms1.sys
2013-08-06 08:54 . 2013-04-10 06:01        983400        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys
2013-08-06 08:54 . 2011-02-03 11:25        144384        ----a-w-        c:\windows\system32\cdd.dll
2013-08-06 08:54 . 2013-05-08 06:39        1910632        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-08-06 08:54 . 2013-01-03 06:00        288088        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2013-08-06 08:54 . 2013-02-27 05:52        14172672        ----a-w-        c:\windows\system32\shell32.dll
2013-08-06 08:54 . 2013-02-27 05:52        197120        ----a-w-        c:\windows\system32\shdocvw.dll
2013-08-06 08:54 . 2013-02-27 05:48        1930752        ----a-w-        c:\windows\system32\authui.dll
2013-08-06 08:54 . 2013-02-27 06:02        111448        ----a-w-        c:\windows\system32\consent.exe
2013-08-06 08:54 . 2013-02-27 05:47        70144        ----a-w-        c:\windows\system32\appinfo.dll
2013-08-06 08:54 . 2013-02-27 04:49        1796096        ----a-w-        c:\windows\SysWow64\authui.dll
2013-08-06 08:52 . 2013-06-05 03:34        3153920        ----a-w-        c:\windows\system32\win32k.sys
2013-08-06 08:52 . 2013-05-10 05:49        30720        ----a-w-        c:\windows\system32\cryptdlg.dll
2013-08-06 08:52 . 2013-05-10 03:20        24576        ----a-w-        c:\windows\SysWow64\cryptdlg.dll
2013-08-06 08:52 . 2013-04-10 05:48        1732608        ----a-w-        c:\program files\Windows Journal\NBDoc.DLL
2013-08-06 08:52 . 2013-04-10 05:46        1367040        ----a-w-        c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-08-06 08:52 . 2013-04-10 05:46        1402880        ----a-w-        c:\program files\Windows Journal\JNWDRV.dll
2013-08-06 08:52 . 2013-04-10 05:46        1393152        ----a-w-        c:\program files\Windows Journal\JNTFiltr.dll
2013-08-06 08:52 . 2013-04-10 05:03        936448        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-08-06 08:52 . 2013-01-24 06:01        223752        ----a-w-        c:\windows\system32\drivers\fvevol.sys
2013-08-06 08:51 . 2013-05-13 05:51        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2013-08-06 08:51 . 2013-05-13 05:51        1464320        ----a-w-        c:\windows\system32\crypt32.dll
2013-08-06 08:51 . 2013-05-13 04:45        1160192        ----a-w-        c:\windows\SysWow64\crypt32.dll
2013-08-06 08:51 . 2013-05-13 03:43        1192448        ----a-w-        c:\windows\system32\certutil.exe
2013-08-06 08:51 . 2013-05-13 03:08        903168        ----a-w-        c:\windows\SysWow64\certutil.exe
2013-08-06 08:51 . 2013-05-13 05:51        139776        ----a-w-        c:\windows\system32\cryptnet.dll
2013-08-06 08:51 . 2013-05-13 05:50        52224        ----a-w-        c:\windows\system32\certenc.dll
2013-08-06 08:51 . 2013-05-13 04:45        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2013-08-06 08:51 . 2013-05-13 04:45        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2013-08-06 08:51 . 2013-05-13 03:08        43008        ----a-w-        c:\windows\SysWow64\certenc.dll
2013-08-06 08:50 . 2013-03-19 06:04        5550424        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-08-06 08:50 . 2013-03-19 05:04        3968856        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2013-08-06 08:50 . 2013-03-19 05:04        3913560        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2013-08-06 08:50 . 2013-03-19 03:06        112640        ----a-w-        c:\windows\system32\smss.exe
2013-08-06 08:50 . 2013-03-19 05:46        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2013-08-06 08:50 . 2013-03-19 04:47        6656        ----a-w-        c:\windows\SysWow64\apisetschema.dll
2013-08-06 08:50 . 2013-04-25 23:30        1505280        ----a-w-        c:\windows\SysWow64\d3d11.dll
2013-08-06 08:50 . 2013-03-31 22:52        1887232        ----a-w-        c:\windows\system32\d3d11.dll
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\programdata\Malwarebytes
2013-08-05 10:26 . 2013-08-06 22:09        --------        d-----w-        c:\program files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 09:49 . 2013-08-05 09:49        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Avira
2013-08-05 09:44 . 2013-08-05 09:44        83672        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
2013-08-05 09:42 . 2013-08-05 09:35        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-08-05 09:42 . 2013-08-05 09:35        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-08-05 09:42 . 2013-08-05 09:35        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-08-05 09:42 . 2013-08-05 09:43        --------        d-----w-        c:\programdata\Avira
2013-08-05 09:42 . 2013-08-05 09:42        --------        d-----w-        c:\program files (x86)\Avira
2013-07-23 16:47 . 2013-07-23 16:47        --------        d-----w-        c:\users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 16:20 . 2013-07-29 16:44        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 16:20 . 2013-08-01 01:08        32328        ----a-w-        c:\windows\Launcher.exe
2013-07-17 16:43 . 2013-07-17 16:43        --------        d-----w-        c:\users\Lissi1\AppData\Local\Deployment
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-12 18:41 . 2012-12-16 15:13        1093032        ----a-w-        c:\windows\system32\npDeployJava1.dll
2013-08-12 18:41 . 2011-07-18 21:14        972712        ----a-w-        c:\windows\system32\deployJava1.dll
2013-06-23 22:57 . 2011-07-18 20:31        78277128        ----a-w-        c:\windows\system32\MRT.exe
2013-05-15 06:13 . 2011-03-29 01:36        22240        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-12-20 844296]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-14 343168]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-01-31 542632]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-08-05 345144]
.
c:\users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
net.lnk - c:\users\Lissi1\AppData\Roaming\Windows Net Data\net.exe [2013-7-23 709120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Scanner Finder.lnk - c:\program files (x86)\ScanWizard 5\ScannerFinder.exe [2012-2-4 344064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled\
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe [2013-5-17 1393744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS;c:\windows\SYSNATIVE\DRIVERS\PFC027.SYS [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [x]
S2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 50864556
*Deregistered* - 50864556
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-12 18:41]
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 12673128]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944]
"IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - Elektronik, Autos, Mode, Sammlerstücke, Gutscheine und mehr Online-Shopping | eBay
IE: {{92808042-fb78-4fa0-bb4f-c9a95e0e9c10} - {ba696155-d96e-4281-b467-0367a0456474} -
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)
WebBrowser-{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - (no file)
WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - (no file)
AddRemove-Adobe Flash Player ActiveX - c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
AddRemove-_{707EB912-C597-49D8-9460-46CC9AB03EBE} - c:\program files (x86)\Corel\Corel Painter Photo Essentials 4\MSILauncher {707EB912-C597-49D8-9460-46CC9AB03EBE}
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ba696155-d96e-4281-b467-0367a0456474}]
@Denied: (A 2) (Administrators)
@Denied: (A 2) (S-1-5-21-4060780361-2962197505-3855748707-1000)
"Flags"=dword:00000400
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32]
@DACL=(02 0000)
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-12  21:03:01
ComboFix-quarantined-files.txt  2013-08-12 19:03
ComboFix2.txt  2013-08-06 08:33
.
Vor Suchlauf: 15 Verzeichnis(se), 1.376.416.366.592 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 1.376.293.629.952 Bytes frei
.
- - End Of File - - 75C97ADD0078F14CDF79A6EE2965772D

--- --- ---
D41D8CD98F00B204E9800998ECF8427E

also combfix wurde noch nie ausgeführtAdwCleaner Logfile:
Code:

# AdwCleaner v2.100 - Datei am 16/12/2012 um 16:36:49 erstellt
# Aktualisiert am 09/12/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lissi1 - LISSI1-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ITKH2QGW\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gefunden : C:\user.js
Ordner Gefunden : C:\Program Files (x86)\BrowserCompanion
Ordner Gefunden : C:\Program Files (x86)\Conduit
Ordner Gefunden : C:\Program Files (x86)\Windows Searchqu Toolbar
Ordner Gefunden : C:\ProgramData\Babylon
Ordner Gefunden : C:\ProgramData\boost_interprocess
Ordner Gefunden : C:\ProgramData\Partner
Ordner Gefunden : C:\Users\Lissi1\AppData\Local\Conduit
Ordner Gefunden : C:\Users\Lissi1\AppData\LocalLow\BabylonToolbar
Ordner Gefunden : C:\Users\Lissi1\AppData\LocalLow\bbrs_002.tb
Ordner Gefunden : C:\Users\Lissi1\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\Lissi1\AppData\LocalLow\PriceGong
Ordner Gefunden : C:\Users\Lissi1\AppData\Roaming\Babylon
Ordner Gefunden : C:\Users\Lissi1\AppData\Roaming\BrowserCompanion
Ordner Gefunden : C:\Users\Lissi1\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\DataMngr
Schlüssel Gefunden : HKCU\Software\IGearSettings
Schlüssel Gefunden : HKCU\Software\Iminent
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Schlüssel Gefunden : HKLM\Software\Babylon
Schlüssel Gefunden : HKLM\Software\BrowserCompanion
Schlüssel Gefunden : HKLM\Software\BrowserMngr
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\tdataprotocol.CTData
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\tdataprotocol.CTData.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_launcher
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_launcher.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_printmanager
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_printmanager.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.tbtoolband
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.tbtoolband.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.useroptions
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.useroptions.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\updatebho.TimerBHO
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\wit4ie.WitBHO
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\wit4ie.WitBHO.2
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\DataMngr
Schlüssel Gefunden : HKLM\Software\Iminent
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Schlüssel Gefunden : HKLM\SOFTWARE\DataMngr
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Schlüssel Gefunden : HKLM\SOFTWARE\Software
Schlüssel Gefunden : HKU\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKU\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}
Schlüssel Gefunden : HKU\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKU\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [BrowserMngr Start Page]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [BrowserMngrDefaultScope]
Wert Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16457

[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=109958&tt=120912_pcp_3812_1&babsrc=NT_ss&mntrId=204c3cc00000000000006c626d8c2b78

*************************

AdwCleaner[R1].txt - [19427 octets] - [16/12/2012 16:36:49]

########## EOF - C:\AdwCleaner[R1].txt - [19488 octets] ##########

--- --- ---

AdwCleaner Logfile:
Code:

# AdwCleaner v2.306 - Datei am 11/08/2013 um 18:22:17 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lissi1 - LISSI1-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lissi1\Desktop\adwcleaner06.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp

***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16496

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v28.0.1500.95

Datei : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R10].txt - [1811 octets] - [06/08/2013 10:08:35]
AdwCleaner[R11].txt - [1872 octets] - [06/08/2013 10:10:31]
AdwCleaner[R12].txt - [1933 octets] - [06/08/2013 11:58:38]
AdwCleaner[R13].txt - [1994 octets] - [06/08/2013 11:58:54]
AdwCleaner[R14].txt - [2055 octets] - [06/08/2013 11:59:28]
AdwCleaner[R17].txt - [2117 octets] - [07/08/2013 18:28:41]
AdwCleaner[R18].txt - [15178 octets] - [11/08/2013 18:16:18]
AdwCleaner[R19].txt - [2613 octets] - [11/08/2013 18:22:01]
AdwCleaner[R1].txt - [19448 octets] - [16/12/2012 17:36:49]
AdwCleaner[R2].txt - [877 octets] - [16/12/2012 17:52:35]
AdwCleaner[R3].txt - [78717 octets] - [05/08/2013 11:51:39]
AdwCleaner[R4].txt - [78778 octets] - [05/08/2013 11:53:06]
AdwCleaner[R5].txt - [1664 octets] - [05/08/2013 12:02:00]
AdwCleaner[R6].txt - [1534 octets] - [05/08/2013 12:08:03]
AdwCleaner[R7].txt - [1654 octets] - [05/08/2013 12:21:17]
AdwCleaner[R8].txt - [1714 octets] - [05/08/2013 12:26:45]
AdwCleaner[R9].txt - [1976 octets] - [05/08/2013 19:23:07]
AdwCleaner[S10].txt - [2180 octets] - [07/08/2013 18:29:03]
AdwCleaner[S11].txt - [15091 octets] - [11/08/2013 18:16:40]
AdwCleaner[S12].txt - [2125 octets] - [11/08/2013 18:22:17]
AdwCleaner[S1].txt - [18899 octets] - [16/12/2012 17:37:22]
AdwCleaner[S2].txt - [820 octets] - [16/12/2012 17:48:57]
AdwCleaner[S3].txt - [938 octets] - [16/12/2012 17:52:45]
AdwCleaner[S4].txt - [33765 octets] - [05/08/2013 11:53:23]
AdwCleaner[S5].txt - [1726 octets] - [05/08/2013 12:02:18]
AdwCleaner[S6].txt - [1596 octets] - [05/08/2013 12:08:14]
AdwCleaner[S7].txt - [2038 octets] - [05/08/2013 19:23:32]

########## EOF - C:\AdwCleaner[S12].txt - [2606 octets] ##########

--- --- ---

ADWCleaner wursde mehrmals ausgeführt, insgesammt 12 mal

tdskiller ist gepostet

2013-08-12 19:01:56 . 2013-08-12 19:01:56 377 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47}.reg.dat
2013-08-08 09:07:04 . 2013-08-08 09:07:12 85 ----a-w- C:\Qoobox\Quarantine\C\Windows\wininit.ini.vir
2013-08-06 08:33:14 . 2013-08-06 08:33:14 0 ----a-w- C:\Qoobox\Quarantine\MBR_HardDisk0.mbr
2013-08-06 08:32:24 . 2013-08-12 19:01:58 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}.reg.dat
2013-08-06 08:32:24 . 2013-08-12 19:01:58 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}.reg.dat
2013-08-06 08:32:23 . 2013-08-12 19:01:58 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}.reg.dat
2013-08-06 08:32:23 . 2013-08-06 08:32:23 113 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233}.reg.dat
2013-08-06 08:32:23 . 2013-08-06 08:32:23 113 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}.reg.dat
2013-08-06 08:32:12 . 2013-08-06 08:32:12 311 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKLM-Run-ZoneAlarm Installer.reg.dat
2013-08-06 08:32:11 . 2013-08-06 08:32:11 177 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKCU-Run-DriverScanner.reg.dat
2013-08-06 08:32:11 . 2013-08-12 19:01:47 2,166 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-Toolbar-{ba696155-d96e-4281-b467-0367a0456474}.reg.dat
2013-08-06 08:32:11 . 2013-08-12 19:01:47 125 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233}.reg.dat
2013-08-06 08:32:11 . 2013-08-12 19:01:47 125 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}.reg.dat
2013-08-06 08:32:10 . 2013-08-12 19:01:47 1,069 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-BHO-{ba696155-d96e-4281-b467-0367a0456474}.reg.dat
2013-08-06 08:25:36 . 2013-08-12 18:59:02 9,034 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2013-08-06 08:18:40 . 2013-08-12 18:52:38 102 ----a-w- C:\Qoobox\Quarantine\catchme.log
2012-12-24 21:33:53 . 2012-12-24 21:33:53 1,758,720 ----atw- C:\Qoobox\Quarantine\C\Users\Lissi1\AppData\Roaming\Microsoft\engine_vx.dll.vir
2012-03-27 12:02:23 . 2012-03-27 12:02:23 8 ----a-w- C:\Qoobox\Quarantine\C\ProgramData\19795AD46B.sys.vir
2012-02-04 18:57:29 . 1998-11-17 12:44:44 328,704 ----a-w- C:\Qoobox\Quarantine\C\Windows\IsUn0407.exe.vir

Combofix Logfile:
Code:

ComboFix 13-08-05.03 - Lissi1 06.08.2013  10:20:55.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4023.1577 [GMT 2:00]
ausgeführt von:: c:\users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HN7EU4GZ\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\19795AD46B.sys
c:\users\Lissi1\AppData\Roaming\Microsoft\engine_vx.dll
c:\windows\IsUn0407.exe
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-07-06 bis 2013-08-06  ))))))))))))))))))))))))))))))
.
.
2013-08-06 08:26 . 2013-08-06 08:26        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\programdata\Malwarebytes
2013-08-05 10:28 . 2013-04-04 12:50        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-08-05 10:26 . 2013-08-05 10:26        --------        d-----w-        c:\program files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 09:49 . 2013-08-05 09:49        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Avira
2013-08-05 09:44 . 2013-08-05 09:44        83672        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
2013-08-05 09:42 . 2013-08-05 09:35        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-08-05 09:42 . 2013-08-05 09:35        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-08-05 09:42 . 2013-08-05 09:35        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-08-05 09:42 . 2013-08-05 09:43        --------        d-----w-        c:\programdata\Avira
2013-08-05 09:42 . 2013-08-05 09:42        --------        d-----w-        c:\program files (x86)\Avira
2013-07-23 16:47 . 2013-07-23 16:47        --------        d-----w-        c:\users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 16:20 . 2013-07-29 16:44        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 16:20 . 2013-08-01 01:08        32328        ----a-w-        c:\windows\Launcher.exe
2013-07-23 16:19 . 2013-07-23 16:19        --------        d-----w-        c:\programdata\FreeSystemUtilities
2013-07-23 16:18 . 2013-07-23 16:18        --------        d-----w-        c:\programdata\Package Cache
2013-07-17 16:43 . 2013-07-17 16:43        --------        d-----w-        c:\users\Lissi1\AppData\Local\Deployment
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-16 06:25 . 2012-05-01 08:51        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-07-16 06:25 . 2011-10-14 12:15        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-15 06:13 . 2011-03-29 01:36        22240        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-11 07:39 . 2012-02-24 15:55        3402        --sha-w-        c:\programdata\KGyGaAvL.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-12-20 844296]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-14 343168]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-01-31 542632]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-08-05 345144]
.
c:\users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
net.lnk - c:\users\Lissi1\AppData\Roaming\Windows Net Data\net.exe [2013-7-23 709120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Scanner Finder.lnk - c:\program files (x86)\ScanWizard 5\ScannerFinder.exe [2012-2-4 344064]
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe [2013-5-17 1393744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R1 A2DDA;A2 Direct Disk Access Support Driver;c:\users\Lissi1\AppData\Local\Temp\Rar$EXa0.359\Run\a2ddax64.sys;c:\users\Lissi1\AppData\Local\Temp\Rar$EXa0.359\Run\a2ddax64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS;c:\windows\SYSNATIVE\DRIVERS\PFC027.SYS [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [x]
S2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-02 15:55        1173456        ----a-w-        c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-01 06:25]
.
2013-08-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
2013-08-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 12673128]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944]
"IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mStart Page = about:newtab
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - Elektronik, Autos, Mode, Sammlerstücke, Gutscheine und mehr Online-Shopping | eBay
IE: {{92808042-fb78-4fa0-bb4f-c9a95e0e9c10} - {ba696155-d96e-4281-b467-0367a0456474} -
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
Wow6432Node-HKCU-Run-DriverScanner - c:\program files (x86)\Uniblue\DriverScanner\launcher.exe
Wow6432Node-HKLM-Run-ZoneAlarm Installer - c:\program files (x86)\CheckPoint\Install\Launcher.exe
Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)
WebBrowser-{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - (no file)
WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - (no file)
AddRemove-_{707EB912-C597-49D8-9460-46CC9AB03EBE} - c:\program files (x86)\Corel\Corel Painter Photo Essentials 4\MSILauncher {707EB912-C597-49D8-9460-46CC9AB03EBE}
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ba696155-d96e-4281-b467-0367a0456474}]
@Denied: (A 2) (Administrators)
@Denied: (A 2) (S-1-5-21-4060780361-2962197505-3855748707-1000)
"Flags"=dword:00000400
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32]
@DACL=(02 0000)
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\crypserv.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-08-06  10:33:13 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-08-06 08:33
.
Vor Suchlauf: 11 Verzeichnis(se), 1.368.118.669.312 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 1.367.759.712.256 Bytes frei
.
- - End Of File - - 25322264282D6DD98948261655E28D25

--- --- ---
D41D8CD98F00B204E9800998ECF8427E

markusg 12.08.2013 20:27

Hi das ist das combofix log von heute, liegen dort noch mehr?

und ich sag dir gern noch mal, dass es bereits ausgeführt wurde, ich sehe das in combofix und im frst Log. poste mir außerdem mal das neueste ADW cleaner log, das ist aus 2012.

baby-lissa 12.08.2013 20:33

ich habe die alles gepostet was uner combofix zu finden ist, ich habe combofix voerher noch nie gehört also kann es auch nicht gelaufen sein auf dem rechner!!! ich bin der einzige der ihn benutzt und ich habe combo noch nie geladen.

alle adw logs sind da 01 und 12

combo hat meinen ganzen pc umgebau nach dem scan ich habe kein explorer mehr sondern in como plore und der arbeitsplatz heist jetzt c: combofix

das zum schon mal gelaufen
das program zerledert gerde stück für stück meinen pc

markusg 12.08.2013 20:35

Hi, wie gesagt sehe ich von 2 Programmen das es schon mal gelaufen ist
aber egal.

was is como plore
starte mal neu, schaue ob es dann wieder passt.
wenn du auf arbeitsplatz klickst ksiehst du deine Laufwerke nicht mehr oder wie?

baby-lissa 12.08.2013 20:35

das ist der combo scan von ebend gerade!!!!
angeblich vom 06.08.2013 10 uhr

Combofix Logfile:
Code:

ComboFix 13-08-05.03 - Lissi1 06.08.2013  10:20:55.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4023.1577 [GMT 2:00]
ausgeführt von:: c:\users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HN7EU4GZ\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\19795AD46B.sys
c:\users\Lissi1\AppData\Roaming\Microsoft\engine_vx.dll
c:\windows\IsUn0407.exe
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-07-06 bis 2013-08-06  ))))))))))))))))))))))))))))))
.
.
2013-08-06 08:26 . 2013-08-06 08:26        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\programdata\Malwarebytes
2013-08-05 10:28 . 2013-04-04 12:50        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-08-05 10:26 . 2013-08-05 10:26        --------        d-----w-        c:\program files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 09:49 . 2013-08-05 09:49        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Avira
2013-08-05 09:44 . 2013-08-05 09:44        83672        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
2013-08-05 09:42 . 2013-08-05 09:35        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-08-05 09:42 . 2013-08-05 09:35        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-08-05 09:42 . 2013-08-05 09:35        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-08-05 09:42 . 2013-08-05 09:43        --------        d-----w-        c:\programdata\Avira
2013-08-05 09:42 . 2013-08-05 09:42        --------        d-----w-        c:\program files (x86)\Avira
2013-07-23 16:47 . 2013-07-23 16:47        --------        d-----w-        c:\users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 16:20 . 2013-07-29 16:44        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 16:20 . 2013-08-01 01:08        32328        ----a-w-        c:\windows\Launcher.exe
2013-07-23 16:19 . 2013-07-23 16:19        --------        d-----w-        c:\programdata\FreeSystemUtilities
2013-07-23 16:18 . 2013-07-23 16:18        --------        d-----w-        c:\programdata\Package Cache
2013-07-17 16:43 . 2013-07-17 16:43        --------        d-----w-        c:\users\Lissi1\AppData\Local\Deployment
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-16 06:25 . 2012-05-01 08:51        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-07-16 06:25 . 2011-10-14 12:15        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-15 06:13 . 2011-03-29 01:36        22240        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-11 07:39 . 2012-02-24 15:55        3402        --sha-w-        c:\programdata\KGyGaAvL.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-12-20 844296]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-14 343168]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-01-31 542632]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-08-05 345144]
.
c:\users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
net.lnk - c:\users\Lissi1\AppData\Roaming\Windows Net Data\net.exe [2013-7-23 709120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Scanner Finder.lnk - c:\program files (x86)\ScanWizard 5\ScannerFinder.exe [2012-2-4 344064]
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe [2013-5-17 1393744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R1 A2DDA;A2 Direct Disk Access Support Driver;c:\users\Lissi1\AppData\Local\Temp\Rar$EXa0.359\Run\a2ddax64.sys;c:\users\Lissi1\AppData\Local\Temp\Rar$EXa0.359\Run\a2ddax64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS;c:\windows\SYSNATIVE\DRIVERS\PFC027.SYS [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [x]
S2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-02 15:55        1173456        ----a-w-        c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-01 06:25]
.
2013-08-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
2013-08-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 12673128]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944]
"IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mStart Page = about:newtab
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - Elektronik, Autos, Mode, Sammlerstücke, Gutscheine und mehr Online-Shopping | eBay
IE: {{92808042-fb78-4fa0-bb4f-c9a95e0e9c10} - {ba696155-d96e-4281-b467-0367a0456474} -
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
Wow6432Node-HKCU-Run-DriverScanner - c:\program files (x86)\Uniblue\DriverScanner\launcher.exe
Wow6432Node-HKLM-Run-ZoneAlarm Installer - c:\program files (x86)\CheckPoint\Install\Launcher.exe
Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)
WebBrowser-{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - (no file)
WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - (no file)
AddRemove-_{707EB912-C597-49D8-9460-46CC9AB03EBE} - c:\program files (x86)\Corel\Corel Painter Photo Essentials 4\MSILauncher {707EB912-C597-49D8-9460-46CC9AB03EBE}
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ba696155-d96e-4281-b467-0367a0456474}]
@Denied: (A 2) (Administrators)
@Denied: (A 2) (S-1-5-21-4060780361-2962197505-3855748707-1000)
"Flags"=dword:00000400
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32]
@DACL=(02 0000)
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\crypserv.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-08-06  10:33:13 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-08-06 08:33
.
Vor Suchlauf: 11 Verzeichnis(se), 1.368.118.669.312 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 1.367.759.712.256 Bytes frei
.
- - End Of File - - 25322264282D6DD98948261655E28D25

--- --- ---
D41D8CD98F00B204E9800998ECF8427E

markusg 12.08.2013 20:37

das ist der vom 08.05
ComboFix 13-08-05.03 - Lissi1 06.08.2013 10:20:55.1.4 - x64
vergleiche das mal mit der Kopfzeile deines ersten Scans.
ComboFix 13-08-12.01 - Lissi1 12.08.2013 20:53:39.2.4 - x64
also doch 2 mal gelaufen

baby-lissa 12.08.2013 20:43

ich habe nur einen scan gemacht mit comobfix um 20:53 uhr, davor noch nie das programm gehabt oder davon gehört.
Also ein scan und zwei loggs ??? was sagt mir das? Scheiß Programm!!!
Ich habe keinen Arbeitsplatz mehr und kein Explorer mehr, combofix hat sich das mal kurzerhand umbenannt und einiges gelöscht

Die Logs von Adwcleaner sind von dieser Woche
das 01 vom Montag lezter woche und das 12 von Heute 14 uhr

markusg 12.08.2013 20:50

Hi,
oder jemand nutzt deinen pc. nicht nur combofix zeigt die unterschiedlichen datumsangaben sondern auch andere Programme, die nicht vom selben autor sind. außerdem sind die Einträge in den Protokollen anders und du währst der Erste bei dem soetwas passiert.
du sagst du hast ein adw cleaner log von 2013 gepostet? da sind zwar welche

AdwCleaner[R3].txt - [78717 octets] - [05/08/2013 11:51:39]
AdwCleaner[R4].txt - [78778 octets] - [05/08/2013 11:53:06]
AdwCleaner[R5].txt - [1664 octets] - [05/08/2013 12:02:00]
AdwCleaner[R6].txt - [1534 octets] - [05/08/2013 12:08:03]
AdwCleaner[R7].txt - [1654 octets] - [05/08/2013 12:21:17]
AdwCleaner[R8].txt - [1714 octets] - [05/08/2013 12:26:45]
AdwCleaner[R9].txt - [1976 octets] - [05/08/2013 19:23:07]
AdwCleaner[S10].txt - [2180 octets] - [07/08/2013 18:29:03]
AdwCleaner[S11].txt - [15091 octets] - [11/08/2013 18:16:40]
AdwCleaner[S12].txt - [2125 octets] - [11/08/2013 18:22:17]
AdwCleaner[S1].txt - [18899 octets] - [16/12/2012 17:37:22]
AdwCleaner[S2].txt - [820 octets] - [16/12/2012 17:48:57]
AdwCleaner[S3].txt - [938 octets] - [16/12/2012 17:52:45]
AdwCleaner[S4].txt - [33765 octets] - [05/08/2013 11:53:23]
AdwCleaner[S5].txt - [1726 octets] - [05/08/2013 12:02:18]
AdwCleaner[S6].txt - [1596 octets] - [05/08/2013 12:08:14]
AdwCleaner[S7].txt - [2038 octets] - [05/08/2013 19:23:32]
(was übrigens auch mit dem Datum vom Combofix zusammenpasst)
du hast mir aber leider
########## EOF - C:\AdwCleaner[R1].txt - [19488 octets] ##########
welches aus 2012 ist
gepostet
meine Frage aus post 16 sind nicht beantwortet.
was meinst du mit
como plore
und wo wird dir combofix als laufwerk angezeigt direkt unter c:? kannst du andere Laufwerke öffnen und wie siehts nach neustart aus?

baby-lissa 12.08.2013 20:53

der neustart hatte auch nichts gebracht, die datei dich combofix umbenannt hat waren alle noch umbenannt, c:/computer war c:combofix
c:/windos war c:/combofix win
und der explorer ist aus dem system gelöscht worden

markusg 12.08.2013 20:56

Hi,
na wenn die explorer.exe gelöscht währe, hättest du z.B. keine desktop objekte, die hast du aber noch oder?
wenn du über start ausführen gehst und z.b.:
c:\
aufrufst, sind dort alle Ordner zu sehen, also windows, programme etc?

baby-lissa 12.08.2013 20:59

das sind sie ADW logs von Heute Nachmittag!!!
Datum war bis combofix installation noch richtig jetzt nicht mehr?!
die meisten anderen Logs sind gelöscht dank combofix
AdwCleaner Logfile:
Code:

# AdwCleaner v2.306 - Datei am 11/08/2013 um 18:22:01 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lissi1 - LISSI1-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lissi1\Desktop\adwcleaner06.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gefunden : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gefunden : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp

***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16496

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v28.0.1500.95

Datei : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R10].txt - [1811 octets] - [06/08/2013 10:08:35]
AdwCleaner[R11].txt - [1872 octets] - [06/08/2013 10:10:31]
AdwCleaner[R12].txt - [1933 octets] - [06/08/2013 11:58:38]
AdwCleaner[R13].txt - [1994 octets] - [06/08/2013 11:58:54]
AdwCleaner[R14].txt - [2055 octets] - [06/08/2013 11:59:28]
AdwCleaner[R17].txt - [2117 octets] - [07/08/2013 18:28:41]
AdwCleaner[R18].txt - [15178 octets] - [11/08/2013 18:16:18]
AdwCleaner[R19].txt - [1397 octets] - [11/08/2013 18:22:01]
AdwCleaner[R1].txt - [19448 octets] - [16/12/2012 17:36:49]
AdwCleaner[R2].txt - [877 octets] - [16/12/2012 17:52:35]
AdwCleaner[R3].txt - [78717 octets] - [05/08/2013 11:51:39]
AdwCleaner[R4].txt - [78778 octets] - [05/08/2013 11:53:06]
AdwCleaner[R5].txt - [1664 octets] - [05/08/2013 12:02:00]
AdwCleaner[R6].txt - [1534 octets] - [05/08/2013 12:08:03]
AdwCleaner[R7].txt - [1654 octets] - [05/08/2013 12:21:17]
AdwCleaner[R8].txt - [1714 octets] - [05/08/2013 12:26:45]
AdwCleaner[R9].txt - [1976 octets] - [05/08/2013 19:23:07]
AdwCleaner[S10].txt - [2180 octets] - [07/08/2013 18:29:03]
AdwCleaner[S11].txt - [15091 octets] - [11/08/2013 18:16:40]
AdwCleaner[S1].txt - [18899 octets] - [16/12/2012 17:37:22]
AdwCleaner[S2].txt - [820 octets] - [16/12/2012 17:48:57]
AdwCleaner[S3].txt - [938 octets] - [16/12/2012 17:52:45]
AdwCleaner[S4].txt - [33765 octets] - [05/08/2013 11:53:23]
AdwCleaner[S5].txt - [1726 octets] - [05/08/2013 12:02:18]
AdwCleaner[S6].txt - [1596 octets] - [05/08/2013 12:08:14]
AdwCleaner[S7].txt - [2038 octets] - [05/08/2013 19:23:32]

########## EOF - C:\AdwCleaner[R19].txt - [2543 octets] ##########

--- --- ---
AdwCleaner Logfile:
Code:

# AdwCleaner v2.306 - Datei am 11/08/2013 um 18:22:17 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lissi1 - LISSI1-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lissi1\Desktop\adwcleaner06.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp

***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16496

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v28.0.1500.95

Datei : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R10].txt - [1811 octets] - [06/08/2013 10:08:35]
AdwCleaner[R11].txt - [1872 octets] - [06/08/2013 10:10:31]
AdwCleaner[R12].txt - [1933 octets] - [06/08/2013 11:58:38]
AdwCleaner[R13].txt - [1994 octets] - [06/08/2013 11:58:54]
AdwCleaner[R14].txt - [2055 octets] - [06/08/2013 11:59:28]
AdwCleaner[R17].txt - [2117 octets] - [07/08/2013 18:28:41]
AdwCleaner[R18].txt - [15178 octets] - [11/08/2013 18:16:18]
AdwCleaner[R19].txt - [2613 octets] - [11/08/2013 18:22:01]
AdwCleaner[R1].txt - [19448 octets] - [16/12/2012 17:36:49]
AdwCleaner[R2].txt - [877 octets] - [16/12/2012 17:52:35]
AdwCleaner[R3].txt - [78717 octets] - [05/08/2013 11:51:39]
AdwCleaner[R4].txt - [78778 octets] - [05/08/2013 11:53:06]
AdwCleaner[R5].txt - [1664 octets] - [05/08/2013 12:02:00]
AdwCleaner[R6].txt - [1534 octets] - [05/08/2013 12:08:03]
AdwCleaner[R7].txt - [1654 octets] - [05/08/2013 12:21:17]
AdwCleaner[R8].txt - [1714 octets] - [05/08/2013 12:26:45]
AdwCleaner[R9].txt - [1976 octets] - [05/08/2013 19:23:07]
AdwCleaner[S10].txt - [2180 octets] - [07/08/2013 18:29:03]
AdwCleaner[S11].txt - [15091 octets] - [11/08/2013 18:16:40]
AdwCleaner[S12].txt - [2125 octets] - [11/08/2013 18:22:17]
AdwCleaner[S1].txt - [18899 octets] - [16/12/2012 17:37:22]
AdwCleaner[S2].txt - [820 octets] - [16/12/2012 17:48:57]
AdwCleaner[S3].txt - [938 octets] - [16/12/2012 17:52:45]
AdwCleaner[S4].txt - [33765 octets] - [05/08/2013 11:53:23]
AdwCleaner[S5].txt - [1726 octets] - [05/08/2013 12:02:18]
AdwCleaner[S6].txt - [1596 octets] - [05/08/2013 12:08:14]
AdwCleaner[S7].txt - [2038 octets] - [05/08/2013 19:23:32]

########## EOF - C:\AdwCleaner[S12].txt - [2606 octets] ##########

--- --- ---


AdwCleaner Logfile:
Code:

# AdwCleaner v2.306 - Datei am 11/08/2013 um 18:16:40 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lissi1 - LISSI1-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lissi1\Desktop\adwcleaner06.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : SystemStoreService

***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\Freemium
Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gelöscht : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Ordner Gelöscht : C:\Users\Lissi1\AppData\Roaming\Babylon

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Plus-HD-2.4
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\FoxyDeal
Schlüssel Gelöscht : HKCU\Software\Iminent
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311341134}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033434.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033434.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033434.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033434.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440344344434}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311341134}
Schlüssel Gelöscht : HKLM\Software\Plus-HD-2.4
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\596da8ab76fbf41
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{11111111-1111-1111-1111-110311341134}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{22222222-2222-2222-2222-220322342234}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{55555555-5555-5555-5555-550355345534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66666666-6666-6666-6666-660366346634}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311341134}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-2.4
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355345534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366346634}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16496

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v28.0.1500.95

Datei : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R10].txt - [1811 octets] - [06/08/2013 10:08:35]
AdwCleaner[R11].txt - [1872 octets] - [06/08/2013 10:10:31]
AdwCleaner[R12].txt - [1933 octets] - [06/08/2013 11:58:38]
AdwCleaner[R13].txt - [1994 octets] - [06/08/2013 11:58:54]
AdwCleaner[R14].txt - [2055 octets] - [06/08/2013 11:59:28]
AdwCleaner[R17].txt - [2117 octets] - [07/08/2013 18:28:41]
AdwCleaner[R18].txt - [15178 octets] - [11/08/2013 18:16:18]
AdwCleaner[R1].txt - [19448 octets] - [16/12/2012 17:36:49]
AdwCleaner[R2].txt - [877 octets] - [16/12/2012 17:52:35]
AdwCleaner[R3].txt - [78717 octets] - [05/08/2013 11:51:39]
AdwCleaner[R4].txt - [78778 octets] - [05/08/2013 11:53:06]
AdwCleaner[R5].txt - [1664 octets] - [05/08/2013 12:02:00]
AdwCleaner[R6].txt - [1534 octets] - [05/08/2013 12:08:03]
AdwCleaner[R7].txt - [1654 octets] - [05/08/2013 12:21:17]
AdwCleaner[R8].txt - [1714 octets] - [05/08/2013 12:26:45]
AdwCleaner[R9].txt - [1976 octets] - [05/08/2013 19:23:07]
AdwCleaner[S10].txt - [2180 octets] - [07/08/2013 18:29:03]
AdwCleaner[S11].txt - [14630 octets] - [11/08/2013 18:16:40]
AdwCleaner[S1].txt - [18899 octets] - [16/12/2012 17:37:22]
AdwCleaner[S2].txt - [820 octets] - [16/12/2012 17:48:57]
AdwCleaner[S3].txt - [938 octets] - [16/12/2012 17:52:45]
AdwCleaner[S4].txt - [33765 octets] - [05/08/2013 11:53:23]
AdwCleaner[S5].txt - [1726 octets] - [05/08/2013 12:02:18]
AdwCleaner[S6].txt - [1596 octets] - [05/08/2013 12:08:14]
AdwCleaner[S7].txt - [2038 octets] - [05/08/2013 19:23:32]

########## EOF - C:\AdwCleaner[S11].txt - [15112 octets] ##########

--- --- ---
AdwCleaner Logfile:
Code:

# AdwCleaner v2.306 - Datei am 11/08/2013 um 18:16:18 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lissi1 - LISSI1-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lissi1\Desktop\adwcleaner06.exe
# Option [Suche]


**** [Dienste] ****

Gefunden : SystemStoreService

***** [Dateien / Ordner] *****

Ordner Gefunden : C:\Program Files (x86)\SoftwareUpdater
Ordner Gefunden : C:\ProgramData\Babylon
Ordner Gefunden : C:\Users\Lissi1\AppData\Local\DownloadGuide
Ordner Gefunden : C:\Users\Lissi1\AppData\Local\Freemium
Ordner Gefunden : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gefunden : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Ordner Gefunden : C:\Users\Lissi1\AppData\Roaming\Babylon

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Plus-HD-2.4
Schlüssel Gefunden : HKCU\Software\BabSolution
Schlüssel Gefunden : HKCU\Software\BI
Schlüssel Gefunden : HKCU\Software\DataMngr
Schlüssel Gefunden : HKCU\Software\DataMngr_Toolbar
Schlüssel Gefunden : HKCU\Software\Delta
Schlüssel Gefunden : HKCU\Software\FoxyDeal
Schlüssel Gefunden : HKCU\Software\Iminent
Schlüssel Gefunden : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311341134}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0033434.BHO
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0033434.BHO.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0033434.Sandbox
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0033434.Sandbox.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440344344434}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gefunden : HKLM\Software\DataMngr
Schlüssel Gefunden : HKLM\Software\Delta
Schlüssel Gefunden : HKLM\Software\Iminent
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311341134}
Schlüssel Gefunden : HKLM\Software\Plus-HD-2.4
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\596da8ab76fbf41
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{11111111-1111-1111-1111-110311341134}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{22222222-2222-2222-2222-220322342234}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{55555555-5555-5555-5555-550355345534}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66666666-6666-6666-6666-660366346634}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311341134}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-2.4
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355345534}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366346634}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gefunden : HKU\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16496

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v28.0.1500.95

Datei : C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R10].txt - [1811 octets] - [06/08/2013 10:08:35]
AdwCleaner[R11].txt - [1872 octets] - [06/08/2013 10:10:31]
AdwCleaner[R12].txt - [1933 octets] - [06/08/2013 11:58:38]
AdwCleaner[R13].txt - [1994 octets] - [06/08/2013 11:58:54]
AdwCleaner[R14].txt - [2055 octets] - [06/08/2013 11:59:28]
AdwCleaner[R17].txt - [2117 octets] - [07/08/2013 18:28:41]
AdwCleaner[R18].txt - [14114 octets] - [11/08/2013 18:16:18]
AdwCleaner[R1].txt - [19448 octets] - [16/12/2012 17:36:49]
AdwCleaner[R2].txt - [877 octets] - [16/12/2012 17:52:35]
AdwCleaner[R3].txt - [78717 octets] - [05/08/2013 11:51:39]
AdwCleaner[R4].txt - [78778 octets] - [05/08/2013 11:53:06]
AdwCleaner[R5].txt - [1664 octets] - [05/08/2013 12:02:00]
AdwCleaner[R6].txt - [1534 octets] - [05/08/2013 12:08:03]
AdwCleaner[R7].txt - [1654 octets] - [05/08/2013 12:21:17]
AdwCleaner[R8].txt - [1714 octets] - [05/08/2013 12:26:45]
AdwCleaner[R9].txt - [1976 octets] - [05/08/2013 19:23:07]
AdwCleaner[S10].txt - [2180 octets] - [07/08/2013 18:29:03]
AdwCleaner[S1].txt - [18899 octets] - [16/12/2012 17:37:22]
AdwCleaner[S2].txt - [820 octets] - [16/12/2012 17:48:57]
AdwCleaner[S3].txt - [938 octets] - [16/12/2012 17:52:45]
AdwCleaner[S4].txt - [33765 octets] - [05/08/2013 11:53:23]
AdwCleaner[S5].txt - [1726 octets] - [05/08/2013 12:02:18]
AdwCleaner[S6].txt - [1596 octets] - [05/08/2013 12:08:14]
AdwCleaner[S7].txt - [2038 octets] - [05/08/2013 19:23:32]

########## EOF - C:\AdwCleaner[R18].txt - [15199 octets] ##########

--- --- ---

markusg 12.08.2013 20:59

wie ist das Datum momentan? klicke auf die Uhr und passe es, wenn nötig an. laut den 2 Logs die ich von Combofix habe ist keine Textdatei gelöscht worden bitte noch Frage von oben beantworten

baby-lissa 12.08.2013 21:02

nach dem Neustart ist das Datum und Uhrzeit wieder angepasst worden

welche Frage?????

es sind nicht mehr alle programme zu sehen
kein Windows
die Datei Computer hies Combofix auf der rechten seite
und start ist ziemlich leer

markusg 12.08.2013 21:03

mach mir mal einen screenshot oder 2 falls nötig

baby-lissa 12.08.2013 21:05

scrensot lässt euer programm ja nicht zu!
wie soll ich dir ein Bild senden wenn hier keine Bilder versendet werden können?

markusg 12.08.2013 21:07

Hi,
wir lassen bilder zu, png, jpg etc.
oder archive
auf antworten klicken, anhänge verwalten

baby-lissa 12.08.2013 21:09

das desktopsymbol vom Computer hier ComboFix
und viele Desktop symbole sind weg

ich lann hier nur URLS einfügen oder Text

mehr lässt das programm nicht zu
kein JPG, grfik über URL oder Link über URL einfügen mehr geht hier nicht

markusg 12.08.2013 21:09

Kein Screenshot hängt an
und wie du bilder einfügst hab ich dir grad erklärt
wenn du das nicht hinbringst lads irgendwo hoch und poste den link

baby-lissa 12.08.2013 21:12

ich kann nur eine url versenden mehr geht hier nicht!!!!
ich habe keine möglichkeit bilder oder grafiken zu versenden

wenn ich auf grafik versenden gehe kommt : bitte geben sie die zugehörige URL ein
http:\\___

markusg 12.08.2013 21:13

du sollst sie als datei anhängen.
wie das geht steht in post 28
oder bei einem bilderhoster hochladen. und link posten.

baby-lissa 12.08.2013 21:16

ich habe kein anhänge verwalten

ich habe nur grafiken anhängen!!!!!!!!!!!

nichts mit bilder schicken sorry aber macht euer programm nicht

die möglich keit anhänge zu verwalten habe ich nicht!!!!!

ich kann die einen scree als mail schicken aber was anderes geht hier nicht

markusg 12.08.2013 21:18

Naja, wir haben sie schon, habs vor 3 Minuten überprüft.
lads mal da hoch:
File-Upload.net - Ihr kostenloser File Hoster!
und poste den Link zum download

baby-lissa 12.08.2013 21:23

File-Upload.net - Grafik.docx

File-Upload.net - screen.docx

File-Upload.net - Troja.docx

markusg 12.08.2013 21:24

ich brauch den ganzen link. das was unter download link steht einfach reinkopieren in die Antwort

baby-lissa 12.08.2013 21:24

so und wo ist da Datei anhängen???

markusg 12.08.2013 21:25

hab ich auch schon auf der vorherigen seite geschrieben. auf antworten klicken, anhänge verwalten

baby-lissa 12.08.2013 21:25

solltet ihr mal euer programm besser machen ich habe den ganzen link geschickt, euer programm schreddert die wichtigste hälte
File-Upload.net - Troja.docx

markusg 12.08.2013 21:27

nein, es ändert nur http auf hxxp damit nicht jeder links schicken kann, bei dir fehlen aber noch mehr teile.
und auch hier, alle anderen Hilfesuchenen kommen damit zurecht, evtl. solltest du dir jemanden suchen, aus dem bekanntenkreis, der dich ein wenig unterstützt damit wir die Infos bekommen

baby-lissa 12.08.2013 21:29

ich kann hier nicht auf Verwalten klicken wo ist denn das ???????????
ich habe dir ein schree von dem Antworten butten zugesannt und da zeige mir wo es ist!

File-Upload.net - Troja.docx

7956174/Troja.docx.html

ja euer system schredderd den ganzen link nur den Namen lässt er zu

markusg 12.08.2013 21:30

dein Link geht immernoch nicht, aber wir kommen der sache näher, mail mir einfach mal deine screenshots
wieso eig docs, sollte doch ein screensholt, also pg oder etwas in der art sein
das is open office oder ähnliches

baby-lissa 12.08.2013 21:37

ich habe die alle daten 3 mal gesendet aber euer programm schreddert die zahlen einfach.
ich habe die links nicht gespeicher und wenn ich sie einfüge kommen sie nicht an

also lasst euch etwas besseres einfallen

download-7956174/Troja.docx.html

download-7956226/Grafik.docx.html

download-7956235/screen.docx.html

das ist ein ganz eifaches word dok

drei sots habe ich gepostet

vom screen, und vom Antwortfenster

File-Upload.net - Ihr kostenloser File Hoster!

vor das down ist ein /
davor das ht und ww file-upload.net /

markusg 12.08.2013 21:37

maile es mir adresse ist in meiner signatur. dann hänge ich das bild an

baby-lissa 12.08.2013 21:55

ok mail geht auch nicht wird von dir abgelehnt
super

wie bekomme ich nun diesen verkakten trojaner vom pc?

getwindow info nerft langsam
java updat und adobe update gehen ´nicht mehr weil immer der IE läuft

und wie weis ich ob meine datei wieder gelöscht werden auf file upload?

mail ist raus und sollte angekommen sein

markusg 12.08.2013 21:56

so, hängs erst mal an, hab hunger und sehs mir später an

baby-lissa 12.08.2013 22:33

der Butten unten rechts direkt antworten hat bei mir keine funktion

markusg 12.08.2013 22:37

ne nich direkt antworten, der heißt nur "antworten" aber is jetzt erst mal wurscht :-) sehs mir später an, dann werden wir schon ne lösung finden.p.s. bei direkt antworten springst du nur in das unten angezeigte Eingabefeld

baby-lissa 12.08.2013 22:45

jetzt kann ich aus outlook mail wieder nicht direkt über den link auf die Internet seite springen. das ging bis vorhin

markusg 12.08.2013 22:53

ich habs doch jetzt schon, es hängt doch weiter oben an
aber heute seh ich mir das nich mehr an.
hab hunger und dann is ende für heute

baby-lissa 12.08.2013 22:58

ich danke dir erstmal bis hier und mache mich auch ins bett.
muss um 6 hoch.

Danke

markusg 12.08.2013 23:29

Kein ding, das bekommen wir schon wieder hin.

markusg 13.08.2013 18:29

hi, kannst du mal die Systemwiederherstellung nutzen, und den neuesten Punkt, vor combofix, nutzen, wie sieht es dann aus?

baby-lissa 13.08.2013 19:02

ich habe die letzten tage offe eine system wiederherstellung gemacht, da is keine änderung getwindow und TBupdater bleiben
den rest habe ich wieder hinbekommen mit den ganzen änderungen die combfix vorgenommen hat

markusg 13.08.2013 19:52

Hi, häufige Systemwiederherstellungen sind auch eher ungünstig für das System, grade bei malware befall.
Es sind 2 Logs zu erstellen.
1.

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


neustarten.
2.
HitmanPro - Download - Filepony
Doppelklicken, Scan klicken. Log speichern und posten, bzw als XML exportieren, packen und anhängen. hitmanpro schließen

baby-lissa 13.08.2013 20:03

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.4 (08.12.2013:1)
OS: Windows 7 Home Premium x64
Ran by Lissi1 on 13.08.2013 at 20:58:44,28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\lyricstar



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\big fish games"
Successfully deleted: [Folder] "C:\Users\Lissi1\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\Lissi1\appdata\local\adawarebp"
Successfully deleted: [Folder] "C:\Users\Lissi1\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Program Files (x86)\eusing free registry cleaner"
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{02609373-5111-4B90-AFD7-048DEB1A6F46}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{03E0EA8E-253B-440D-B88C-68B7EACC4BA3}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{0A04C22E-6CBF-43C6-ABA6-02DEAC20BB7E}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{16448AE2-E8B0-4F48-B32A-62966ED71488}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{18E7094B-C336-4991-BF13-F91229F75C0F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{1B8E8497-931A-4D57-A3F5-6D4189C88ADB}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{1D5E136E-47AF-461C-A4BB-45E8817CCDF3}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{27628329-BD4D-481B-89C9-837588A4BF27}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{2D21CAF1-E27F-424F-9F6A-3C2B7F8E8FE5}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{2D41A860-B623-47C2-8731-3B430AE4CF0A}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{2ED5AABC-37B3-4540-909D-29FBD29F1D22}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{36BB5711-0587-47A0-AAA0-163985EE50DD}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{38F828AB-BA1B-43C6-BD18-9797AD23DB83}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{3934A644-4783-43E5-8546-A7E5E2E99FE0}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{3A677267-0C79-41AA-974C-FD5D32D71BDC}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{3E47F9AD-8E93-463B-9185-39019E67D959}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{468453D5-42FA-45DB-96BD-B5453883F110}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{532BDFBC-7432-4825-813D-EDEFB471BEA0}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{54D97109-37AC-437A-B7FD-FEB3C83C71CA}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{5909F39D-864C-4800-84F2-06134F7456A8}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{5B53BAF3-AC66-4D09-AA90-8B326CD10E2F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{5E8850F2-2580-42B9-AC9E-E6042DB2B730}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{667AD1F6-8812-4604-A2A3-AD2CAA52BF1E}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{672DF01E-A489-4D2E-9AE1-5F6D567475E3}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{675F4FF7-94FD-48D3-96E0-2A37CD88CD7F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{69E757AE-996A-45B7-9E18-B7AB1B5A2FF2}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{6CE0CCFD-225C-4457-9FAB-F361BAF51AE1}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{6F21E2AD-3A39-4686-A5F0-15BFD8138730}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{77288DC9-C300-47E8-926A-F3BA8CF8E711}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{776DAD39-B110-4BB8-8E5D-C94A0562B076}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{79D351A7-86AB-4734-97E9-C42B3C381CD0}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{7A12071F-9FAB-4AA7-86D0-4489B3AC3235}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{7AEFFBA2-FD0E-43B9-AC68-1FF08B2F9EF3}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{7DAAA44A-3D30-43B7-B626-34F03F8E3CB3}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{804FC1F1-CDC1-4979-BBFD-D775F292CB10}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{81977D28-7A78-46C9-9E73-CDB86105139F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{81C35152-3CE8-453A-BD85-C8F4E2296579}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{82CCD1D6-A3C2-4B6A-8BF1-AF713CE7385D}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{830EA2F8-F69A-49D2-9B64-F5E9790F2677}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{87BB76C1-82E0-437C-A37C-0433E34C4B33}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{880A9B20-9E10-4D93-B15B-D80B28950967}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{8B102F25-1113-48D3-9381-DA6E4B9A6BA8}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{8EF11119-F58F-43BF-BC83-8F60387DADED}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{9366A743-3BD8-4380-AE36-C99E98B79B62}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{95826115-80F8-4238-BFCE-1177E17E2FFF}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{9637470F-AE6B-4822-9194-58F37C469FC7}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{9873A470-EC12-42A5-9F56-6A62A9DEB945}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{9B7ABD7B-822A-483F-A475-D671903D64EF}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{9FEF4429-2533-4C31-8AB5-FBB1585CC41D}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A040C1EC-0FB9-4412-9CD2-3434098464C5}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A0C81183-369E-4919-AC2C-82AA199BCF7D}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A2D353A1-7E51-4F51-875C-1EA0F13613DE}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A2FDA827-159E-4898-9016-E6A1408AFA4C}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A3086875-9814-4F33-8EC1-236AF2B094AE}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A345F238-FDCA-4C02-9A52-88D2DA0505CB}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A65E6B54-9310-434B-9A0A-26CE3B767B2A}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A7BE3289-00DF-4484-9A84-2380F775A250}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{A986A8D2-8C53-43BD-BB7F-09537526B731}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{AF213750-53F5-4C27-8A1E-BAF5E2778914}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{B5779169-D1A5-4C31-BA23-B4A9123AE13D}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{B642DF27-9873-4482-A375-2B735EA9D70F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{BA0C9FED-39A9-4AC8-A205-1C95FF5609C5}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{BA876620-B304-4EBC-9B28-B11DC4C2D703}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{BA9E8F27-38B9-4427-8160-93872581451F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{BE6E1C0D-66D9-4C9E-8AA5-1A30BF5FDB8F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{C3AEB925-43A5-40D4-ABAB-ADB1C94C7594}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{C4211C59-A835-48C6-96DA-2F9BB2663DFB}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{C5B9907E-F2B0-426F-A80C-169E15F37514}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{C7CC719C-2D94-4AE4-88D9-2E84AC2F934B}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{CA8566FC-AED6-4BA2-9469-943D7E84BFBA}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{CDBAD07D-AB10-4D36-A71B-456595780BCD}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{D4D01763-31D6-49D0-8FC8-9903D712EA34}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{D6A1D2E4-B865-4D69-B4E6-D803A9860973}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{DBC7E3C0-F354-401D-92E6-15B243B19887}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{DCDF58CB-0C51-4511-B596-A1080D2D4185}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{DD568614-BA5E-4E12-A84B-C59CF2C03B1F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{DE11E9FA-552E-4879-B78D-509C2A1EC08B}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{DEEDEAF9-8B66-4AF5-AF42-1BFA525AC0A8}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{DFB01DC9-80B9-4EE5-AAC8-37E1BEDBF69A}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{E051A85D-66D4-4715-AFC6-7B7CC85D5D05}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{E669DA13-D1D7-4467-8C6E-03285C19EF68}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{E900B956-EAE5-4E8F-9FC7-2A7A38DE1A04}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{E95A0597-7764-4DA2-A260-121245F79BBA}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{EAE373F6-8DFB-4671-9E9A-041A58F96C65}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{EF25D2C6-40D8-47D4-A3C0-363D55768472}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{F0D17F3A-03DE-467E-9812-7A5D587DCC21}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{F0D51062-19A9-4E31-83FE-E0BCC7766AA0}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{F26DFEA9-156A-4CEB-B8EC-AA44320EACC8}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{F3385001-E86E-4DF6-81EC-DC40C0B41094}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{F3A2D1F1-C34E-4FAA-B303-DDE9DDF2FEDB}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{F7AF5272-E645-4906-AE3B-A2C820B821E7}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{FAF84326-4611-466D-B67A-0E297DF11DC0}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{FC13AC0B-BDBC-47F5-968F-FA6BEBDD1E5E}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{FEF9DA53-1155-4AD2-9665-0C49488BAE0F}
Successfully deleted: [Empty Folder] C:\Users\Lissi1\appdata\local\{FF9A8822-4474-4304-9014-9D112D469C43}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.08.2013 at 21:02:23,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

markusg 13.08.2013 20:15

Hitmanpro fehlt.

baby-lissa 13.08.2013 20:20

ich habe kein log bekommen von hitman

habe es als Screenshot auf eine Word doc gepackt und sende es dir als MAil

Code:

HitmanPro 3.7.7.203
www.hitmanpro.com

  Computer name . . . . : LISSI1-PC
  Windows . . . . . . . : 6.1.1.7601.X64/4
  User name . . . . . . : Lissi1-PC\Lissi1
  UAC . . . . . . . . . : Enabled
  License . . . . . . . : Trial (30 days left)

  Scan date . . . . . . : 2013-08-13 21:11:23
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 3m 32s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 9
  Traces  . . . . . . . : 119

  Objects scanned . . . : 1.968.380
  Files scanned . . . . : 38.216
  Remnants scanned  . . : 494.400 files / 1.435.764 keys

Malware _____________________________________________________________________

  C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TTDT2QBV\JRT.exe -> Quarantined
      Size . . . . . . . : 1.158.722 bytes
      Age  . . . . . . . : 0.0 days (2013-08-13 20:58:26)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : BB6B57BA57C7FF4D3AA76AC5BECE1ECA885526015EA1FFE21F98262727E1D7EF
      Product  . . . . . : Junkware Removal Tool
      Publisher  . . . . : Thisisu
      Version  . . . . . : 1.0.0.1
      Source URL . . . . : hxxp://thisisudax.org/downloads/JRT.exe
    > Ikarus . . . . . . : Virus.Win32.PePatch!IK
      Fuzzy  . . . . . . : 114.0
      Forensic Cluster
        -23.7s C:\Users\Lissi1\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{470752FC-044A-11E3-BC7E-6C626D8C2B78}.dat
        -23.5s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WZMYHXGV\download-junkware_removal_tool[1].htm
        -23.4s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PX0PKE4O\css[1].css
        -23.3s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S850FDQ4\junkware_removal_tool[2].png
        -23.3s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PWV4IM6U\junkware_removal_tool2[1].jpg
        -23.3s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WZMYHXGV\aimp[1].png
        -23.3s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PX0PKE4O\junkware_removal_tool1[1].jpg
        -23.2s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S850FDQ4\junkware_removal_tool[3].png
        -23.2s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PWV4IM6U\junkware_removal_tool[1].jpg
        -22.9s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AO0IQ7C6\faviconCAE5F23M.ico
        -20.6s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WZMYHXGV\get-mirror-server[1].htm
        -20.0s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PX0PKE4O\ads[3].js
        -19.8s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S850FDQ4\8275612509822117742[1].gif
        -19.7s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PWV4IM6U\redir[1].htm
        -19.7s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WZMYHXGV\iframe[1].htm
          0.0s C:\Users\Lissi1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TTDT2QBV\JRT.exe
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\APPID_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\APPID_files.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\APPPATHS.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\APPROVEDEXTENSIONS_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\ask.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\askCLSID.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\askregkey_x64.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\askregkey_x86.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\askregvalue_x64.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\askregvalue_x86.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\askservices.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\badAPPINIT.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\badFOLDERS.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\badFOLDERScom.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\badFOLDERSstart.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\badLNK.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\badvalues.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\BHO_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\BHO_name.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\browsermngr_keys.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\browsermngr_values.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\CHOICE.DAT
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\chrome.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\CHRregkey_x64.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\CHRregkey_x86.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\CHR_extensions.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\clean_shortcut.vbs
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\CLSID_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\currentmd5.txt
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\CUT.DAT
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\defaultscope.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\delfolders.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\delorphans.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\ELEVATIONPOLICY_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\ERDNT.E_E
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\ERDNTDOS.LOC
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\ERDNTWIN.LOC
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE.manifest
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\ERUNT.LOC
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\erunt\README.TXT
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\ev_clear.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\EXT.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFbrowsermngr.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFextensions.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFpluginREG.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFplugins.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFprefs.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFregkey_x64.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFregkey_x86.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFwhtlist.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFXML.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FFXPI.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\firefox.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FWCLSID.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\FWPolicy.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\get.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\IEwhtlst.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\iexplore.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\IFEO.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\INTERFACE_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\JRT.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\medfos.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\MENUEXT.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\merger.reg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\misc.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\modules.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\modules.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\moduleservices.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\NIRCMD.DAT
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\NOTIFY.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\PREAPPROVED_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\prelim.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\REGhcr.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\REGhkcu_and_hklm_allow.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\REGhkcu_and_hklm_software.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\REGhkcu_software_appdatalow.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\REGhkcu_software_microsoft.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\REGhklm_software_classes.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\runvalues.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\runvalues_x64.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\runvalues_x86.cfg
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\S1518COMPONENTS.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\searchlnk.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\SED.DAT
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\sednewline.txt
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\services.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\SETTINGS_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\SHORTCUT.DAT
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\STATS_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\TDL4.bat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\temp\
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\temp\
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\TRACING.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\TYPELIB_clsid.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\UpgradeCodes.dat
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\WGET.DAT
          0.7s C:\Users\Lissi1\AppData\Local\Temp\jrt\WOW6432NODE.dat
          5.6s C:\Users\Lissi1\AppData\Local\Temp\jrt\newmd5.txt


Potential Unwanted Programs _________________________________________________

  HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1\ (Babylon)
  HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager\ (Babylon)
  HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}\ (Babylon)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E\ (AskBar)

Cookies _____________________________________________________________________

  C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Cookies\2PW9DALU.txt
  C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Cookies\DY0KIIN6.txt

sorry war unter temp gespeichert

markusg 13.08.2013 20:26

hast du kookies und unwanted programs auch gelöscht? bitte noch mal scannen lassen und schauen, dass alle Funde entfernt wurden.
Danach neues FRST Log

baby-lissa 13.08.2013 20:27

mit welchem programm löschen????
ich habe garnichts bisher gelöscht

markusg 13.08.2013 20:30

Hi,
doch laut log hast du einen Fund in die Quarantäne geschickt, hast du in Hitmanpro auf weiter geklickt, dann passiert das nämlich.
lasse also hitmanpro noch mal scannen, markiere alle Funde gehe auf weiter und lösche sie.
Browser aber bitte vorher schließen.
Dann neustarten, neues frst log

baby-lissa 13.08.2013 20:34

Code:

HitmanPro 3.7.7.203
www.hitmanpro.com

  Computer name . . . . : LISSI1-PC
  Windows . . . . . . . : 6.1.1.7601.X64/4
  User name . . . . . . : Lissi1-PC\Lissi1
  UAC . . . . . . . . . : Enabled
  License . . . . . . . : Trial (30 days left)

  Scan date . . . . . . : 2013-08-13 21:29:12
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 2m 40s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 0
  Traces  . . . . . . . : 105

  Objects scanned . . . : 1.742.561
  Files scanned . . . . : 38.002
  Remnants scanned  . . : 494.232 files / 1.210.327 keys

Potential Unwanted Programs _________________________________________________

  HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1\ (Babylon)
  HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager\ (Babylon)
  HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}\ (Babylon)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF\ (AskBar)
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E\ (AskBar)

den log kann ich nur senden und ansehen wenn ich auf weiter klicke also weiter oder kein log?!

markusg 13.08.2013 20:37

joa, alle funde zum löschen markiert?b

baby-lissa 13.08.2013 21:03

Combofix Logfile:
Code:

ComboFix 13-08-13.02 - Lissi1 13.08.2013  21:45:53.3.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4023.2284 [GMT 2:00]
ausgeführt von:: c:\users\Lissi1\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Lavasoft Ad-Aware *Disabled/Outdated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
 * Neuer Wiederherstellungspunkt wurde erstellt
 * Im Speicher befindliches AV aktiv.
.
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\19795AD46B.sys
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-07-13 bis 2013-08-13  ))))))))))))))))))))))))))))))
.
.
2013-08-13 19:54 . 2013-08-13 19:54        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-08-13 19:11 . 2013-08-13 19:19        --------        d-----w-        c:\programdata\HitmanPro
2013-08-13 19:06 . 2013-08-13 19:07        --------        d-----w-        c:\users\Lissi1\AppData\Local\adawarebp
2013-08-13 18:58 . 2013-08-13 18:58        --------        d-----w-        c:\windows\ERUNT
2013-08-13 09:57 . 2011-06-27 07:31        9728        ----a-w-        c:\windows\SysWow64\HWLMSET2PS.dll
2013-08-13 09:57 . 2011-06-27 07:31        589824        ----a-w-        c:\windows\SysWow64\HWLMSET2.exe
2013-08-13 09:57 . 2013-08-13 09:57        --------        d-----w-        c:\windows\HerculesWebcamUpdater
2013-08-13 09:57 . 2011-06-16 14:34        3359832        ----a-w-        c:\windows\system32\drivers\S6000KNT.sys
2013-08-13 09:57 . 2009-06-04 07:34        65024        ----a-w-        c:\windows\system32\drivers\guillflt.sys
2013-08-13 09:57 . 2009-02-08 21:43        111104        ----a-w-        c:\windows\system32\drivers\hxctlflt.sys
2013-08-13 09:57 . 2013-08-13 09:57        --------        d-----w-        c:\program files (x86)\Hercules
2013-08-13 09:57 . 2011-06-16 14:34        76376        ----a-w-        c:\windows\system32\S6000DIF.dll
2013-08-13 09:57 . 2011-06-16 14:34        436824        ----a-w-        c:\windows\system\S6000Dex.dll
2013-08-13 09:56 . 2013-08-13 09:56        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\InstallShield
2013-08-12 19:08 . 2013-08-12 19:08        --------        d-----w-        C:\Computer
2013-08-12 18:41 . 2013-08-12 18:41        312232        ----a-w-        c:\windows\system32\javaws.exe
2013-08-12 18:41 . 2013-08-12 18:41        189352        ----a-w-        c:\windows\system32\javaw.exe
2013-08-12 18:41 . 2013-08-12 18:41        188840        ----a-w-        c:\windows\system32\java.exe
2013-08-12 18:41 . 2013-08-12 18:41        108968        ----a-w-        c:\windows\system32\WindowsAccessBridge-64.dll
2013-08-12 18:41 . 2013-08-12 18:41        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-12 18:41 . 2013-08-12 18:41        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-12 09:03 . 2013-08-12 18:39        --------        d-----w-        c:\users\Lissi1\AppData\Local\Adobe
2013-08-12 05:17 . 2013-08-12 05:17        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-11 14:37 . 2013-08-11 14:37        --------        d-----w-        C:\found.000
2013-08-07 17:58 . 2013-08-11 14:06        --------        d-----w-        c:\program files (x86)\Plus-HD-2.4
2013-08-07 08:31 . 2013-08-07 08:31        --------        d-----w-        c:\program files\Enigma Software Group
2013-08-07 08:30 . 2013-08-07 09:35        --------        d-----w-        c:\windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 08:30 . 2013-08-07 08:30        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-07 08:23 . 2013-04-17 07:02        1230336        ----a-w-        c:\windows\SysWow64\WindowsCodecs.dll
2013-08-07 08:23 . 2013-04-17 06:24        1424384        ----a-w-        c:\windows\system32\WindowsCodecs.dll
2013-08-07 08:14 . 2013-08-07 08:14        --------        d-----w-        C:\FRST
2013-08-06 16:55 . 2013-04-02 22:51        1643520        ----a-w-        c:\windows\system32\DWrite.dll
2013-08-06 16:55 . 2013-04-09 23:34        1247744        ----a-w-        c:\windows\SysWow64\DWrite.dll
2013-08-06 16:13 . 2012-03-14 03:00        385024        ----a-w-        c:\windows\system32\CNMLMAW.DLL
2013-08-06 16:00 . 2012-08-24 18:05        340992        ----a-w-        c:\windows\system32\schannel.dll
2013-08-06 16:00 . 2012-08-24 16:57        247808        ----a-w-        c:\windows\SysWow64\schannel.dll
2013-08-06 16:00 . 2012-08-24 18:13        154480        ----a-w-        c:\windows\system32\drivers\ksecpkg.sys
2013-08-06 16:00 . 2012-08-24 18:09        458712        ----a-w-        c:\windows\system32\drivers\cng.sys
2013-08-06 16:00 . 2012-08-24 18:03        1448448        ----a-w-        c:\windows\system32\lsasrv.dll
2013-08-06 16:00 . 2012-08-24 16:57        22016        ----a-w-        c:\windows\SysWow64\secur32.dll
2013-08-06 16:00 . 2012-08-24 16:53        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll
2013-08-06 12:38 . 2013-08-06 12:38        9728        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 08:56 . 2013-05-29 06:24        182936        ----a-w-        c:\program files\Internet Explorer\sqmapi.dll
2013-08-06 08:54 . 2013-04-10 06:01        265064        ----a-w-        c:\windows\system32\drivers\dxgmms1.sys
2013-08-06 08:54 . 2013-04-10 06:01        983400        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys
2013-08-06 08:54 . 2011-02-03 11:25        144384        ----a-w-        c:\windows\system32\cdd.dll
2013-08-06 08:54 . 2013-05-08 06:39        1910632        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-08-06 08:54 . 2013-01-03 06:00        288088        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2013-08-06 08:54 . 2013-02-27 05:52        14172672        ----a-w-        c:\windows\system32\shell32.dll
2013-08-06 08:54 . 2013-02-27 05:52        197120        ----a-w-        c:\windows\system32\shdocvw.dll
2013-08-06 08:54 . 2013-02-27 05:48        1930752        ----a-w-        c:\windows\system32\authui.dll
2013-08-06 08:54 . 2013-02-27 06:02        111448        ----a-w-        c:\windows\system32\consent.exe
2013-08-06 08:54 . 2013-02-27 05:47        70144        ----a-w-        c:\windows\system32\appinfo.dll
2013-08-06 08:54 . 2013-02-27 04:49        1796096        ----a-w-        c:\windows\SysWow64\authui.dll
2013-08-06 08:52 . 2013-06-05 03:34        3153920        ----a-w-        c:\windows\system32\win32k.sys
2013-08-06 08:52 . 2013-05-10 05:49        30720        ----a-w-        c:\windows\system32\cryptdlg.dll
2013-08-06 08:52 . 2013-05-10 03:20        24576        ----a-w-        c:\windows\SysWow64\cryptdlg.dll
2013-08-06 08:52 . 2013-04-10 05:48        1732608        ----a-w-        c:\program files\Windows Journal\NBDoc.DLL
2013-08-06 08:52 . 2013-04-10 05:46        1367040        ----a-w-        c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-08-06 08:52 . 2013-04-10 05:46        1402880        ----a-w-        c:\program files\Windows Journal\JNWDRV.dll
2013-08-06 08:52 . 2013-04-10 05:46        1393152        ----a-w-        c:\program files\Windows Journal\JNTFiltr.dll
2013-08-06 08:52 . 2013-04-10 05:03        936448        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-08-06 08:52 . 2013-01-24 06:01        223752        ----a-w-        c:\windows\system32\drivers\fvevol.sys
2013-08-06 08:51 . 2013-05-13 05:51        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2013-08-06 08:51 . 2013-05-13 05:51        1464320        ----a-w-        c:\windows\system32\crypt32.dll
2013-08-06 08:51 . 2013-05-13 04:45        1160192        ----a-w-        c:\windows\SysWow64\crypt32.dll
2013-08-06 08:51 . 2013-05-13 03:43        1192448        ----a-w-        c:\windows\system32\certutil.exe
2013-08-06 08:51 . 2013-05-13 03:08        903168        ----a-w-        c:\windows\SysWow64\certutil.exe
2013-08-06 08:51 . 2013-05-13 05:51        139776        ----a-w-        c:\windows\system32\cryptnet.dll
2013-08-06 08:51 . 2013-05-13 05:50        52224        ----a-w-        c:\windows\system32\certenc.dll
2013-08-06 08:51 . 2013-05-13 04:45        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2013-08-06 08:51 . 2013-05-13 04:45        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2013-08-06 08:51 . 2013-05-13 03:08        43008        ----a-w-        c:\windows\SysWow64\certenc.dll
2013-08-06 08:50 . 2013-03-19 06:04        5550424        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-08-06 08:50 . 2013-03-19 05:04        3968856        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2013-08-06 08:50 . 2013-03-19 05:04        3913560        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2013-08-06 08:50 . 2013-03-19 03:06        112640        ----a-w-        c:\windows\system32\smss.exe
2013-08-06 08:50 . 2013-03-19 05:46        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2013-08-06 08:50 . 2013-03-19 04:47        6656        ----a-w-        c:\windows\SysWow64\apisetschema.dll
2013-08-06 08:50 . 2013-04-25 23:30        1505280        ----a-w-        c:\windows\SysWow64\d3d11.dll
2013-08-06 08:50 . 2013-03-31 22:52        1887232        ----a-w-        c:\windows\system32\d3d11.dll
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 10:28 . 2013-08-05 10:28        --------        d-----w-        c:\programdata\Malwarebytes
2013-08-05 10:26 . 2013-08-06 22:09        --------        d-----w-        c:\program files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 09:49 . 2013-08-05 09:49        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Avira
2013-08-05 09:44 . 2013-08-05 09:44        83672        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
2013-08-05 09:42 . 2013-08-05 09:35        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-08-05 09:42 . 2013-08-05 09:35        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-08-05 09:42 . 2013-08-05 09:35        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-08-05 09:42 . 2013-08-05 09:43        --------        d-----w-        c:\programdata\Avira
2013-08-05 09:42 . 2013-08-05 09:42        --------        d-----w-        c:\program files (x86)\Avira
2013-07-23 16:47 . 2013-07-23 16:47        --------        d-----w-        c:\users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 16:20 . 2013-07-29 16:44        --------        d-----w-        c:\users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 16:20 . 2013-08-01 01:08        32328        ----a-w-        c:\windows\Launcher.exe
2013-07-17 16:43 . 2013-07-17 16:43        --------        d-----w-        c:\users\Lissi1\AppData\Local\Deployment
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-12 21:37 . 2012-02-24 15:55        6738        --sha-w-        c:\programdata\KGyGaAvL.sys
2013-08-12 18:41 . 2012-12-16 15:13        1093032        ----a-w-        c:\windows\system32\npDeployJava1.dll
2013-08-12 18:41 . 2011-07-18 21:14        972712        ----a-w-        c:\windows\system32\deployJava1.dll
2013-06-23 22:57 . 2011-07-18 20:31        78277128        ----a-w-        c:\windows\system32\MRT.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        130736        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-12-20 844296]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-14 343168]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-01-31 542632]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-08-05 345144]
.
c:\users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
net.lnk - c:\users\Lissi1\AppData\Roaming\Windows Net Data\net.exe [2013-7-23 709120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Scanner Finder.lnk - c:\program files (x86)\ScanWizard 5\ScannerFinder.exe [2012-2-4 344064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled\
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe [2013-5-17 1393744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0bootdelete
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS;c:\windows\SYSNATIVE\DRIVERS\PFC027.SYS [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [x]
S2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 guillflt;Guillemot Audio Lower Filter;c:\windows\system32\DRIVERS\guillflt.sys;c:\windows\SYSNATIVE\DRIVERS\guillflt.sys [x]
S3 hxctlflt;hxctlflt;c:\windows\system32\Drivers\hxctlflt.sys;c:\windows\SYSNATIVE\Drivers\hxctlflt.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 S6000KNT;Hercules HD Exchange;c:\windows\system32\Drivers\S6000KNT.sys;c:\windows\SYSNATIVE\Drivers\S6000KNT.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-12 18:41]
.
2013-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
2013-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-04 16:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36        164016        ----a-w-        c:\users\Lissi1\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 12673128]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944]
"IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272]
"CamserviceHDExchange"="c:\program files (x86)\Hercules\Hercules HD Exchange\XtrCtrlEx.exe" [2012-01-12 3391344]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - Elektronik, Autos, Mode, Sammlerstücke, Gutscheine und mehr Online-Shopping | eBay
IE: {{92808042-fb78-4fa0-bb4f-c9a95e0e9c10} - {ba696155-d96e-4281-b467-0367a0456474} -
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
Toolbar-!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{ba696155-d96e-4281-b467-0367a0456474} - (no file)
WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)
WebBrowser-{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - (no file)
WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - (no file)
AddRemove-Adobe Flash Player ActiveX - c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
AddRemove-_{707EB912-C597-49D8-9460-46CC9AB03EBE} - c:\program files (x86)\Corel\Corel Painter Photo Essentials 4\MSILauncher {707EB912-C597-49D8-9460-46CC9AB03EBE}
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-4060780361-2962197505-3855748707-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ba696155-d96e-4281-b467-0367a0456474}]
@Denied: (A 2) (Administrators)
@Denied: (A 2) (S-1-5-21-4060780361-2962197505-3855748707-1000)
"Flags"=dword:00000400
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32]
@DACL=(02 0000)
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-13  21:55:47
ComboFix-quarantined-files.txt  2013-08-13 19:55
ComboFix2.txt  2013-08-12 19:03
ComboFix3.txt  2013-08-06 08:33
.
Vor Suchlauf: 16 Verzeichnis(se), 1.377.346.707.456 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 1.377.332.973.568 Bytes frei
.
- - End Of File - - 4E759CF96FCBB330B83F1AF8FF9B2F72

--- --- ---
D41D8CD98F00B204E9800998ECF8427E

also hitman hat nichts gelöscht, nur ignoriert!!!
>Alle probleme sind weiterhin vorhanden, jetzt ist get windowinfo dreimal da und tbupdater ist auch geblieben, dafür hat combo wieder den Explorer umbenannt, ad-aware gelöscht und mault über avira, avira meldet seit hitman 156 viren oder unerwünschte datein.
Wie bekomme ich combo, hitman und den anderen dreck von meinem pc?


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-08-2013 01
Ran by Lissi1 (administrator) on 13-08-2013 22:02:17
Running from C:\Users\Lissi1\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Guillemot Corporation S.A.) C:\Program Files (x86)\Hercules\Hercules HD Exchange\XtrCtrlEx.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CrypKey (Canada) Ltd.) C:\Windows\system32\crypserv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [Monitor] - C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [IntelliType Pro] - c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [CamserviceHDExchange] - C:\Program Files (x86)\Hercules\Hercules HD Exchange\XtrCtrlEx.exe [3391344 2012-01-12] (Guillemot Corporation S.A.)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung)
HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [542632 2013-01-31] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-08-05] (Avira Operations GmbH & Co. KG)
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Scanner Finder.lnk
ShortcutTarget: Scanner Finder.lnk -> C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled ()
Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Lissi1\AppData\Roaming\Windows Net Data\net.exe (Windows Net)
BootExecute: autocheck autochk * bootdelete

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {00B6DEF0-C572-45D3-AF51-CD416F2DA9C0} URL = hxxp://www.bing.com/search?FORM=BDT3DF&PC=BDT3&dt=080613&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKCU - 63D76E6EC6B04284B071A585DCBE8EA6 URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=53E641BF-D5D6-4646-8077-EE58703B9D12&apn_sauid=45E38BAC-10B5-487C-BE1B-F389560F4295
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {120A8821-2BEE-4C29-BCDA-62C577781992} -  No File
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Deaktivierungs-Add-on für Browser von Google Analytics - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll (Google, Inc.)
BHO-x32: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} -  No File
BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} -  No File
Toolbar: HKLM - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
Toolbar: HKLM-x32 - No Name - !{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} -  No File
Toolbar: HKLM-x32 - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} -  No File
Toolbar: HKLM-x32 - HomeTab - {ba696155-d96e-4281-b467-0367a0456474} -  No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -  No File
Toolbar: HKCU - No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} -  No File
Toolbar: HKCU - No Name - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} -  No File
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage:                "homepage":        "",
CHR RestoreOnStartup: "hxxp://www.msn.com/?pc=BDT3&ocid=BDT3DHP&dt=080613"
CHR Extension: (Plus-HD-2.4) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.23.29_0
CHR Extension: (Skype Click to Call) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.0.0_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

==================== Services (Whitelisted) =================

R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-02-14] (Lavasoft Limited)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-05] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-08-05] (Avira Operations GmbH & Co. KG)
S3 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [45056 2006-12-14] (Sony Corporation)
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [57344 2006-12-14] ()
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
S3 SonicStage Back-End Service; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe [112184 2007-02-05] (Sony Corporation)
S3 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [69632 2006-12-14] (Sony Corporation)
S3 SSScsiSV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe [75320 2007-02-05] (Sony Corporation)
R2 Crypkey License; crypserv.exe [x]

==================== Drivers (Whitelisted) ====================

S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-05] (Avira Operations GmbH & Co. KG)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-02-22] (GFI Software)
R3 guillflt; C:\Windows\System32\DRIVERS\guillflt.sys [65024 2009-06-04] (Guillemot Corp S.A.)
R3 hxctlflt; C:\Windows\System32\Drivers\hxctlflt.sys [111104 2009-02-08] (Guillemot Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] ()
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.)
R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3359832 2011-06-16] (Windows (R) Win 7 DDK provider)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-13 21:56 - 2013-08-13 21:56 - 00065536 ___HT C:\Users\Lissi1\~Outlooklissa.pst.tmp
2013-08-13 21:55 - 2013-08-13 21:55 - 00030385 _____ C:\ComboFix.txt
2013-08-13 21:38 - 2013-08-13 21:38 - 00005254 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2138.log
2013-08-13 21:32 - 2013-08-13 21:32 - 00005256 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2131.log
2013-08-13 21:19 - 2013-08-13 21:19 - 00025732 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2119.log
2013-08-13 21:11 - 2013-08-13 21:19 - 00000000 ____D C:\ProgramData\HitmanPro
2013-08-13 21:06 - 2013-08-13 21:07 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-13 21:02 - 2013-08-13 21:02 - 00011433 _____ C:\Users\Lissi1\Desktop\JRT.txt
2013-08-13 20:58 - 2013-08-13 20:58 - 00000000 ____D C:\Windows\ERUNT
2013-08-13 12:59 - 2013-08-13 12:59 - 00000000 ____D C:\Users\Lissi1\Desktop\Stinger
2013-08-13 11:58 - 2013-08-13 11:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_guillflt_01007.Wdf
2013-08-13 11:57 - 2013-08-13 11:57 - 02063600 _____ C:\Windows\vcredist_x64.log
2013-08-13 11:57 - 2013-08-13 11:57 - 02058774 _____ C:\Windows\vcredist_x86.log
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Windows\HerculesWebcamUpdater
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Program Files (x86)\Hercules
2013-08-13 11:57 - 2011-06-27 09:31 - 00589824 _____ (Guillemot Corporation S.A.) C:\Windows\SysWOW64\HWLMSET2.exe
2013-08-13 11:57 - 2011-06-27 09:31 - 00009728 _____ C:\Windows\SysWOW64\HWLMSET2PS.dll
2013-08-13 11:57 - 2011-06-16 16:34 - 03359832 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\S6000KNT.sys
2013-08-13 11:57 - 2011-06-16 16:34 - 00076376 _____ C:\Windows\system32\S6000DIF.dll
2013-08-13 11:57 - 2009-06-04 09:34 - 00065024 _____ (Guillemot Corp S.A.) C:\Windows\system32\Drivers\guillflt.sys
2013-08-13 11:57 - 2009-02-08 23:43 - 00111104 _____ (Guillemot Corporation) C:\Windows\system32\Drivers\hxctlflt.sys
2013-08-13 11:57 - 2003-09-23 04:36 - 00013448 _____ C:\Windows\S6000Twn.src
2013-08-13 11:57 - 2003-09-23 03:49 - 00015190 _____ C:\Windows\S6000Twn.ini
2013-08-13 11:56 - 2013-08-13 11:56 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\InstallShield
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____H C:\Users\Lissi1\Desktop\Desktop.event
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____D C:\Users\Lissi1\Saved Games\Documents\Corel VideoStudio Pro
2013-08-12 21:08 - 2013-08-12 21:08 - 00000000 ____D C:\Computer
2013-08-12 20:50 - 2013-08-13 21:39 - 05103833 ____R (Swearware) C:\Users\Lissi1\Desktop\ComboFix.exe
2013-08-12 20:41 - 2013-08-13 21:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-12 20:41 - 2013-08-12 20:41 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-08-12 20:41 - 2013-08-12 20:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-12 20:41 - 2013-08-12 20:41 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-12 20:38 - 2013-08-12 20:41 - 33150376 _____ (Oracle Corporation) C:\Users\Lissi1\Downloads\jre-7u25-windows-x64.exe
2013-08-12 20:34 - 2013-08-12 20:34 - 00067897 _____ C:\Users\Lissi1\Desktop\FRST1.txt
2013-08-12 20:33 - 2013-08-12 20:33 - 00044584 _____ C:\Users\Lissi1\Desktop\Addition.txt
2013-08-12 11:03 - 2013-08-12 20:39 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-11 18:22 - 2013-08-11 18:22 - 00002676 _____ C:\AdwCleaner[S12].txt
2013-08-11 18:22 - 2013-08-11 18:22 - 00002613 _____ C:\AdwCleaner[R19].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015178 _____ C:\AdwCleaner[R18].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015091 _____ C:\AdwCleaner[S11].txt
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 ____D C:\found.000
2013-08-09 19:38 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-07 19:58 - 2013-08-11 16:06 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4
2013-08-07 18:29 - 2013-08-07 18:29 - 00002180 _____ C:\AdwCleaner[S10].txt
2013-08-07 18:28 - 2013-08-07 18:28 - 00002117 _____ C:\AdwCleaner[R17].txt
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 10:31 - 2013-08-07 10:31 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-07 10:30 - 2013-08-07 11:35 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:23 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-08-07 10:23 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-08-07 10:14 - 2013-08-07 10:14 - 00000000 ____D C:\FRST
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-06 18:55 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-08-06 18:55 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-08-06 18:20 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-08-06 18:20 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-08-06 18:20 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2013-08-06 18:20 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-08-06 18:20 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-08-06 18:20 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-08-06 18:20 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-08-06 18:20 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-08-06 18:20 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-08-06 18:20 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-08-06 18:20 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-08-06 18:20 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-08-06 18:20 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-08-06 18:20 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-08-06 18:20 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-08-06 18:18 - 2013-08-06 18:20 - 00000000 ____D C:\Windows\system32\MRT
2013-08-06 18:13 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMAW.DLL
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:06 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 18:00 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-08-06 18:00 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-08-06 18:00 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-08-06 18:00 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-08-06 18:00 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:35 - 2013-08-06 14:44 - 00010360 _____ C:\Windows\IE10_main.log
2013-08-06 11:59 - 2013-08-06 11:59 - 00002055 _____ C:\AdwCleaner[R14].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001994 _____ C:\AdwCleaner[R13].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001933 _____ C:\AdwCleaner[R12].txt
2013-08-06 10:56 - 2013-05-29 08:15 - 17829376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-06 10:56 - 2013-05-29 07:50 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-06 10:56 - 2013-05-29 07:43 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-06 10:56 - 2013-05-29 07:36 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-06 10:56 - 2013-05-29 07:35 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-06 10:56 - 2013-05-29 07:34 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-06 10:56 - 2013-05-29 07:33 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-06 10:56 - 2013-05-29 07:31 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-06 10:56 - 2013-05-29 07:27 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-06 10:56 - 2013-05-29 07:27 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-06 10:56 - 2013-05-29 07:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-06 10:56 - 2013-05-29 07:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-06 10:56 - 2013-05-29 07:18 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-06 10:56 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-06 10:56 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-06 10:56 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-06 10:56 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-06 10:56 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-06 10:56 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-06 10:56 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-06 10:56 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-06 10:56 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-06 10:56 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-08-06 10:56 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-06 10:56 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-06 10:56 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-06 10:56 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-06 10:56 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-06 10:56 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-06 10:54 - 2013-05-08 08:39 - 01910632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-06 10:54 - 2013-04-10 08:01 - 00983400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-08-06 10:54 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-08-06 10:54 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-08-06 10:54 - 2013-02-27 07:52 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-08-06 10:54 - 2013-02-27 07:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-08-06 10:54 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-08-06 10:54 - 2013-01-03 08:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-08-06 10:54 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-08-06 10:53 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-08-06 10:53 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-08-06 10:53 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-06 10:53 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-06 10:53 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-08-06 10:53 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-08-06 10:53 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-08-06 10:53 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-08-06 10:53 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023x.sys
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-08-06 10:53 - 2013-01-04 07:46 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-08-06 10:53 - 2013-01-04 06:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-06 10:53 - 2013-01-04 04:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-06 10:53 - 2013-01-04 04:47 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-06 10:53 - 2013-01-04 04:47 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-06 10:53 - 2013-01-04 04:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-06 10:52 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-08-06 10:52 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-08-06 10:52 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-08-06 10:52 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-08-06 10:51 - 2013-05-13 07:51 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-06 10:51 - 2013-05-13 07:51 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-06 10:51 - 2013-05-13 07:51 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-06 10:51 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-06 10:51 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-08-06 10:50 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-08-06 10:50 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-08-06 10:50 - 2013-03-19 08:04 - 05550424 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-06 10:50 - 2013-03-19 07:46 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-08-06 10:50 - 2013-03-19 07:04 - 03968856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-06 10:50 - 2013-03-19 07:04 - 03913560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-06 10:50 - 2013-03-19 06:47 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-08-06 10:50 - 2013-03-19 05:06 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-08-06 10:18 - 2013-08-13 21:55 - 00000000 ____D C:\Qoobox
2013-08-06 10:18 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-06 10:18 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-06 10:18 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-06 10:17 - 2013-08-06 10:32 - 00000000 ____D C:\Windows\erdnt
2013-08-06 10:10 - 2013-08-06 10:10 - 00001872 _____ C:\AdwCleaner[R11].txt
2013-08-06 10:08 - 2013-08-06 10:08 - 00001811 _____ C:\AdwCleaner[R10].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00002038 _____ C:\AdwCleaner[S7].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00001976 _____ C:\AdwCleaner[R9].txt
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 12:26 - 2013-08-07 00:09 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 12:26 - 2013-08-05 12:26 - 00001714 _____ C:\AdwCleaner[R8].txt
2013-08-05 12:21 - 2013-08-05 12:21 - 00001654 _____ C:\AdwCleaner[R7].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001596 _____ C:\AdwCleaner[S6].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001534 _____ C:\AdwCleaner[R6].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001726 _____ C:\AdwCleaner[S5].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001664 _____ C:\AdwCleaner[R5].txt
2013-08-05 12:01 - 2013-08-05 12:01 - 00666633 _____ C:\Users\Lissi1\Desktop\adwcleaner06.exe
2013-08-05 11:53 - 2013-08-05 11:53 - 00078778 _____ C:\AdwCleaner[R4].txt
2013-08-05 11:53 - 2013-08-05 11:53 - 00033765 _____ C:\AdwCleaner[S4].txt
2013-08-05 11:51 - 2013-08-05 11:51 - 00078717 _____ C:\AdwCleaner[R3].txt
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:42 - 2013-08-05 11:43 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:42 - 2013-08-05 11:35 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-26 13:22 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:22 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-07-25 16:48 - 2013-07-25 19:12 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-23 18:47 - 2013-07-23 18:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 18:20 - 2013-08-09 12:00 - 00003874 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-07-23 18:20 - 2013-08-01 03:08 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-23 18:20 - 2013-07-29 18:44 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 16:53 - 2013-07-22 17:03 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-22 14:41 - 2013-07-14 19:47 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430 - Kopie.mov
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 16:37 - 2013-07-17 17:49 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 16:37 - 2013-07-17 17:49 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-14 18:38 - 2013-07-14 19:47 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430.mov

==================== One Month Modified Files and Folders =======

2013-08-13 22:01 - 2013-05-08 20:36 - 190989312 _____ C:\Users\Lissi1\Outlooklissa.pst
2013-08-13 21:56 - 2013-08-13 21:56 - 00065536 ___HT C:\Users\Lissi1\~Outlooklissa.pst.tmp
2013-08-13 21:56 - 2012-02-04 18:48 - 00000000 ____D C:\Users\Lissi1
2013-08-13 21:55 - 2013-08-13 21:55 - 00030385 _____ C:\ComboFix.txt
2013-08-13 21:55 - 2013-08-06 10:18 - 00000000 ____D C:\Qoobox
2013-08-13 21:54 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-13 21:49 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-13 21:49 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-13 21:44 - 2013-08-12 20:41 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-13 21:44 - 2012-02-04 18:44 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-13 21:41 - 2013-03-05 20:06 - 00008680 _____ C:\Windows\error.log
2013-08-13 21:41 - 2012-10-23 16:46 - 00000000 ___RD C:\Users\Lissi1\Dropbox
2013-08-13 21:41 - 2012-10-23 16:44 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Dropbox
2013-08-13 21:40 - 2013-04-04 12:45 - 00010993 _____ C:\Windows\setupact.log
2013-08-13 21:40 - 2013-03-05 20:05 - 00003333 _____ C:\Windows\errord.log
2013-08-13 21:40 - 2012-02-04 18:44 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-13 21:40 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-13 21:39 - 2013-08-12 20:50 - 05103833 ____R (Swearware) C:\Users\Lissi1\Desktop\ComboFix.exe
2013-08-13 21:39 - 2012-02-04 18:43 - 01555458 _____ C:\Windows\WindowsUpdate.log
2013-08-13 21:38 - 2013-08-13 21:38 - 00005254 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2138.log
2013-08-13 21:32 - 2013-08-13 21:32 - 00005256 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2131.log
2013-08-13 21:19 - 2013-08-13 21:19 - 00025732 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2119.log
2013-08-13 21:19 - 2013-08-13 21:11 - 00000000 ____D C:\ProgramData\HitmanPro
2013-08-13 21:10 - 2012-12-24 23:53 - 00004084 _____ C:\Windows\System32\Tasks\Software Updater Ui
2013-08-13 21:10 - 2012-12-24 23:51 - 00004122 _____ C:\Windows\System32\Tasks\Software Updater
2013-08-13 21:07 - 2013-08-13 21:06 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-13 21:02 - 2013-08-13 21:02 - 00011433 _____ C:\Users\Lissi1\Desktop\JRT.txt
2013-08-13 20:58 - 2013-08-13 20:58 - 00000000 ____D C:\Windows\ERUNT
2013-08-13 18:45 - 2012-04-13 16:05 - 03463168 ___SH C:\Users\Lissi1\Desktop\Thumbs.db
2013-08-13 17:50 - 2012-09-20 17:48 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Skype
2013-08-13 12:59 - 2013-08-13 12:59 - 00000000 ____D C:\Users\Lissi1\Desktop\Stinger
2013-08-13 11:58 - 2013-08-13 11:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_guillflt_01007.Wdf
2013-08-13 11:57 - 2013-08-13 11:57 - 02063600 _____ C:\Windows\vcredist_x64.log
2013-08-13 11:57 - 2013-08-13 11:57 - 02058774 _____ C:\Windows\vcredist_x86.log
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Windows\HerculesWebcamUpdater
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Program Files (x86)\Hercules
2013-08-13 11:57 - 2011-07-18 23:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-13 11:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2013-08-13 11:56 - 2013-08-13 11:56 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\InstallShield
2013-08-12 23:38 - 2013-08-09 19:38 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-12 23:38 - 2013-07-26 13:22 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-08-12 23:38 - 2013-07-25 19:22 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-08-12 23:38 - 2013-06-15 16:45 - 00000000 ____D C:\Users\Lissi1\Desktop\Fohlenhof
2013-08-12 23:38 - 2013-06-12 17:55 - 00000000 ____D C:\Users\Lissi1\Desktop\LissiSchwimmfest
2013-08-12 23:38 - 2013-06-12 13:51 - 00000000 ____D C:\Users\Lissi1\Desktop\schwimmfest2013
2013-08-12 23:38 - 2013-06-11 07:55 - 00000000 ____D C:\Users\Lissi1\Desktop\garten2013
2013-08-12 23:38 - 2013-06-11 07:54 - 00000000 ____D C:\Users\Lissi1\Desktop\Norderney
2013-08-12 23:38 - 2013-06-08 14:03 - 00000000 ____D C:\Users\Lissi1\Desktop\tiergartenSommer
2013-08-12 23:38 - 2013-05-25 21:23 - 00000000 ____D C:\Users\Lissi1\Desktop\Turnier2013
2013-08-12 23:38 - 2012-02-05 11:48 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Ulead Systems
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____H C:\Users\Lissi1\Desktop\Desktop.event
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____D C:\Users\Lissi1\Saved Games\Documents\Corel VideoStudio Pro
2013-08-12 23:37 - 2012-02-24 17:55 - 00006738 ___SH C:\ProgramData\KGyGaAvL.sys
2013-08-12 21:46 - 2012-11-13 07:22 - 00127648 _____ C:\Windows\PFRO.log
2013-08-12 21:08 - 2013-08-12 21:08 - 00000000 ____D C:\Computer
2013-08-12 20:44 - 2012-05-27 20:06 - 00000000 ____D C:\Program Files (x86)\Intenium
2013-08-12 20:41 - 2013-08-12 20:41 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-08-12 20:41 - 2013-08-12 20:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-12 20:41 - 2013-08-12 20:41 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-12 20:41 - 2013-08-12 20:38 - 33150376 _____ (Oracle Corporation) C:\Users\Lissi1\Downloads\jre-7u25-windows-x64.exe
2013-08-12 20:41 - 2012-12-16 17:13 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-08-12 20:41 - 2011-07-18 23:14 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-08-12 20:39 - 2013-08-12 11:03 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-12 20:34 - 2013-08-12 20:34 - 00067897 _____ C:\Users\Lissi1\Desktop\FRST1.txt
2013-08-12 20:33 - 2013-08-12 20:33 - 00044584 _____ C:\Users\Lissi1\Desktop\Addition.txt
2013-08-12 20:26 - 2012-07-07 11:03 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-08-12 20:24 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-12 20:23 - 2012-07-15 22:08 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\DVDVideoSoft
2013-08-12 20:22 - 2012-12-27 12:37 - 00000000 ____D C:\Program Files (x86)\Biet-O-Matic
2013-08-12 20:22 - 2012-08-12 12:59 - 00000000 ____D C:\Program Files (x86)\AVS4YOU
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-11 19:57 - 2012-12-24 23:48 - 00000000 ____D C:\Program Files (x86)\SelfUpdater
2013-08-11 18:22 - 2013-08-11 18:22 - 00002676 _____ C:\AdwCleaner[S12].txt
2013-08-11 18:22 - 2013-08-11 18:22 - 00002613 _____ C:\AdwCleaner[R19].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015178 _____ C:\AdwCleaner[R18].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015091 _____ C:\AdwCleaner[S11].txt
2013-08-11 17:11 - 2012-05-09 15:14 - 00000000 ____D C:\Program Files (x86)\Free FLV Converter
2013-08-11 16:44 - 2013-03-10 20:20 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\MyPhoneExplorer
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 ____D C:\found.000
2013-08-11 16:06 - 2013-08-07 19:58 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4
2013-08-10 18:26 - 2013-03-10 20:25 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-08-10 18:25 - 2013-03-10 21:04 - 00002065 _____ C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2013-08-10 18:25 - 2013-03-10 21:04 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2013-08-09 12:00 - 2013-07-23 18:20 - 00003874 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-08-07 20:07 - 2012-05-09 15:16 - 00002592 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-07 18:29 - 2013-08-07 18:29 - 00002180 _____ C:\AdwCleaner[S10].txt
2013-08-07 18:28 - 2013-08-07 18:28 - 00002117 _____ C:\AdwCleaner[R17].txt
2013-08-07 11:35 - 2013-08-07 10:30 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 10:31 - 2013-08-07 10:31 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-07 10:14 - 2013-08-07 10:14 - 00000000 ____D C:\FRST
2013-08-07 01:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-07 00:09 - 2013-08-05 12:26 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-06 18:38 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-06 18:38 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-06 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-08-06 18:33 - 2011-04-12 10:28 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-08-06 18:20 - 2013-08-06 18:18 - 00000000 ____D C:\Windows\system32\MRT
2013-08-06 18:12 - 2011-05-16 16:04 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-08-06 18:12 - 2011-05-16 16:04 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-08-06 18:12 - 2009-07-14 07:13 - 01519624 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:07 - 2013-08-06 18:06 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 17:43 - 2011-07-18 22:54 - 00000000 ____D C:\Windows\Panther
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sl-SI
2013-08-06 14:51 - 2012-02-04 19:29 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-06 14:44 - 2013-08-06 14:35 - 00010360 _____ C:\Windows\IE10_main.log
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 11:59 - 2013-08-06 11:59 - 00002055 _____ C:\AdwCleaner[R14].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001994 _____ C:\AdwCleaner[R13].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001933 _____ C:\AdwCleaner[R12].txt
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-08-06 10:33 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-06 10:32 - 2013-08-06 10:17 - 00000000 ____D C:\Windows\erdnt
2013-08-06 10:10 - 2013-08-06 10:10 - 00001872 _____ C:\AdwCleaner[R11].txt
2013-08-06 10:08 - 2013-08-06 10:08 - 00001811 _____ C:\AdwCleaner[R10].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00002038 _____ C:\AdwCleaner[S7].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00001976 _____ C:\AdwCleaner[R9].txt
2013-08-05 16:22 - 2013-05-11 14:02 - 00000000 ____D C:\ProgramData\Avery
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 12:26 - 2013-08-05 12:26 - 00001714 _____ C:\AdwCleaner[R8].txt
2013-08-05 12:21 - 2013-08-05 12:21 - 00001654 _____ C:\AdwCleaner[R7].txt
2013-08-05 12:09 - 2012-02-04 23:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\CheckPoint
2013-08-05 12:08 - 2013-08-05 12:08 - 00001596 _____ C:\AdwCleaner[S6].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001534 _____ C:\AdwCleaner[R6].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001726 _____ C:\AdwCleaner[S5].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001664 _____ C:\AdwCleaner[R5].txt
2013-08-05 12:01 - 2013-08-05 12:01 - 00666633 _____ C:\Users\Lissi1\Desktop\adwcleaner06.exe
2013-08-05 11:53 - 2013-08-05 11:53 - 00078778 _____ C:\AdwCleaner[R4].txt
2013-08-05 11:53 - 2013-08-05 11:53 - 00033765 _____ C:\AdwCleaner[S4].txt
2013-08-05 11:51 - 2013-08-05 11:51 - 00078717 _____ C:\AdwCleaner[R3].txt
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:43 - 2013-08-05 11:42 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:35 - 2013-08-05 11:42 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-01 03:08 - 2013-07-23 18:20 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-29 18:44 - 2013-07-23 18:20 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:12 - 2013-07-25 16:48 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-23 18:47 - 2013-07-23 18:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 17:03 - 2013-07-22 16:53 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-18 20:44 - 2012-12-27 12:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\BOM
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 18:43 - 2012-09-17 16:53 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Apps\2.0
2013-07-17 18:34 - 2013-02-09 17:40 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus
2013-07-17 18:34 - 2012-05-09 15:14 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\FreeFLVConverter
2013-07-17 18:34 - 2012-02-04 21:31 - 00000000 ____D C:\Program Files (x86)\ScanWizard 5
2013-07-17 18:34 - 2011-07-18 23:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-17 18:21 - 2011-04-12 10:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-07-17 18:13 - 2013-02-09 17:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Ad-Aware Antivirus
2013-07-17 17:49 - 2013-07-17 16:37 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 17:49 - 2013-07-17 16:37 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-17 09:24 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files\Google
2013-07-16 08:43 - 2012-02-04 19:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Google
2013-07-16 08:43 - 2012-02-04 18:44 - 00000000 ____D C:\ProgramData\Google
2013-07-14 19:47 - 2013-07-22 14:41 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430 - Kopie.mov
2013-07-14 19:47 - 2013-07-14 18:38 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430.mov

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-12 05:58

==================== End Of Log ============================

--- --- ---

--- --- ---

baby-lissa 14.08.2013 12:55

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-08-2013 01
Ran by Lissi1 (administrator) on 13-08-2013 22:02:17
Running from C:\Users\Lissi1\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Guillemot Corporation S.A.) C:\Program Files (x86)\Hercules\Hercules HD Exchange\XtrCtrlEx.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CrypKey (Canada) Ltd.) C:\Windows\system32\crypserv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [Monitor] - C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [IntelliType Pro] - c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [CamserviceHDExchange] - C:\Program Files (x86)\Hercules\Hercules HD Exchange\XtrCtrlEx.exe [3391344 2012-01-12] (Guillemot Corporation S.A.)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung)
HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [542632 2013-01-31] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-08-05] (Avira Operations GmbH & Co. KG)
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Scanner Finder.lnk
ShortcutTarget: Scanner Finder.lnk -> C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled ()
Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Lissi1\AppData\Roaming\Windows Net Data\net.exe (Windows Net)
BootExecute: autocheck autochk * bootdelete

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {00B6DEF0-C572-45D3-AF51-CD416F2DA9C0} URL = hxxp://www.bing.com/search?FORM=BDT3DF&PC=BDT3&dt=080613&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKCU - 63D76E6EC6B04284B071A585DCBE8EA6 URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=53E641BF-D5D6-4646-8077-EE58703B9D12&apn_sauid=45E38BAC-10B5-487C-BE1B-F389560F4295
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {120A8821-2BEE-4C29-BCDA-62C577781992} -  No File
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Deaktivierungs-Add-on für Browser von Google Analytics - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll (Google, Inc.)
BHO-x32: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} -  No File
BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} -  No File
Toolbar: HKLM - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
Toolbar: HKLM-x32 - No Name - !{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} -  No File
Toolbar: HKLM-x32 - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} -  No File
Toolbar: HKLM-x32 - HomeTab - {ba696155-d96e-4281-b467-0367a0456474} -  No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -  No File
Toolbar: HKCU - No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} -  No File
Toolbar: HKCU - No Name - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} -  No File
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage:                "homepage":        "",
CHR RestoreOnStartup: "hxxp://www.msn.com/?pc=BDT3&ocid=BDT3DHP&dt=080613"
CHR Extension: (Plus-HD-2.4) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.23.29_0
CHR Extension: (Skype Click to Call) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.0.0_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

==================== Services (Whitelisted) =================

R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-02-14] (Lavasoft Limited)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-05] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-08-05] (Avira Operations GmbH & Co. KG)
S3 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [45056 2006-12-14] (Sony Corporation)
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [57344 2006-12-14] ()
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
S3 SonicStage Back-End Service; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe [112184 2007-02-05] (Sony Corporation)
S3 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [69632 2006-12-14] (Sony Corporation)
S3 SSScsiSV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe [75320 2007-02-05] (Sony Corporation)
R2 Crypkey License; crypserv.exe [x]

==================== Drivers (Whitelisted) ====================

S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-05] (Avira Operations GmbH & Co. KG)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-02-22] (GFI Software)
R3 guillflt; C:\Windows\System32\DRIVERS\guillflt.sys [65024 2009-06-04] (Guillemot Corp S.A.)
R3 hxctlflt; C:\Windows\System32\Drivers\hxctlflt.sys [111104 2009-02-08] (Guillemot Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] ()
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.)
R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3359832 2011-06-16] (Windows (R) Win 7 DDK provider)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-13 21:56 - 2013-08-13 21:56 - 00065536 ___HT C:\Users\Lissi1\~Outlooklissa.pst.tmp
2013-08-13 21:55 - 2013-08-13 21:55 - 00030385 _____ C:\ComboFix.txt
2013-08-13 21:38 - 2013-08-13 21:38 - 00005254 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2138.log
2013-08-13 21:32 - 2013-08-13 21:32 - 00005256 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2131.log
2013-08-13 21:19 - 2013-08-13 21:19 - 00025732 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2119.log
2013-08-13 21:11 - 2013-08-13 21:19 - 00000000 ____D C:\ProgramData\HitmanPro
2013-08-13 21:06 - 2013-08-13 21:07 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-13 21:02 - 2013-08-13 21:02 - 00011433 _____ C:\Users\Lissi1\Desktop\JRT.txt
2013-08-13 20:58 - 2013-08-13 20:58 - 00000000 ____D C:\Windows\ERUNT
2013-08-13 12:59 - 2013-08-13 12:59 - 00000000 ____D C:\Users\Lissi1\Desktop\Stinger
2013-08-13 11:58 - 2013-08-13 11:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_guillflt_01007.Wdf
2013-08-13 11:57 - 2013-08-13 11:57 - 02063600 _____ C:\Windows\vcredist_x64.log
2013-08-13 11:57 - 2013-08-13 11:57 - 02058774 _____ C:\Windows\vcredist_x86.log
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Windows\HerculesWebcamUpdater
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Program Files (x86)\Hercules
2013-08-13 11:57 - 2011-06-27 09:31 - 00589824 _____ (Guillemot Corporation S.A.) C:\Windows\SysWOW64\HWLMSET2.exe
2013-08-13 11:57 - 2011-06-27 09:31 - 00009728 _____ C:\Windows\SysWOW64\HWLMSET2PS.dll
2013-08-13 11:57 - 2011-06-16 16:34 - 03359832 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\S6000KNT.sys
2013-08-13 11:57 - 2011-06-16 16:34 - 00076376 _____ C:\Windows\system32\S6000DIF.dll
2013-08-13 11:57 - 2009-06-04 09:34 - 00065024 _____ (Guillemot Corp S.A.) C:\Windows\system32\Drivers\guillflt.sys
2013-08-13 11:57 - 2009-02-08 23:43 - 00111104 _____ (Guillemot Corporation) C:\Windows\system32\Drivers\hxctlflt.sys
2013-08-13 11:57 - 2003-09-23 04:36 - 00013448 _____ C:\Windows\S6000Twn.src
2013-08-13 11:57 - 2003-09-23 03:49 - 00015190 _____ C:\Windows\S6000Twn.ini
2013-08-13 11:56 - 2013-08-13 11:56 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\InstallShield
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____H C:\Users\Lissi1\Desktop\Desktop.event
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____D C:\Users\Lissi1\Saved Games\Documents\Corel VideoStudio Pro
2013-08-12 21:08 - 2013-08-12 21:08 - 00000000 ____D C:\Computer
2013-08-12 20:50 - 2013-08-13 21:39 - 05103833 ____R (Swearware) C:\Users\Lissi1\Desktop\ComboFix.exe
2013-08-12 20:41 - 2013-08-13 21:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-12 20:41 - 2013-08-12 20:41 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-08-12 20:41 - 2013-08-12 20:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-12 20:41 - 2013-08-12 20:41 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-12 20:38 - 2013-08-12 20:41 - 33150376 _____ (Oracle Corporation) C:\Users\Lissi1\Downloads\jre-7u25-windows-x64.exe
2013-08-12 20:34 - 2013-08-12 20:34 - 00067897 _____ C:\Users\Lissi1\Desktop\FRST1.txt
2013-08-12 20:33 - 2013-08-12 20:33 - 00044584 _____ C:\Users\Lissi1\Desktop\Addition.txt
2013-08-12 11:03 - 2013-08-12 20:39 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-11 18:22 - 2013-08-11 18:22 - 00002676 _____ C:\AdwCleaner[S12].txt
2013-08-11 18:22 - 2013-08-11 18:22 - 00002613 _____ C:\AdwCleaner[R19].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015178 _____ C:\AdwCleaner[R18].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015091 _____ C:\AdwCleaner[S11].txt
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 ____D C:\found.000
2013-08-09 19:38 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-07 19:58 - 2013-08-11 16:06 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4
2013-08-07 18:29 - 2013-08-07 18:29 - 00002180 _____ C:\AdwCleaner[S10].txt
2013-08-07 18:28 - 2013-08-07 18:28 - 00002117 _____ C:\AdwCleaner[R17].txt
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 10:31 - 2013-08-07 10:31 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-07 10:30 - 2013-08-07 11:35 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:23 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-08-07 10:23 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-08-07 10:14 - 2013-08-07 10:14 - 00000000 ____D C:\FRST
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-06 18:55 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-08-06 18:55 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-08-06 18:20 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-08-06 18:20 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-08-06 18:20 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2013-08-06 18:20 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-08-06 18:20 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-08-06 18:20 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-08-06 18:20 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-08-06 18:20 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-08-06 18:20 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-08-06 18:20 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-08-06 18:20 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-08-06 18:20 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-08-06 18:20 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-08-06 18:20 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-08-06 18:20 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-08-06 18:18 - 2013-08-06 18:20 - 00000000 ____D C:\Windows\system32\MRT
2013-08-06 18:13 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMAW.DLL
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:06 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 18:00 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-08-06 18:00 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-08-06 18:00 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-08-06 18:00 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-08-06 18:00 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:35 - 2013-08-06 14:44 - 00010360 _____ C:\Windows\IE10_main.log
2013-08-06 11:59 - 2013-08-06 11:59 - 00002055 _____ C:\AdwCleaner[R14].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001994 _____ C:\AdwCleaner[R13].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001933 _____ C:\AdwCleaner[R12].txt
2013-08-06 10:56 - 2013-05-29 08:15 - 17829376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-06 10:56 - 2013-05-29 07:50 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-06 10:56 - 2013-05-29 07:43 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-06 10:56 - 2013-05-29 07:36 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-06 10:56 - 2013-05-29 07:35 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-06 10:56 - 2013-05-29 07:34 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-06 10:56 - 2013-05-29 07:33 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-06 10:56 - 2013-05-29 07:31 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-06 10:56 - 2013-05-29 07:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-06 10:56 - 2013-05-29 07:27 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-06 10:56 - 2013-05-29 07:27 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-06 10:56 - 2013-05-29 07:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-06 10:56 - 2013-05-29 07:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-06 10:56 - 2013-05-29 07:18 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-06 10:56 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-06 10:56 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-06 10:56 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-06 10:56 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-06 10:56 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-06 10:56 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-06 10:56 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-06 10:56 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-06 10:56 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-06 10:56 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-08-06 10:56 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-06 10:56 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-06 10:56 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-06 10:56 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-06 10:56 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-06 10:56 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-06 10:54 - 2013-05-08 08:39 - 01910632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-06 10:54 - 2013-04-10 08:01 - 00983400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-08-06 10:54 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-08-06 10:54 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-08-06 10:54 - 2013-02-27 07:52 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-08-06 10:54 - 2013-02-27 07:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-08-06 10:54 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-08-06 10:54 - 2013-01-03 08:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-08-06 10:54 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-08-06 10:53 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-08-06 10:53 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-08-06 10:53 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-06 10:53 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-06 10:53 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-08-06 10:53 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-08-06 10:53 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-08-06 10:53 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-08-06 10:53 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023x.sys
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-08-06 10:53 - 2013-01-04 07:46 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-08-06 10:53 - 2013-01-04 06:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-06 10:53 - 2013-01-04 04:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-06 10:53 - 2013-01-04 04:47 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-06 10:53 - 2013-01-04 04:47 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-06 10:53 - 2013-01-04 04:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-06 10:52 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-08-06 10:52 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-08-06 10:52 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-08-06 10:52 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-08-06 10:51 - 2013-05-13 07:51 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-06 10:51 - 2013-05-13 07:51 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-06 10:51 - 2013-05-13 07:51 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-06 10:51 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-06 10:51 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-06 10:51 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-08-06 10:50 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-08-06 10:50 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-08-06 10:50 - 2013-03-19 08:04 - 05550424 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-06 10:50 - 2013-03-19 07:46 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-08-06 10:50 - 2013-03-19 07:04 - 03968856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-06 10:50 - 2013-03-19 07:04 - 03913560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-06 10:50 - 2013-03-19 06:47 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-08-06 10:50 - 2013-03-19 05:06 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-08-06 10:18 - 2013-08-13 21:55 - 00000000 ____D C:\Qoobox
2013-08-06 10:18 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-06 10:18 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-06 10:18 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-06 10:18 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-06 10:17 - 2013-08-06 10:32 - 00000000 ____D C:\Windows\erdnt
2013-08-06 10:10 - 2013-08-06 10:10 - 00001872 _____ C:\AdwCleaner[R11].txt
2013-08-06 10:08 - 2013-08-06 10:08 - 00001811 _____ C:\AdwCleaner[R10].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00002038 _____ C:\AdwCleaner[S7].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00001976 _____ C:\AdwCleaner[R9].txt
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 12:26 - 2013-08-07 00:09 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 12:26 - 2013-08-05 12:26 - 00001714 _____ C:\AdwCleaner[R8].txt
2013-08-05 12:21 - 2013-08-05 12:21 - 00001654 _____ C:\AdwCleaner[R7].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001596 _____ C:\AdwCleaner[S6].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001534 _____ C:\AdwCleaner[R6].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001726 _____ C:\AdwCleaner[S5].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001664 _____ C:\AdwCleaner[R5].txt
2013-08-05 12:01 - 2013-08-05 12:01 - 00666633 _____ C:\Users\Lissi1\Desktop\adwcleaner06.exe
2013-08-05 11:53 - 2013-08-05 11:53 - 00078778 _____ C:\AdwCleaner[R4].txt
2013-08-05 11:53 - 2013-08-05 11:53 - 00033765 _____ C:\AdwCleaner[S4].txt
2013-08-05 11:51 - 2013-08-05 11:51 - 00078717 _____ C:\AdwCleaner[R3].txt
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:42 - 2013-08-05 11:43 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:42 - 2013-08-05 11:35 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-26 13:22 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:22 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-07-25 16:48 - 2013-07-25 19:12 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-23 18:47 - 2013-07-23 18:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 18:20 - 2013-08-09 12:00 - 00003874 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-07-23 18:20 - 2013-08-01 03:08 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-23 18:20 - 2013-07-29 18:44 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 16:53 - 2013-07-22 17:03 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-22 14:41 - 2013-07-14 19:47 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430 - Kopie.mov
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 16:37 - 2013-07-17 17:49 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 16:37 - 2013-07-17 17:49 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-14 18:38 - 2013-07-14 19:47 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430.mov

==================== One Month Modified Files and Folders =======

2013-08-13 22:01 - 2013-05-08 20:36 - 190989312 _____ C:\Users\Lissi1\Outlooklissa.pst
2013-08-13 21:56 - 2013-08-13 21:56 - 00065536 ___HT C:\Users\Lissi1\~Outlooklissa.pst.tmp
2013-08-13 21:56 - 2012-02-04 18:48 - 00000000 ____D C:\Users\Lissi1
2013-08-13 21:55 - 2013-08-13 21:55 - 00030385 _____ C:\ComboFix.txt
2013-08-13 21:55 - 2013-08-06 10:18 - 00000000 ____D C:\Qoobox
2013-08-13 21:54 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-13 21:49 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-13 21:49 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-13 21:44 - 2013-08-12 20:41 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-13 21:44 - 2012-02-04 18:44 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-13 21:41 - 2013-03-05 20:06 - 00008680 _____ C:\Windows\error.log
2013-08-13 21:41 - 2012-10-23 16:46 - 00000000 ___RD C:\Users\Lissi1\Dropbox
2013-08-13 21:41 - 2012-10-23 16:44 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Dropbox
2013-08-13 21:40 - 2013-04-04 12:45 - 00010993 _____ C:\Windows\setupact.log
2013-08-13 21:40 - 2013-03-05 20:05 - 00003333 _____ C:\Windows\errord.log
2013-08-13 21:40 - 2012-02-04 18:44 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-13 21:40 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-13 21:39 - 2013-08-12 20:50 - 05103833 ____R (Swearware) C:\Users\Lissi1\Desktop\ComboFix.exe
2013-08-13 21:39 - 2012-02-04 18:43 - 01555458 _____ C:\Windows\WindowsUpdate.log
2013-08-13 21:38 - 2013-08-13 21:38 - 00005254 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2138.log
2013-08-13 21:32 - 2013-08-13 21:32 - 00005256 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2131.log
2013-08-13 21:19 - 2013-08-13 21:19 - 00025732 _____ C:\Users\Lissi1\Desktop\HitmanPro_20130813_2119.log
2013-08-13 21:19 - 2013-08-13 21:11 - 00000000 ____D C:\ProgramData\HitmanPro
2013-08-13 21:10 - 2012-12-24 23:53 - 00004084 _____ C:\Windows\System32\Tasks\Software Updater Ui
2013-08-13 21:10 - 2012-12-24 23:51 - 00004122 _____ C:\Windows\System32\Tasks\Software Updater
2013-08-13 21:07 - 2013-08-13 21:06 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-13 21:02 - 2013-08-13 21:02 - 00011433 _____ C:\Users\Lissi1\Desktop\JRT.txt
2013-08-13 20:58 - 2013-08-13 20:58 - 00000000 ____D C:\Windows\ERUNT
2013-08-13 18:45 - 2012-04-13 16:05 - 03463168 ___SH C:\Users\Lissi1\Desktop\Thumbs.db
2013-08-13 17:50 - 2012-09-20 17:48 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Skype
2013-08-13 12:59 - 2013-08-13 12:59 - 00000000 ____D C:\Users\Lissi1\Desktop\Stinger
2013-08-13 11:58 - 2013-08-13 11:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_guillflt_01007.Wdf
2013-08-13 11:57 - 2013-08-13 11:57 - 02063600 _____ C:\Windows\vcredist_x64.log
2013-08-13 11:57 - 2013-08-13 11:57 - 02058774 _____ C:\Windows\vcredist_x86.log
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Windows\HerculesWebcamUpdater
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Program Files (x86)\Hercules
2013-08-13 11:57 - 2011-07-18 23:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-13 11:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2013-08-13 11:56 - 2013-08-13 11:56 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\InstallShield
2013-08-12 23:38 - 2013-08-09 19:38 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-12 23:38 - 2013-07-26 13:22 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-08-12 23:38 - 2013-07-25 19:22 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-08-12 23:38 - 2013-06-15 16:45 - 00000000 ____D C:\Users\Lissi1\Desktop\Fohlenhof
2013-08-12 23:38 - 2013-06-12 17:55 - 00000000 ____D C:\Users\Lissi1\Desktop\LissiSchwimmfest
2013-08-12 23:38 - 2013-06-12 13:51 - 00000000 ____D C:\Users\Lissi1\Desktop\schwimmfest2013
2013-08-12 23:38 - 2013-06-11 07:55 - 00000000 ____D C:\Users\Lissi1\Desktop\garten2013
2013-08-12 23:38 - 2013-06-11 07:54 - 00000000 ____D C:\Users\Lissi1\Desktop\Norderney
2013-08-12 23:38 - 2013-06-08 14:03 - 00000000 ____D C:\Users\Lissi1\Desktop\tiergartenSommer
2013-08-12 23:38 - 2013-05-25 21:23 - 00000000 ____D C:\Users\Lissi1\Desktop\Turnier2013
2013-08-12 23:38 - 2012-02-05 11:48 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Ulead Systems
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____H C:\Users\Lissi1\Desktop\Desktop.event
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____D C:\Users\Lissi1\Saved Games\Documents\Corel VideoStudio Pro
2013-08-12 23:37 - 2012-02-24 17:55 - 00006738 ___SH C:\ProgramData\KGyGaAvL.sys
2013-08-12 21:46 - 2012-11-13 07:22 - 00127648 _____ C:\Windows\PFRO.log
2013-08-12 21:08 - 2013-08-12 21:08 - 00000000 ____D C:\Computer
2013-08-12 20:44 - 2012-05-27 20:06 - 00000000 ____D C:\Program Files (x86)\Intenium
2013-08-12 20:41 - 2013-08-12 20:41 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-08-12 20:41 - 2013-08-12 20:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-12 20:41 - 2013-08-12 20:41 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-12 20:41 - 2013-08-12 20:38 - 33150376 _____ (Oracle Corporation) C:\Users\Lissi1\Downloads\jre-7u25-windows-x64.exe
2013-08-12 20:41 - 2012-12-16 17:13 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-08-12 20:41 - 2011-07-18 23:14 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-08-12 20:39 - 2013-08-12 11:03 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-12 20:34 - 2013-08-12 20:34 - 00067897 _____ C:\Users\Lissi1\Desktop\FRST1.txt
2013-08-12 20:33 - 2013-08-12 20:33 - 00044584 _____ C:\Users\Lissi1\Desktop\Addition.txt
2013-08-12 20:26 - 2012-07-07 11:03 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-08-12 20:24 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-12 20:23 - 2012-07-15 22:08 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\DVDVideoSoft
2013-08-12 20:22 - 2012-12-27 12:37 - 00000000 ____D C:\Program Files (x86)\Biet-O-Matic
2013-08-12 20:22 - 2012-08-12 12:59 - 00000000 ____D C:\Program Files (x86)\AVS4YOU
2013-08-12 07:17 - 2013-08-12 07:17 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\SUPERAntiSpyware.com
2013-08-11 19:57 - 2012-12-24 23:48 - 00000000 ____D C:\Program Files (x86)\SelfUpdater
2013-08-11 18:22 - 2013-08-11 18:22 - 00002676 _____ C:\AdwCleaner[S12].txt
2013-08-11 18:22 - 2013-08-11 18:22 - 00002613 _____ C:\AdwCleaner[R19].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015178 _____ C:\AdwCleaner[R18].txt
2013-08-11 18:16 - 2013-08-11 18:16 - 00015091 _____ C:\AdwCleaner[S11].txt
2013-08-11 17:11 - 2012-05-09 15:14 - 00000000 ____D C:\Program Files (x86)\Free FLV Converter
2013-08-11 16:44 - 2013-03-10 20:20 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\MyPhoneExplorer
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 ____D C:\found.000
2013-08-11 16:06 - 2013-08-07 19:58 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4
2013-08-10 18:26 - 2013-03-10 20:25 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-08-10 18:25 - 2013-03-10 21:04 - 00002065 _____ C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2013-08-10 18:25 - 2013-03-10 21:04 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2013-08-09 12:00 - 2013-07-23 18:20 - 00003874 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-08-07 20:07 - 2012-05-09 15:16 - 00002592 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-07 18:29 - 2013-08-07 18:29 - 00002180 _____ C:\AdwCleaner[S10].txt
2013-08-07 18:28 - 2013-08-07 18:28 - 00002117 _____ C:\AdwCleaner[R17].txt
2013-08-07 11:35 - 2013-08-07 10:30 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 10:31 - 2013-08-07 10:31 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-07 10:14 - 2013-08-07 10:14 - 00000000 ____D C:\FRST
2013-08-07 01:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-07 00:09 - 2013-08-05 12:26 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-06 18:38 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-06 18:38 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-06 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-08-06 18:33 - 2011-04-12 10:28 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-08-06 18:20 - 2013-08-06 18:18 - 00000000 ____D C:\Windows\system32\MRT
2013-08-06 18:12 - 2011-05-16 16:04 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-08-06 18:12 - 2011-05-16 16:04 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-08-06 18:12 - 2009-07-14 07:13 - 01519624 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:07 - 2013-08-06 18:06 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 17:43 - 2011-07-18 22:54 - 00000000 ____D C:\Windows\Panther
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sl-SI
2013-08-06 14:51 - 2012-02-04 19:29 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-06 14:44 - 2013-08-06 14:35 - 00010360 _____ C:\Windows\IE10_main.log
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 11:59 - 2013-08-06 11:59 - 00002055 _____ C:\AdwCleaner[R14].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001994 _____ C:\AdwCleaner[R13].txt
2013-08-06 11:58 - 2013-08-06 11:58 - 00001933 _____ C:\AdwCleaner[R12].txt
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-08-06 10:33 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-06 10:32 - 2013-08-06 10:17 - 00000000 ____D C:\Windows\erdnt
2013-08-06 10:10 - 2013-08-06 10:10 - 00001872 _____ C:\AdwCleaner[R11].txt
2013-08-06 10:08 - 2013-08-06 10:08 - 00001811 _____ C:\AdwCleaner[R10].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00002038 _____ C:\AdwCleaner[S7].txt
2013-08-05 19:23 - 2013-08-05 19:23 - 00001976 _____ C:\AdwCleaner[R9].txt
2013-08-05 16:22 - 2013-05-11 14:02 - 00000000 ____D C:\ProgramData\Avery
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 12:26 - 2013-08-05 12:26 - 00001714 _____ C:\AdwCleaner[R8].txt
2013-08-05 12:21 - 2013-08-05 12:21 - 00001654 _____ C:\AdwCleaner[R7].txt
2013-08-05 12:09 - 2012-02-04 23:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\CheckPoint
2013-08-05 12:08 - 2013-08-05 12:08 - 00001596 _____ C:\AdwCleaner[S6].txt
2013-08-05 12:08 - 2013-08-05 12:08 - 00001534 _____ C:\AdwCleaner[R6].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001726 _____ C:\AdwCleaner[S5].txt
2013-08-05 12:02 - 2013-08-05 12:02 - 00001664 _____ C:\AdwCleaner[R5].txt
2013-08-05 12:01 - 2013-08-05 12:01 - 00666633 _____ C:\Users\Lissi1\Desktop\adwcleaner06.exe
2013-08-05 11:53 - 2013-08-05 11:53 - 00078778 _____ C:\AdwCleaner[R4].txt
2013-08-05 11:53 - 2013-08-05 11:53 - 00033765 _____ C:\AdwCleaner[S4].txt
2013-08-05 11:51 - 2013-08-05 11:51 - 00078717 _____ C:\AdwCleaner[R3].txt
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:43 - 2013-08-05 11:42 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:35 - 2013-08-05 11:42 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-01 03:08 - 2013-07-23 18:20 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-29 18:44 - 2013-07-23 18:20 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Windows Net Data
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:12 - 2013-07-25 16:48 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-23 18:47 - 2013-07-23 18:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\FreeSystemUtilities
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 17:03 - 2013-07-22 16:53 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-18 20:44 - 2012-12-27 12:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\BOM
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 18:43 - 2012-09-17 16:53 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Apps\2.0
2013-07-17 18:34 - 2013-02-09 17:40 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus
2013-07-17 18:34 - 2012-05-09 15:14 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\FreeFLVConverter
2013-07-17 18:34 - 2012-02-04 21:31 - 00000000 ____D C:\Program Files (x86)\ScanWizard 5
2013-07-17 18:34 - 2011-07-18 23:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-17 18:21 - 2011-04-12 10:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-07-17 18:13 - 2013-02-09 17:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Ad-Aware Antivirus
2013-07-17 17:49 - 2013-07-17 16:37 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 17:49 - 2013-07-17 16:37 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-17 09:24 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files\Google
2013-07-16 08:43 - 2012-02-04 19:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Google
2013-07-16 08:43 - 2012-02-04 18:44 - 00000000 ____D C:\ProgramData\Google
2013-07-14 19:47 - 2013-07-22 14:41 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430 - Kopie.mov
2013-07-14 19:47 - 2013-07-14 18:38 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430.mov

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-12 05:58

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---

--- --- ---


Code:

HitmanPro 3.7.7.203
www.hitmanpro.com

  Computer name . . . . : LISSI1-PC
  Windows . . . . . . . : 6.1.1.7601.X64/4
  User name . . . . . . : Lissi1-PC\Lissi1
  UAC . . . . . . . . . : Enabled
  License . . . . . . . : Trial (30 days left)

  Scan date . . . . . . : 2013-08-13 22:07:19
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 2m 31s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 0
  Traces  . . . . . . . : 0

  Objects scanned . . . : 1.744.014
  Files scanned . . . . : 37.460
  Remnants scanned  . . : 493.333 files / 1.213.221 keys

wie gesagt get window info ist dreimal jetzt da und tbupdater ist auch da aber hitmen meint alles ok

wie bokomme ich die vieren weg?

also immer noch getwindow und tbupdater, meine programme konnte ich retten!

wie bekomme ich den schrott weg den ich für diene log geladen habe?
keins deiner Programme hatte irgeneinen nährwert, außer meine pc zu blockieren und langsam zu machen, gelöscht wurde nicht von den bedrohungen.
Also wie jetzt mal richtig weiter?

welches Programm kann die Malware löschen ohne das ich dafür 3 Tage brauche und Programme lösche die nichts damit zu tun haben?

so wie bekomme ich die vieren vom Rechner???? getwindow startet jetzt drei mal und tbupdater ist auch noch da, antivirus muste ich neu installieren weil deine löschprogramme es mal kurzerhand gekillt haben genau wie adaware.
Die meisten programme habe ich jetzt gerettet aber mein Problem ist immer noch da weshalb ich dich um hilfe bat.

Also wie kann ich getwindow und TBUpdater nun endlich vom System löschen????

markusg 15.08.2013 18:58

Hi,
1.
Fix mit FRST
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Lissi1\AppData\Roaming\Windows Net Data\net.exe (Windows Net)
SearchScopes: HKCU - 63D76E6EC6B04284B071A585DCBE8EA6 URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=53E641BF-D5D6-4646-8077-EE58703B9D12&apn_sauid=45E38BAC-10B5-487C-BE1B-F389560F4295
BHO-x32: No Name - {120A8821-2BEE-4C29-BCDA-62C577781992} -  No File
BHO-x32: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} -  No File
BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} -  No File
Toolbar: HKLM - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - No Name - !{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} -  No File
Toolbar: HKLM-x32 - No Name - !{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
C:\Users\Lissi1\AppData\Roaming\Windows Net Data

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).[list][*] Starte nun FRST erneut
und klicke den Fix Button.[*] Das Tool erstellt eine
nach Neustart.
2.
bitte teste, ob es im Firefox, internet explorer, und sonstigen
evtl. instalierte Browser, irgendwelche ungewollten toolbars, umleitungen oder sonstigen Probleme gibt.
Teste wie pc und programme allgemein laufen.
Wenn nu alles geht:

3.
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


4. PC absichern:
als antimalware programm würde ich emsisoft empfehlen.
diese haben für mich den besten schutz kostet aber etwas.
Computeractive Software Store - Emsisoft Anti-Malware 8 [1-PC] - 63% off RRP
testversion:
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware
insbesondere wenn du onlinebanking, einkäufe, sonstige zahlungsabwicklungen oder ähnlich wichtiges, wie zb berufliches machst, also sensible daten zu schützen sind, solltest du in sicherheitssoftware investieren.
vor dem aktivieren der lizenz die 30 tage testzeitraum ausnutzen.

kostenlos, aber eben nicht ganz so gut währe avast zu empfehlen.
http://www.trojaner-board.de/110895-...antivirus.html

sag mir welches du nutzt, dann gebe ich konfigurationshinweise.
bitte dein bisheriges av deinstalieren
die folgende anleitung ist umfangreich, dass ist mir klar, sie sollte aber umgesetzt werden, da nur dann dein pc sicher ist. stelle so viele fragen wie nötig, ich arbeite gern alles mit dir durch!

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
als browser rate ich dir zu chrome:
http://support.google.com/chrome/bin...&answer=118663
anleitung lesen bitte
falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung anpassen.


Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
Sandboxie - Download - Filepony

anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
Sandbox Einstellungen |

bitte folgende zusatz konfiguration machen:
sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen.
dort klicke auf sandbox einstellungen.
beschrenkungen, bei programm start und internet zugriff schreibe:
chrome.exe
dann gehe auf anwendungen, webbrowser, chrome.
dort aktiviere alles außer gesammten profil ordner freigeben.
Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
anmerkung zu file hippo.
in den settings zusätzlich auswählen:
hide beta updates.
Run updateChecker when Windows starts

Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
http://www.trojaner-board.de/82962-w...en-backup.html
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
bitte auch lesen, wie mache ich programme für alle sichtbar:
Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

passwort sicherheit:
jeder dienst benötigt ein eigenes, mindestens 12-stelliges passwort
bei der passwort verwaltung und erstellung hilft roboform
Password Manager, Form Filler, Password Management | RoboForm Password Manager
anleitung:
RoboForm Manual

baby-lissa 15.08.2013 20:01

Hi,

getwindow Info habe ich gestern selber per Hand gelöscht bekommen und TBUpdater ist immer noch da!!!
habe gestern meine Programme wieder aufgespielt die Combofix gelöscht hat.
Coral, Avira. Outlook habe ich wieder zurück benannt, hieß ComboFixO und meinen Windows Explorer habe ich nach suchen auch wieder gefunden hieß Combofix.

www_getwindowinfo ist dank ProcessExplorer gafunden und gekillt, TBUpdater ist weiter da und Stört.

Combo will seine files nicht löschen und leider habe ich nicht alle gefunden und per Hand löschen können.

gibt es noch eione andere Möglichkeit TBUpdater zu killen?

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-08-2013 01
Ran by Lissi1 at 2013-08-15 20:49:01 Run:2
Running from C:\Users\Lissi1\Desktop
Boot Mode: Normal
==============================================

C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk not found.
C:\Users\Lissi1\AppData\Roaming\Windows Net Data\net.exe not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\63D76E6EC6B04284B071A585DCBE8EA6 URL = => Value not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{120A8821-2BEE-4C29-BCDA-62C577781992} => Key not found.
HKCR\Wow6432Node\CLSID\{120A8821-2BEE-4C29-BCDA-62C577781992} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key not found.
HKCR\Wow6432Node\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba696155-d96e-4281-b467-0367a0456474} => Key not found.
HKCR\Wow6432Node\CLSID\{ba696155-d96e-4281-b467-0367a0456474} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\!{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => Value not found.
HKCR\CLSID\!{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} => Value not found.
HKCR\Wow6432Node\CLSID\!{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\!{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => Value not found.
HKCR\Wow6432Node\CLSID\!{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => Key not found.
"C:\Users\Lissi1\AppData\Roaming\Windows Net Data" => File/Directory not found.

==== End of Fixlog ====


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-08-2013 01
Ran by Lissi1 (administrator) on 15-08-2013 20:50:57
Running from C:\Users\Lissi1\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(CrypKey (Canada) Ltd.) C:\Windows\system32\crypserv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Guillemot Corporation S.A.) C:\Program Files (x86)\Hercules\Hercules HD Exchange\XtrCtrlEx.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe
(Dropbox, Inc.) C:\Users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Lavasoft Limited) C:\PROGRA~2\AD-AWA~1\AdAware.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe
(Microsoft Corporation) C:\Windows\sysWow64\SearchProtocolHost.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [Monitor] - C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [IntelliType Pro] - c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [CamserviceHDExchange] - C:\Program Files (x86)\Hercules\Hercules HD Exchange\XtrCtrlEx.exe [3391344 2012-01-12] (Guillemot Corporation S.A.)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung)
HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [542632 2013-01-31] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-08-05] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-15] (Renesas Electronics Corporation)
HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Scanner Finder.lnk
ShortcutTarget: Scanner Finder.lnk -> C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled ()
Startup: C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lissi1\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Deaktivierungs-Add-on für Browser von Google Analytics - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll (Google, Inc.)
Toolbar: HKLM-x32 - Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} -  No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -  No File
Toolbar: HKCU - No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} -  No File
Toolbar: HKCU - No Name - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} -  No File
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.msn.com/?pc=BDT3&ocid=BDT3DHP&dt=080613"
CHR Extension: (Plus-HD-2.4) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.23.29_0
CHR Extension: (Skype Click to Call) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Lissi1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.0.0_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

==================== Services (Whitelisted) =================

R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-02-14] (Lavasoft Limited)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-05] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-08-05] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [45056 2006-12-14] (Sony Corporation)
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [57344 2006-12-14] ()
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
S3 SonicStage Back-End Service; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe [112184 2007-02-05] (Sony Corporation)
S3 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [69632 2006-12-14] (Sony Corporation)
S3 SSScsiSV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe [75320 2007-02-05] (Sony Corporation)
R2 Crypkey License; crypserv.exe [x]

==================== Drivers (Whitelisted) ====================

S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-08-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-05] (Avira Operations GmbH & Co. KG)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-02-22] (GFI Software)
R3 guillflt; C:\Windows\System32\DRIVERS\guillflt.sys [65024 2009-06-04] (Guillemot Corp S.A.)
R3 hxctlflt; C:\Windows\System32\Drivers\hxctlflt.sys [111104 2009-02-08] (Guillemot Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] ()
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.)
R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3359832 2011-06-16] (Windows (R) Win 7 DDK provider)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 hitmanpro37; \??\C:\Windows\system32\drivers\hitmanpro37.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-15 20:43 - 2013-08-15 20:43 - 00039966 _____ C:\Users\Lissi1\Desktop\Addition.txt
2013-08-15 20:42 - 2013-08-15 20:42 - 00000000 ____D C:\FRST
2013-08-15 20:37 - 2013-08-15 20:37 - 01575570 _____ (Farbar) C:\Users\Lissi1\Desktop\FRST64.exe
2013-08-15 20:36 - 2013-08-15 20:36 - 00001165 _____ C:\DelFix.txt
2013-08-15 20:34 - 2013-08-15 20:34 - 00706916 _____ C:\Users\Lissi1\Downloads\delfix.exe
2013-08-14 22:16 - 2013-08-14 22:17 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Rovio Entertainment Ltd
2013-08-14 22:16 - 2013-08-14 22:16 - 00001318 _____ C:\Users\Public\Desktop\Angry Birds Star Wars.lnk
2013-08-14 22:16 - 2013-08-14 22:16 - 00000000 ____D C:\Program Files (x86)\Rovio Entertainment Ltd
2013-08-14 22:10 - 2013-08-14 22:16 - 78705368 _____ (Rovio Entertainment Ltd.) C:\Users\Lissi1\Desktop\AngryBirdsStarWarsInstaller_1-2-0.exe
2013-08-14 20:24 - 2013-08-14 20:24 - 00000260 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_202410.reg
2013-08-14 20:23 - 2013-08-14 20:23 - 00096454 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_202313.reg
2013-08-14 20:23 - 2013-08-14 20:23 - 00002466 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_202348.reg
2013-08-14 17:56 - 2013-08-15 20:25 - 00004144 _____ C:\Windows\PFRO.log
2013-08-14 17:55 - 2013-08-14 17:55 - 00000085 _____ C:\Windows\wininit.ini
2013-08-14 16:40 - 2013-08-14 16:40 - 01191834 _____ C:\Users\Lissi1\Desktop\ProcessExplorer_1540.zip
2013-08-14 16:20 - 2013-08-14 16:20 - 525840747 _____ C:\Windows\MEMORY.DMP
2013-08-14 16:20 - 2013-08-14 16:20 - 00455144 _____ C:\Windows\Minidump\081413-15568-01.dmp
2013-08-14 15:18 - 2013-08-15 20:45 - 00001240 _____ C:\Windows\error.log
2013-08-14 15:18 - 2013-08-15 20:44 - 00000840 _____ C:\Windows\setupact.log
2013-08-14 15:18 - 2013-08-14 15:18 - 00000000 _____ C:\Windows\setuperr.log
2013-08-14 15:17 - 2013-08-15 20:44 - 00000280 _____ C:\Windows\errord.log
2013-08-14 14:53 - 2013-08-14 15:10 - 00013576 _____ C:\Windows\IE10_main.log
2013-08-14 14:46 - 2013-08-14 14:46 - 00017342 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_144558.reg
2013-08-14 14:45 - 2013-08-14 14:45 - 00093606 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_144536.reg
2013-08-14 14:38 - 2013-08-14 14:38 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-08-14 14:38 - 2013-08-14 14:38 - 00000000 ____D C:\Program Files\CCleaner
2013-08-14 12:42 - 2013-08-14 12:46 - 00000000 ____D C:\AdwCleaner
2013-08-14 12:42 - 2013-07-25 05:31 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 12:42 - 2013-07-25 05:30 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 12:42 - 2013-07-25 05:29 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-14 12:42 - 2013-07-25 05:28 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-14 12:42 - 2013-07-25 05:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 12:42 - 2013-07-25 05:27 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-14 12:42 - 2013-07-25 05:26 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 12:42 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 12:42 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 12:42 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-14 12:42 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-08-14 12:42 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-14 12:42 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 12:42 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 12:42 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-14 12:41 - 2013-07-25 05:54 - 17830400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 12:41 - 2013-07-25 05:37 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 12:41 - 2013-07-25 05:35 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 12:41 - 2013-07-25 05:29 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-14 12:41 - 2013-07-25 05:29 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 12:41 - 2013-07-25 05:28 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 12:41 - 2013-07-25 05:28 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 12:41 - 2013-07-25 05:28 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 12:41 - 2013-07-25 05:28 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-14 12:41 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 12:41 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 12:41 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 12:41 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-14 12:41 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 12:41 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 12:41 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 12:41 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 08:56 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 08:56 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 08:56 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 08:56 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 08:56 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 08:56 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 08:56 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 08:56 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 08:56 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 08:56 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 08:56 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 08:56 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 08:56 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 08:56 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 08:56 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 08:56 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 08:56 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 08:56 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 08:56 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 08:56 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 08:56 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 08:55 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 08:55 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 08:55 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 08:55 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 08:55 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 08:55 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-13 23:08 - 2013-08-13 23:08 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-13 23:08 - 2013-08-13 23:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-13 23:08 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-13 23:01 - 2013-08-13 23:01 - 00002226 _____ C:\Users\Public\Desktop\Webcam Station Evolution SE.lnk
2013-08-13 22:36 - 2013-08-13 22:37 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-13 22:34 - 2013-08-13 22:34 - 00000542 _____ C:\Windows\system32\.crusader
2013-08-13 20:58 - 2013-08-15 20:36 - 00000000 ____D C:\Windows\ERUNT
2013-08-13 11:58 - 2013-08-13 11:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_guillflt_01007.Wdf
2013-08-13 11:57 - 2013-08-13 23:01 - 00000000 ____D C:\Program Files (x86)\Hercules
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Windows\HerculesWebcamUpdater
2013-08-13 11:57 - 2011-06-27 09:31 - 00589824 _____ (Guillemot Corporation S.A.) C:\Windows\SysWOW64\HWLMSET2.exe
2013-08-13 11:57 - 2011-06-27 09:31 - 00009728 _____ C:\Windows\SysWOW64\HWLMSET2PS.dll
2013-08-13 11:57 - 2011-06-16 16:34 - 03359832 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\S6000KNT.sys
2013-08-13 11:57 - 2011-06-16 16:34 - 00076376 _____ C:\Windows\system32\S6000DIF.dll
2013-08-13 11:57 - 2009-06-04 09:34 - 00065024 _____ (Guillemot Corp S.A.) C:\Windows\system32\Drivers\guillflt.sys
2013-08-13 11:57 - 2009-02-08 23:43 - 00111104 _____ (Guillemot Corporation) C:\Windows\system32\Drivers\hxctlflt.sys
2013-08-13 11:57 - 2003-09-23 04:36 - 00013448 _____ C:\Windows\S6000Twn.src
2013-08-13 11:57 - 2003-09-23 03:49 - 00015190 _____ C:\Windows\S6000Twn.ini
2013-08-13 11:56 - 2013-08-13 11:56 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\InstallShield
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____D C:\Users\Lissi1\Saved Games\Documents\Corel VideoStudio Pro
2013-08-12 21:08 - 2013-08-12 21:08 - 00000000 ____D C:\Computer
2013-08-12 20:41 - 2013-08-15 20:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-12 20:41 - 2013-08-12 20:41 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-08-12 20:41 - 2013-08-12 20:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-12 20:41 - 2013-08-12 20:41 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-12 11:03 - 2013-08-12 20:39 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 ____D C:\found.000
2013-08-09 19:38 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 10:30 - 2013-08-07 11:35 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:23 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-08-07 10:23 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-06 18:55 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-08-06 18:55 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-08-06 18:20 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-08-06 18:20 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-08-06 18:20 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2013-08-06 18:20 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-08-06 18:20 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-08-06 18:20 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-08-06 18:20 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-08-06 18:20 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-08-06 18:20 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-08-06 18:20 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-08-06 18:20 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-08-06 18:20 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-08-06 18:20 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-08-06 18:20 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-08-06 18:20 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-08-06 18:20 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-08-06 18:20 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-08-06 18:20 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-08-06 18:20 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-08-06 18:20 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-08-06 18:18 - 2013-08-14 12:45 - 00000000 ____D C:\Windows\system32\MRT
2013-08-06 18:13 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMAW.DLL
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:06 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 18:00 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-08-06 18:00 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-08-06 18:00 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-08-06 18:00 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-08-06 18:00 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-08-06 18:00 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 10:54 - 2013-04-10 08:01 - 00983400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-08-06 10:54 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-08-06 10:54 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-08-06 10:54 - 2013-02-27 07:52 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-08-06 10:54 - 2013-02-27 07:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-08-06 10:54 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-08-06 10:54 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-08-06 10:54 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-08-06 10:54 - 2013-01-03 08:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-08-06 10:54 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-08-06 10:53 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-08-06 10:53 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-08-06 10:53 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-08-06 10:53 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-08-06 10:53 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-08-06 10:53 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-08-06 10:53 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023x.sys
2013-08-06 10:53 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-08-06 10:53 - 2013-01-04 07:46 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-08-06 10:52 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-08-06 10:52 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-08-06 10:52 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-08-06 10:52 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-08-06 10:51 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-08-06 10:51 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-08-06 10:51 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-08-06 10:50 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-08-06 10:50 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-08-06 10:50 - 2013-03-19 07:46 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-08-06 10:50 - 2013-03-19 06:47 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-08-06 10:50 - 2013-03-19 05:06 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-08-06 10:17 - 2013-08-06 10:32 - 00000000 ____D C:\Windows\erdnt
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 12:26 - 2013-08-07 00:09 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:42 - 2013-08-05 11:43 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:42 - 2013-08-05 11:35 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:42 - 2013-08-05 11:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-26 13:22 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:22 - 2013-08-12 23:38 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-07-25 16:48 - 2013-07-25 19:12 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-23 18:20 - 2013-08-14 15:13 - 00003876 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-07-23 18:20 - 2013-08-01 03:08 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 16:53 - 2013-07-22 17:03 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-22 14:41 - 2013-07-14 19:47 - 977585085 _____ C:\Users\Lissi1\Desktop\20130709-1430 - Kopie.mov
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 16:37 - 2013-07-17 17:49 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 16:37 - 2013-07-17 17:49 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk

==================== One Month Modified Files and Folders =======

2013-08-15 20:49 - 2012-12-24 23:53 - 00004086 _____ C:\Windows\System32\Tasks\Software Updater Ui
2013-08-15 20:49 - 2012-12-24 23:51 - 00004122 _____ C:\Windows\System32\Tasks\Software Updater
2013-08-15 20:47 - 2013-08-15 20:47 - 00065536 ___HT C:\Users\Lissi1\~Outlooklissa.pst.tmp
2013-08-15 20:47 - 2012-02-04 18:48 - 00000000 ____D C:\Users\Lissi1
2013-08-15 20:46 - 2012-10-23 16:44 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Dropbox
2013-08-15 20:45 - 2013-08-14 15:18 - 00001240 _____ C:\Windows\error.log
2013-08-15 20:45 - 2012-10-23 16:46 - 00000000 ___RD C:\Users\Lissi1\Dropbox
2013-08-15 20:45 - 2012-02-04 18:44 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-15 20:45 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-15 20:44 - 2013-08-14 15:18 - 00000840 _____ C:\Windows\setupact.log
2013-08-15 20:44 - 2013-08-14 15:17 - 00000280 _____ C:\Windows\errord.log
2013-08-15 20:44 - 2013-08-12 20:41 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-15 20:44 - 2012-02-04 18:44 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-15 20:44 - 2012-02-04 18:43 - 01861237 _____ C:\Windows\WindowsUpdate.log
2013-08-15 20:43 - 2013-08-15 20:43 - 00039966 _____ C:\Users\Lissi1\Desktop\Addition.txt
2013-08-15 20:42 - 2013-08-15 20:42 - 00000000 ____D C:\FRST
2013-08-15 20:37 - 2013-08-15 20:37 - 01575570 _____ (Farbar) C:\Users\Lissi1\Desktop\FRST64.exe
2013-08-15 20:36 - 2013-08-15 20:36 - 00001165 _____ C:\DelFix.txt
2013-08-15 20:36 - 2013-08-13 20:58 - 00000000 ____D C:\Windows\ERUNT
2013-08-15 20:34 - 2013-08-15 20:34 - 00706916 _____ C:\Users\Lissi1\Downloads\delfix.exe
2013-08-15 20:34 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-15 20:34 - 2009-07-14 06:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-15 20:25 - 2013-08-14 17:56 - 00004144 _____ C:\Windows\PFRO.log
2013-08-15 20:23 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-15 08:12 - 2012-09-20 17:48 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Skype
2013-08-14 22:17 - 2013-08-14 22:16 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Rovio Entertainment Ltd
2013-08-14 22:16 - 2013-08-14 22:16 - 00001318 _____ C:\Users\Public\Desktop\Angry Birds Star Wars.lnk
2013-08-14 22:16 - 2013-08-14 22:16 - 00000000 ____D C:\Program Files (x86)\Rovio Entertainment Ltd
2013-08-14 22:16 - 2013-08-14 22:10 - 78705368 _____ (Rovio Entertainment Ltd.) C:\Users\Lissi1\Desktop\AngryBirdsStarWarsInstaller_1-2-0.exe
2013-08-14 20:24 - 2013-08-14 20:24 - 00000260 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_202410.reg
2013-08-14 20:23 - 2013-08-14 20:23 - 00096454 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_202313.reg
2013-08-14 20:23 - 2013-08-14 20:23 - 00002466 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_202348.reg
2013-08-14 17:55 - 2013-08-14 17:55 - 00000085 _____ C:\Windows\wininit.ini
2013-08-14 16:40 - 2013-08-14 16:40 - 01191834 _____ C:\Users\Lissi1\Desktop\ProcessExplorer_1540.zip
2013-08-14 16:20 - 2013-08-14 16:20 - 525840747 _____ C:\Windows\MEMORY.DMP
2013-08-14 16:20 - 2013-08-14 16:20 - 00455144 _____ C:\Windows\Minidump\081413-15568-01.dmp
2013-08-14 16:20 - 2013-05-02 17:05 - 00000000 ____D C:\Windows\Minidump
2013-08-14 15:19 - 2012-04-13 16:05 - 03463168 ___SH C:\Users\Lissi1\Desktop\Thumbs.db
2013-08-14 15:18 - 2013-08-14 15:18 - 00000000 _____ C:\Windows\setuperr.log
2013-08-14 15:13 - 2013-07-23 18:20 - 00003876 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint
2013-08-14 15:12 - 2012-12-24 23:50 - 00003518 _____ C:\Windows\System32\Tasks\Hoolapp for Android
2013-08-14 15:12 - 2012-12-24 23:50 - 00003316 _____ C:\Windows\System32\Tasks\Hoolapp Init
2013-08-14 15:10 - 2013-08-14 14:53 - 00013576 _____ C:\Windows\IE10_main.log
2013-08-14 14:46 - 2013-08-14 14:46 - 00017342 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_144558.reg
2013-08-14 14:45 - 2013-08-14 14:45 - 00093606 _____ C:\Users\Lissi1\Saved Games\Documents\cc_20130814_144536.reg
2013-08-14 14:44 - 2011-07-18 22:54 - 00000000 ____D C:\Windows\Panther
2013-08-14 14:38 - 2013-08-14 14:38 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-08-14 14:38 - 2013-08-14 14:38 - 00000000 ____D C:\Program Files\CCleaner
2013-08-14 13:51 - 2012-09-20 17:48 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-08-14 13:51 - 2012-09-20 17:48 - 00000000 ____D C:\ProgramData\Skype
2013-08-14 12:50 - 2012-02-04 19:29 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-14 12:49 - 2011-05-16 16:04 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-08-14 12:49 - 2011-05-16 16:04 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-08-14 12:49 - 2009-07-14 07:13 - 01519624 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-14 12:46 - 2013-08-14 12:42 - 00000000 ____D C:\AdwCleaner
2013-08-14 12:45 - 2013-08-06 18:18 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 12:44 - 2011-07-18 22:31 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-13 23:08 - 2013-08-13 23:08 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-13 23:08 - 2013-08-13 23:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-13 23:01 - 2013-08-13 23:01 - 00002226 _____ C:\Users\Public\Desktop\Webcam Station Evolution SE.lnk
2013-08-13 23:01 - 2013-08-13 11:57 - 00000000 ____D C:\Program Files (x86)\Hercules
2013-08-13 23:01 - 2011-07-18 23:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-13 22:37 - 2013-08-13 22:36 - 00000000 ____D C:\Users\Lissi1\AppData\Local\adawarebp
2013-08-13 22:34 - 2013-08-13 22:34 - 00000542 _____ C:\Windows\system32\.crusader
2013-08-13 21:54 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-13 11:58 - 2013-08-13 11:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_guillflt_01007.Wdf
2013-08-13 11:57 - 2013-08-13 11:57 - 00000000 ____D C:\Windows\HerculesWebcamUpdater
2013-08-13 11:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2013-08-13 11:56 - 2013-08-13 11:56 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\InstallShield
2013-08-12 23:38 - 2013-08-09 19:38 - 00000000 ____D C:\Users\Lissi1\Desktop\hagen
2013-08-12 23:38 - 2013-07-26 13:22 - 00000000 ____D C:\Users\Lissi1\Desktop\Lissi Teich
2013-08-12 23:38 - 2013-07-25 19:22 - 00000000 ____D C:\Users\Lissi1\Desktop\MalleTauchen
2013-08-12 23:38 - 2013-06-15 16:45 - 00000000 ____D C:\Users\Lissi1\Desktop\Fohlenhof
2013-08-12 23:38 - 2013-06-12 17:55 - 00000000 ____D C:\Users\Lissi1\Desktop\LissiSchwimmfest
2013-08-12 23:38 - 2013-06-12 13:51 - 00000000 ____D C:\Users\Lissi1\Desktop\schwimmfest2013
2013-08-12 23:38 - 2013-06-11 07:55 - 00000000 ____D C:\Users\Lissi1\Desktop\garten2013
2013-08-12 23:38 - 2013-06-11 07:54 - 00000000 ____D C:\Users\Lissi1\Desktop\Norderney
2013-08-12 23:38 - 2013-06-08 14:03 - 00000000 ____D C:\Users\Lissi1\Desktop\tiergartenSommer
2013-08-12 23:38 - 2013-05-25 21:23 - 00000000 ____D C:\Users\Lissi1\Desktop\Turnier2013
2013-08-12 23:38 - 2012-02-05 11:48 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Ulead Systems
2013-08-12 23:37 - 2013-08-12 23:37 - 00000000 ____D C:\Users\Lissi1\Saved Games\Documents\Corel VideoStudio Pro
2013-08-12 23:37 - 2012-02-24 17:55 - 00006738 ___SH C:\ProgramData\KGyGaAvL.sys
2013-08-12 21:08 - 2013-08-12 21:08 - 00000000 ____D C:\Computer
2013-08-12 20:44 - 2012-05-27 20:06 - 00000000 ____D C:\Program Files (x86)\Intenium
2013-08-12 20:41 - 2013-08-12 20:41 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-08-12 20:41 - 2013-08-12 20:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-08-12 20:41 - 2013-08-12 20:41 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-12 20:41 - 2013-08-12 20:41 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-12 20:41 - 2012-12-16 17:13 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-08-12 20:41 - 2011-07-18 23:14 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-08-12 20:39 - 2013-08-12 11:03 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Adobe
2013-08-12 20:24 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-12 20:23 - 2012-07-15 22:08 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\DVDVideoSoft
2013-08-12 20:22 - 2012-08-12 12:59 - 00000000 ____D C:\Program Files (x86)\AVS4YOU
2013-08-11 19:57 - 2012-12-24 23:48 - 00000000 ____D C:\Program Files (x86)\SelfUpdater
2013-08-11 16:44 - 2013-03-10 20:20 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\MyPhoneExplorer
2013-08-11 16:37 - 2013-08-11 16:37 - 00000000 ____D C:\found.000
2013-08-10 18:26 - 2013-03-10 20:25 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-08-10 18:25 - 2013-03-10 21:04 - 00002065 _____ C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2013-08-10 18:25 - 2013-03-10 21:04 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2013-08-07 20:07 - 2012-05-09 15:16 - 00002592 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-07 11:35 - 2013-08-07 10:30 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-07 10:32 - 2013-08-07 10:32 - 00000000 _____ C:\autoexec.bat
2013-08-07 01:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-07 00:12 - 2013-08-07 00:12 - 00141008 _____ C:\Users\Lissi1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-07 00:10 - 2013-08-07 00:10 - 00524744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-07 00:09 - 2013-08-05 12:26 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2013-08-06 18:38 - 2012-02-04 18:47 - 00000000 ___RD C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-06 18:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-06 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-08-06 18:33 - 2011-04-12 10:28 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-08-06 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-08-06 18:07 - 2013-08-06 18:07 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag (1).js
2013-08-06 18:07 - 2013-08-06 18:06 - 00003031 _____ C:\Users\Lissi1\Downloads\writeBatchmediaTag.js
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI
2013-08-06 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sl-SI
2013-08-06 14:38 - 2013-08-06 14:38 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 14:38 - 2013-08-06 14:38 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-06 11:44 - 2012-11-24 19:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-08-06 10:33 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-06 10:32 - 2013-08-06 10:17 - 00000000 ____D C:\Windows\erdnt
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Malwarebytes
2013-08-05 12:28 - 2013-08-05 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-05 11:49 - 2013-08-05 11:49 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Avira
2013-08-05 11:44 - 2013-08-05 11:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-05 11:43 - 2013-08-05 11:42 - 00000000 ____D C:\ProgramData\Avira
2013-08-05 11:42 - 2013-08-05 11:42 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-05 11:35 - 2013-08-05 11:42 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-05 11:35 - 2013-08-05 11:42 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-01 03:08 - 2013-07-23 18:20 - 00032328 _____ C:\Windows\Launcher.exe
2013-07-26 06:15 - 2013-07-26 06:15 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
2013-07-25 19:12 - 2013-07-25 16:48 - 1071260076 _____ C:\Users\Lissi1\Downloads\Archiv20130709-1430.zip
2013-07-25 11:25 - 2013-08-14 08:56 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-25 10:57 - 2013-08-14 08:56 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-25 05:54 - 2013-08-14 12:41 - 17830400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-25 05:37 - 2013-08-14 12:41 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-25 05:35 - 2013-08-14 12:41 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-25 05:31 - 2013-08-14 12:42 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-25 05:30 - 2013-08-14 12:42 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-25 05:29 - 2013-08-14 12:42 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-25 05:29 - 2013-08-14 12:41 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-25 05:29 - 2013-08-14 12:41 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-25 05:28 - 2013-08-14 12:42 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-25 05:28 - 2013-08-14 12:41 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-25 05:28 - 2013-08-14 12:41 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-25 05:28 - 2013-08-14 12:41 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-25 05:28 - 2013-08-14 12:41 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-25 05:27 - 2013-08-14 12:42 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-25 05:27 - 2013-08-14 12:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-25 05:26 - 2013-08-14 12:42 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-25 04:40 - 2013-08-14 12:41 - 12334080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-25 04:32 - 2013-08-14 12:41 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-25 04:30 - 2013-08-14 12:41 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-25 04:26 - 2013-08-14 12:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-25 04:26 - 2013-08-14 12:42 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-25 04:25 - 2013-08-14 12:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-07-25 04:24 - 2013-08-14 12:42 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-07-25 04:24 - 2013-08-14 12:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-25 04:23 - 2013-08-14 12:42 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-07-25 04:23 - 2013-08-14 12:42 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-07-25 04:23 - 2013-08-14 12:41 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-25 04:23 - 2013-08-14 12:41 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-25 04:23 - 2013-08-14 12:41 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-25 04:22 - 2013-08-14 12:42 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-25 04:22 - 2013-08-14 12:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-25 04:22 - 2013-08-14 12:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-07-23 18:20 - 2013-07-23 18:20 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-07-22 17:03 - 2013-07-22 17:03 - 00004171 _____ C:\Users\Lissi1\Desktop\TauchenAlissa.wlmp
2013-07-22 17:03 - 2013-07-22 16:53 - 00004166 _____ C:\Users\Lissi1\Desktop\Tauchen1.wlmp
2013-07-19 03:58 - 2013-08-14 08:56 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-07-19 03:41 - 2013-08-14 08:56 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-07-18 20:44 - 2012-12-27 12:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\BOM
2013-07-17 18:43 - 2013-07-17 18:43 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Deployment
2013-07-17 18:43 - 2012-09-17 16:53 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Apps\2.0
2013-07-17 18:34 - 2013-02-09 17:40 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus
2013-07-17 18:34 - 2012-02-04 21:31 - 00000000 ____D C:\Program Files (x86)\ScanWizard 5
2013-07-17 18:34 - 2011-07-18 23:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-17 18:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-17 18:21 - 2011-04-12 10:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-07-17 18:13 - 2013-02-09 17:37 - 00000000 ____D C:\Users\Lissi1\AppData\Roaming\Ad-Aware Antivirus
2013-07-17 17:49 - 2013-07-17 16:37 - 00001447 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-17 17:49 - 2013-07-17 16:37 - 00001413 _____ C:\Users\Lissi1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-17 09:24 - 2012-02-04 18:44 - 00000000 ____D C:\Program Files\Google
2013-07-16 08:43 - 2012-02-04 19:47 - 00000000 ____D C:\Users\Lissi1\AppData\Local\Google
2013-07-16 08:43 - 2012-02-04 18:44 - 00000000 ____D C:\ProgramData\Google

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-12 05:58

==================== End Of Log ============================

--- --- ---

--- --- ---





Ich nutze kein Google Chrom, ich nute nur google auf IE9

markusg 15.08.2013 20:13

Hi, script noch mal editiert, führe es bitte noch mal aus, gucke dann, wie es läuft.
welche Fehlermeldung gibts denn beim löschen? bzw hat Delfix auch was ausgeworfen?

baby-lissa 15.08.2013 20:36

welches Skript????
es wird ja nihcts gelöscht von dem TBUpdater, FRST macht nichts.
delfix hat nichts ausgeworfen

nur FRST und alle TXT gelöscht

in der reg sind keine einträge wie die Folgenden die du gesentet hast.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\63D76E6EC6B04284B071A585DCBE8EA6 URL = => Value not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{120A8821-2BEE-4C29-BCDA-62C577781992} => Key not found.
HKCR\Wow6432Node\CLSID\{120A8821-2BEE-4C29-BCDA-62C577781992} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key not found.
HKCR\Wow6432Node\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key not found.

und dennoch bleibt TBUpdater beim Start stehen und kommt so alle 10 Minuten wieder wenn man ihn abbricht

markusg 15.08.2013 22:10

bitte führe das script trotzdem aus oder lass von mir aus die 3 zeilen weg.
frst musst du dann natürlich evtl. neu laden


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:09 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131