Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.20.02
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Helmut :: HELMUT-NB [Administrator]
Schutz: Aktiviert
20.08.2013 19:21:05
mbam-log-2013-08-20 (19-21-05).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 224816
Laufzeit: 16 Minute(n), 2 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 3
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f34c9277-6577-4dff-b2d7-7d58092f272f} (PUP.Datamngr) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 1
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0S1P1Q1U1LtI0NtH0D -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 1
C:\ProgramData\IBUpdaterService (PUP.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 1
C:\ProgramData\IBUpdaterService\repository.xml (PUP.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Code:
# AdwCleaner v3.000 - Report created 20/08/2013 at 20:02:35
# Updated 20/08/2013 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Helmut - HELMUT-NB
# Running from : C:\Users\Helmut\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : SystemStoreService
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Covus Freemium
Folder Deleted : C:\Program Files\Covus Freemium
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Program Files\SoftwareUpdater
Folder Deleted : C:\Program Files\Common Files\DVDVideoSoft\TB
Folder Deleted : C:\Users\Helmut\AppData\Local\DownloadGuide
Folder Deleted : C:\Users\Helmut\AppData\Local\Freemium
Folder Deleted : C:\Users\Helmut\AppData\Local\PackageAware
Folder Deleted : C:\Users\Helmut\AppData\LocalLow\AskSBar
Folder Deleted : C:\Users\Helmut\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Helmut\AppData\LocalLow\delta
Folder Deleted : C:\Users\Helmut\AppData\LocalLow\searchresultstb
Folder Deleted : C:\Users\Helmut\AppData\LocalLow\Softonic
Folder Deleted : C:\Users\Helmut\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\Helmut\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\Helmut\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Folder Deleted : C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
File Deleted : C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\searchplugins\Search_Results.xml
File Deleted : C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\searchplugins\softonic.xml
File Deleted : C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKLM\Software\systweak
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16502
-\\ Mozilla Firefox v8.0.1 (de)
[ File : C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\prefs.js ]
Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("browser.search.selectedEngine", "Search the web (Softonic)");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=13&cc=&mi=94c5d1f7000000000000001b9e55de7a");
Line Deleted : user_pref("extensions.Softonic.admin", false);
Line Deleted : user_pref("extensions.Softonic.aflt", "SD");
Line Deleted : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
Line Deleted : user_pref("extensions.Softonic.autoRvrt", "false");
Line Deleted : user_pref("extensions.Softonic.dfltLng", "de");
Line Deleted : user_pref("extensions.Softonic.dfltSrch", true);
Line Deleted : user_pref("extensions.Softonic.dnsErr", true);
Line Deleted : user_pref("extensions.Softonic.excTlbr", false);
Line Deleted : user_pref("extensions.Softonic.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.Softonic.hmpg", true);
Line Deleted : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=13&cc=&mi=94c5d1f7000000000000001b9e55de7a");
Line Deleted : user_pref("extensions.Softonic.hpOld0", "hxxp://www.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=94c5d1f7000000000000001b9e55de7a");
Line Deleted : user_pref("extensions.Softonic.id", "94c5d1f7000000000000001b9e55de7a");
Line Deleted : user_pref("extensions.Softonic.instlDay", "15886");
Line Deleted : user_pref("extensions.Softonic.instlRef", "MOY00006");
Line Deleted : user_pref("extensions.Softonic.kw_url", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=2&cc=&mi=94c5d1f7000000000000001b9e55de7a&q=");
Line Deleted : user_pref("extensions.Softonic.newTab", true);
Line Deleted : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00006/tb_v1/?SearchSource=15&cc=&mi=94c5d1f7000000000000001b9e55de7a");
Line Deleted : user_pref("extensions.Softonic.prdct", "Softonic");
Line Deleted : user_pref("extensions.Softonic.prtnrId", "softonic");
Line Deleted : user_pref("extensions.Softonic.rvrt", "false");
Line Deleted : user_pref("extensions.Softonic.smplGrp", "none");
Line Deleted : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Line Deleted : user_pref("extensions.Softonic.tlbrId", "BASEirobinhoodActive");
Line Deleted : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=1&cc=&mi=94c5d1f7000000000000001b9e55de7a&q=");
Line Deleted : user_pref("extensions.Softonic.vrsn", "1.8.19.3");
Line Deleted : user_pref("extensions.Softonic.vrsnTs", "1.8.19.317:07:27");
Line Deleted : user_pref("extensions.Softonic.vrsni", "1.8.19.3");
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "en");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.id", "94c5d1f7000000000000001b9e55de7a");
Line Deleted : user_pref("extensions.delta.instlDay", "15738");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.10.0");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.10.014:40:28");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.10.0");
-\\ Google Chrome v
[ File : C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : homepage
Deleted : search_url
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [7432 octets] - [20/08/2013 19:58:55]
AdwCleaner[S0].txt - [7523 octets] - [20/08/2013 20:02:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7583 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.1 (08.19.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Helmut on 20.08.2013 at 20:15:29,42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{01A2D565-256D-4055-B438-5614D95DE8E5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\pc1data"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.08.2013 at 20:23:12,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-08-2013 04
Ran by Helmut (administrator) on 20-08-2013 20:25:57
Running from C:\Users\Helmut\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Siber Systems) C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\program files\avira\antivir desktop\avcenter.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4444160 2007-07-09] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1822720 2007-07-09] (Realtek Semiconductor Corp.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-01] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation)
HKCU\...\Run: [RoboForm] - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [109784 2013-06-28] (Siber Systems)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2006-11-13] (TOSHIBA)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {6569938F-EEC8-433C-9BFD-5DB19259A985} URL = hxxp://at.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO: RoboForm Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU -&RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
Toolbar: HKCU -No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} hxxp://support.f-secure.com/ols/fscax.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553542000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{1F8A1508-49A8-49DF-99D8-47F16D8D593D}: [NameServer]194.48.124.202 194.48.124.200
FireFox:
========
FF ProfilePath: C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=13 - C:\Program Files\Google\Google Updater\2.4.1441.4352\npCIDetect13.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Helmut\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
FF Extension: No Name - C:\Users\Helmut\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: DownloadHelper - C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: Torbutton - C:\Users\Helmut\AppData\Roaming\Mozilla\Firefox\Profiles\4h5wi929.default\Extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] C:\Program Files\Siber Systems\AI RoboForm\Firefox
FF Extension: RoboForm Toolbar for Firefox - C:\Program Files\Siber Systems\AI RoboForm\Firefox
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-02-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-02-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [19456 2006-07-28] (COMPAL ELECTRONIC INC.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-29] (Samsung Electronics)
R3 UVCFTR; C:\Windows\System32\DRIVERS\UVCFTR_S.SYS [11264 2007-03-12] (Chicony Electronics Co., Ltd.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 catchme; \??\C:\Users\Helmut\AppData\Local\Temp\catchme.sys [x]
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S0 Lbd; system32\DRIVERS\Lbd.sys [x]
S1 mferkdk; \??\C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S0 qdugc; System32\drivers\xndko.sys [x]
S3 Tosrfcom; No ImagePath
S3 TpChoice; system32\DRIVERS\TpChoice.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-20 20:23 - 2013-08-20 20:23 - 00001303 _____ C:\Users\Helmut\Desktop\JRT.txt
2013-08-20 20:15 - 2013-08-20 20:15 - 00000000 ____D C:\Windows\ERUNT
2013-08-20 20:12 - 2013-08-20 20:13 - 01018949 _____ (Thisisu) C:\Users\Helmut\Desktop\JRT.exe
2013-08-20 19:58 - 2013-08-20 20:02 - 00000000 ____D C:\AdwCleaner
2013-08-20 19:58 - 2013-08-20 19:58 - 00975858 _____ C:\Users\Helmut\Desktop\adwcleaner.exe
2013-08-20 14:11 - 2013-08-20 14:11 - 00000871 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 14:11 - 2013-08-20 14:11 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-20 14:11 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-19 19:47 - 2013-08-19 19:47 - 00018201 _____ C:\ComboFix.txt
2013-08-19 19:19 - 2013-08-19 19:22 - 05105821 ____R (Swearware) C:\Users\Helmut\Desktop\ComboFix.exe
2013-08-19 19:17 - 2013-08-19 19:47 - 00000000 ____D C:\Qoobox
2013-08-19 19:17 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-19 19:17 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-19 19:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-19 19:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-19 19:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-19 19:17 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-19 19:17 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-19 19:17 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-19 19:16 - 2013-08-19 19:42 - 00000000 ____D C:\Windows\erdnt
2013-08-19 09:53 - 2013-08-19 09:53 - 00000000 ____D C:\FRST
2013-08-19 09:49 - 2013-08-19 09:49 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\SmartFTP
2013-08-19 09:46 - 2013-08-19 09:46 - 00001844 _____ C:\Users\Public\Desktop\SmartFTP Client.lnk
2013-08-19 09:46 - 2013-08-19 09:46 - 00000000 ____D C:\Program Files\SmartFTP Client
2013-08-19 09:39 - 2013-08-19 09:47 - 16072408 _____ (SmartSoft Ltd) C:\Users\Helmut\Desktop\SFTPMSI1333.exe
2013-08-15 13:00 - 2013-08-15 13:00 - 00000796 _____ C:\Windows\setupact.log
2013-08-15 13:00 - 2013-08-15 13:00 - 00000000 _____ C:\Windows\setuperr.log
2013-08-15 07:07 - 2013-08-15 07:06 - 05401808 _____ (PC Cleaners) C:\ProgramData\pclunst.exe
2013-08-15 06:50 - 2013-08-20 20:04 - 00001744 _____ C:\Windows\PFRO.log
2013-08-14 21:17 - 2013-08-14 21:24 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 20:58 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 20:58 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 20:58 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 20:58 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 20:58 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 20:58 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-14 20:58 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-14 20:58 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 20:58 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 20:58 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 20:58 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 20:58 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-14 20:58 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-14 20:58 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 20:58 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 20:58 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-14 20:46 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 20:46 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 20:46 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 20:46 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-14 20:46 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 20:46 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 20:46 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 20:46 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 20:46 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 20:46 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 20:46 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-08-14 20:46 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 20:32 - 2013-08-14 20:32 - 00001918 _____ C:\Users\Public\Desktop\Free System Utilities.lnk
2013-08-14 20:32 - 2013-08-14 20:32 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-08-14 20:31 - 2013-08-14 20:31 - 00000000 ____D C:\ProgramData\Package Cache
2013-07-23 21:00 - 2013-07-23 21:00 - 00000847 _____ C:\Users\Helmut\Desktop\Jodix Free WMA to MP3 Converter.lnk
2013-07-23 21:00 - 2013-07-23 21:00 - 00000000 ____D C:\Program Files\Free WMA to MP3 Converter
2013-07-23 20:59 - 2013-07-23 20:59 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\XMedia Recode
2013-07-23 20:32 - 2013-07-23 20:38 - 00000000 ____D C:\Users\Helmut\Desktop\Unbekannter Interpret
==================== One Month Modified Files and Folders =======
2013-08-20 20:25 - 2013-08-20 20:25 - 01070233 _____ (Farbar) C:\Users\Helmut\Desktop\FRST.exe
2013-08-20 20:23 - 2013-08-20 20:23 - 00001303 _____ C:\Users\Helmut\Desktop\JRT.txt
2013-08-20 20:16 - 2010-09-26 13:55 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-20 20:15 - 2013-08-20 20:15 - 00000000 ____D C:\Windows\ERUNT
2013-08-20 20:15 - 2008-06-27 16:43 - 01112393 _____ C:\Windows\WindowsUpdate.log
2013-08-20 20:14 - 2012-04-03 05:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-20 20:13 - 2013-08-20 20:12 - 01018949 _____ (Thisisu) C:\Users\Helmut\Desktop\JRT.exe
2013-08-20 20:05 - 2010-09-26 13:54 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-20 20:05 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-20 20:05 - 2006-11-02 14:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-20 20:05 - 2006-11-02 14:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-20 20:04 - 2013-08-15 06:50 - 00001744 _____ C:\Windows\PFRO.log
2013-08-20 20:03 - 2006-11-02 15:01 - 00032582 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-20 20:02 - 2013-08-20 19:58 - 00000000 ____D C:\AdwCleaner
2013-08-20 20:02 - 2010-12-30 18:08 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-08-20 19:58 - 2013-08-20 19:58 - 00975858 _____ C:\Users\Helmut\Desktop\adwcleaner.exe
2013-08-20 14:11 - 2013-08-20 14:11 - 00000871 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 14:11 - 2013-08-20 14:11 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-20 14:05 - 2008-12-25 17:49 - 00000868 _____ C:\Windows\Tasks\Google Software Updater.job
2013-08-19 19:47 - 2013-08-19 19:47 - 00018201 _____ C:\ComboFix.txt
2013-08-19 19:47 - 2013-08-19 19:17 - 00000000 ____D C:\Qoobox
2013-08-19 19:47 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2013-08-19 19:47 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-08-19 19:42 - 2013-08-19 19:16 - 00000000 ____D C:\Windows\erdnt
2013-08-19 19:41 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2013-08-19 19:39 - 2008-06-27 17:04 - 00000000 ____D C:\Users\Helmut
2013-08-19 19:22 - 2013-08-19 19:19 - 05105821 ____R (Swearware) C:\Users\Helmut\Desktop\ComboFix.exe
2013-08-19 10:19 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-19 09:53 - 2013-08-19 09:53 - 00000000 ____D C:\FRST
2013-08-19 09:49 - 2013-08-19 09:49 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\SmartFTP
2013-08-19 09:47 - 2013-08-19 09:39 - 16072408 _____ (SmartSoft Ltd) C:\Users\Helmut\Desktop\SFTPMSI1333.exe
2013-08-19 09:46 - 2013-08-19 09:46 - 00001844 _____ C:\Users\Public\Desktop\SmartFTP Client.lnk
2013-08-19 09:46 - 2013-08-19 09:46 - 00000000 ____D C:\Program Files\SmartFTP Client
2013-08-15 13:06 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-08-15 13:03 - 2006-11-02 12:33 - 01482950 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-15 13:00 - 2013-08-15 13:00 - 00000796 _____ C:\Windows\setupact.log
2013-08-15 13:00 - 2013-08-15 13:00 - 00000000 _____ C:\Windows\setuperr.log
2013-08-15 07:06 - 2013-08-15 07:07 - 05401808 _____ (PC Cleaners) C:\ProgramData\pclunst.exe
2013-08-15 06:39 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-14 21:24 - 2013-08-14 21:17 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 21:17 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-08-14 21:13 - 2008-08-14 08:58 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-14 21:01 - 2013-05-24 14:03 - 00000000 ____D C:\Users\Helmut\Desktop\Alia
2013-08-14 20:32 - 2013-08-14 20:32 - 00001918 _____ C:\Users\Public\Desktop\Free System Utilities.lnk
2013-08-14 20:32 - 2013-08-14 20:32 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-08-14 20:31 - 2013-08-14 20:31 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-12 10:36 - 2010-11-14 12:43 - 00000769 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-12 10:36 - 2010-08-25 20:35 - 00000000 ____D C:\Program Files\CCleaner
2013-07-25 07:41 - 2008-08-14 09:11 - 00002593 _____ C:\Users\Helmut\Desktop\Microsoft Office Excel 2007.lnk
2013-07-25 04:40 - 2013-08-14 20:58 - 12334080 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-25 04:32 - 2013-08-14 20:58 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-25 04:30 - 2013-08-14 20:58 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-25 04:26 - 2013-08-14 20:58 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-25 04:26 - 2013-08-14 20:58 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-25 04:25 - 2013-08-14 20:58 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-25 04:24 - 2013-08-14 20:58 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-25 04:24 - 2013-08-14 20:58 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-25 04:23 - 2013-08-14 20:58 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-25 04:23 - 2013-08-14 20:58 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-25 04:23 - 2013-08-14 20:58 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-25 04:23 - 2013-08-14 20:58 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-25 04:23 - 2013-08-14 20:58 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-25 04:22 - 2013-08-14 20:58 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-25 04:22 - 2013-08-14 20:58 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-25 04:22 - 2013-08-14 20:58 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-23 21:00 - 2013-07-23 21:00 - 00000847 _____ C:\Users\Helmut\Desktop\Jodix Free WMA to MP3 Converter.lnk
2013-07-23 21:00 - 2013-07-23 21:00 - 00000000 ____D C:\Program Files\Free WMA to MP3 Converter
2013-07-23 20:59 - 2013-07-23 20:59 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\XMedia Recode
2013-07-23 20:38 - 2013-07-23 20:32 - 00000000 ____D C:\Users\Helmut\Desktop\Unbekannter Interpret
Files to move or delete:
====================
C:\ProgramData\pclunst.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-20 20:16
==================== End Of Log ============================ --- --- ---
--- --- --- |