Malwarebytes Anti-Malware:
[CODE][Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.27.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
user :: USER-THINK [limitiert]
27.08.2013 12:19:55
mbam-log-2013-08-27 (12-19-55).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 272176
Laufzeit: 4 Minute(n), 14 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
/CODE]
AdwCleaner:
Code:
# AdwCleaner v3.001 - Report created 27/08/2013 at 12:27:02
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : user - USER-THINK
# Running from : C:\Users\user\Downloads\adwcleaner (1).exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16502
-\\ Mozilla Firefox v
-\\ Google Chrome v28.0.1500.95
[ File : C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : homepage
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [7675 octets] - [26/08/2013 18:42:55]
AdwCleaner[R1].txt - [1017 octets] - [27/08/2013 12:25:58]
AdwCleaner[S0].txt - [7184 octets] - [26/08/2013 18:44:07]
AdwCleaner[S1].txt - [890 octets] - [27/08/2013 12:27:02]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [949 octets] ##########
Junkware Removal Tool:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.4 (08.22.2013:1)
OS: Windows 7 Professional x64
Ran by user on 27.08.2013 at 12:34:40,72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.08.2013 at 12:41:33,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-08-2013 01
Ran by user (administrator) on 27-08-2013 12:44:09
Running from C:\Users\user\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AuthenTec, Inc) C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe
(Lenovo.) C:\Windows\system32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Infowatch) C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SAsrv.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\TouchControl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\x86\BioMonitor.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Lenovo Group Limited) C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\SysWOW64\NOTEPAD.EXE
(Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Thisisu) C:\Users\user\Downloads\JRT (1).exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\user\Downloads\FRST64 (1).exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BLEServicesCtrl] - C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [177936 2012-02-17] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2012-02-21] (Intel Corporation)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1654400 2012-02-21] (Conexant Systems, Inc.)
HKLM\...\Run: [TpShocks] - C:\Windows\system32\TpShocks.exe [382528 2012-02-24] (Lenovo.)
HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [283984 2012-04-10] (Lenovo Group Limited)
HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-05-02] (Facebook Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-06-18] (Google Inc.)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-03-07] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation)
HKLM-x32\...\Run: [RotateImage] - C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [PWMTRV] - C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL [5939776 2012-04-11] (Lenovo Group Limited)
HKLM-x32\...\Run: [Fastboot] - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo)
HKLM-x32\...\Run: [Lenovo Registration] - C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.)
HKLM-x32\...\Run: [IntelSBA] - C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe [4243168 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356968 2012-12-20] (Kaspersky Lab ZAO)
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-08-08] (Lenovo)
HKU\Default\...\RunOnce: [] - [x]
HKU\Default\...\RunOnce: [Lenovoautoqdrive] - C:\PROGRA~2\Common~1\Lenovo\Lenovo~1\LenovoAutorunreg.exe [159744 2011-12-15] ()
HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-08-08] (Lenovo)
HKU\Default User\...\RunOnce: [] - [x]
HKU\Default User\...\RunOnce: [Lenovoautoqdrive] - C:\PROGRA~2\Common~1\Lenovo\Lenovo~1\LenovoAutorunreg.exe [159744 2011-12-15] ()
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [266448 2013-06-21] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,start page = hxxp://www.bing.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.DLL (AuthenTec Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll (Kaspersky Lab)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - No File
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - TrueSuite Toolbar - {C98EE38D-21E4-4A50-907D-2B56FEC7013E} - C:\Program Files\AuthenTec TrueSuite\IEBHO.DLL (AuthenTec Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - No Name - {C98EE38D-21E4-4A50-907D-2B56FEC7013E} - No File
Toolbar: HKLM-x32 - Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll (Kaspersky Lab)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Extension: ftdownloader - C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftdownloader@ftdownloader.com.xpi
FF HKLM-x32\...\Firefox\Extensions: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\online_banking@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [VIP5X@verisign.com] C:\Program Files (x86)\Symantec\VIP Access Client\
FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\
Chrome:
=======
CHR HomePage: hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=65bf0910-8955-4ea2-ba62-2e0a7ef14d9a&searchtype=hp&installDate=27/06/2013
CHR RestoreOnStartup: "hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=65bf0910-8955-4ea2-ba62-2e0a7ef14d9a&searchtype=hp&installDate=27/06/2013", "hxxp://www.google.com"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0
CHR Extension: (Safe Money) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_0
CHR Extension: (Website Logon) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombkllfdikmoepjdpmdaiinfbjpnkboa\2.0_0
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR Extension: (Anti-Banner) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [gkjoindjjcmbdpbfppabdgflnkgbbcli] - C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [ombkllfdikmoepjdpmdaiinfbjpnkboa] - C:\Program Files\AuthenTec TrueSuite\x86\tschrome.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\ab.crx
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356968 2012-12-20] (Kaspersky Lab ZAO)
R2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [819040 2012-12-21] (Infowatch)
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [8447848 2011-11-09] (DisplayLink Corp.)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo)
R2 FPLService; C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe [313672 2011-12-22] (AuthenTec, Inc)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-07] ()
R2 Intel(R) Small Business Advantage; C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [49376 2012-02-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-07] (Intel Corporation)
R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [175440 2012-04-10] (Lenovo Group Limited)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [21416 2012-09-13] ()
R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-10] (Symantec Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [84536 2011-06-02] (Infowatch)
R1 CSVirtualDiskDrv; C:\Windows\System32\DRIVERS\CSVirtualDiskDrv.sys [66616 2011-06-02] (Infowatch)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-27] (DT Soft Ltd)
S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620128 2013-08-14] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-09-03] (Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29528 2012-09-03] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-08-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-08-14] (Kaspersky Lab ZAO)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
R1 PHCORE; C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [33344 2012-01-30] (Lenovo Group Limited)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.)
R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility)
S3 AIDA64Driver; \??\E:\AIDA64 Extreme Edition 2.50\kerneld.x64 [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-27 12:16 - 2013-08-27 12:16 - 01021434 _____ (Thisisu) C:\Users\user\Downloads\JRT (1).exe
2013-08-27 12:16 - 2013-08-27 12:16 - 00994642 _____ C:\Users\user\Downloads\adwcleaner (1).exe
2013-08-27 12:15 - 2013-08-27 12:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300 (1).exe
2013-08-27 11:50 - 2013-08-27 11:51 - 01578852 _____ (Farbar) C:\Users\user\Downloads\FRST64 (1).exe
2013-08-27 01:35 - 2013-08-27 01:35 - 00000970 _____ C:\Users\user\Documents\Fixlist.txt
2013-08-26 19:11 - 2013-08-26 19:11 - 02347384 _____ (ESET) C:\Users\user\Downloads\esetsmartinstaller_enu.exe
2013-08-26 19:11 - 2013-08-26 19:11 - 00891115 _____ C:\Users\user\Downloads\SecurityCheck.exe
2013-08-26 19:09 - 2013-08-26 19:09 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-08-26 19:08 - 2013-08-27 12:18 - 00001124 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-26 19:08 - 2013-08-27 12:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-26 19:08 - 2013-08-26 19:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-26 19:08 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-26 19:07 - 2013-08-26 19:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-26 18:51 - 2013-08-26 18:51 - 00000000 ____D C:\Windows\ERUNT
2013-08-26 18:49 - 2013-08-26 18:49 - 01021434 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-08-26 18:42 - 2013-08-27 12:27 - 00000000 ____D C:\AdwCleaner
2013-08-26 18:41 - 2013-08-26 18:42 - 00994642 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-08-26 18:31 - 2013-08-26 18:31 - 00040860 _____ C:\ComboFix.txt
2013-08-26 17:21 - 2013-08-26 18:34 - 00000000 ____D C:\ComboFix
2013-08-26 15:38 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-26 15:38 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-26 15:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-26 15:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-26 15:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-26 15:38 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-26 15:38 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-26 15:38 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-26 15:37 - 2013-08-26 18:34 - 00000000 ____D C:\Qoobox
2013-08-26 15:37 - 2013-08-26 18:18 - 00000000 ____D C:\Windows\erdnt
2013-08-26 15:34 - 2013-08-26 15:34 - 05113393 ____R (Swearware) C:\Users\user\Downloads\ComboFix.exe
2013-08-26 15:32 - 2013-08-27 12:05 - 00026103 _____ C:\Users\user\Downloads\Addition.txt
2013-08-26 15:30 - 2013-08-26 15:30 - 00000000 ____D C:\FRST
2013-08-26 15:26 - 2013-08-26 15:26 - 01577068 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-08-26 15:21 - 2013-08-26 15:21 - 00001088 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2013-08-26 15:21 - 2013-08-26 15:21 - 00000000 ____D C:\Users\user\AppData\Local\VS Revo Group
2013-08-26 15:21 - 2013-08-26 15:21 - 00000000 ____D C:\ProgramData\VS Revo Group
2013-08-26 15:21 - 2013-08-26 15:21 - 00000000 ____D C:\Program Files\VS Revo Group
2013-08-26 15:21 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2013-08-26 15:19 - 2013-08-26 15:19 - 10031224 _____ (VS Revo Group ) C:\Users\user\Downloads\RevoUninProSetup.exe
2013-08-26 15:14 - 2013-08-26 15:14 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer (2).exe
2013-08-26 15:14 - 2013-08-26 15:14 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer (1).exe
2013-08-26 13:40 - 2013-08-26 13:40 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-26 13:40 - 2013-08-26 13:40 - 00000000 _____ C:\autoexec.bat
2013-08-26 13:39 - 2013-08-26 15:36 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-26 13:37 - 2013-08-26 13:37 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer.exe
2013-08-17 10:55 - 2013-08-17 10:55 - 00002270 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-17 09:58 - 2013-08-17 09:58 - 00985600 _____ C:\Users\user\Downloads\MicrosoftFixit50123.msi
2013-08-17 09:55 - 2013-08-17 09:55 - 00000134 _____ C:\Users\user\Desktop\Internet Explorer-Problembehebung.url
2013-08-15 17:25 - 2013-08-15 17:31 - 00000000 ____D C:\Users\user\Desktop\Neuer Ordner (2)
2013-08-15 17:24 - 2013-08-15 17:24 - 00001449 _____ C:\Users\Public\Desktop\Free Audio Converter.lnk
2013-08-15 17:24 - 2013-08-15 17:24 - 00000000 ____D C:\Users\user\AppData\Roaming\DVDVideoSoft
2013-08-15 17:24 - 2013-08-15 17:24 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-08-15 17:19 - 2013-08-15 17:23 - 00000000 ____D C:\Users\user\Desktop\Settle (Deluxe Version)
2013-08-15 17:07 - 2013-08-15 18:38 - 00000000 ____D C:\Program Files (x86)\Free mp3 Wma Converter
2013-08-15 17:07 - 2013-08-15 17:07 - 00000000 ____D C:\Users\user\AppData\Roaming\FreeAudioPack
2013-08-15 17:07 - 2011-09-29 14:20 - 02084864 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\AudDesign.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 01986560 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\AudFile.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 01212416 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\AudioInfos.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 00479232 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\AudioVisu.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 00458752 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\AudPlayer.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 00454656 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\AudioRecord.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 00417792 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\AudDisplay.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 00348160 _____ (NCT Company Ltd.) C:\Windows\SysWOW64\WMAFile.dll
2013-08-15 17:07 - 2011-09-29 14:20 - 00164144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMCT232.OCX
2013-08-15 17:07 - 2011-09-29 14:20 - 00116296 _____ C:\Windows\SysWOW64\NCTWMAProfiles.prx
2013-08-15 17:07 - 2011-09-29 14:19 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2013-08-15 17:07 - 2011-09-29 14:19 - 00224016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TABCTL32.OCX
2013-08-15 17:07 - 2011-09-29 14:19 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX
2013-08-15 17:07 - 2011-09-29 14:19 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCFR.DLL
2013-08-15 17:07 - 2011-09-29 14:19 - 00119568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6FR.DLL
2013-08-15 17:07 - 2011-09-29 14:19 - 00115920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.OCX
2013-08-15 17:07 - 2011-09-29 14:19 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6STKIT.DLL
2013-08-15 17:07 - 2011-09-29 14:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mscc2fr.dll
2013-08-15 17:07 - 2011-09-29 14:19 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CMDLGFR.DLL
2013-08-15 17:07 - 2011-09-29 14:19 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TABCTFR.DLL
2013-08-15 17:07 - 2011-09-29 14:19 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetfr.DLL
2013-08-15 17:06 - 2013-08-15 17:06 - 00458744 _____ (Bandoo Media Inc) C:\Users\user\Downloads\Setup21_FreeConverter.exe
2013-08-14 14:42 - 2013-08-14 14:46 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 14:35 - 2013-07-25 05:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 14:35 - 2013-07-25 05:27 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-14 14:35 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 14:35 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-14 14:34 - 2013-07-25 05:54 - 17830400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 14:34 - 2013-07-25 05:37 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 14:34 - 2013-07-25 05:35 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 14:34 - 2013-07-25 05:31 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 14:34 - 2013-07-25 05:30 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 14:34 - 2013-07-25 05:29 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-14 14:34 - 2013-07-25 05:29 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-14 14:34 - 2013-07-25 05:29 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 14:34 - 2013-07-25 05:28 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 14:34 - 2013-07-25 05:28 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 14:34 - 2013-07-25 05:28 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 14:34 - 2013-07-25 05:28 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-14 14:34 - 2013-07-25 05:28 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-14 14:34 - 2013-07-25 05:26 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 14:34 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 14:34 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 14:34 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 14:34 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 14:34 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 14:34 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-14 14:34 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-14 14:34 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 14:34 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 14:34 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 14:34 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 14:34 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-08-14 14:34 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-14 14:34 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 14:33 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 14:33 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 14:33 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 14:33 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 14:33 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 14:33 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 14:33 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 14:33 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 14:32 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 14:32 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 14:32 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 14:32 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 14:27 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 14:27 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 14:10 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 14:10 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 14:10 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 14:10 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 14:10 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 14:10 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 14:10 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 14:10 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 14:10 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 14:10 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 14:10 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 14:09 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 14:07 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 14:00 - 2013-08-14 14:00 - 00002231 _____ C:\Users\user\Desktop\Sicherer Zahlungsverkehr.lnk
2013-08-14 13:52 - 2013-08-14 13:52 - 00001089 _____ C:\Users\Public\Desktop\Kaspersky PURE 3.0.lnk
2013-08-14 13:52 - 2012-07-11 17:09 - 00064856 _____ (Kaspersky Lab) C:\Windows\system32\klfphc.dll
2013-08-14 13:51 - 2013-08-14 13:51 - 00000000 ____D C:\Windows\ELAMBKUP
2013-08-14 13:51 - 2011-06-02 14:39 - 00084536 _____ (Infowatch) C:\Windows\system32\Drivers\CSCrySec.sys
2013-08-14 13:51 - 2011-06-02 14:39 - 00066616 _____ (Infowatch) C:\Windows\system32\Drivers\CSVirtualDiskDrv.sys
2013-08-14 13:50 - 2013-08-27 12:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-08-14 13:50 - 2013-08-14 14:28 - 00620128 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-08-14 13:50 - 2013-08-14 14:28 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2013-08-14 13:50 - 2013-08-14 13:50 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2013-08-14 00:21 - 2013-08-14 00:21 - 00002002 _____ C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2013-08-14 00:00 - 2013-08-17 09:55 - 00015109 _____ C:\Windows\IE10_main.log
2013-08-13 23:54 - 2013-08-14 00:12 - 188740896 _____ (Kaspersky Lab) C:\Users\user\Downloads\pure13.0.2.558DE_4340.exe
2013-08-13 23:39 - 2013-08-27 12:28 - 00001643 _____ C:\Windows\setupact.log
2013-08-13 23:39 - 2013-08-27 01:16 - 00012148 _____ C:\Windows\PFRO.log
2013-08-13 23:39 - 2013-08-13 23:39 - 00000000 _____ C:\Windows\setuperr.log
2013-08-13 23:09 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-08-13 23:09 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-08-13 23:08 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-08-13 23:08 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-08-13 23:08 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-08-13 23:08 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-08-13 23:07 - 2013-03-19 07:46 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-08-13 23:07 - 2013-03-19 06:47 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-08-13 23:07 - 2013-03-19 05:06 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-08-13 22:42 - 2013-08-13 22:47 - 70300856 _____ (WinFuture) C:\Users\user\Downloads\WinFuture_7_x64_UpdatePack_1.36_April_2013-Upgrade.exe
2013-08-13 22:40 - 2013-08-13 22:40 - 00347424 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.wu.FISC.196299856852161036.1.3.Run.exe
2013-08-13 22:36 - 2013-08-13 22:36 - 00347424 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.WinFileFolder.FISC.196299856852161036.1.2.Run.exe
2013-08-13 22:35 - 2013-08-13 22:35 - 00347424 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.malware.FISC.196299856852161036.1.1.Run.exe
2013-08-13 22:32 - 2013-08-13 22:52 - 00000000 ____D C:\Users\user\AppData\Local\WEKA DVD Interface
2013-08-13 00:18 - 2013-04-10 08:01 - 00983400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-08-13 00:18 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-08-13 00:18 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-08-12 23:31 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-08-12 23:31 - 2013-02-27 07:52 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-08-12 23:31 - 2013-02-27 07:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-08-12 23:31 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-08-12 23:31 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-08-12 23:31 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-08-12 23:31 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-08-12 23:31 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-08-12 23:31 - 2013-02-15 08:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-08-12 23:31 - 2013-02-15 08:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-08-12 23:31 - 2013-02-15 08:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-08-12 23:31 - 2013-02-15 06:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-08-12 23:31 - 2013-02-15 06:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-08-12 23:31 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-08-12 23:30 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-08-12 23:30 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-08-12 23:30 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-08-12 23:30 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-08-12 23:30 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-08-12 23:30 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-08-12 23:30 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-08-12 23:30 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-08-12 23:30 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-08-12 23:30 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-08-12 23:22 - 2013-04-10 07:45 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-08-12 23:21 - 2013-04-10 07:02 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-08-12 22:24 - 2013-08-12 22:59 - 00000000 ____D C:\Users\user\Downloads\Kaspersky Rescue2Usb
2013-08-12 22:13 - 2013-08-12 22:23 - 261507072 _____ C:\Users\user\Desktop\kav_rescue_10-31.iso
2013-08-12 22:12 - 2013-08-12 22:12 - 00387584 _____ C:\Users\user\Downloads\rescue2usb.exe
2013-08-12 21:20 - 2013-08-12 21:32 - 00000000 ____D C:\Users\user\Desktop\Neuer Ordner
2013-08-12 20:46 - 2013-08-12 20:47 - 00000000 ____D C:\Users\user\AppData\Roaming\U3
2013-08-12 20:40 - 2013-08-12 20:40 - 03395840 _____ (Piriform Ltd) C:\Users\user\Downloads\ccsetup404_slim.exe
2013-08-12 20:35 - 2013-08-12 20:56 - 00000624 _____ C:\Users\user\Downloads\Stinger_12082013_203502.html
2013-08-12 20:34 - 2013-08-12 21:15 - 00000112 ___RH C:\Users\user\Downloads\Stinger.opt
2013-08-12 20:34 - 2013-08-12 20:49 - 00000000 ____D C:\Program Files\stinger
2013-08-12 20:34 - 2013-08-12 20:34 - 12725280 _____ (McAfee Inc) C:\Users\user\Downloads\stinger64_12.0.0.483.exe
2013-08-12 20:11 - 2013-08-12 20:11 - 02828552 _____ (AVAST Software) C:\Users\user\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-08-11 22:18 - 2013-08-11 22:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\PwrMgr
2013-08-11 21:49 - 2013-08-11 21:49 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Softland
2013-08-11 21:47 - 2013-08-11 21:47 - 00123208 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\McAfee
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Lenovo
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Leadertech
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Apple Computer
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Local\Lenovo
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 _____ C:\Users\Administrator\agent.log
2013-08-11 21:46 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator
2013-08-11 21:46 - 2013-08-11 21:46 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Vorlagen
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Startmenü
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Intel
2013-08-11 21:46 - 2013-04-08 22:39 - 00000000 ____D C:\Users\Administrator\AppData\Local\Microsoft Help
2013-08-11 21:46 - 2012-12-09 19:34 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\TuneUp Software
2013-08-11 21:46 - 2012-06-18 14:24 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
2013-08-11 20:21 - 2013-08-11 20:21 - 00000017 _____ C:\Users\user\AppData\Local\resmon.resmoncfg
2013-08-11 17:41 - 2013-08-11 17:41 - 00000000 _____ C:\Users\user\AppData\Roaming\AbsoluteReminder.xml
2013-08-11 17:40 - 2013-08-11 17:40 - 00007140 _____ C:\Users\user\Documents\cc_20130811_174011.reg
2013-08-11 16:51 - 2013-08-11 16:51 - 21728904 _____ (Microsoft Corporation) C:\Users\user\Downloads\Windows-KB890830-x64-V5.2.exe
2013-08-11 16:21 - 2013-08-11 16:21 - 00003418 _____ C:\Windows\System32\Tasks\{B25F1987-1535-4B53-9232-FF697284ADCB}
2013-08-11 16:11 - 2013-08-11 16:11 - 05990376 _____ (IObit ) C:\Users\user\Downloads\defragsetup_2811221.exe
2013-08-11 16:05 - 2013-08-11 16:05 - 04100432 _____ (Piriform Ltd) C:\Users\user\Downloads\dfsetup215 (1).exe
2013-08-11 16:03 - 2013-08-11 16:04 - 03368056 _____ (hxxp://www.maxuninstaller.com/ ) C:\Users\user\Downloads\MaxUninstaller_Setup.exe
2013-08-11 15:48 - 2013-08-11 15:48 - 04100432 _____ (Piriform Ltd) C:\Users\user\Downloads\dfsetup215.exe
2013-08-11 15:43 - 2013-08-11 15:45 - 04100432 _____ (Piriform Ltd) C:\Users\user\Downloads\dfsetup_2.15.741.exe
2013-08-11 12:29 - 2013-08-11 12:29 - 00003704 _____ C:\Windows\System32\Tasks\Java Update Scheduler
2013-08-11 12:29 - 2013-08-11 12:29 - 00003694 _____ C:\Windows\System32\Tasks\Adobe online update program
2013-08-11 12:19 - 2013-08-11 12:19 - 00000000 ____D C:\Users\user\AppData\Roaming\McAfee
2013-08-11 12:19 - 2013-08-11 12:18 - 00099056 _____ (McAfee, Inc.) C:\Windows\system32\MfeOtlkAddin.dll
2013-08-11 12:19 - 2013-08-11 12:18 - 00074848 _____ (McAfee, Inc.) C:\Windows\SysWOW64\MfeOtlkAddin.dll
2013-08-11 12:19 - 2013-08-11 12:18 - 00022816 _____ (McAfee, Inc.) C:\Windows\SysWOW64\MFEOtlk.dll
2013-08-11 12:18 - 2013-08-13 23:39 - 00000000 ____D C:\Program Files\Common Files\McAfee
2013-08-11 12:17 - 2013-08-13 23:03 - 00000000 ____D C:\ProgramData\McAfee
2013-08-11 12:17 - 2013-08-13 23:02 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-08-11 10:42 - 2013-08-11 10:42 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-08-11 10:42 - 2013-08-11 10:42 - 00000000 ____D C:\Users\user\Desktop\Tune Up Utilities 2012
2013-08-09 12:34 - 2013-08-09 12:35 - 11348656 _____ (Lenovo ) C:\Users\user\Downloads\systemupdate502-06-26-2013.exe
2013-08-08 22:59 - 2013-08-08 22:59 - 00069456 _____ C:\Users\user\Documents\cc_20130808_225910.reg
2013-08-08 18:41 - 2013-08-08 18:42 - 03482040 _____ C:\Users\user\Downloads\avg_remover_2013_3341.zip
2013-08-08 12:12 - 2013-08-08 12:12 - 00262144 _____ C:\Windows\system32\config\elam
2013-08-08 11:25 - 2013-08-08 11:25 - 00866592 _____ C:\Users\user\Downloads\Norton_Removal_Tool.exe
2013-08-04 19:01 - 2013-08-04 19:04 - 189379192 _____ (Kaspersky Lab) C:\Users\user\Downloads\kis13.0.1.4190abcdefgDE_4608.exe
==================== One Month Modified Files and Folders =======
2013-08-27 12:41 - 2013-08-27 12:41 - 00000624 _____ C:\Users\user\Desktop\JRT.txt
2013-08-27 12:38 - 2009-07-14 06:45 - 00034432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-27 12:38 - 2009-07-14 06:45 - 00034432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-27 12:34 - 2012-06-18 14:05 - 01094053 _____ C:\Windows\WindowsUpdate.log
2013-08-27 12:33 - 2013-08-14 13:50 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-08-27 12:29 - 2012-06-18 14:34 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-27 12:29 - 2012-06-18 14:11 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-08-27 12:28 - 2013-08-13 23:39 - 00001643 _____ C:\Windows\setupact.log
2013-08-27 12:28 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-27 12:27 - 2013-08-26 18:42 - 00000000 ____D C:\AdwCleaner
2013-08-27 12:18 - 2013-08-26 19:08 - 00001124 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-27 12:18 - 2013-08-26 19:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-27 12:16 - 2013-08-27 12:16 - 01021434 _____ (Thisisu) C:\Users\user\Downloads\JRT (1).exe
2013-08-27 12:16 - 2013-08-27 12:16 - 00994642 _____ C:\Users\user\Downloads\adwcleaner (1).exe
2013-08-27 12:16 - 2013-08-27 12:15 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300 (1).exe
2013-08-27 12:16 - 2012-06-18 14:34 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-27 12:05 - 2013-08-26 15:32 - 00026103 _____ C:\Users\user\Downloads\Addition.txt
2013-08-27 11:51 - 2013-08-27 11:50 - 01578852 _____ (Farbar) C:\Users\user\Downloads\FRST64 (1).exe
2013-08-27 11:40 - 2013-05-02 11:35 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4132708011-2150104516-3946137186-1001UA.job
2013-08-27 11:40 - 2013-05-02 11:35 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4132708011-2150104516-3946137186-1001Core.job
2013-08-27 11:38 - 2012-12-07 23:45 - 00000000 ____D C:\Users\user\AppData\Roaming\vlc
2013-08-27 09:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-27 01:35 - 2013-08-27 01:35 - 00000970 _____ C:\Users\user\Documents\Fixlist.txt
2013-08-27 01:16 - 2013-08-13 23:39 - 00012148 _____ C:\Windows\PFRO.log
2013-08-26 19:11 - 2013-08-26 19:11 - 02347384 _____ (ESET) C:\Users\user\Downloads\esetsmartinstaller_enu.exe
2013-08-26 19:11 - 2013-08-26 19:11 - 00891115 _____ C:\Users\user\Downloads\SecurityCheck.exe
2013-08-26 19:09 - 2013-08-26 19:09 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-08-26 19:08 - 2013-08-26 19:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-26 19:08 - 2013-08-26 19:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-26 18:51 - 2013-08-26 18:51 - 00000000 ____D C:\Windows\ERUNT
2013-08-26 18:49 - 2013-08-26 18:49 - 01021434 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-08-26 18:42 - 2013-08-26 18:41 - 00994642 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-08-26 18:34 - 2013-08-26 17:21 - 00000000 ____D C:\ComboFix
2013-08-26 18:34 - 2013-08-26 15:37 - 00000000 ____D C:\Qoobox
2013-08-26 18:32 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-26 18:31 - 2013-08-26 18:31 - 00040860 _____ C:\ComboFix.txt
2013-08-26 18:18 - 2013-08-26 15:37 - 00000000 ____D C:\Windows\erdnt
2013-08-26 17:45 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-26 15:36 - 2013-08-26 13:39 - 00000000 ____D C:\Windows\67E1227ED5534A6A96CD40CCBBC705D8.TMP
2013-08-26 15:34 - 2013-08-26 15:34 - 05113393 ____R (Swearware) C:\Users\user\Downloads\ComboFix.exe
2013-08-26 15:30 - 2013-08-26 15:30 - 00000000 ____D C:\FRST
2013-08-26 15:26 - 2013-08-26 15:26 - 01577068 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-08-26 15:21 - 2013-08-26 15:21 - 00001088 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2013-08-26 15:21 - 2013-08-26 15:21 - 00000000 ____D C:\Users\user\AppData\Local\VS Revo Group
2013-08-26 15:21 - 2013-08-26 15:21 - 00000000 ____D C:\ProgramData\VS Revo Group
2013-08-26 15:21 - 2013-08-26 15:21 - 00000000 ____D C:\Program Files\VS Revo Group
2013-08-26 15:19 - 2013-08-26 15:19 - 10031224 _____ (VS Revo Group ) C:\Users\user\Downloads\RevoUninProSetup.exe
2013-08-26 15:14 - 2013-08-26 15:14 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer (2).exe
2013-08-26 15:14 - 2013-08-26 15:14 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer (1).exe
2013-08-26 13:43 - 2012-06-18 14:11 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-08-26 13:40 - 2013-08-26 13:40 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-26 13:40 - 2013-08-26 13:40 - 00000000 _____ C:\autoexec.bat
2013-08-26 13:37 - 2013-08-26 13:37 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer.exe
2013-08-18 20:22 - 2012-11-23 16:17 - 00001424 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-08-17 12:51 - 2011-12-08 22:43 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-17 12:51 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\winrm
2013-08-17 12:51 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\sysprep
2013-08-17 12:51 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2013-08-17 12:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-08-17 12:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-08-17 12:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-17 12:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-08-17 12:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2013-08-17 12:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-08-17 12:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-17 12:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2013-08-17 12:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2013-08-17 12:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-08-17 12:51 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-08-17 12:50 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\WCN
2013-08-17 12:50 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2013-08-17 12:50 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\winrm
2013-08-17 12:50 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\WCN
2013-08-17 12:50 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\slmgr
2013-08-17 12:50 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2013-08-17 12:50 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\oobe
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\MUI
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\migwiz
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Dism
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\com
2013-08-17 12:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\IME
2013-08-17 10:55 - 2013-08-17 10:55 - 00002270 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-17 10:55 - 2012-11-25 17:32 - 00000000 ____D C:\Users\user\AppData\Local\Google
2013-08-17 09:58 - 2013-08-17 09:58 - 00985600 _____ C:\Users\user\Downloads\MicrosoftFixit50123.msi
2013-08-17 09:57 - 2012-12-07 22:01 - 00000000 ____D C:\Users\user\AppData\Roaming\Spotify
2013-08-17 09:55 - 2013-08-17 09:55 - 00000134 _____ C:\Users\user\Desktop\Internet Explorer-Problembehebung.url
2013-08-17 09:55 - 2013-08-14 00:00 - 00015109 _____ C:\Windows\IE10_main.log
2013-08-15 18:41 - 2012-12-17 15:42 - 00000000 ____D C:\Program Files (x86)\MediaMonkey
2013-08-15 18:38 - 2013-08-15 17:07 - 00000000 ____D C:\Program Files (x86)\Free mp3 Wma Converter
2013-08-15 17:32 - 2012-12-17 15:42 - 00000000 ____D C:\Users\user\AppData\Roaming\MediaMonkey
2013-08-15 17:31 - 2013-08-15 17:25 - 00000000 ____D C:\Users\user\Desktop\Neuer Ordner (2)
2013-08-15 17:24 - 2013-08-15 17:24 - 00001449 _____ C:\Users\Public\Desktop\Free Audio Converter.lnk
2013-08-15 17:24 - 2013-08-15 17:24 - 00000000 ____D C:\Users\user\AppData\Roaming\DVDVideoSoft
2013-08-15 17:24 - 2013-08-15 17:24 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-08-15 17:23 - 2013-08-15 17:19 - 00000000 ____D C:\Users\user\Desktop\Settle (Deluxe Version)
2013-08-15 17:07 - 2013-08-15 17:07 - 00000000 ____D C:\Users\user\AppData\Roaming\FreeAudioPack
2013-08-15 17:06 - 2013-08-15 17:06 - 00458744 _____ (Bandoo Media Inc) C:\Users\user\Downloads\Setup21_FreeConverter.exe
2013-08-15 14:10 - 2012-12-07 22:02 - 00000000 ____D C:\Users\user\AppData\Local\Spotify
2013-08-14 15:04 - 2012-11-23 16:17 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-14 15:04 - 2012-11-23 16:17 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-14 15:01 - 2009-07-14 06:45 - 00440808 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-14 14:51 - 2013-02-21 20:18 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-14 14:48 - 2012-12-11 21:39 - 01498666 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-08-14 14:46 - 2013-08-14 14:42 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 14:42 - 2012-12-07 20:15 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 14:28 - 2013-08-14 13:50 - 00620128 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-08-14 14:28 - 2013-08-14 13:50 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2013-08-14 14:28 - 2012-10-18 14:50 - 00054368 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kltdi.sys
2013-08-14 14:28 - 2012-08-13 16:49 - 00178448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2013-08-14 14:00 - 2013-08-14 14:00 - 00002231 _____ C:\Users\user\Desktop\Sicherer Zahlungsverkehr.lnk
2013-08-14 13:52 - 2013-08-14 13:52 - 00001089 _____ C:\Users\Public\Desktop\Kaspersky PURE 3.0.lnk
2013-08-14 13:51 - 2013-08-14 13:51 - 00000000 ____D C:\Windows\ELAMBKUP
2013-08-14 13:50 - 2013-08-14 13:50 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2013-08-14 01:49 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-14 01:29 - 2012-11-23 16:18 - 00000000 ____D C:\Users\user\AppData\Roaming\LSC
2013-08-14 00:21 - 2013-08-14 00:21 - 00002002 _____ C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2013-08-14 00:21 - 2012-09-12 08:40 - 00000000 ____D C:\ldiag
2013-08-14 00:21 - 2012-06-18 14:24 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2013-08-14 00:21 - 2012-06-18 14:13 - 00000000 ____D C:\Program Files\Lenovo
2013-08-14 00:19 - 2012-06-18 14:24 - 00000000 ____D C:\Windows\Downloaded Installations
2013-08-14 00:12 - 2013-08-13 23:54 - 188740896 _____ (Kaspersky Lab) C:\Users\user\Downloads\pure13.0.2.558DE_4340.exe
2013-08-13 23:59 - 2012-06-18 23:53 - 00717052 _____ C:\Windows\system32\perfh007.dat
2013-08-13 23:59 - 2012-06-18 23:53 - 00007972 _____ C:\Windows\system32\perfc007.dat
2013-08-13 23:39 - 2013-08-13 23:39 - 00000000 _____ C:\Windows\setuperr.log
2013-08-13 23:39 - 2013-08-11 12:18 - 00000000 ____D C:\Program Files\Common Files\McAfee
2013-08-13 23:18 - 2013-04-08 22:56 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-13 23:18 - 2013-04-08 22:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-08-13 23:03 - 2013-08-11 12:17 - 00000000 ____D C:\ProgramData\McAfee
2013-08-13 23:02 - 2013-08-11 12:17 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-08-13 22:52 - 2013-08-13 22:32 - 00000000 ____D C:\Users\user\AppData\Local\WEKA DVD Interface
2013-08-13 22:47 - 2013-08-13 22:42 - 70300856 _____ (WinFuture) C:\Users\user\Downloads\WinFuture_7_x64_UpdatePack_1.36_April_2013-Upgrade.exe
2013-08-13 22:40 - 2013-08-13 22:40 - 00347424 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.wu.FISC.196299856852161036.1.3.Run.exe
2013-08-13 22:36 - 2013-08-13 22:36 - 00347424 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.WinFileFolder.FISC.196299856852161036.1.2.Run.exe
2013-08-13 22:35 - 2013-08-13 22:35 - 00347424 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.malware.FISC.196299856852161036.1.1.Run.exe
2013-08-12 22:59 - 2013-08-12 22:24 - 00000000 ____D C:\Users\user\Downloads\Kaspersky Rescue2Usb
2013-08-12 22:23 - 2013-08-12 22:13 - 261507072 _____ C:\Users\user\Desktop\kav_rescue_10-31.iso
2013-08-12 22:12 - 2013-08-12 22:12 - 00387584 _____ C:\Users\user\Downloads\rescue2usb.exe
2013-08-12 21:32 - 2013-08-12 21:20 - 00000000 ____D C:\Users\user\Desktop\Neuer Ordner
2013-08-12 21:15 - 2013-08-12 20:34 - 00000112 ___RH C:\Users\user\Downloads\Stinger.opt
2013-08-12 21:10 - 2013-02-11 20:21 - 00000000 ____D C:\Users\user\Desktop\Programme
2013-08-12 20:56 - 2013-08-12 20:35 - 00000624 _____ C:\Users\user\Downloads\Stinger_12082013_203502.html
2013-08-12 20:49 - 2013-08-12 20:34 - 00000000 ____D C:\Program Files\stinger
2013-08-12 20:47 - 2013-08-12 20:46 - 00000000 ____D C:\Users\user\AppData\Roaming\U3
2013-08-12 20:40 - 2013-08-12 20:40 - 03395840 _____ (Piriform Ltd) C:\Users\user\Downloads\ccsetup404_slim.exe
2013-08-12 20:34 - 2013-08-12 20:34 - 12725280 _____ (McAfee Inc) C:\Users\user\Downloads\stinger64_12.0.0.483.exe
2013-08-12 20:11 - 2013-08-12 20:11 - 02828552 _____ (AVAST Software) C:\Users\user\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-08-11 22:18 - 2013-08-11 22:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\PwrMgr
2013-08-11 21:49 - 2013-08-11 21:49 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Softland
2013-08-11 21:48 - 2012-11-23 16:18 - 00123208 _____ C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-11 21:47 - 2013-08-11 21:47 - 00123208 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\McAfee
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Lenovo
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Leadertech
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Apple Computer
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 ____D C:\Users\Administrator\AppData\Local\Lenovo
2013-08-11 21:47 - 2013-08-11 21:47 - 00000000 _____ C:\Users\Administrator\agent.log
2013-08-11 21:47 - 2013-08-11 21:46 - 00000000 ____D C:\Users\Administrator
2013-08-11 21:46 - 2013-08-11 21:46 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Vorlagen
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Startmenü
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten
2013-08-11 21:46 - 2013-08-11 21:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Intel
2013-08-11 20:21 - 2013-08-11 20:21 - 00000017 _____ C:\Users\user\AppData\Local\resmon.resmoncfg
2013-08-11 18:08 - 2012-11-22 10:03 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-11 17:41 - 2013-08-11 17:41 - 00000000 _____ C:\Users\user\AppData\Roaming\AbsoluteReminder.xml
2013-08-11 17:40 - 2013-08-11 17:40 - 00007140 _____ C:\Users\user\Documents\cc_20130811_174011.reg
2013-08-11 16:51 - 2013-08-11 16:51 - 21728904 _____ (Microsoft Corporation) C:\Users\user\Downloads\Windows-KB890830-x64-V5.2.exe
2013-08-11 16:21 - 2013-08-11 16:21 - 00003418 _____ C:\Windows\System32\Tasks\{B25F1987-1535-4B53-9232-FF697284ADCB}
2013-08-11 16:11 - 2013-08-11 16:11 - 05990376 _____ (IObit ) C:\Users\user\Downloads\defragsetup_2811221.exe
2013-08-11 16:05 - 2013-08-11 16:05 - 04100432 _____ (Piriform Ltd) C:\Users\user\Downloads\dfsetup215 (1).exe
2013-08-11 16:04 - 2013-08-11 16:03 - 03368056 _____ (hxxp://www.maxuninstaller.com/ ) C:\Users\user\Downloads\MaxUninstaller_Setup.exe
2013-08-11 15:48 - 2013-08-11 15:48 - 04100432 _____ (Piriform Ltd) C:\Users\user\Downloads\dfsetup215.exe
2013-08-11 15:45 - 2013-08-11 15:43 - 04100432 _____ (Piriform Ltd) C:\Users\user\Downloads\dfsetup_2.15.741.exe
2013-08-11 12:29 - 2013-08-11 12:29 - 00003704 _____ C:\Windows\System32\Tasks\Java Update Scheduler
2013-08-11 12:29 - 2013-08-11 12:29 - 00003694 _____ C:\Windows\System32\Tasks\Adobe online update program
2013-08-11 12:29 - 2013-06-12 21:33 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2013-08-11 12:19 - 2013-08-11 12:19 - 00000000 ____D C:\Users\user\AppData\Roaming\McAfee
2013-08-11 12:18 - 2013-08-11 12:19 - 00099056 _____ (McAfee, Inc.) C:\Windows\system32\MfeOtlkAddin.dll
2013-08-11 12:18 - 2013-08-11 12:19 - 00074848 _____ (McAfee, Inc.) C:\Windows\SysWOW64\MfeOtlkAddin.dll
2013-08-11 12:18 - 2013-08-11 12:19 - 00022816 _____ (McAfee, Inc.) C:\Windows\SysWOW64\MFEOtlk.dll
2013-08-11 11:55 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2013-08-11 10:43 - 2012-11-25 18:42 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-08-11 10:42 - 2013-08-11 10:42 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-08-11 10:42 - 2013-08-11 10:42 - 00000000 ____D C:\Users\user\Desktop\Tune Up Utilities 2012
2013-08-09 12:35 - 2013-08-09 12:34 - 11348656 _____ (Lenovo ) C:\Users\user\Downloads\systemupdate502-06-26-2013.exe
2013-08-09 12:32 - 2013-05-05 22:46 - 00000000 ____D C:\Users\user\AppData\Roaming\Audacity
2013-08-08 22:59 - 2013-08-08 22:59 - 00069456 _____ C:\Users\user\Documents\cc_20130808_225910.reg
2013-08-08 22:56 - 2013-06-27 21:44 - 00000000 ____D C:\Users\user\AppData\Roaming\DAEMON Tools Lite
2013-08-08 22:56 - 2012-11-25 18:41 - 00000000 ____D C:\Users\user\AppData\Roaming\DAEMON Tools Pro
2013-08-08 22:44 - 2012-06-18 14:34 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-08 18:42 - 2013-08-08 18:41 - 03482040 _____ C:\Users\user\Downloads\avg_remover_2013_3341.zip
2013-08-08 12:51 - 2012-12-10 12:58 - 00000000 ____D C:\Users\user\Desktop\Spiele
2013-08-08 12:50 - 2013-02-11 20:17 - 00000000 ____D C:\Users\user\Desktop\UT Psychologie
2013-08-08 12:12 - 2013-08-08 12:12 - 00262144 _____ C:\Windows\system32\config\elam
2013-08-08 11:57 - 2012-11-25 18:41 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-08-08 11:26 - 2012-06-18 14:40 - 00000000 ____D C:\ProgramData\Norton
2013-08-08 11:25 - 2013-08-08 11:25 - 00866592 _____ C:\Users\user\Downloads\Norton_Removal_Tool.exe
2013-08-08 10:56 - 2013-03-02 17:13 - 00000000 ____D C:\Users\user\Desktop\Congstar
2013-08-08 01:17 - 2013-02-19 22:02 - 00000000 ____D C:\Users\user\AppData\Roaming\dvdcss
2013-08-07 04:22 - 2010-11-21 05:27 - 00278800 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-08-04 19:04 - 2013-08-04 19:01 - 189379192 _____ (Kaspersky Lab) C:\Users\user\Downloads\kis13.0.1.4190abcdefgDE_4608.exe
Files to move or delete:
====================
C:\Users\user\AppData\Local\Temp\Quarantine.exe
C:\Users\user\AppData\Local\Temp\RarSFX1\SecurityCheck\Objlist.exe
C:\Users\user\AppData\Local\Temp\RarSFX1\SecurityCheck\runprocesses.exe
C:\Users\user\AppData\Local\Temp\RarSFX1\SecurityCheck\uninstalllist.exe
C:\Users\user\AppData\Local\Temp\RarSFX1\SecurityCheck\Other\cmdinfo.exe
C:\Users\user\AppData\Local\Temp\RarSFX1\SecurityCheck\Other\nircmdc.exe
C:\Users\user\AppData\Local\Temp\RarSFX1\SecurityCheck\Other\sed.exe
C:\Users\user\AppData\Local\Temp\RarSFX1\SecurityCheck\Other\swreg.exe
C:\Users\user\AppData\Local\Temp\RarSFX0\SecurityCheck\Objlist.exe
C:\Users\user\AppData\Local\Temp\RarSFX0\SecurityCheck\runprocesses.exe
C:\Users\user\AppData\Local\Temp\RarSFX0\SecurityCheck\uninstalllist.exe
C:\Users\user\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\cmdinfo.exe
C:\Users\user\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\nircmdc.exe
C:\Users\user\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\sed.exe
C:\Users\user\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\swreg.exe
C:\Users\user\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-27 09:39
==================== End Of Log ============================
--- --- ---