| Paraglider58 |  10.09.2013 14:57 |        Hier die Logfiles:  
Malwarebytes:   Code:  
 Malwarebytes Anti-Malware (Test) 1.75.0.1300 
www.malwarebytes.org   
Datenbank Version: v2013.09.10.07   
Windows 7 Service Pack 1 x86 NTFS 
Internet Explorer 10.0.9200.16660 
PC 1 :: PC1-PC [Administrator]   
Schutz: Aktiviert   
10.09.2013 15:20:49 
mbam-log-2013-09-10 (15-20-49).txt   
Art des Suchlaufs: Quick-Scan 
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM 
Deaktivierte Suchlaufeinstellungen: P2P 
Durchsuchte Objekte: 268356 
Laufzeit: 5 Minute(n), 45 Sekunde(n)   
Infizierte Speicherprozesse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Speichermodule: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungsschlüssel: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungswerte: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateiobjekte der Registrierung: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Verzeichnisse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateien: 0 
(Keine bösartigen Objekte gefunden)   
(Ende)   AdwCleaner: 
AdwCleaner Logfile:   Code:  
 # AdwCleaner v3.003 - Bericht erstellt am 09/09/2013 um 15:42:10 
# Updated 07/09/2013 von Xplode 
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) 
# Benutzername : PC 1 - PC1-PC 
# Gestartet von : D:\Downloads\Büro\Antiviruspgms\adwcleaner.exe 
# Option : Löschen   
***** [ Dienste ] *****     
***** [ Dateien / Ordner ] *****   
Ordner Gelöscht : C:\Program Files\driver-soft 
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\Common\LuaRT 
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\DataMgr 
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\fbDownloader 
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\Intermediate 
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\SCheck 
Ordner Gelöscht : C:\Users\PC 1\AppData\Roaming\SSync 
Datei Gelöscht : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\om@offermosquito.com.xpi 
Datei Gelöscht : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\searchplugins\search.xml   
***** [ Verknüpfungen ] *****     
***** [ Registrierungsdatenbank ] *****   
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DataMgr] 
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Intermediate] 
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [scheck] 
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ssync] 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_barcode-forge_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_barcode-forge_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_blender_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_blender_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fwsim_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fwsim_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gamespy-arcade_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gamespy-arcade_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} 
Schlüssel Gelöscht : HKCU\Software\Softonic   
***** [ Browser ] *****   
-\\ Internet Explorer v10.0.9200.16660     
-\\ Mozilla Firefox v23.0.1 (de)   
[ Datei : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\prefs.js ]   
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://searchqm.com/search.php?channel=msus200fbdgy6&q="); 
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://searchqm.com/?channel=msus200fbdgy6"); 
Zeile gelöscht : user_pref("keyword.URL", "hxxp://searchqm.com/search.php?channel=msus200fbdgy6&q="); 
Zeile gelöscht : user_pref("om.config", "{\"active\":true,\"name\":\"sfprt\",\"id\":9,\"dispId\":\"CH-9\",\"aboutLink\":\"\",\"trackingGeneral\":true,\"gaAccount\":\"UA-39484183-1\",\"gaDomain\":\"offermosquito.com\",[...]   
*************************   
AdwCleaner[R0].txt - [4004 octets] - [09/09/2013 15:40:34] 
AdwCleaner[S0].txt - [3939 octets] - [09/09/2013 15:42:10]   
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3999 octets] ##########   --- --- --- 
AdwCleaner Logfile:   Code:  
 # AdwCleaner v3.003 - Bericht erstellt am 10/09/2013 um 15:37:25 
# Updated 07/09/2013 von Xplode 
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) 
# Benutzername : PC 1 - PC1-PC 
# Gestartet von : C:\Users\PC 1\Desktop\adwcleaner.exe 
# Option : Löschen   
***** [ Dienste ] *****     
***** [ Dateien / Ordner ] *****   
Datei Gelöscht : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\om@offermosquito.com.xpi   
***** [ Verknüpfungen ] *****     
***** [ Registrierungsdatenbank ] *****     
***** [ Browser ] *****   
-\\ Internet Explorer v10.0.9200.16660     
-\\ Mozilla Firefox v23.0.1 (de)   
[ Datei : C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\prefs.js ]   
Zeile gelöscht : user_pref("om.config", "{\"active\":true,\"name\":\"sfprt\",\"id\":9,\"dispId\":\"CH-9\",\"aboutLink\":\"\",\"trackingGeneral\":true,\"gaAccount\":\"UA-39484183-1\",\"gaDomain\":\"offermosquito.com\",[...]   
*************************   
AdwCleaner[R0].txt - [5211 octets] - [09/09/2013 15:40:34] 
AdwCleaner[S0].txt - [5147 octets] - [09/09/2013 15:42:10]   
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5207 octets] ##########   --- --- ---   
JRT:   Code:  
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Junkware Removal Tool (JRT) by Thisisu 
Version: 5.5.9 (09.07.2013:1) 
OS: Windows 7 Home Premium x86 
Ran by PC 1 on 10.09.2013 at 15:42:18,66 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~         
~~~ Services       
~~~ Registry Values       
~~~ Registry Keys   
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp       
~~~ Files       
~~~ Folders   
Successfully deleted: [Folder] "C:\Users\PC 1\appdata\local\adawarebp"       
~~~ FireFox   
Emptied folder: C:\Users\PC 1\AppData\Roaming\mozilla\firefox\profiles\17thmgg3.default\minidumps [46 files]       
~~~ Event Viewer Logs were cleared           
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Scan was completed on 10.09.2013 at 15:45:41,79 
End of JRT log 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~   FRST:   
FRST Logfile:  
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 01 
Ran by PC 1 (administrator) on PC1-PC on 10-09-2013 15:46:43 
Running from C:\Users\PC 1\Desktop 
Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: German Standard 
Internet Explorer Version 10 
Boot Mode: Normal   
==================== Processes (Whitelisted) ===================   
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe 
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe 
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe 
() C:\Program Files\GNU\GnuPG\dirmngr.exe 
(Google Inc.) C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe 
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe 
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe 
() C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe 
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE 
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe 
(Microsoft Corporation) C:\Windows\system32\UI0Detect.exe 
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe 
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe 
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\itype.exe 
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\ipoint.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 
() C:\Program Files\Smart PDF Converter Pro\SmartSoft PDF Printer Agent.exe 
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe 
() C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe 
(Bartels Media GmbH) D:\Program Files\PhraseExpress\phraseexpress.exe 
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE   
==================== Registry (Whitelisted) ==================   
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor) 
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) 
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) 
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [153672 2010-06-14] (Logitech Inc.) 
HKLM\...\Run: [IntelliType Pro] - C:\Program Files\Microsoft Device Center\itype.exe [1109072 2012-06-26] (Microsoft Corporation) 
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft Device Center\ipoint.exe [1629280 2012-06-26] (Microsoft Corporation) 
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG) 
HKLM\...\Run: [SmartSoft PDF Printer Agent] - C:\Program Files\Smart PDF Converter Pro\SmartSoft PDF Printer Agent.exe [52952 2011-12-12] () 
HKLM\...\Run: [LifeCam] - C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) 
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) 
HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation) 
HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft) 
HKLM\...\Run: [HOSTS Anti-Adware_PUPs] - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961 2013-09-09] () 
HKLM\...\Policies\Explorer: [NoDrives] 0 
HKCU\...\Run: [Snoozer] - C:\Users\PC 1\AppData\Roaming\Snz\Snz.exe [1137683 2013-07-23] () 
HKCU\...\Policies\Explorer: [NoDrives] 0 
Lsa: [Authentication Packages] msv1_0 relog_ap 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk 
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass) 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk 
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass) 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PhraseExpress.lnk 
ShortcutTarget: PhraseExpress.lnk -> D:\Program Files\PhraseExpress\phraseexpress.exe (Bartels Media GmbH) 
Startup: C:\Users\PC 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk 
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)   
==================== Internet (Whitelisted) ====================   
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch 
SearchScopes: HKLM - DefaultScope value is missing. 
SearchScopes: HKLM - {40E1CB6C-A17F-496D-B213-873DC0467429} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS 
SearchScopes: HKCU - {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-flv 
BHO: LastPass Vault - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files\LastPass\LPToolbar.dll (LastPass) 
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) 
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll (LastPass) 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) 
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 33 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1   
FireFox: 
======== 
FF ProfilePath: C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default 
FF DefaultSearchEngine: Search 
FF Homepage: http://www.trojaner-board.de/141283-...ml#post1151816 
FF NetworkProxy: "ftp", "62.162.6.11" 
FF NetworkProxy: "ftp_port", 3128 
FF NetworkProxy: "http", "62.162.6.11" 
FF NetworkProxy: "http_port", 3128 
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" 
FF NetworkProxy: "share_proxy_settings", true 
FF NetworkProxy: "socks", "62.162.6.11" 
FF NetworkProxy: "socks_port", 3128 
FF NetworkProxy: "ssl", "62.162.6.11" 
FF NetworkProxy: "ssl_port", 3128 
FF NetworkProxy: "type", 0 
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () 
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) 
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) 
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) 
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) 
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) 
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) 
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) 
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) 
FF Plugin: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) 
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) 
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin: @videolan.org/vlc,version=2.0.4 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) 
FF Plugin: @videolan.org/vlc,version=2.0.8 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) 
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\adawaretb.xml 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml 
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\fb_add_on@avm.de 
FF Extension: LastPass - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\support@lastpass.com 
FF Extension: DownloadHelper - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} 
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} 
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\7a05ead03bbae1ec9295bcf8836b8a28270676558747f31d563e66739e36a29b_lp.key 
FF Extension: elemhidehelper - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\elemhidehelper@adblockplus.org.xpi 
FF Extension: firefox - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\firefox@ghostery.com.xpi 
FF Extension: firejump - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\firejump@firejump.net.xpi 
FF Extension: stealthyextension - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\stealthyextension@gmail.com.xpi 
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi 
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi 
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi 
FF Extension: No Name - C:\Users\PC 1\AppData\Roaming\Mozilla\Firefox\Profiles\17thmgg3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi   
========================== Services (Whitelisted) =================   
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [427288 2007-12-03] (Acronis) 
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-04] (Avira Operations GmbH & Co. KG) 
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG) 
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG) 
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG) 
R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [218112 2013-05-28] () 
S2 HOSTS Anti-PUPs; C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2013-09-09] () 
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) 
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) 
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14573856 2013-08-27] (NVIDIA Corporation) 
S3 Samsung UPD Service; C:\Windows\System32\SUPDSvc.exe [131888 2010-08-09] (Samsung Electronics CO., LTD.) 
R2 TryAndDecideService; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [498792 2007-12-03] ()   
==================== Drivers (Whitelisted) ====================   
R2 ACEDRV05; C:\Windows\system32\drivers\ACEDRV05.sys [97792 2013-01-26] (Protect Software GmbH) 
R0 amd_sata; C:\Windows\System32\drivers\amd_sata.sys [70784 2011-12-12] (Advanced Micro Devices) 
R0 amd_xata; C:\Windows\System32\drivers\amd_xata.sys [34944 2011-12-12] (Advanced Micro Devices) 
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG) 
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-04] (Avira Operations GmbH & Co. KG) 
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-25] (Avira Operations GmbH & Co. KG) 
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2013-08-24] (AVM Berlin) 
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) 
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-08-16] (GFI Software) 
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [91248 2012-03-02] (Qualcomm Atheros Co., Ltd.) 
S3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [30360 2011-09-02] (Logitech, Inc.) 
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) 
S3 NvStUSB; C:\Windows\system32\drivers\nvstusb.sys [429800 2012-08-30] (NVIDIA Corporation) 
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [33568 2013-08-20] (NVIDIA Corporation) 
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-10-09] (Avira GmbH) 
R0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [368480 2012-09-24] (Acronis) 
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2012-09-24] (Acronis) 
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.) 
R3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.) 
R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.) 
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.) 
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) 
S3 catchme; \??\C:\Users\PC1~1\AppData\Local\Temp\catchme.sys [x] 
S1 HWiNFO32; \??\C:\Program Files\Driver-Soft\DriverGenius\HWiNFO32.SYS [x]   
==================== NetSvcs (Whitelisted) ===================     
==================== One Month Created Files and Folders ========   
2013-09-10 15:38 - 2013-09-10 15:38 - 00000022 _____ C:\Windows\S.dirmngr 
2013-09-10 15:30 - 2013-09-10 15:30 - 01029490 _____ (Thisisu) C:\Users\PC 1\Desktop\JRT.exe 
2013-09-10 15:29 - 2013-09-10 15:29 - 01037278 _____ C:\Users\PC 1\Desktop\adwcleaner.exe 
2013-09-10 14:13 - 2013-09-10 14:13 - 96922344 _____ C:\Windows\system32\ꮯˀ바_ 
2013-09-10 13:20 - 2013-09-10 13:20 - 00020668 _____ C:\ComboFix.txt 
2013-09-10 12:59 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 
2013-09-10 12:59 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 
2013-09-10 12:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 
2013-09-10 12:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 
2013-09-10 12:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 
2013-09-10 12:59 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 
2013-09-10 12:59 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 
2013-09-10 12:59 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 
2013-09-10 12:58 - 2013-09-10 13:20 - 00000000 ____D C:\Qoobox 
2013-09-10 12:58 - 2013-09-10 13:14 - 00000000 ____D C:\Windows\erdnt 
2013-09-10 12:57 - 2013-09-10 12:57 - 05125565 ____R (Swearware) C:\Users\PC 1\Desktop\ComboFix.exe 
2013-09-10 11:37 - 2013-09-10 11:37 - 00023245 _____ C:\Users\PC 1\Desktop\Addition.txt 
2013-09-10 11:36 - 2013-09-10 11:36 - 00000000 ____D C:\FRST 
2013-09-10 11:35 - 2013-09-10 11:35 - 01082349 _____ (Farbar) C:\Users\PC 1\Desktop\FRST.exe 
2013-09-09 18:16 - 2013-09-09 18:16 - 96732368 _____ C:\Windows\system32\鳜�바o 
2013-09-09 17:28 - 2013-09-10 15:14 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\PC 1\Desktop\mbam-setup-1.75.0.1300.exe 
2013-09-09 17:17 - 2013-09-09 17:17 - 00000747 _____ C:\Users\Public\Desktop\VLC media player.lnk 
2013-09-09 17:02 - 2013-09-09 17:03 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Foxit Software 
2013-09-09 17:02 - 2013-09-09 17:02 - 00002018 _____ C:\Users\Public\Desktop\Foxit Reader.lnk 
2013-09-09 17:02 - 2013-09-09 17:02 - 00000000 ____D C:\Program Files\Foxit Software 
2013-09-09 17:02 - 2013-06-09 21:59 - 00216064 _____ C:\Windows\system32\gcapi_dll.dll 
2013-09-09 16:25 - 2013-09-09 16:25 - 00000000 ____D C:\Program Files\ESET 
2013-09-09 16:21 - 2013-09-10 13:22 - 00001140 _____ C:\Windows\PFRO.log 
2013-09-09 16:10 - 2013-09-10 15:15 - 00001077 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
2013-09-09 16:10 - 2013-09-10 15:15 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Malwarebytes 
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\ProgramData\Malwarebytes 
2013-09-09 16:10 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 
2013-09-09 16:03 - 2013-09-09 16:03 - 00000000 ____D C:\Windows\ERUNT 
2013-09-09 15:58 - 2013-09-09 15:58 - 00001149 _____ C:\Users\PC 1\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk 
2013-09-09 15:58 - 2013-09-09 15:58 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs 
2013-09-09 15:44 - 2013-09-10 15:39 - 00000840 _____ C:\Windows\setupact.log 
2013-09-09 15:44 - 2013-09-09 15:44 - 00000000 _____ C:\Windows\setuperr.log 
2013-09-09 15:40 - 2013-09-10 15:37 - 00000000 ____D C:\AdwCleaner 
2013-09-09 15:34 - 2013-09-09 15:34 - 00000975 _____ C:\Users\Public\Desktop\CCleaner.lnk 
2013-09-09 13:33 - 2013-09-09 13:34 - 11634176 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe 
2013-09-09 13:33 - 2013-09-09 13:33 - 06484992 _____ C:\Program Files\LPPlugin.dll 
2013-09-09 13:33 - 2013-09-09 13:33 - 01068544 _____ (LastPass) C:\Program Files\LPIEHome.ocx 
2013-09-09 13:33 - 2013-09-09 13:33 - 00612864 _____ (LastPass) C:\Program Files\LPToolbar.dll 
2013-09-09 13:33 - 2013-09-09 13:33 - 00180736 _____ C:\Program Files\WinBioStandalone.exe 
2013-09-09 13:33 - 2013-09-09 13:33 - 00058282 _____ C:\Program Files\iehome2.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00023666 _____ C:\Program Files\iehome.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00006582 _____ C:\Program Files\vaultcommonc.js 
2013-09-09 13:33 - 2013-09-09 13:33 - 00006260 _____ C:\Program Files\menu.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00002972 _____ C:\Program Files\json2c.js 
2013-09-09 13:33 - 2013-09-09 13:33 - 00001174 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000716 _____ C:\Program Files\context.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000223 _____ C:\Program Files\img.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000081 _____ C:\Program Files\programfiles.txt 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deleteprogramfiles.txt 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deletelocallowlastpass.txt 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\lang 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\images 
2013-09-09 13:32 - 2013-09-09 13:34 - 00000000 ____D C:\Program Files\LastPass 
2013-09-06 14:24 - 2013-09-06 14:24 - 96334488 _____ C:\Windows\system32\覑�바_ 
2013-09-05 15:39 - 2013-09-05 15:39 - 00000000 ____D C:\Program Files\BrainWave Generator 
2013-09-05 14:44 - 2013-09-05 14:44 - 00001294 _____ C:\Users\Public\Desktop\Paint.NET.lnk 
2013-09-04 15:38 - 2013-09-04 15:38 - 00002133 _____ C:\Users\Public\Desktop\PC-Kaufmann Komplettpaket Pro 2014.lnk 
2013-09-02 15:49 - 2013-09-02 15:49 - 00001159 _____ C:\Users\PC 1\Desktop\Bwgen.lnk 
2013-09-02 15:32 - 1997-11-19 15:49 - 00303616 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe 
2013-08-30 08:32 - 2013-08-20 15:33 - 00033568 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys 
2013-08-24 07:54 - 2013-08-24 07:54 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys 
2013-08-18 12:01 - 2013-08-18 12:01 - 00000000 ____D C:\Users\PC 1\Desktop\Komunikation 
2013-08-18 12:00 - 2013-08-18 12:04 - 00000000 ____D C:\Users\PC 1\Desktop\Film und Ton 
2013-08-18 11:57 - 2013-08-18 12:32 - 00000000 ____D C:\Users\PC 1\Desktop\Systemprogramme 
2013-08-18 11:42 - 2013-08-18 12:39 - 00000000 ____D C:\ProgramData\SecTaskMan 
2013-08-18 11:42 - 2013-08-18 11:50 - 00000000 ____D C:\Program Files\Security Task Manager 
2013-08-18 11:07 - 2013-08-18 11:08 - 00000000 ____D C:\Program Files\Sysinternals 
2013-08-17 11:02 - 2013-08-17 11:02 - 00000000 ____D C:\Program Files\Mozilla Firefox 
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\LavasoftStatistics 
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\ProgramData\Ad-Aware Antivirus 
2013-08-16 14:23 - 2013-08-16 14:32 - 00000000 ____D C:\Program Files\Ad-Aware Antivirus 
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Lavasoft 
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Downloaded Installations 
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 
2013-08-16 14:22 - 2013-08-16 14:33 - 00000000 ____D C:\Program Files\Lavasoft 
2013-08-16 14:21 - 2013-08-16 14:31 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Ad-Aware Antivirus 
2013-08-16 14:21 - 2013-08-16 14:21 - 00044424 _____ (GFI Software) C:\Windows\system32\sbbd.exe 
2013-08-16 14:21 - 2013-08-16 14:21 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 
2013-08-14 06:47 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 
2013-08-14 06:47 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 
2013-08-14 06:47 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 
2013-08-14 06:47 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 
2013-08-14 06:47 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 
2013-08-14 06:47 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 
2013-08-14 06:47 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 
2013-08-14 06:47 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 
2013-08-14 06:47 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 
2013-08-14 06:33 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 
2013-08-14 06:33 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 
2013-08-14 06:33 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 
2013-08-14 06:33 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 
2013-08-14 06:33 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 
2013-08-14 06:33 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 
2013-08-14 06:33 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 
2013-08-14 06:33 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 
2013-08-14 06:33 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 
2013-08-14 06:33 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 
2013-08-14 06:33 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 
2013-08-14 06:33 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 
2013-08-11 07:57 - 2013-08-11 07:58 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Axialis 
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\NewFreeScreensavers 
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\Common Files\NewFreeScreensavers 
2013-08-11 07:57 - 2011-05-11 16:56 - 11046329 _____ (Axialis Software) C:\Windows\system32\nfsFireworks2.scr   
==================== One Month Modified Files and Folders =======   
2013-09-10 15:46 - 2009-07-14 06:34 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
2013-09-10 15:46 - 2009-07-14 06:34 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
2013-09-10 15:45 - 2013-09-10 15:45 - 00000926 _____ C:\Users\PC 1\Desktop\JRT.txt 
2013-09-10 15:45 - 2010-11-20 23:01 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 
2013-09-10 15:44 - 2013-02-28 11:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 
2013-09-10 15:43 - 2013-03-27 11:56 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 
2013-09-10 15:39 - 2013-09-09 15:44 - 00000840 _____ C:\Windows\setupact.log 
2013-09-10 15:38 - 2013-09-10 15:38 - 00000022 _____ C:\Windows\S.dirmngr 
2013-09-10 15:38 - 2013-08-10 09:16 - 01804100 _____ C:\Windows\WindowsUpdate.log 
2013-09-10 15:38 - 2013-03-27 11:56 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 
2013-09-10 15:38 - 2012-09-19 10:10 - 00000000 ____D C:\ProgramData\NVIDIA 
2013-09-10 15:38 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 
2013-09-10 15:37 - 2013-09-09 15:40 - 00000000 ____D C:\AdwCleaner 
2013-09-10 15:30 - 2013-09-10 15:30 - 01029490 _____ (Thisisu) C:\Users\PC 1\Desktop\JRT.exe 
2013-09-10 15:29 - 2013-09-10 15:29 - 01037278 _____ C:\Users\PC 1\Desktop\adwcleaner.exe 
2013-09-10 15:15 - 2013-09-09 16:10 - 00001077 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
2013-09-10 15:15 - 2013-09-09 16:10 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 
2013-09-10 15:14 - 2013-09-09 17:28 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\PC 1\Desktop\mbam-setup-1.75.0.1300.exe 
2013-09-10 14:13 - 2013-09-10 14:13 - 96922344 _____ C:\Windows\system32\ꮯˀ바_ 
2013-09-10 13:22 - 2013-09-09 16:21 - 00001140 _____ C:\Windows\PFRO.log 
2013-09-10 13:21 - 2012-09-21 14:43 - 00000000 ____D C:\Users\PC 1\Documents\PhraseExpress 
2013-09-10 13:20 - 2013-09-10 13:20 - 00020668 _____ C:\ComboFix.txt 
2013-09-10 13:20 - 2013-09-10 12:58 - 00000000 ____D C:\Qoobox 
2013-09-10 13:20 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 
2013-09-10 13:14 - 2013-09-10 12:58 - 00000000 ____D C:\Windows\erdnt 
2013-09-10 13:09 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 
2013-09-10 12:57 - 2013-09-10 12:57 - 05125565 ____R (Swearware) C:\Users\PC 1\Desktop\ComboFix.exe 
2013-09-10 11:37 - 2013-09-10 11:37 - 00023245 _____ C:\Users\PC 1\Desktop\Addition.txt 
2013-09-10 11:36 - 2013-09-10 11:36 - 00000000 ____D C:\FRST 
2013-09-10 11:35 - 2013-09-10 11:35 - 01082349 _____ (Farbar) C:\Users\PC 1\Desktop\FRST.exe 
2013-09-09 19:21 - 2012-09-21 13:12 - 00000234 _____ C:\Windows\ktel.ini 
2013-09-09 18:16 - 2013-09-09 18:16 - 96732368 _____ C:\Windows\system32\鳜�바o 
2013-09-09 17:17 - 2013-09-09 17:17 - 00000747 _____ C:\Users\Public\Desktop\VLC media player.lnk 
2013-09-09 17:17 - 2012-11-28 15:34 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\vlc 
2013-09-09 17:03 - 2013-09-09 17:02 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Foxit Software 
2013-09-09 17:02 - 2013-09-09 17:02 - 00002018 _____ C:\Users\Public\Desktop\Foxit Reader.lnk 
2013-09-09 17:02 - 2013-09-09 17:02 - 00000000 ____D C:\Program Files\Foxit Software 
2013-09-09 16:25 - 2013-09-09 16:25 - 00000000 ____D C:\Program Files\ESET 
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Malwarebytes 
2013-09-09 16:10 - 2013-09-09 16:10 - 00000000 ____D C:\ProgramData\Malwarebytes 
2013-09-09 16:03 - 2013-09-09 16:03 - 00000000 ____D C:\Windows\ERUNT 
2013-09-09 15:58 - 2013-09-09 15:58 - 00001149 _____ C:\Users\PC 1\Desktop\Desinstaller_HOSTS_Anti-PUPs.lnk 
2013-09-09 15:58 - 2013-09-09 15:58 - 00000000 ____D C:\Program Files\Hosts_Anti_Adwares_PUPs 
2013-09-09 15:44 - 2013-09-09 15:44 - 00000000 _____ C:\Windows\setuperr.log 
2013-09-09 15:42 - 2013-02-01 12:25 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Common 
2013-09-09 15:37 - 2012-03-16 08:58 - 00000000 ____D C:\Windows\Panther 
2013-09-09 15:34 - 2013-09-09 15:34 - 00000975 _____ C:\Users\Public\Desktop\CCleaner.lnk 
2013-09-09 15:34 - 2012-09-24 13:45 - 00000000 ____D C:\Program Files\CCleaner 
2013-09-09 13:34 - 2013-09-09 13:33 - 11634176 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe 
2013-09-09 13:34 - 2013-09-09 13:32 - 00000000 ____D C:\Program Files\LastPass 
2013-09-09 13:33 - 2013-09-09 13:33 - 06484992 _____ C:\Program Files\LPPlugin.dll 
2013-09-09 13:33 - 2013-09-09 13:33 - 01068544 _____ (LastPass) C:\Program Files\LPIEHome.ocx 
2013-09-09 13:33 - 2013-09-09 13:33 - 00612864 _____ (LastPass) C:\Program Files\LPToolbar.dll 
2013-09-09 13:33 - 2013-09-09 13:33 - 00180736 _____ C:\Program Files\WinBioStandalone.exe 
2013-09-09 13:33 - 2013-09-09 13:33 - 00058282 _____ C:\Program Files\iehome2.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00023666 _____ C:\Program Files\iehome.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00006582 _____ C:\Program Files\vaultcommonc.js 
2013-09-09 13:33 - 2013-09-09 13:33 - 00006260 _____ C:\Program Files\menu.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00002972 _____ C:\Program Files\json2c.js 
2013-09-09 13:33 - 2013-09-09 13:33 - 00001174 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000716 _____ C:\Program Files\context.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000223 _____ C:\Program Files\img.html 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000081 _____ C:\Program Files\programfiles.txt 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deleteprogramfiles.txt 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000019 _____ C:\Program Files\deletelocallowlastpass.txt 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\lang 
2013-09-09 13:33 - 2013-09-09 13:33 - 00000000 ____D C:\Program Files\images 
2013-09-06 17:55 - 2012-10-03 16:45 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Skype 
2013-09-06 17:41 - 2013-06-24 11:56 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Paint.NET 
2013-09-06 14:24 - 2013-09-06 14:24 - 96334488 _____ C:\Windows\system32\覑�바_ 
2013-09-05 15:39 - 2013-09-05 15:39 - 00000000 ____D C:\Program Files\BrainWave Generator 
2013-09-05 14:44 - 2013-09-05 14:44 - 00001294 _____ C:\Users\Public\Desktop\Paint.NET.lnk 
2013-09-05 14:43 - 2013-06-24 11:56 - 00000000 ____D C:\Program Files\Paint.NET 
2013-09-04 16:14 - 2012-09-21 13:02 - 00000052 _____ C:\Windows\seumain.INI 
2013-09-04 15:39 - 2012-09-19 10:12 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 
2013-09-04 15:38 - 2013-09-04 15:38 - 00002133 _____ C:\Users\Public\Desktop\PC-Kaufmann Komplettpaket Pro 2014.lnk 
2013-09-04 15:38 - 2012-09-21 13:00 - 00271906 _____ C:\outlooksync.log 
2013-09-04 15:38 - 2012-09-21 13:00 - 00148852 _____ C:\eBay.log 
2013-09-04 15:38 - 2012-09-21 12:59 - 00278084 _____ C:\BankCom.log 
2013-09-04 15:38 - 2012-09-21 12:59 - 00205086 _____ C:\ElsterShared.log 
2013-09-04 15:37 - 2012-09-21 12:59 - 00228068 _____ C:\BankContacts.log 
2013-09-04 15:37 - 2012-09-21 12:59 - 00159364 _____ C:\Saip.log 
2013-09-04 15:37 - 2012-09-21 12:59 - 00152570 _____ C:\Cockpit.log 
2013-09-04 15:37 - 2012-09-21 12:59 - 00000000 ____D C:\Program Files\Common Files\Sage KHK Shared 
2013-09-04 15:37 - 2012-09-21 12:59 - 00000000 ____D C:\Program Files\Common Files\Sage Group 
2013-09-04 15:37 - 2012-09-21 12:47 - 00000000 ____D C:\Program Files\Common Files\Sage Software Shared 
2013-09-04 13:59 - 2013-05-02 11:12 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 
2013-09-04 13:59 - 2012-10-09 13:31 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 
2013-09-04 13:59 - 2012-10-09 13:31 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 
2013-09-02 15:49 - 2013-09-02 15:49 - 00001159 _____ C:\Users\PC 1\Desktop\Bwgen.lnk 
2013-09-01 09:09 - 2013-07-31 11:00 - 00000000 ____D C:\Users\PC1~1\AppData\Local\FRITZ! 
2013-08-31 09:59 - 2012-09-21 13:07 - 00000000 ___RD C:\Users\PC 1\Desktop\Büro 
2013-08-30 08:32 - 2012-09-19 10:10 - 00000000 ____D C:\Program Files\NVIDIA Corporation 
2013-08-28 14:55 - 2013-05-01 16:16 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Deployment 
2013-08-24 07:54 - 2013-08-24 07:54 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys 
2013-08-22 12:28 - 2012-10-19 12:54 - 00000000 ____D C:\Users\PC 1\dwhelper 
2013-08-20 15:33 - 2013-08-30 08:32 - 00033568 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys 
2013-08-20 15:32 - 2013-07-31 07:52 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll 
2013-08-19 16:51 - 2012-10-24 15:59 - 00000000 ____D C:\Users\PC 1\Documents\FW-Sim 
2013-08-19 16:48 - 2012-10-24 15:49 - 00000571 _____ C:\Users\Public\Desktop\FWsim.lnk 
2013-08-18 12:39 - 2013-08-18 11:42 - 00000000 ____D C:\ProgramData\SecTaskMan 
2013-08-18 12:32 - 2013-08-18 11:57 - 00000000 ____D C:\Users\PC 1\Desktop\Systemprogramme 
2013-08-18 12:04 - 2013-08-18 12:00 - 00000000 ____D C:\Users\PC 1\Desktop\Film und Ton 
2013-08-18 12:04 - 2012-09-25 15:32 - 00000000 ___RD C:\Users\PC 1\Desktop\Flugsimulator 
2013-08-18 12:01 - 2013-08-18 12:01 - 00000000 ____D C:\Users\PC 1\Desktop\Komunikation 
2013-08-18 11:50 - 2013-08-18 11:42 - 00000000 ____D C:\Program Files\Security Task Manager 
2013-08-18 11:08 - 2013-08-18 11:07 - 00000000 ____D C:\Program Files\Sysinternals 
2013-08-18 07:45 - 2012-09-21 12:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 
2013-08-17 11:02 - 2013-08-17 11:02 - 00000000 ____D C:\Program Files\Mozilla Firefox 
2013-08-16 14:33 - 2013-08-16 14:22 - 00000000 ____D C:\Program Files\Lavasoft 
2013-08-16 14:32 - 2013-08-16 14:23 - 00000000 ____D C:\Program Files\Ad-Aware Antivirus 
2013-08-16 14:31 - 2013-08-16 14:21 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\Ad-Aware Antivirus 
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\Users\PC 1\AppData\Roaming\LavasoftStatistics 
2013-08-16 14:26 - 2013-08-16 14:26 - 00000000 ____D C:\ProgramData\Ad-Aware Antivirus 
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Lavasoft 
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Downloaded Installations 
2013-08-16 14:23 - 2013-08-16 14:23 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 
2013-08-16 14:23 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 
2013-08-16 14:21 - 2013-08-16 14:21 - 00044424 _____ (GFI Software) C:\Windows\system32\sbbd.exe 
2013-08-16 14:21 - 2013-08-16 14:21 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 
2013-08-16 09:48 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 
2013-08-16 09:20 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 
2013-08-15 13:00 - 2012-09-21 12:59 - 01045776 _____ (Microsoft Corporation) C:\Windows\system32\msjet35.dll 
2013-08-15 13:00 - 2012-09-21 12:59 - 00487424 _____ (Microsoft Corporation) C:\Windows\system32\msvcp70.dll 
2013-08-15 13:00 - 2012-09-21 12:59 - 00407312 _____ (Microsoft Corporation) C:\Windows\system32\msrepl35.dll 
2013-08-15 13:00 - 2012-09-21 12:59 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msvcr70.dll 
2013-08-15 13:00 - 2012-09-21 12:59 - 00252176 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x35.dll 
2013-08-15 13:00 - 2012-09-21 12:59 - 00123664 _____ (Microsoft Corporation) C:\Windows\system32\msjint35.dll 
2013-08-15 13:00 - 2012-09-21 12:59 - 00098304 _____ (Inner Media, Inc.) C:\Windows\system32\dunzip32.dll 
2013-08-15 13:00 - 2012-09-21 12:59 - 00024848 _____ (Microsoft Corporation) C:\Windows\system32\msjter35.dll 
2013-08-15 09:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 
2013-08-14 06:52 - 2013-07-26 21:18 - 00000000 ____D C:\Windows\system32\MRT 
2013-08-14 06:50 - 2012-09-26 08:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 
2013-08-14 06:50 - 2012-09-21 11:39 - 00000000 ____D C:\ProgramData\Microsoft Help 
2013-08-11 07:58 - 2013-08-11 07:57 - 00000000 ____D C:\Users\PC1~1\AppData\Local\Axialis 
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\NewFreeScreensavers 
2013-08-11 07:57 - 2013-08-11 07:57 - 00000000 ____D C:\Program Files\Common Files\NewFreeScreensavers   
Files to move or delete: 
==================== 
C:\Users\PC1~1\AppData\Local\Temp\Quarantine.exe   
==================== Bamital & volsnap Check =================   
C:\Windows\explorer.exe => MD5 is legit 
C:\Windows\System32\winlogon.exe => MD5 is legit 
C:\Windows\System32\wininit.exe => MD5 is legit 
C:\Windows\System32\svchost.exe => MD5 is legit 
C:\Windows\System32\services.exe => MD5 is legit 
C:\Windows\System32\User32.dll => MD5 is legit 
C:\Windows\System32\userinit.exe => MD5 is legit 
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit     
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!     
LastRegBack: 2013-09-02 12:11   
==================== End Of Log ===========================   --- --- ---  
--- --- ---   
Gruß Paraglider58    |