Hallo Schrauber,
hier das Logfile von Malewarebytes:
2013/09/23 20:55:42 +0200 PAPA Thomas MESSAGE Executing scheduled update: Daily
2013/09/23 20:55:45 +0200 PAPA Thomas MESSAGE Starting protection
2013/09/23 20:55:45 +0200 PAPA Thomas MESSAGE Protection started successfully
2013/09/23 20:55:45 +0200 PAPA Thomas MESSAGE Starting IP protection
2013/09/23 20:56:07 +0200 PAPA Thomas MESSAGE IP Protection started successfully
2013/09/23 20:56:30 +0200 PAPA Thomas MESSAGE Starting database refresh
2013/09/23 20:56:30 +0200 PAPA Thomas MESSAGE Stopping IP protection
2013/09/23 20:56:32 +0200 PAPA Thomas MESSAGE IP Protection stopped successfully
2013/09/23 20:56:35 +0200 PAPA Thomas MESSAGE Database refreshed successfully
2013/09/23 20:56:35 +0200 PAPA Thomas MESSAGE Starting IP protection
2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE IP Protection started successfully
2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE Starting database refresh
2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE Stopping IP protection
2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE IP Protection stopped successfully
2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE Scheduled update executed successfully: database updated from version v2013.04.04.07 to version v2013.09.23.10
2013/09/23 20:56:43 +0200 PAPA Thomas MESSAGE Database refreshed successfully
2013/09/23 20:56:43 +0200 PAPA Thomas MESSAGE Starting IP protection
2013/09/23 20:56:46 +0200 PAPA Thomas MESSAGE IP Protection started successfully
2013/09/23 21:04:42 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:04:50 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:05:00 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:36:46 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:36:54 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:36:57 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:38:04 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:38:12 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:38:56 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:39:00 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:40:08 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:44:30 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:44:32 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:44:33 +0200 PAPA Thomas DETECTION C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll PUP.Optional.Delta QUARANTINE
2013/09/23 21:44:33 +0200 PAPA Thomas DETECTION C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll PUP.Optional.Delta QUARANTINE
2013/09/23 21:44:42 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:44:47 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:44:59 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:45:03 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:45:06 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:45:10 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:47:30 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:48:38 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:48:44 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:56:37 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:57:46 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:57:51 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:59:04 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:59:08 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:59:23 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
2013/09/23 21:59:51 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE
Hier die Ergebnisse vom AdwCleanerAdwCleaner Logfile:
Code:
# AdwCleaner v3.005 - Bericht erstellt am 24/09/2013 um 09:40:32
# Updated 22/09/2013 von Xplode
# Betriebssystem : Windows 8 Pro (64 bits)
# Benutzername : Thomas - PAPA
# Gestartet von : C:\Users\Thomas\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : BitGuard
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\Program Files (x86)\delta
Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\delta
Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\file scout
Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Datei Gelöscht : C:\Windows\System32\Tasks\BitGuard
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\96df8fb23ae546
Schlüssel Gelöscht : HKLM\SOFTWARE\96df8fb23ae546
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
[#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\filescout
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16688
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
*************************
AdwCleaner[R0].txt - [6170 octets] - [24/09/2013 09:38:43]
AdwCleaner[S0].txt - [5707 octets] - [24/09/2013 09:40:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5767 octets] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 8 Pro x64
Ran by Thomas on 24.09.2013 at 9:45:41,85
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1303693457-2561116457-2898103115-1001\Software\SweetIM
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.09.2013 at 9:49:15,26
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2013
Ran by Thomas (administrator) on PAPA on 24-09-2013 10:00:23
Running from C:\Users\Thomas\Desktop
Windows 8 Pro (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Opera Software) C:\Program Files (x86)\Opera\Opera.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
AppInit_DLLs-x32: c:\PROGRA~3\BitGuard\261673~1.238\{C16C1~1\BitGuard.dll [ ] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x77EA5E02A133CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
==================== Services (Whitelisted) =================
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2012-12-29] (IvoSoft)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-04-01] (Freemake)
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-04-01] (Ellora Assets Corp.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-24 09:57 - 2013-09-24 09:57 - 01955802 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe
2013-09-24 09:54 - 2013-09-24 09:54 - 00000617 _____ C:\Users\Thomas\Desktop\JRT.txt
2013-09-24 09:45 - 2013-09-24 09:45 - 00000000 ____D C:\Windows\ERUNT
2013-09-24 09:44 - 2013-09-24 09:44 - 01030038 _____ (Thisisu) C:\Users\Thomas\Desktop\JRT.exe
2013-09-24 09:36 - 2013-09-24 09:40 - 00000000 ____D C:\AdwCleaner
2013-09-24 09:36 - 2013-09-24 09:36 - 01042066 _____ C:\Users\Thomas\Desktop\adwcleaner.exe
2013-09-23 20:55 - 2013-09-23 20:55 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2013-09-23 20:54 - 2013-09-23 20:54 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-22 08:57 - 2013-09-22 09:21 - 00000000 ____D C:\ComboFix
2013-09-22 08:57 - 2013-09-22 09:15 - 00000000 ____D C:\Windows\erdnt
2013-09-22 08:57 - 2013-09-22 09:04 - 00000000 ____D C:\Qoobox
2013-09-22 08:57 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-22 08:57 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-22 08:57 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-22 08:57 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-22 08:57 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-22 08:57 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2013-09-22 08:57 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-22 08:57 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-22 08:57 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-22 08:49 - 2013-09-22 08:50 - 05128554 ____R (Swearware) C:\Users\Thomas\Desktop\ComboFix.exe
2013-09-22 08:49 - 2013-08-07 07:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-09-17 20:34 - 2013-09-17 20:34 - 00000188 _____ C:\Users\Thomas\Desktop\Trojaner Board.url
2013-09-17 20:29 - 2013-09-17 20:29 - 00025221 _____ C:\Users\Thomas\Desktop\Addition.txt
2013-09-17 20:28 - 2013-09-17 20:28 - 00028372 _____ C:\Users\Thomas\Documents\FRST.txt
2013-09-17 20:28 - 2013-09-17 20:28 - 00025221 _____ C:\Users\Thomas\Documents\Addition.txt
2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST
2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso
2013-09-12 21:55 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2013-09-12 21:55 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2013-09-12 21:55 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-09-12 21:55 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2013-09-12 21:55 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2013-09-12 21:55 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-09-12 21:55 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2013-09-12 21:55 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2013-09-12 21:55 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll
2013-09-12 21:55 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-09-12 21:55 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-09-12 21:55 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2013-09-12 21:55 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2013-09-12 21:54 - 2013-08-21 06:12 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-12 21:54 - 2013-08-21 06:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-12 21:54 - 2013-08-21 06:11 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-12 21:54 - 2013-08-21 06:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-12 21:54 - 2013-08-21 04:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-12 21:54 - 2013-08-21 04:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-12 21:54 - 2013-08-21 04:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-12 21:54 - 2013-08-21 04:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-12 21:54 - 2013-08-21 04:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-12 21:54 - 2013-08-21 03:43 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-12 21:54 - 2013-08-21 01:52 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-09-12 21:54 - 2013-08-03 06:30 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 21:54 - 2013-07-09 10:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys
2013-09-12 21:54 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2013-09-12 21:54 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2013-09-12 21:54 - 2013-07-09 05:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2013-09-12 21:54 - 2013-07-09 00:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2013-09-12 21:54 - 2013-07-09 00:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2013-09-12 21:54 - 2013-07-09 00:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll
2013-09-12 21:54 - 2013-07-09 00:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2013-09-12 21:54 - 2013-07-06 02:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-09-12 21:54 - 2013-07-03 02:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-09-12 21:54 - 2013-07-03 02:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2013-09-12 21:54 - 2013-07-03 02:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2013-09-12 21:54 - 2013-07-03 02:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-09-12 21:54 - 2013-07-03 02:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-09-12 21:54 - 2013-07-03 02:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-09-12 21:54 - 2013-07-03 02:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2013-09-12 21:54 - 2013-07-02 00:08 - 00387583 _____ C:\Windows\system32\ApnDatabase.xml
2013-09-12 21:54 - 2013-07-01 00:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe
2013-09-12 21:54 - 2013-07-01 00:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe
2013-09-12 21:54 - 2013-06-29 08:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-09-12 21:54 - 2013-06-29 08:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-09-12 21:54 - 2013-06-29 07:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2013-09-12 21:54 - 2013-06-29 03:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-09-12 21:54 - 2013-06-26 05:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2013-09-12 21:54 - 2013-06-26 04:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2013-09-12 21:54 - 2013-06-25 00:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-09-12 21:54 - 2013-06-25 00:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2013-09-12 21:54 - 2013-06-25 00:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2013-09-12 21:54 - 2013-06-19 07:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll
2013-09-12 21:54 - 2013-06-19 07:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2013-09-12 21:54 - 2013-06-19 00:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll
2013-09-12 21:54 - 2013-06-19 00:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2013-09-12 21:54 - 2013-06-12 01:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2013-09-12 21:54 - 2013-06-12 01:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2013-09-12 21:54 - 2013-06-10 23:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2013-09-12 21:54 - 2013-06-10 21:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-09-12 21:54 - 2013-06-10 21:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-09-12 21:54 - 2013-06-10 21:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2013-09-12 21:54 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-09-12 21:54 - 2013-06-10 21:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-09-12 21:54 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-09-12 21:54 - 2013-06-06 10:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2013-08-26 23:19 - 2013-08-26 23:19 - 00000850 _____ C:\Users\Thomas\AppData\Local\recently-used.xbel
2013-08-26 23:18 - 2013-08-26 23:18 - 00000000 ____D C:\Users\Thomas\.thumbnails
2013-08-26 23:17 - 2013-08-26 23:20 - 00000000 ____D C:\Users\Thomas\.gimp-2.8
2013-08-26 23:17 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\gegl-0.2
2013-08-25 09:29 - 2013-09-14 09:27 - 00000000 ____D C:\Windows\system32\MRT
==================== One Month Modified Files and Folders =======
2013-09-24 10:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-09-24 09:57 - 2013-09-24 09:57 - 01955802 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe
2013-09-24 09:54 - 2013-09-24 09:54 - 00000617 _____ C:\Users\Thomas\Desktop\JRT.txt
2013-09-24 09:52 - 2013-07-02 22:41 - 01534619 _____ C:\Windows\WindowsUpdate.log
2013-09-24 09:46 - 2013-04-07 16:59 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1303693457-2561116457-2898103115-1001
2013-09-24 09:46 - 2012-07-26 12:27 - 00714240 _____ C:\Windows\system32\perfh007.dat
2013-09-24 09:46 - 2012-07-26 12:27 - 00147840 _____ C:\Windows\system32\perfc007.dat
2013-09-24 09:46 - 2012-07-26 09:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-24 09:45 - 2013-09-24 09:45 - 00000000 ____D C:\Windows\ERUNT
2013-09-24 09:44 - 2013-09-24 09:44 - 01030038 _____ (Thisisu) C:\Users\Thomas\Desktop\JRT.exe
2013-09-24 09:41 - 2013-04-08 21:16 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-24 09:41 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-24 09:40 - 2013-09-24 09:36 - 00000000 ____D C:\AdwCleaner
2013-09-24 09:36 - 2013-09-24 09:36 - 01042066 _____ C:\Users\Thomas\Desktop\adwcleaner.exe
2013-09-24 09:33 - 2013-08-20 13:51 - 00069578 _____ C:\Windows\PFRO.log
2013-09-23 20:55 - 2013-09-23 20:55 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2013-09-23 20:54 - 2013-09-23 20:54 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-22 09:31 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF
2013-09-22 09:23 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-09-22 09:21 - 2013-09-22 08:57 - 00000000 ____D C:\ComboFix
2013-09-22 09:15 - 2013-09-22 08:57 - 00000000 ____D C:\Windows\erdnt
2013-09-22 09:07 - 2012-07-26 07:26 - 00000215 _____ C:\Windows\system.ini
2013-09-22 09:06 - 2012-07-26 07:26 - 53215232 _____ C:\Windows\system32\config\SOFTWARE.bak
2013-09-22 09:06 - 2012-07-26 07:26 - 11010048 _____ C:\Windows\system32\config\SYSTEM.bak
2013-09-22 09:06 - 2012-07-26 07:26 - 00524288 _____ C:\Windows\system32\config\DEFAULT.bak
2013-09-22 09:06 - 2012-07-26 07:26 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak
2013-09-22 09:06 - 2012-07-26 07:26 - 00262144 _____ C:\Windows\system32\config\SAM.bak
2013-09-22 09:04 - 2013-09-22 08:57 - 00000000 ____D C:\Qoobox
2013-09-22 08:50 - 2013-09-22 08:49 - 05128554 ____R (Swearware) C:\Users\Thomas\Desktop\ComboFix.exe
2013-09-22 08:48 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-09-17 20:34 - 2013-09-17 20:34 - 00000188 _____ C:\Users\Thomas\Desktop\Trojaner Board.url
2013-09-17 20:29 - 2013-09-17 20:29 - 00025221 _____ C:\Users\Thomas\Desktop\Addition.txt
2013-09-17 20:28 - 2013-09-17 20:28 - 00028372 _____ C:\Users\Thomas\Documents\FRST.txt
2013-09-17 20:28 - 2013-09-17 20:28 - 00025221 _____ C:\Users\Thomas\Documents\Addition.txt
2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST
2013-09-14 13:10 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-14 11:03 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe
2013-09-14 09:27 - 2013-08-25 09:29 - 00000000 ____D C:\Windows\system32\MRT
2013-09-14 09:25 - 2013-04-08 23:50 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso
2013-09-05 22:09 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-05 22:09 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-02 08:49 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-26 23:20 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\.gimp-2.8
2013-08-26 23:19 - 2013-08-26 23:19 - 00000850 _____ C:\Users\Thomas\AppData\Local\recently-used.xbel
2013-08-26 23:18 - 2013-08-26 23:18 - 00000000 ____D C:\Users\Thomas\.thumbnails
2013-08-26 23:18 - 2013-04-07 16:50 - 00000000 ____D C:\Users\Thomas
2013-08-26 23:17 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\gegl-0.2
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-23 21:45
==================== End Of Log ============================
--- --- ---
--- --- ---