Als aller erstes hatte ich gestern Malwarebytes Anti-Malware laufen lassen und alle infizierten Funde gelöscht. Hier der Log dazu:
Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.12.01.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
PC :: ---- [Administrator]
Schutz: Aktiviert
01.12.2013 17:02:20
mbam-log-2013-12-01 (17-02-20).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 509795
Laufzeit: 1 Stunde(n), 46 Minute(n), 26 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 18
HKCR\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\YontooIEClient.Layers.1 (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\YontooIEClient.Layers (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\nationzoomSoftware (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo (PUP.Optional.Elex.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 2
HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {0BEF0CB3-FDC5-11E2-B890-002618D6A2BF} -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {0BEF0CB3-FDC5-11E2-B890-002618D6A2BF} -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 6
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (PUP.Optional.NationZoom.A) -> Bösartig: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (iexplore.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (PUP.Optional.Qone8) -> Bösartig: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}) Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\Software\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
Infizierte Verzeichnisse: 1
C:\Users\PC\Documents\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 10
C:\Program Files (x86)\Yontoo Layers\YontooIEClient.dll (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\mgsqlite3.7z (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\mgsqlite3.dll (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\fullpackage_temp1385907047\Baofeng.exe (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\fullpackage_temp1385907047\tmp\eGdpSvc.exe (PUP.Optional.Wsys.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\installer.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\software\OptimizerPro.exe (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\software\tugs_nationzoom.exe (PUP.Optional.SkyTech.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\Documents\Optimizer Pro\CookiesException.txt (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
--- --- --- --- --- --- --- ---- --- ---- --- ---- ---
Anschließend startete ich AdwCleaner und erhielt diese 2 Logs (AdwCleaner[RO]:
Code:
# AdwCleaner v3.014 - Bericht erstellt am 01/12/2013 um 21:13:19
# Updated 01/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : PC - ----
# Gestartet von : C:\Users\PC\Desktop\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
Datei Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
Datei Gefunden : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Ordner Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
Ordner Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Ordner Gefunden C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gefunden C:\Program Files (x86)\DAEMON Tools Toolbar
Ordner Gefunden C:\Program Files (x86)\iMesh Applications
Ordner Gefunden C:\Program Files (x86)\MyPC Backup
Ordner Gefunden C:\Program Files (x86)\Yontoo Layers
Ordner Gefunden C:\ProgramData\Ask
Ordner Gefunden C:\ProgramData\eSafe
Ordner Gefunden C:\ProgramData\Tarma Installer
Ordner Gefunden C:\Users\PC\AppData\Local\cool_mirage
Ordner Gefunden C:\Users\PC\AppData\Local\Mail.Ru
Ordner Gefunden C:\Users\PC\AppData\LocalLow\iac
Ordner Gefunden C:\Users\PC\AppData\Roaming\dvdvideosoftiehelpers
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Schlüssel Gefunden : [x64] HKCU\Software\Softonic
Schlüssel Gefunden : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\FTDownloader
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\lgnbhdnimikkoodkogjlcllngimhlapp
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D6F0AC3-0C2E-4E07-8FDA-11268AB51211}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Tarma Installer
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Wert Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v
-\\ Google Chrome v31.0.1650.57
[ Datei : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [6713 octets] - [01/12/2013 21:13:19]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6773 octets] ##########
und diesen hier AdwCleaner[SO]:
Code:
# AdwCleaner v3.014 - Bericht erstellt am 01/12/2013 um 21:14:08
# Updated 01/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : PC - ----
# Gestartet von : C:\Users\PC\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\eSafe
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files (x86)\DAEMON Tools Toolbar
Ordner Gelöscht : C:\Program Files (x86)\iMesh Applications
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\Yontoo Layers
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\PC\AppData\Local\cool_mirage
Ordner Gelöscht : C:\Users\PC\AppData\Local\Mail.Ru
Ordner Gelöscht : C:\Users\PC\AppData\LocalLow\iac
Ordner Gelöscht : C:\Users\PC\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
Ordner Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Datei Gelöscht : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Datei Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
Datei Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\lgnbhdnimikkoodkogjlcllngimhlapp
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FTDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D6F0AC3-0C2E-4E07-8FDA-11268AB51211}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v
-\\ Google Chrome v31.0.1650.57
[ Datei : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [6929 octets] - [01/12/2013 21:13:19]
AdwCleaner[S0].txt - [6633 octets] - [01/12/2013 21:14:08]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6693 octets] ##########
--- --- --- --- --- --- --- --- --- -- -- --- --- ---- -- --- ---
Nun als 3. began ich den Scan mit Junkware Removal Tool und erhielt diesen Log:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by PC on 01.12.2013 at 21:28:08,57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D3998AED-51D6-46E1-9C87-042CA1ED8F95}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{04953E20-4820-445F-84ED-D91A1500D620}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{050B921F-6B59-4988-88F8-4CE19EFB7286}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{05A7CC7D-5873-4C57-B5E3-228EBFC44C66}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{0A4654BF-5C29-4A45-829E-BD5FF6611034}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{0B1F7094-EE18-458F-9FE9-E43C043A68FB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{0CADB3C3-4EC9-4584-BB39-F3BA4B49990D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{11B7B8FC-E114-4D8E-962D-A88891CD4A75}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{138FE3B8-6DC2-4CF7-90FB-9C9BABFE2B18}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{13F2885D-142F-475F-88F9-FAC37B62FC52}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{17783E3C-1114-4162-9663-A5D9A36170A7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{1C49A864-3D29-4C53-BBDF-32CD694A2399}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{1EC59320-0C98-4D12-A3DF-FD1E082179A9}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2491CDE2-86A0-4639-AC84-66E0F747C6E1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{265D547E-7718-4791-B278-CEA603765AD7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2737684E-2CBA-4AFF-8CC1-EB7061AA069F}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{27DBBE79-BA63-4B0B-BDF5-02FA3415B759}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{298EBE99-45FF-4713-9E44-60CFB93DB894}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2C42268D-5AD0-471A-A79A-7F2618E37D4B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2E60CDFF-E4AA-4CAB-B21B-CB92D066F978}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2EBE1BD2-F438-47F6-B755-BF059E256EBF}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2FBE6959-68BF-42DF-8D3C-71F912FB061B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2FE4E312-0355-4D2F-97A4-0C4BAEA820F7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3143108B-FE67-4A20-96F7-97D323B65DA2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{330A3231-195F-4719-9616-D7FD5DAA03C1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3487BD39-A6B8-448E-BA3E-BD3522B33331}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{361F230D-2A0D-4EFA-84E2-F2EB634E05E4}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{36D6C777-EF9D-4A63-AE35-A4F1DD3C1B3B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3922E2EC-C23B-4160-A060-169FDEB106D8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{39389053-8FEB-4B78-B409-E6D17375598B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3A443088-0761-42B3-BAA6-E2E95004DFCA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3C3D17DF-54C7-4636-9DBF-2AA63C85E615}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3D037E2E-3B5F-441B-958E-2EB8D7D8D8BA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3D3661AB-10BC-4FE0-AF67-479F216A9679}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4055D348-A94F-4C72-8F6C-06BAFCE26393}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{438B8403-E4DA-41FC-BCD1-5CDE95E905FC}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4AC85563-CF31-4907-B074-E7A9D5E0EB59}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4B8F0C97-2989-47AD-B74F-4EDAE51EB3BB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4D34FCC4-2BEE-41FE-A471-029B599F5407}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4D497D84-12C0-4F77-BE80-77DC7FC32121}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4D650055-5D7E-44AE-84BD-4BA67D6CAB65}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5261A561-3D7F-4BBD-A6AF-099011462D7E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{52FEB6BD-FCB3-4392-968E-6E8BCB0B0BC1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{54BE864B-A4A0-446B-9F26-B4E3EBF22B74}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{56D8E757-5B57-4E19-B55D-6DB81D045121}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5806E4FC-7824-4269-835C-C50F60BC4B9C}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{59EEB5ED-5EBC-47A3-9442-3D4C138FB373}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5A0AE002-6E00-4E56-9346-0AE0898FB766}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5A3031F0-0CF7-444F-BDDF-BD8A3BF77738}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5AAAC3C6-08DA-4FCC-8484-ECED54C1994B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5C491509-5756-4793-8844-0E92D4228ED4}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5C6A030D-E693-40FE-892B-CE3917342FDD}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{604CEBC6-FCB1-4D34-8F4E-9042A99A49D6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{61211C89-13C3-440A-8931-6F65CBCA99DF}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{614D6FC4-29B8-49DF-8F6B-EE7743338E86}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{61A31803-A659-4560-B87E-0358A0D9F461}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{684D023F-8285-4572-9543-C7D2C19E0BCB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6906BA98-C1AE-4B1F-9B46-DAA9339EFBF3}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6AC0986C-C779-4F9D-A304-C34CFA22988D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6DA56D56-2BD2-43EB-A518-DA5BA0C784E6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6FB6FDF7-B797-4DE0-A61A-52F873AD368D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{70698485-0CD8-432F-8F3B-CCE785048582}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{7119EBD4-8C47-46B4-8D2D-992103830F32}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{728872D4-A9E8-4D3E-A9D8-41BA95F0C144}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{77209029-1A41-459E-B12C-F4B1837A6CD7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{7770EB46-E78C-441C-B75C-A089937019E7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{7F03D821-2C49-46E7-8950-34BF00BEBFE9}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8060126E-928A-456C-BF0F-F7ED4A1E40D8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{845D3436-68A4-41DF-B883-6166E318D86E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8558F393-5E67-4830-86DA-4BCB44077301}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{873961C3-CCC6-4303-AEA6-C57D647D3BE7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8883CEDD-DEAF-4842-82A5-CCFAC6093A9A}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8A8FEDA9-1ADD-4D97-8A40-6A16D9D35687}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8E17E7A6-420E-4674-8180-C056CF48A19B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8E747BEA-888F-4800-9C4D-DAB1C487EB47}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8FFADD15-274F-43B2-8655-132B5F38EBE2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{916719F1-EB08-40C0-A774-EE2FE9A919F7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{944EB0A1-F795-4E80-BE77-CF72C9E2ABAB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{95E39759-0163-42E2-9862-A3C5950C66DF}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{96E52183-2929-46A7-AEBC-E7F87223BE4C}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{97EE4707-160F-4B5B-A8DA-8DBA3F4192BD}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9CF4AA93-77FA-4155-8D67-CAAE9117ADC5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9DD2251A-68E4-4C00-80FE-B40B4A43ED4D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9E02FD86-67E8-4413-ACDD-10CC7FD58D9D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9E3CFE55-A021-4081-8F83-A1B2D320AE37}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A0218593-7E03-4839-B9D4-2671B0DF2CC6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A0F1DF6F-7473-460B-8860-897908639844}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A7748B2F-1CB4-49A5-A7CB-7E203E30E077}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A94297AE-94B9-4B80-BE1C-83FC96070C92}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A9B26D94-2AAE-4433-BC96-36A429E0E9B8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{ADE83510-A846-4326-9B25-F56CA935CFA3}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{AE205D29-086D-4E27-B369-1E7FB08A326E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{B37CDE30-7230-4870-A9B4-0535148B86A2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{B962A9B9-A3C6-4652-90C8-87044E33B9D5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{BB8B3563-E0D3-4D1F-92A5-6E55382C98D3}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{BC568405-17D4-460A-B88F-E1D3746B37A4}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{BCF60FD0-FDB5-47B5-AD29-B778545D9BE7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C0AC7D20-4865-4D70-A41C-DF4BD16A1EA6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C311D297-36DF-48A1-A107-290DC5180C47}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C3B816CC-3F2B-493B-ADDA-1A38E8BAE45F}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C4AC966A-C0D5-4F09-96F1-757E36E69E69}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{CB120509-264A-42B4-8927-A8EF4A6FE809}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{CB360A3C-FF3A-4118-8D01-A477662E2324}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{CBC096C3-5B09-4A68-B6B8-5777683A05AA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D05E4A6E-60B6-4BA8-894B-9C7515104774}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D0D113DF-1415-4040-BF35-5FEE82672E5B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D43C719C-7508-4491-AB72-489A2AB79839}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D569C51D-8099-4CBE-91DD-B8460DB4691E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D6AD0781-DCFA-4F18-A52D-05B4CCAF79A1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D8693CD1-3C66-4F81-908D-C91DC47B39C2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D8E124EE-7687-4300-B53A-C7F697E01150}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D980688C-CD5F-43D0-9221-BB3309704DDA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{DA4C17B4-5821-42D9-8548-5B1F8702EFC5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{DB8A75DD-120F-4DB9-B25D-9D801CC38BCD}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E21FFDE9-54B2-435F-8367-7F92DFF19903}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E318E4BA-02CD-454D-A68A-AA88F6BD7462}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E33A6783-688D-4DE8-B042-6BA674A40AC7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E4B86607-9671-4F5A-B3A2-8004F92B59FA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EA084B54-7280-49C5-B259-1829B997FFEE}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EA4E351B-EE45-48F7-B4DB-A9DF101B2130}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EC38AA63-CF99-4B8C-8869-B03960E2F968}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EFFF8069-B70E-457E-9E8C-6DF02B23C8F5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F3AAEBA0-60EA-4475-B81E-ACFDDC237DD8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F40C664A-09CC-41C3-967E-ACE3C290441E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F40CF757-7D9B-4824-8078-F43EEA17E260}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F475DE67-AC25-4C42-8101-95AF25178B0F}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F72FC534-9CDC-4104-8DC1-D2A4313EBF38}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F861EEDA-A303-4F94-B838-871A0828CAD6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FAF2C561-BCC2-4DB1-8822-D471174FC623}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FBE820AF-8682-469B-A5CB-6FC814A7B006}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FC61FECA-4A46-4755-A34A-DD0C9D931577}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FF7229E2-2EF8-4AC6-A627-6102AB285977}
~~~ Chrome
Successfully deleted: [Folder] C:\Users\PC\appdata\local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.12.2013 at 21:34:54,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- ---
Da ich vor dem Malewarebytes Anti-Maleware Vorgang noch nicht diese seite hier entdeckt habe, habe ich leider vor all dem hier kein FRST benutzt.
Ich stieß während meinem Malewarebytes Anti-Malware Scan auf Trojaner-Board und habe daher erst nach all dem hier das FRST gestartet.
Hier sind die Letzten Logs vorerst:
FRST:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by PC (administrator) on ---- on 01-12-2013 22:12:00
Running from C:\Users\PC\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(TeamSpeak Systems GmbH) C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7574048 2009-03-30] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-10-30] ()
MountPoints2: {2a8763ce-c1a6-11df-9d01-002618d6a2bf} - F:\Autorun.exe
MountPoints2: {4d126ea1-d5e6-11df-b593-002618d6a2bf} - G:\Autorun.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2349392 2013-11-11] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs: [ ] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x328D93A362C9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {434D452D-5637-006A-76A7-7A786E7484D7} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: No Name - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: ftd - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi
Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Unity Player) - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Assassin's Creed IV Black Flag) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\agibflpbghgmiinfaefgnldmfajdance\1.2_0
CHR Extension: (Google Docs) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2011-12-25] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2010-05-25] (Devguru Co., Ltd)
R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [18816 2008-01-17] (Razer USA Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2008-01-21] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-09-16] ()
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [129024 2010-04-27] (MCCI Corporation)
U3 avy50mb9; C:\Windows\System32\Drivers\avy50mb9.sys [0 ] (Microsoft Corporation)
S3 X6va003; \??\C:\Users\PC\AppData\Local\Temp\003977D.tmp [x]
S3 X6va005; \??\C:\Users\PC\AppData\Local\Temp\005422E.tmp [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-01 22:12 - 2013-12-01 22:12 - 00013785 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 22:10 - 2013-12-01 22:10 - 01959184 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:12 - 2013-12-01 21:16 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:57 - 2013-12-01 16:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:57 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-01 16:51 - 2013-12-01 16:55 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-26 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 03:01 - 2013-11-26 03:09 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-14 02:40 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 02:40 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 02:40 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 02:40 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 02:40 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 02:40 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 02:40 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 02:40 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 02:40 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 02:40 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 02:40 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 02:40 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-14 02:39 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 02:39 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 02:39 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment
==================== One Month Modified Files and Folders =======
2013-12-01 22:12 - 2013-12-01 22:12 - 00013785 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 22:10 - 2013-12-01 22:10 - 01959184 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-01 21:52 - 2011-01-29 12:21 - 00000000 ____D C:\Users\PC\AppData\Local\PMB Files
2013-12-01 21:45 - 2013-04-13 17:11 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-01 21:37 - 2013-04-04 20:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:28 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-01 21:28 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:25 - 2010-01-14 17:55 - 01509709 _____ C:\Windows\WindowsUpdate.log
2013-12-01 21:24 - 2012-09-01 12:35 - 00000000 ____D C:\Users\PC\AppData\Roaming\TS3Client
2013-12-01 21:24 - 2009-07-14 05:51 - 00233743 _____ C:\Windows\setupact.log
2013-12-01 21:22 - 2012-12-18 23:41 - 00000000 ____D C:\Users\PC\AppData\Local\LogMeIn Hamachi
2013-12-01 21:21 - 2013-04-13 17:11 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-01 21:20 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-01 21:16 - 2013-12-01 21:12 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 21:09 - 2011-01-29 12:21 - 00000000 ____D C:\ProgramData\PMB Files
2013-12-01 20:42 - 2011-10-17 17:42 - 00188760 _____ C:\Windows\PFRO.log
2013-12-01 19:18 - 2012-12-29 19:56 - 01251840 ___SH C:\Users\PC\Desktop\Thumbs.db
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:58 - 2013-12-01 16:57 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:55 - 2013-12-01 16:51 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-12-01 15:43 - 2013-10-15 20:59 - 00000000 ____D C:\ProgramData\Oracle
2013-12-01 15:39 - 2010-01-14 17:56 - 00000000 ___RD C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-01 15:11 - 2010-01-14 17:56 - 00001641 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 01:17 - 2011-04-08 19:42 - 00000000 ____D C:\Users\PC\Desktop\Fotos
2013-12-01 01:17 - 2010-12-04 17:22 - 00000000 ____D C:\Users\PC\Desktop\bilder
2013-12-01 01:13 - 2010-11-30 19:39 - 00000000 ____D C:\Users\PC\Desktop\Lehre
2013-11-30 14:08 - 2013-01-23 23:17 - 00000000 ____D C:\Users\PC\Desktop\Mouseclick, Schneiden - Umwandeln
2013-11-30 14:07 - 2012-10-06 02:02 - 00000000 ____D C:\Users\PC\Desktop\TS
2013-11-30 14:05 - 2009-07-14 18:58 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-11-30 14:05 - 2009-07-14 18:58 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-11-30 14:05 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-26 03:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-26 03:09 - 2013-11-26 03:01 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-25 16:40 - 2010-06-05 12:07 - 00001534 _____ C:\Users\PC\Desktop\Passwörter.txt
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-22 23:36 - 2012-08-12 11:24 - 00000000 ____D C:\Users\PC\AppData\Roaming\Skype
2013-11-22 14:01 - 2012-10-19 14:00 - 00000000 ____D C:\Users\PC\AppData\Roaming\.minecraft
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-19 13:35 - 2013-08-07 10:58 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-17 21:44 - 2010-03-22 03:29 - 00000000 ____D C:\Users\PC\Desktop\Wallpaper
2013-11-16 22:57 - 2013-02-25 00:42 - 00000000 ____D C:\Users\PC\Desktop\TS 3 Icons
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files\Google
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-15 14:55 - 2012-08-17 16:56 - 00000000 ____D C:\Users\PC\AppData\Local\Google
2013-11-15 14:54 - 2013-04-04 20:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-15 14:54 - 2013-04-04 20:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-15 14:54 - 2013-04-04 20:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-15 14:54 - 2010-03-22 03:53 - 00000000 ____D C:\Users\PC\AppData\Local\Adobe
2013-11-15 03:13 - 2010-03-22 03:57 - 00000000 ____D C:\Users\PC\Desktop\Musik
2013-11-15 00:14 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-14 02:46 - 2013-07-14 01:17 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 02:45 - 2010-03-22 03:11 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-12 12:48 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-11 05:50 - 2010-03-22 02:59 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment
2013-11-07 22:06 - 2012-08-10 14:59 - 00000000 ____D C:\Users\PC\AppData\Local\Apps\2.0
2013-11-06 21:02 - 2012-12-12 01:41 - 00000000 ___RD C:\Users\PC\Desktop\Movie Maker
2013-11-04 15:32 - 2012-10-08 19:41 - 00000000 ____D C:\Users\PC\Desktop\Text-Dokumente
Some content of TEMP:
====================
C:\Users\PC\AppData\Local\Temp\7za.exe
C:\Users\PC\AppData\Local\Temp\APNStub.exe
C:\Users\PC\AppData\Local\Temp\AskSLib.dll
C:\Users\PC\AppData\Local\Temp\avgnt.exe
C:\Users\PC\AppData\Local\Temp\BackupSetup.exe
C:\Users\PC\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\PC\AppData\Local\Temp\drm_dialogs.dll
C:\Users\PC\AppData\Local\Temp\drm_dyndata_7370007.dll
C:\Users\PC\AppData\Local\Temp\FileSystemView.dll
C:\Users\PC\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\PC\AppData\Local\Temp\InstallAX.exe
C:\Users\PC\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\Quarantine.exe
C:\Users\PC\AppData\Local\Temp\SkypeSetup.exe
C:\Users\PC\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\PC\AppData\Local\Temp\vcredist_x64.exe
C:\Users\PC\AppData\Local\Temp\war3_Install.exe
C:\Users\PC\AppData\Local\Temp\_isAB9A.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-11 16:55
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- --- --- --- --- --- --- --- --- ---- --- --- --- --- --- --- --- ---
Und hier der Addition Log:
Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-12-2013
Ran by PC at 2013-12-01 22:13:22
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.152)
Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8)
AION Free-to-Play Version 1.0 (x32 Version: 1.0)
AMD Catalyst Install Manager (Version: 8.0.903.0)
Assassin's Creed Brotherhood (x32 Version: 1.03)
ATI AVIVO64 Codecs (Version: 10.10.0.40918)
ATI Problem Report Wizard (Version: 3.0.745.0)
Avira Free Antivirus (x32 Version: 14.0.1.749)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Core Implementation (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Full New (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Light (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Previews Common (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center HydraVision Full (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485)
Catalyst Control Center Localization All (x32 Version: 2009.0918.2132.36825)
CCC Help Chinese Standard (x32 Version: 2009.0918.2131.36825)
CCC Help Chinese Traditional (x32 Version: 2009.0918.2131.36825)
CCC Help Czech (x32 Version: 2009.0918.2131.36825)
CCC Help Danish (x32 Version: 2009.0918.2131.36825)
CCC Help Dutch (x32 Version: 2009.0918.2131.36825)
CCC Help English (x32 Version: 2009.0918.2131.36825)
CCC Help Finnish (x32 Version: 2009.0918.2131.36825)
CCC Help French (x32 Version: 2009.0918.2131.36825)
CCC Help German (x32 Version: 2009.0918.2131.36825)
CCC Help Greek (x32 Version: 2009.0918.2131.36825)
CCC Help Hungarian (x32 Version: 2009.0918.2131.36825)
CCC Help Italian (x32 Version: 2009.0918.2131.36825)
CCC Help Japanese (x32 Version: 2009.0918.2131.36825)
CCC Help Korean (x32 Version: 2009.0918.2131.36825)
CCC Help Norwegian (x32 Version: 2009.0918.2131.36825)
CCC Help Polish (x32 Version: 2009.0918.2131.36825)
CCC Help Portuguese (x32 Version: 2009.0918.2131.36825)
CCC Help Russian (x32 Version: 2009.0918.2131.36825)
CCC Help Spanish (x32 Version: 2009.0918.2131.36825)
CCC Help Swedish (x32 Version: 2009.0918.2131.36825)
CCC Help Thai (x32 Version: 2009.0918.2131.36825)
CCC Help Turkish (x32 Version: 2009.0918.2131.36825)
ccc-core-static (x32 Version: 2009.0918.2132.36825)
ccc-utility64 (Version: 2009.0918.2132.36825)
D3DX10 (x32 Version: 15.4.2368.0902)
Drachenkrieg (with media and plugins), version 1.1.27 (x32)
FlatOut2 (x32 Version: 1.00.0000)
Free YouTube Download version 3.1.39.1015 (x32 Version: 3.1.39.1015)
Free YouTube to MP3 Converter version 3.11.34.1015 (x32 Version: 3.11.34.1015)
Gameforge Live 1.9.0 "Legend" (x32 Version: 1.9.0)
Google Chrome (x32 Version: 31.0.1650.57)
Google Update Helper (x32 Version: 1.3.21.165)
GRID (x32 Version: 1.00.0000)
HydraVision (x32 Version: 4.2.114.0)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
League of Legends (x32 Version: 1.3)
Legend - Legacy Of The Dragons (Chrome)(Chrome), version 3.0.12 (x32)
LogMeIn Hamachi (x32 Version: 2.2.0.105)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Mesh Runtime (x32 Version: 15.4.5722.2)
Messenger Companion (x32 Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
Need For Speed™ World (x32 Version: 1.0.0.131)
NVIDIA PhysX (x32 Version: 9.09.0203)
OpenAL (x32)
OpenOffice.org 3.0 (x32 Version: 3.0.9358)
Overwolf (x32 Version: 0.44.256)
Pando Media Booster (x32 Version: 2.6.0.8)
PDF24 Creator 5.2.0 (x32)
PlanetSide 2 (HKCU Version: 1.0.3.183)
PunkBuster Services (x32 Version: 0.990)
Rapture3D 2.4.4 Game (x32)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5821)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.2300.0)
Skype™ 6.9 (x32 Version: 6.9.106)
TeamSpeak 3 Client (x32 Version: 3.0.13.1)
Ubisoft Game Launcher (x32 Version: 1.0.0.0)
Unity Web Player (HKCU Version: )
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Warcraft III (x32)
Warcraft III: All Products (HKCU)
WAV To MP3 V2 (x32)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinRAR archiver
==================== Restore Points =========================
12-11-2013 11:54:07 Windows Update
14-11-2013 01:43:59 Windows Update
19-11-2013 11:48:36 Windows Update
22-11-2013 11:51:44 Windows Update
26-11-2013 02:00:18 Windows Update
29-11-2013 15:58:46 Windows Update
01-12-2013 14:38:11 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
01-12-2013 14:40:00 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
01-12-2013 14:41:41 Removed Java 7 Update 45
01-12-2013 14:42:56 Installed Java 7 Update 45
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {06B433D2-FB99-42C0-BFF0-C61715C3089D} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector => Rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
Task: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
Task: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
Task: {2A6ED1F6-5671-4112-9207-09A80106B246} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => Rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
Task: {A5269147-4A7F-4748-A8B4-ACCAC317D04F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-13] (Google Inc.)
Task: {A7C73732-9F11-4281-8D19-764D4EC9D94D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe aepdu.dll,AePduRunUpdate
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
Task: {AD3248AA-E511-4EEE-BD9D-4F102787AD6B} - System32\Tasks\{FABC27FC-E434-42E9-9434-9A87C4604791} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?source=lightinstaller&page=tsMain
Task: {C1362E88-A3A2-443D-8F27-C95A4D73AC60} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-13] (Google Inc.)
Task: {CAD0B32F-C8F3-4155-8B82-9A23F3104DE4} - System32\Tasks\{368995C6-CB26-4D45-9BC0-7A1BEBBF06CF} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/abandoninstall?page=tsBing
Task: {D555A0BC-7A38-46F4-8511-70C3A6F00A38} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-15] (Adobe Systems Incorporated)
Task: {D7B6E81D-3CF4-432C-84D2-24213F4316E6} - System32\Tasks\Microsoft\Windows\Autochk\Proxy => Rundll32.exe /d acproxy.dll,PerformAutochkOperations
Task: {E22A8667-F75B-4BA9-BA46-067ED4429DE8} - System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange => Rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2009-08-28 16:08 - 2009-08-28 16:08 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-01-14 20:48 - 2010-01-14 20:48 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2010-10-12 11:21 - 2009-12-12 14:12 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2013-08-06 22:32 - 2013-08-06 22:20 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00230376 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\directsound_win32.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00237032 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win32.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00159208 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\plugins\appscanner_plugin.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00431080 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\plugins\clientquery_plugin.dll
2013-09-11 12:01 - 2013-10-24 12:37 - 00555496 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 4095.12 MB
Available physical RAM: 2618.98 MB
Total Pagefile: 8188.41 MB
Available Pagefile: 6187.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.66 GB) (Free:265.19 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: DACBA7AD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)
==================== End Of Log ============================
--- --- --- --- --- --- --- --- --- -- --- --- --- ---
Ich hab noch etwas vergessen, Entschuldigung dafür. Und zwar habe ich, glaube als aller erstes, scheinbar so ein "Rkill" laufen gelassen, wurde mir in einem YOUTUBE-Video empfohlen. da erhielt ich folgenden Log:
Code:
Rkill 2.6.3 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
hxxp://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 12/01/2013 04:51:13 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\PC\Desktop\rkill\rkill-12-01-2013-04-51-21.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
-- --- --- --- --- --- --- --- --- --- --- --- --- --- ---
Ich danke vielmals im Voraus schon und hoffe das ich niemandem zur Last falle hier.
Lg
Chiara :bussi: