Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.12.06.05
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16736
Frank :: ASUS-PC [Administrator]
06.12.2013 18:26:56
mbam-log-2013-12-06 (18-26-56).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 241179
Laufzeit: 6 Minute(n), 52 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 2
HKLM\Software\LyricsBuddy-1 (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LyricsBuddy-1 (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 2
C:\Users\Frank\AppData\Roaming\Windows Net Data (PUP.Optional.NetData.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1 (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 12
C:\$Recycle.Bin\S-1-5-21-348412604-1390753195-2502655749-1002\$R32ONDA.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\$Recycle.Bin\S-1-5-21-348412604-1390753195-2502655749-1002\$RDPVLFM.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\$Recycle.Bin\S-1-5-21-348412604-1390753195-2502655749-1002\$RRGZDZM.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\Windows Net Data\well.dat (PUP.Optional.NetData.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\41868.xpi (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\background.html (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\Installer.log (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-buttonutil.dll (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-buttonutil64.dll (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-helper.exe (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1.ico (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\Uninstall.exe (PUP.Optional.LyricsBuddy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.004 - Bericht erstellt am 20/09/2013 um 14:07:18
# Updated 15/09/2013 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Frank - ASUS-PC
# Gestartet von : C:\Users\Frank\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : BackupStack
***** [ Dateien / Ordner ] *****
[#] Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Ordner Gelöscht : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\Extensions\addon@dealplyshopping.com
Ordner Gelöscht : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojcgaoafcmbadjkfdippkdddgkeaipbn
Datei Gelöscht : C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Frank\Desktop\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\user.js
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Dealply
Datei Gelöscht : C:\WINDOWS\System32\Tasks\DealPlyUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16688
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\prefs.js ]
Zeile gelöscht : user_pref("browser.newtabpage.pinned", "[{\"url\":\"hxxp://www.dreamies.de/account.php\",\"title\":\"dreamies.de - Mein Account\"},null,{\"url\":\"hxxp://www.jappy.de/\",\"title\":\"Jappy - Deine Onli[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "14136e2c20d4395fed8afb98c80fc56c");
Zeile gelöscht : user_pref("extensions.dealply.channel", "_vitaeazel");
*************************
AdwCleaner[R0].txt - [2374 octets] - [20/09/2013 13:59:22]
AdwCleaner[R1].txt - [2434 octets] - [20/09/2013 14:03:03]
AdwCleaner[S0].txt - [2144 octets] - [20/09/2013 14:07:18]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2204 octets] ##########
--- --- ---
AdwCleaner Logfile:
Code:
# AdwCleaner v3.014 - Bericht erstellt am 06/12/2013 um 19:20:39
# Updated 01/12/2013 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Frank - ASUS-PC
# Gestartet von : C:\Users\Frank\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsBuddy-1
Schlüssel Gelöscht : HKLM\Software\Vittalia
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledThirdPartyPrograms
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Mozilla Firefox v25.0.1 (de)
[ Datei : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\xq0sob8e.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [4182 octets] - [20/09/2013 12:59:22]
AdwCleaner[R1].txt - [2434 octets] - [20/09/2013 13:03:03]
AdwCleaner[R2].txt - [954 octets] - [20/09/2013 17:15:01]
AdwCleaner[S0].txt - [3764 octets] - [20/09/2013 13:07:18]
AdwCleaner[S1].txt - [1014 octets] - [20/09/2013 17:23:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3884 octets] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8 x64
Ran by Frank on 06.12.2013 at 19:26:48,12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\xq0sob8e.default\minidumps [11 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.12.2013 at 19:30:18,71
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-12-2013
Ran by Frank (administrator) on ASUS-PC on 06-12-2013 19:34:51
Running from C:\Users\Frank\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Key Suite\AsKeySuite.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(TeamViewer GmbH) D:\Program Files (x86)\Tools\TeamViewer_Service.exe
(Samsung) C:\Program Files (x86)\Samsung\PC Auto Backup\WiselinkPro.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
() C:\Program Files (x86)\Samsung\PC Auto Backup\http_ss_win_pro.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHVE.EXE
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(Samsung) C:\Program Files (x86)\Samsung\PC Auto Backup\AutoBackup.exe
(Dropbox, Inc.) C:\Users\Frank\AppData\Roaming\Dropbox\bin\Dropbox.exe
(GLS Software & Systeme) D:\Program Files (x86)\GLS Vereinsmeister\BIN32\vminder.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6839952 2012-09-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1218704 2012-09-26] (Realtek Semiconductor)
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\ScCertProp: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Device Detector] - DevDetect.exe -autorun
HKCU\...\Run: [Windows Remote Service] - D:\Program Files (x86)\Tools\Windows Remote Service\WindowsRemoteService.exe [173568 2013-05-24] (Banamalon)
HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_YATIHVE.EXE [241280 2013-07-13] (SEIKO EPSON CORPORATION)
HKCU\...\Policies\Explorer: [DisallowRun] 1
MountPoints2: {93f7af59-14b1-11e3-be7d-08606e07ad67} - "I:\iLinker.exe"
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe [195200 2012-05-24] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\aprp.exe [3187360 2012-11-08] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUS Ai Charger] - C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [IR_SERVER] - C:\PROGRA~1\Realtek\REALTE~1\IR_SERVER.exe
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [TrayServer] - D:\Program Files (x86)\MAGIX\Video_deluxe_17_Plus\Trayserver.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [Ulead AutoDetector v2] - C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\Monitor.exe [90112 2004-11-26] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe
HKLM-x32\...\Run: [InCD] - D:\Program Files (x86)\Ahead\InCD\InCD.exe [1237042 2003-12-05] (Ahead Software AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInit64.dll [18856 2012-10-02] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll [17288 2012-10-02] (NVIDIA Corporation)
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-13.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-14.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-16.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-18.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-19.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-20.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cashcrawler.exe ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Frank\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GLS Reminder.lnk
ShortcutTarget: GLS Reminder.lnk -> D:\Program Files (x86)\GLS Vereinsmeister\BIN32\vminder.exe (GLS Software & Systeme)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = klamm.de :: Geld. News. Promotion!
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = Software Downloads - die sichere Download Quelle - GIGA
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
BHO: LyricsBuddy-1 - {11111111-1111-1111-1111-110411181168} - C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-bho64.dll No File
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\xq0sob8e.default
FF SelectedSearchEngine: benefind
FF Homepage: hxxp://klamm.de|hxxp://www.giga.de/software/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @TrendMicro.com/FFExtension - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Frank\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1164360 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-06-29] (IvoSoft)
S2 InCDsrv; d:\Program Files (x86)\Ahead\InCD\InCDsrv.exe [798772 2003-12-05] (AHEAD Software)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] ()
R2 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 TeamViewer8; D:\Program Files (x86)\Tools\TeamViewer_Service.exe [5071712 2013-09-02] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
R2 WiselinkPro; C:\Program Files (x86)\Samsung\PC Auto Backup\WiselinkPro.exe [7278657 2013-02-08] (Samsung)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-23] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [107416 2013-12-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [83160 2013-10-01] (Avira Operations GmbH & Co. KG)
S4 InCDfs; C:\Windows\SysWow64\Drivers\InCDfs.sys [89168 2003-12-05] (Ahead Software)
S1 InCDPass; C:\Windows\SysWow64\DRIVERS\InCDPass.sys [28592 2003-12-05] (Ahead Software)
U1 InCDrec; C:\Windows\SysWow64\Drivers\InCDrec.sys [9341 2003-12-05] (Ahead Software AG)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4273192 2012-08-08] (Intel Corporation)
R3 RTL2832UBDA; C:\Windows\SysWow64\drivers\RTL2832UBDA.sys [237968 2012-08-03] (REALTEK SEMICONDUCTOR Corp.)
R3 RTL2832UUSB; C:\Windows\SysWow64\Drivers\RTL2832UUSB.sys [39056 2012-08-03] (REALTEK SEMICONDUCTOR Corp.)
R3 S332x64; C:\Windows\system32\DRIVERS\S332x64.sys [78080 2012-02-27] (Identive )
S3 SPR132; C:\Windows\SysWow64\DRIVERS\SPR132.sys [181504 2003-10-10] (SCM Microsystems Inc.)
S3 SPRx32 USB Smart Card Reader; C:\Windows\SysWow64\DRIVERS\SPR332.sys [63252 2003-10-13] (SCM Microsystems Inc.)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-11-29] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-10] (Windows (R) Win 7 DDK provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-06 19:33 - 2013-12-06 19:33 - 01925820 _____ (Farbar) C:\Users\Frank\Downloads\FRST64(1).exe
2013-12-06 19:32 - 2013-12-06 19:32 - 00000000 ____D C:\Users\Frank\Downloads\FRST-OlderVersion
2013-12-06 19:30 - 2013-12-06 19:30 - 00000744 _____ C:\Users\Frank\Desktop\JRT.txt
2013-12-06 19:26 - 2013-12-06 19:26 - 01034531 _____ (Thisisu) C:\Users\Frank\Downloads\JRT.exe
2013-12-06 19:16 - 2013-12-06 19:16 - 01110034 _____ C:\Users\Frank\Downloads\adwcleaner.exe
2013-12-06 18:21 - 2013-12-06 18:21 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Frank\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-12-06 09:33 - 2013-12-06 09:34 - 00026584 _____ C:\Users\Frank\Downloads\Addition.txt
2013-12-06 09:32 - 2013-12-06 19:34 - 00018229 _____ C:\Users\Frank\Downloads\FRST.txt
2013-12-06 09:31 - 2013-12-06 19:32 - 00000000 ____D C:\FRST
2013-12-06 09:29 - 2013-12-06 19:32 - 01925820 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\Downloads\3D-Frohe-Weihnachten-Bildschirmschoner
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\ChromeExtensions
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\AppData\Local\Tempf1b09f9d4f56205b12c8aa296444f2c4
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\AppData\Local\Temp767ce401cf9dd9115d3e165fd5927ce0
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\AppData\Local\Temp12517f93434a0c7f0c87a34b7af03b46
2013-12-04 12:55 - 2005-10-21 14:27 - 09293824 _____ C:\WINDOWS\SysWOW64\Christmas Time 3D Screensaver.scr
2013-12-04 10:11 - 2013-12-04 10:11 - 00000000 ____D C:\Users\Frank\Downloads\James_Blunt-Moon_Landing-2013-VOiCE
2013-12-04 09:52 - 2013-12-04 09:56 - 91475441 _____ C:\Users\Frank\Downloads\James_Blunt-Moon_Landing-2013-VOiCE.rar
2013-12-02 19:58 - 2013-12-02 19:58 - 05629632 _____ (IvoSoft) C:\Users\Frank\Downloads\ClassicShellSetup_4_0_2(1).exe
2013-12-02 12:05 - 2013-12-02 12:05 - 00943872 _____ C:\Users\Frank\Downloads\3D-Frohe-Weihnachten-Bildschirmschoner-Setup.exe
2013-12-02 12:00 - 2013-12-02 12:00 - 01400499 _____ C:\Users\Frank\Downloads\discobaby.exe
2013-11-30 16:29 - 2013-11-30 16:31 - 00000000 ____D C:\Users\Frank\Downloads\Family_Of_The_Year-Loma_Vista-2012-C4
2013-11-30 16:23 - 2013-11-30 16:28 - 81594079 _____ C:\Users\Frank\Downloads\Family_Of_The_Year-Loma_Vista-2012-C4.rar
2013-11-28 12:57 - 2013-11-28 12:57 - 00000915 _____ C:\Users\Public\Desktop\GLS Vereinsmeister.lnk
2013-11-28 12:56 - 2013-11-28 12:56 - 21356256 _____ (GLS Software & Systeme ) C:\Users\Frank\Downloads\vm6update.exe
2013-11-27 11:12 - 2013-11-27 11:12 - 00548792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-25 19:06 - 2013-11-25 19:07 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Notepad++
2013-11-25 19:06 - 2013-11-25 19:06 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2013-11-25 18:45 - 2013-11-25 18:45 - 00048864 _____ C:\Users\Frank\Downloads\feedback_0.31.zip
2013-11-25 18:44 - 2013-11-25 18:44 - 00259153 _____ C:\Users\Frank\Downloads\dirList_0.22.zip
2013-11-25 18:41 - 2013-11-25 18:41 - 00099163 _____ C:\Users\Frank\Downloads\calendar_v2.0.zip
2013-11-25 18:41 - 2013-11-25 18:41 - 00086448 _____ C:\Users\Frank\Downloads\bookings_v2.33.zip
2013-11-25 18:24 - 2013-11-25 18:24 - 05629632 _____ (IvoSoft) C:\Users\Frank\Downloads\ClassicShellSetup_4_0_2.exe
2013-11-25 11:26 - 2013-11-25 11:26 - 00462733 _____ C:\Users\Frank\Downloads\thmax_grafiken_adventskranz.zip
2013-11-25 08:52 - 2013-11-25 08:56 - 00000000 ____D C:\Users\Frank\AppData\Roaming\MOBackup
2013-11-25 08:47 - 2013-11-25 08:47 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MOBackup - Datensicherung für Outlook
2013-11-25 08:46 - 2013-11-25 08:46 - 03095015 _____ C:\Users\Frank\Downloads\mobackup-share(1).exe
2013-11-24 13:06 - 2013-11-24 13:06 - 05425008 _____ (MAGIX AG) C:\Users\Frank\Downloads\vdx17plus_videoplugins_de.exe
2013-11-24 09:41 - 2013-11-24 09:41 - 00117691 _____ C:\Users\Frank\Downloads\lyps.zip
2013-11-24 09:36 - 2013-11-24 09:36 - 00045146 _____ C:\Users\Frank\Downloads\compani.zip
2013-11-24 09:35 - 2013-11-24 09:35 - 00227618 _____ C:\Users\Frank\Downloads\danfuh-business01_v0.3.zip
2013-11-24 09:33 - 2013-11-24 09:33 - 00111171 _____ C:\Users\Frank\Downloads\intwerb_2.de.zip
2013-11-24 09:33 - 2013-11-24 09:33 - 00054486 _____ C:\Users\Frank\Downloads\JoomlaNation.zip
2013-11-24 09:33 - 2013-11-24 09:33 - 00045805 _____ C:\Users\Frank\Downloads\intwerb.de(1).zip
2013-11-24 09:25 - 2013-11-24 09:25 - 00034780 _____ C:\Users\Frank\Downloads\NatureWeb4.zip
2013-11-24 09:24 - 2013-11-24 09:24 - 00045804 _____ C:\Users\Frank\Downloads\intwerb.de.zip
2013-11-24 09:14 - 2013-11-24 09:14 - 00078946 _____ C:\Users\Frank\Downloads\pinzsimple-left.zip
2013-11-21 12:16 - 2013-11-21 12:16 - 00000000 ____D C:\Users\Frank\Downloads\benefind_logos(1)
2013-11-21 12:15 - 2013-11-21 12:15 - 00101495 _____ C:\Users\Frank\Downloads\benefind_logos(1).zip
2013-11-20 17:18 - 2013-11-20 17:18 - 00000053 _____ C:\Users\Frank\Downloads\google4384af50ab5a28e7.html
2013-11-16 10:01 - 2013-11-16 10:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 18:43 - 2013-12-05 18:12 - 00000000 ___HD C:\Users\Frank\Downloads\[Originaldateien]
2013-11-15 18:34 - 2013-11-15 18:43 - 00009762 _____ C:\Users\Frank\Downloads\qrcode(2).jpeg
2013-11-15 18:07 - 2013-11-15 18:07 - 00011342 _____ C:\Users\Frank\Downloads\qrcode(1).jpeg
2013-11-15 17:40 - 2013-11-15 17:40 - 00010056 _____ C:\Users\Frank\Downloads\qrcode.jpeg
2013-11-14 16:16 - 2013-11-14 16:16 - 00000783 _____ C:\Users\UpdatusUser\Desktop\Shortcut to The Logo Creator v3.exe.lnk
2013-11-14 16:16 - 2013-11-14 16:16 - 00000783 _____ C:\Users\Frank\Desktop\Shortcut to The Logo Creator v3.exe.lnk
2013-11-14 16:16 - 2013-11-14 16:16 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Logo Creator v3
2013-11-14 16:16 - 2003-03-15 22:15 - 00090112 _____ (MindVision Software) C:\WINDOWS\unvise32.exe
2013-11-14 10:08 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-14 10:08 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-14 10:08 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-14 10:08 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-14 10:08 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-14 10:08 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-14 10:08 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-14 10:08 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2013-11-14 10:08 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-11-14 10:08 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-14 10:08 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-14 10:08 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-14 10:08 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-14 10:08 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-14 10:08 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-14 10:08 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2013-11-14 10:08 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2013-11-14 10:08 - 2013-10-10 12:53 - 00096600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-14 10:08 - 2013-10-10 10:21 - 01160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-14 10:08 - 2013-10-10 10:20 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-14 10:08 - 2013-10-03 00:25 - 01300992 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-14 10:08 - 2013-10-02 00:37 - 01569280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-14 10:08 - 2013-10-02 00:26 - 01890816 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-14 10:08 - 2013-10-01 23:22 - 01022976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-14 10:08 - 2013-09-23 23:30 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2013-11-14 10:08 - 2013-09-23 23:30 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2013-11-14 10:08 - 2013-09-14 02:15 - 00059416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-14 10:08 - 2013-09-13 23:36 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2013-11-14 10:08 - 2013-09-13 23:36 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ubpm.dll
2013-11-14 10:08 - 2013-09-13 23:36 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2013-11-14 10:08 - 2013-09-13 23:36 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2013-11-14 10:08 - 2013-09-13 23:36 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2013-11-14 10:08 - 2013-09-13 23:34 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2013-11-14 10:08 - 2013-09-13 23:33 - 03279360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-14 10:08 - 2013-09-13 23:33 - 01622016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-14 10:08 - 2013-09-13 23:33 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2013-11-14 10:08 - 2013-09-13 23:33 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2013-11-14 10:08 - 2013-09-13 23:33 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-14 10:08 - 2013-09-13 23:33 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2013-11-14 10:08 - 2013-09-13 23:33 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2013-11-14 10:08 - 2013-09-13 23:33 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2013-11-14 10:08 - 2013-09-04 04:11 - 00576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2013-11-14 10:08 - 2013-08-30 06:43 - 00061784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2013-11-14 10:08 - 2013-08-30 06:20 - 01173504 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-14 10:08 - 2013-08-30 00:48 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2013-11-14 10:08 - 2013-08-23 08:22 - 02062848 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-14 10:08 - 2013-08-23 02:44 - 01711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-14 10:08 - 2013-08-21 07:39 - 00465240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2013-11-14 10:08 - 2013-08-10 07:30 - 00151896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2013-11-14 10:08 - 2013-08-10 06:21 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2013-11-14 10:08 - 2013-08-10 04:58 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2013-11-14 10:08 - 2013-07-25 00:10 - 10799104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-14 10:08 - 2013-07-25 00:07 - 13661696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-14 10:08 - 2013-07-12 02:38 - 00599040 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2013-11-14 10:08 - 2013-07-12 02:30 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2013-11-14 10:07 - 2013-10-02 00:37 - 02035712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2013-11-14 10:07 - 2013-10-02 00:26 - 02304512 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-11 13:04 - 2013-11-11 13:04 - 00000000 ____D C:\Users\Frank\Downloads\Linkin_Park-Recharged-_28Proper%29-2013-MTD(1)
2013-11-11 13:01 - 2013-11-11 13:04 - 127716384 _____ C:\Users\Frank\Downloads\Linkin_Park-Recharged-%28Proper%29-2013-MTD(1).rar
2013-11-11 12:57 - 2013-11-11 12:58 - 00000000 ____D C:\Users\Frank\Downloads\Al_20Stewart_20-_20Indian_20summer_20%201981
2013-11-11 12:56 - 2013-11-11 12:58 - 00000000 ____D C:\Users\Frank\Downloads\AlSChro
2013-11-11 12:56 - 2013-11-11 12:58 - 00000000 ____D C:\Users\Frank\Downloads\Al_20Stewart_20-_20Year_20Of_20The%20Cat
2013-11-11 12:56 - 2013-11-11 12:57 - 00000000 ____D C:\Users\Frank\Downloads\as
2013-11-11 12:32 - 2013-11-11 12:36 - 127712708 _____ C:\Users\Frank\Downloads\Linkin_Park-Recharged-%28Proper%29-2013-MTD.rar
2013-11-11 12:31 - 2013-11-11 12:34 - 96692104 _____ C:\Users\Frank\Downloads\Al%20Stewart%20-%20Indian%20summer%20%201981.rar
2013-11-11 12:18 - 2013-11-11 12:21 - 70531565 _____ C:\Users\Frank\Downloads\AlSChro.rar
2013-11-11 12:17 - 2013-11-11 12:21 - 68698867 _____ C:\Users\Frank\Downloads\as.rar
2013-11-11 12:16 - 2013-11-11 12:18 - 64618432 _____ C:\Users\Frank\Downloads\Al%20Stewart%20-%20Year%20Of%20The%20Cat.rar
==================== One Month Modified Files and Folders =======
2013-12-06 19:35 - 2013-12-06 09:32 - 00018229 _____ C:\Users\Frank\Downloads\FRST.txt
2013-12-06 19:34 - 2012-12-04 07:31 - 01719895 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-06 19:33 - 2013-12-06 19:33 - 01925820 _____ (Farbar) C:\Users\Frank\Downloads\FRST64(1).exe
2013-12-06 19:32 - 2013-12-06 19:32 - 00000000 ____D C:\Users\Frank\Downloads\FRST-OlderVersion
2013-12-06 19:32 - 2013-12-06 09:31 - 00000000 ____D C:\FRST
2013-12-06 19:32 - 2013-12-06 09:29 - 01925820 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe
2013-12-06 19:30 - 2013-12-06 19:30 - 00000744 _____ C:\Users\Frank\Desktop\JRT.txt
2013-12-06 19:26 - 2013-12-06 19:26 - 01034531 _____ (Thisisu) C:\Users\Frank\Downloads\JRT.exe
2013-12-06 19:26 - 2013-07-13 18:09 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-348412604-1390753195-2502655749-1002
2013-12-06 19:26 - 2012-11-08 04:31 - 00756440 _____ C:\WINDOWS\system32\perfh007.dat
2013-12-06 19:26 - 2012-11-08 04:31 - 00157166 _____ C:\WINDOWS\system32\perfc007.dat
2013-12-06 19:26 - 2012-07-26 08:28 - 01757438 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-06 19:22 - 2013-10-23 14:15 - 00000374 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2013-12-06 19:22 - 2013-08-02 10:44 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Dropbox
2013-12-06 19:21 - 2012-12-04 07:31 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-06 19:21 - 2012-07-26 08:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-06 19:20 - 2013-09-20 12:58 - 00000000 ____D C:\AdwCleaner
2013-12-06 19:20 - 2013-07-13 18:01 - 00000000 ___RD C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-06 19:16 - 2013-12-06 19:16 - 01110034 _____ C:\Users\Frank\Downloads\adwcleaner.exe
2013-12-06 19:08 - 2012-11-08 05:15 - 01025012 _____ C:\WINDOWS\PFRO.log
2013-12-06 19:07 - 2012-07-26 06:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-12-06 19:06 - 2013-07-21 10:40 - 00000000 ____D C:\Users\Frank\Documents\2013
2013-12-06 19:00 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\sru
2013-12-06 18:40 - 2013-07-14 07:48 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-06 18:21 - 2013-12-06 18:21 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Frank\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-12-06 09:34 - 2013-12-06 09:33 - 00026584 _____ C:\Users\Frank\Downloads\Addition.txt
2013-12-05 19:40 - 2013-09-27 08:45 - 00000000 ____D C:\Users\Frank\AppData\Roaming\GLS Vereinsmeister
2013-12-05 19:39 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2013-12-05 18:13 - 2013-07-18 10:50 - 00449536 ___SH C:\Users\Frank\Downloads\Thumbs.db
2013-12-05 18:12 - 2013-11-15 18:43 - 00000000 ___HD C:\Users\Frank\Downloads\[Originaldateien]
2013-12-05 11:12 - 2013-07-16 11:39 - 00000000 ____D C:\Program Files (x86)\StarMoney 8.0 S-Edition
2013-12-05 11:12 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-12-04 18:36 - 2013-07-21 11:42 - 00000000 ____D C:\Users\Frank\Documents\Turbo Lister Backup
2013-12-04 18:36 - 2013-07-19 11:07 - 00000000 ____D C:\Users\Frank\AppData\Roaming\FileZilla
2013-12-04 16:03 - 2013-09-26 15:00 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2013-12-04 13:39 - 2013-07-17 08:45 - 00000000 ____D C:\Users\Frank\Documents\1 Exel Tabellen
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\Downloads\3D-Frohe-Weihnachten-Bildschirmschoner
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\ChromeExtensions
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\AppData\Local\Tempf1b09f9d4f56205b12c8aa296444f2c4
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\AppData\Local\Temp767ce401cf9dd9115d3e165fd5927ce0
2013-12-04 12:59 - 2013-12-04 12:59 - 00000000 ____D C:\Users\Frank\AppData\Local\Temp12517f93434a0c7f0c87a34b7af03b46
2013-12-04 12:59 - 2013-07-13 17:59 - 00000000 ____D C:\Users\Frank
2013-12-04 11:47 - 2013-07-20 10:50 - 00001233 _____ C:\Users\Frank\Documents\1gb.txt
2013-12-04 10:11 - 2013-12-04 10:11 - 00000000 ____D C:\Users\Frank\Downloads\James_Blunt-Moon_Landing-2013-VOiCE
2013-12-04 09:56 - 2013-12-04 09:52 - 91475441 _____ C:\Users\Frank\Downloads\James_Blunt-Moon_Landing-2013-VOiCE.rar
2013-12-03 15:10 - 2013-07-21 10:27 - 00000000 ____D C:\Users\Frank\Documents\Blankenburg
2013-12-03 11:00 - 2013-07-14 17:33 - 00107416 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2013-12-02 19:58 - 2013-12-02 19:58 - 05629632 _____ (IvoSoft) C:\Users\Frank\Downloads\ClassicShellSetup_4_0_2(1).exe
2013-12-02 17:54 - 2013-07-18 09:29 - 00019968 _____ C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-02 12:05 - 2013-12-02 12:05 - 00943872 _____ C:\Users\Frank\Downloads\3D-Frohe-Weihnachten-Bildschirmschoner-Setup.exe
2013-12-02 12:00 - 2013-12-02 12:00 - 01400499 _____ C:\Users\Frank\Downloads\discobaby.exe
2013-11-30 16:31 - 2013-11-30 16:29 - 00000000 ____D C:\Users\Frank\Downloads\Family_Of_The_Year-Loma_Vista-2012-C4
2013-11-30 16:28 - 2013-11-30 16:23 - 81594079 _____ C:\Users\Frank\Downloads\Family_Of_The_Year-Loma_Vista-2012-C4.rar
2013-11-28 12:57 - 2013-11-28 12:57 - 00000915 _____ C:\Users\Public\Desktop\GLS Vereinsmeister.lnk
2013-11-28 12:56 - 2013-11-28 12:56 - 21356256 _____ (GLS Software & Systeme ) C:\Users\Frank\Downloads\vm6update.exe
2013-11-27 11:57 - 2013-07-17 17:32 - 00000000 ____D C:\Users\Frank\Documents\BVB
2013-11-27 11:12 - 2013-11-27 11:12 - 00548792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-27 11:12 - 2013-09-22 16:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-25 19:07 - 2013-11-25 19:06 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Notepad++
2013-11-25 19:06 - 2013-11-25 19:06 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2013-11-25 18:45 - 2013-11-25 18:45 - 00048864 _____ C:\Users\Frank\Downloads\feedback_0.31.zip
2013-11-25 18:44 - 2013-11-25 18:44 - 00259153 _____ C:\Users\Frank\Downloads\dirList_0.22.zip
2013-11-25 18:41 - 2013-11-25 18:41 - 00099163 _____ C:\Users\Frank\Downloads\calendar_v2.0.zip
2013-11-25 18:41 - 2013-11-25 18:41 - 00086448 _____ C:\Users\Frank\Downloads\bookings_v2.33.zip
2013-11-25 18:24 - 2013-11-25 18:24 - 05629632 _____ (IvoSoft) C:\Users\Frank\Downloads\ClassicShellSetup_4_0_2.exe
2013-11-25 11:26 - 2013-11-25 11:26 - 00462733 _____ C:\Users\Frank\Downloads\thmax_grafiken_adventskranz.zip
2013-11-25 09:01 - 2013-07-16 11:30 - 00000000 ____D C:\Users\Frank\Documents\mobackups
2013-11-25 08:56 - 2013-11-25 08:52 - 00000000 ____D C:\Users\Frank\AppData\Roaming\MOBackup
2013-11-25 08:47 - 2013-11-25 08:47 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MOBackup - Datensicherung für Outlook
2013-11-25 08:47 - 2013-07-15 08:51 - 00001044 _____ C:\Users\Public\Desktop\MOBackup.lnk
2013-11-25 08:46 - 2013-11-25 08:46 - 03095015 _____ C:\Users\Frank\Downloads\mobackup-share(1).exe
2013-11-24 13:06 - 2013-11-24 13:06 - 05425008 _____ (MAGIX AG) C:\Users\Frank\Downloads\vdx17plus_videoplugins_de.exe
2013-11-24 09:41 - 2013-11-24 09:41 - 00117691 _____ C:\Users\Frank\Downloads\lyps.zip
2013-11-24 09:36 - 2013-11-24 09:36 - 00045146 _____ C:\Users\Frank\Downloads\compani.zip
2013-11-24 09:35 - 2013-11-24 09:35 - 00227618 _____ C:\Users\Frank\Downloads\danfuh-business01_v0.3.zip
2013-11-24 09:33 - 2013-11-24 09:33 - 00111171 _____ C:\Users\Frank\Downloads\intwerb_2.de.zip
2013-11-24 09:33 - 2013-11-24 09:33 - 00054486 _____ C:\Users\Frank\Downloads\JoomlaNation.zip
2013-11-24 09:33 - 2013-11-24 09:33 - 00045805 _____ C:\Users\Frank\Downloads\intwerb.de(1).zip
2013-11-24 09:25 - 2013-11-24 09:25 - 00034780 _____ C:\Users\Frank\Downloads\NatureWeb4.zip
2013-11-24 09:24 - 2013-11-24 09:24 - 00045804 _____ C:\Users\Frank\Downloads\intwerb.de.zip
2013-11-24 09:14 - 2013-11-24 09:14 - 00078946 _____ C:\Users\Frank\Downloads\pinzsimple-left.zip
2013-11-21 12:16 - 2013-11-21 12:16 - 00000000 ____D C:\Users\Frank\Downloads\benefind_logos(1)
2013-11-21 12:15 - 2013-11-21 12:15 - 00101495 _____ C:\Users\Frank\Downloads\benefind_logos(1).zip
2013-11-20 17:18 - 2013-11-20 17:18 - 00000053 _____ C:\Users\Frank\Downloads\google4384af50ab5a28e7.html
2013-11-20 09:51 - 2013-07-14 07:48 - 00000000 ____D C:\Users\Frank\AppData\Local\Adobe
2013-11-20 09:38 - 2013-07-14 07:48 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2013-11-19 16:32 - 2013-07-14 17:33 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2013-11-17 12:34 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\rescache
2013-11-16 14:39 - 2012-07-26 09:12 - 00000000 ___RD C:\WINDOWS\ToastData
2013-11-16 14:39 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-16 10:01 - 2013-11-16 10:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 18:43 - 2013-11-15 18:34 - 00009762 _____ C:\Users\Frank\Downloads\qrcode(2).jpeg
2013-11-15 18:07 - 2013-11-15 18:07 - 00011342 _____ C:\Users\Frank\Downloads\qrcode(1).jpeg
2013-11-15 17:40 - 2013-11-15 17:40 - 00010056 _____ C:\Users\Frank\Downloads\qrcode.jpeg
2013-11-14 17:59 - 2012-07-26 08:21 - 00023618 _____ C:\WINDOWS\setupact.log
2013-11-14 16:16 - 2013-11-14 16:16 - 00000783 _____ C:\Users\UpdatusUser\Desktop\Shortcut to The Logo Creator v3.exe.lnk
2013-11-14 16:16 - 2013-11-14 16:16 - 00000783 _____ C:\Users\Frank\Desktop\Shortcut to The Logo Creator v3.exe.lnk
2013-11-14 16:16 - 2013-11-14 16:16 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Logo Creator v3
2013-11-14 16:14 - 2013-07-14 15:46 - 00000537 _____ C:\Users\Frank\Desktop\Asus.txt
2013-11-14 11:46 - 2013-07-19 09:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 11:43 - 2013-07-14 07:53 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-11 13:04 - 2013-11-11 13:04 - 00000000 ____D C:\Users\Frank\Downloads\Linkin_Park-Recharged-_28Proper%29-2013-MTD(1)
2013-11-11 13:04 - 2013-11-11 13:01 - 127716384 _____ C:\Users\Frank\Downloads\Linkin_Park-Recharged-%28Proper%29-2013-MTD(1).rar
2013-11-11 12:58 - 2013-11-11 12:57 - 00000000 ____D C:\Users\Frank\Downloads\Al_20Stewart_20-_20Indian_20summer_20%201981
2013-11-11 12:58 - 2013-11-11 12:56 - 00000000 ____D C:\Users\Frank\Downloads\AlSChro
2013-11-11 12:58 - 2013-11-11 12:56 - 00000000 ____D C:\Users\Frank\Downloads\Al_20Stewart_20-_20Year_20Of_20The%20Cat
2013-11-11 12:57 - 2013-11-11 12:56 - 00000000 ____D C:\Users\Frank\Downloads\as
2013-11-11 12:36 - 2013-11-11 12:32 - 127712708 _____ C:\Users\Frank\Downloads\Linkin_Park-Recharged-%28Proper%29-2013-MTD.rar
2013-11-11 12:34 - 2013-11-11 12:31 - 96692104 _____ C:\Users\Frank\Downloads\Al%20Stewart%20-%20Indian%20summer%20%201981.rar
2013-11-11 12:21 - 2013-11-11 12:18 - 70531565 _____ C:\Users\Frank\Downloads\AlSChro.rar
2013-11-11 12:21 - 2013-11-11 12:17 - 68698867 _____ C:\Users\Frank\Downloads\as.rar
2013-11-11 12:18 - 2013-11-11 12:16 - 64618432 _____ C:\Users\Frank\Downloads\Al%20Stewart%20-%20Year%20Of%20The%20Cat.rar
2013-11-10 18:22 - 2013-11-03 10:09 - 00000000 ____D C:\Users\Frank\Documents\1Marion
Some content of TEMP:
====================
C:\Users\Frank\AppData\Local\Temp\amazonicon_v3.exe
C:\Users\Frank\AppData\Local\Temp\amazoninstallernircmdc.exe
C:\Users\Frank\AppData\Local\Temp\avgnt.exe
C:\Users\Frank\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Frank\AppData\Local\Temp\Quarantine.exe
C:\Users\Frank\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Frank\AppData\Local\Temp\sdapskill.exe
C:\Users\Frank\AppData\Local\Temp\sHID.dll
C:\Users\Frank\AppData\Local\Temp\vis-de.exe
C:\Users\Frank\AppData\Local\Temp\xmlUpdater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-28 11:18
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
alles erledigt, nur ist der fehler noch nicht behoben :-(