Soo hier sind die nächsten Files :) Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by KomaKuh at 2014-04-01 17:59:47 Run:1
Running from C:\Users\KomaKuh\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
R2 desksvc; C:\Program Files (x86)\Desk 365\deskSvc.exe [425008 2014-03-31] (337 Technology Limited.)
R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [515584 2014-03-17] (Cherished Technololgy LIMITED)
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [496640 2014-03-31] (Cherished Technololgy LIMITED)
(Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginService\PluginService.exe
(337 Technology Limited.) C:\Program Files (x86)\Desk 365\deskSvc.exe
HKU\.DEFAULT\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [Desk 365] - C:\Program Files (x86)\Desk 365\desk365.exe [1017904 2014-03-31] (337 Technology Limited.)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-31]
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Desk 365
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\WPM
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\IePluginService
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\Desk 365
2014-03-31 19:16 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-31 19:15 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Oxy
2014-03-30 20:38 - 2014-03-30 20:54 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\qone8
2014-03-30 20:36 - 2014-03-30 20:36 - 00003604 _____ () C:\Windows\System32\Tasks\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00003576 _____ () C:\Windows\System32\Tasks\PileFile reminder
2014-03-30 20:36 - 2014-03-30 20:36 - 00003174 _____ () C:\Windows\System32\Tasks\PileFile logon
Task: {BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} - System32\Tasks\Oxy => C:\Users\KomaKuh\AppData\Roaming\Oxy\Updater.exe [2014-03-30] () <==== ATTENTION
*****************
desksvc => Service stopped successfully.
desksvc => Service deleted successfully.
IePluginService => Service stopped successfully.
IePluginService => Service deleted successfully.
Wpm => Service stopped successfully.
Wpm => Service deleted successfully.
C:\ProgramData\WPM\wprotectmanager.exe => No running process found
C:\ProgramData\IePluginService\PluginService.exe => No running process found
C:\Program Files (x86)\Desk 365\deskSvc.exe => No running process found
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInternetOpenWith => Value deleted successfully.
HKU\S-1-5-21-268757211-819875313-238986870-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Desk 365 => Value deleted successfully.
HKU\S-1-5-21-268757211-819875313-238986870-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInternetOpenWith => Value deleted successfully.
"C:\\PROGRA~2\\SupTab\\SEARCH~2.DLL" => Value Data removed successfully.
"C:\\PROGRA~2\\SupTab\\SEARCH~1.DLL" => Value Data removed successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully.
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma => Key deleted successfully.
C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\SupTab => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\Desk 365 => Moved successfully.
C:\ProgramData\WPM => Moved successfully.
C:\ProgramData\IePluginService => Moved successfully.
C:\Program Files (x86)\SupTab => Moved successfully.
C:\Program Files (x86)\Desk 365 => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\Oxy => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\qone8 => Moved successfully.
C:\Windows\System32\Tasks\Oxy => Moved successfully.
C:\Windows\System32\Tasks\PileFile reminder => Moved successfully.
C:\Windows\System32\Tasks\PileFile logon => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} => Key deleted successfully.
C:\Windows\System32\Tasks\Oxy not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Oxy => Key deleted successfully.
==== End of Fixlog ==== Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 01.04.2014
Suchlauf-Zeit: 18:32:24
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.01.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: KomaKuh
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 270664
Verstrichene Zeit: 16 Min, 6 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 1
Trojan.Clicker, C:\Users\KomaKuh\AppData\Local\GCC\Controller.exe, 4408, Löschen bei Neustart, [52aec63a39c751af7bec0a9fe61d13ed]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 3
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [738de91729d7bb4507165fab19e99a66],
PUP.Optional.Qone8.A, HKLM\SOFTWARE\WOW6432NODE\qone8Software, In Quarantäne, [3fc1cf319769cb35a8ef3b4ffd06db25],
PUP.Optional.Desk365.A, HKLM\SOFTWARE\WOW6432NODE\V9\Desk 365, In Quarantäne, [d828c33dde22718f17c0006c2dd5a55b],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 18
PUP.Optional.Desk365.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365, In Quarantäne, [728ed7290df34db3a8e988f8b44ffb05],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\en_us, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\es_es, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\pt_br, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\tr_tr, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\zh_cn, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\zh_tw, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\style, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
Dateien: 65
Trojan.Clicker, C:\Users\KomaKuh\AppData\Local\GCC\Controller.exe, Löschen bei Neustart, [52aec63a39c751af7bec0a9fe61d13ed],
Trojan.Clicker, C:\Users\KomaKuh\AppData\Local\Temp\GCSetup_mk.exe, In Quarantäne, [fb05e41c29d7659b56111f8a22e1dd23],
PUP.Optional.Amonetize.A, C:\Users\KomaKuh\AppData\Local\Temp\OxyBrowserUpdater__3338_i491892894_il6465765.exe, In Quarantäne, [38c8837dbd43c040065480bc18e816ea],
PUP.Optional.Amonetize.A, C:\Users\KomaKuh\AppData\Local\Temp\setup.exe, In Quarantäne, [db2519e7718f0af65703bd7f0bf510f0],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\alilog.dll, In Quarantäne, [55ab34cca25e718f2be864cec9375ea2],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\package1.zip, In Quarantäne, [817f43bd7e8251af987b43ef5da3dd23],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\tmp\desk365.exe, In Quarantäne, [5ea26d934fb16f91b8e751bbed1434cc],
PUP.Optional.SupTab.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\tmp\SupTab.exe, In Quarantäne, [38c84bb532ce58a881caed48e41c827e],
PUP.Optional.WpManager, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\tmp\wpm.exe, In Quarantäne, [3fc1be42da26af51840695c3e9180cf4],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\alilog.dll, In Quarantäne, [e41c29d7f40c4fb1d43fa092c43c17e9],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\package1.zip, In Quarantäne, [21dfcb3507f9b14f31e2be7432ce2ad6],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\tmp\desk365.exe, In Quarantäne, [7e829f61b74919e7d9c662aae61bd62a],
PUP.Optional.SupTab.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\tmp\SupTab.exe, In Quarantäne, [7987a15fde2256aacc7f2e0728d8c43c],
PUP.Optional.WpManager, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\tmp\wpm.exe, In Quarantäne, [32ce10f028d8827e4743f068748dff01],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\tmp70FD\mp3_qone8.exe, In Quarantäne, [8d7327d9f40c06fa9e9ae965a65b19e7],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\tmp896D\mp3_qone8.exe, In Quarantäne, [44bc2ad6fb057789063275d955ac05fb],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\eInstall.exe, In Quarantäne, [5ea2ff0123dd5da308975daf28d96e92],
PUP.Optional.Desk365.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365\eUninstall.lnk, In Quarantäne, [728ed7290df34db3a8e988f8b44ffb05],
PUP.Optional.Desk365.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365\Desk 365.lnk, In Quarantäne, [728ed7290df34db3a8e988f8b44ffb05],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\SendTo\Desk 365.lnk, In Quarantäne, [8080ac542dd3fe02bb446026a95aff01],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\main, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\msvcp100.dll, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\msvcr100.dll, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\segoeui.ttf, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\segoeuib.ttf, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\app_icon.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\change_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\combo_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\edit_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_back.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_button_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_checked.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_intermediate.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_uncheck.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_logo.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_resource.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\patch_file_icon.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-error.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-info.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-question.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-warning.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\popup_dialog_bk.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\progressbar_bk.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\progressbar_image.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\radio_normal.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\radio_selected.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\sys_close.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\4zip.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\AirZip.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\edesk.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\gamelogin.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\protocol.txt, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\en_us\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\es_es\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\pt_br\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\tr_tr\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\eDeskInstall.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\gamelogin.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\install_msgbox.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\languageSelect.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\uninstgl.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\style\install_style.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\icudt.dll, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\libcef.dll, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales\en-US.pak, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=61e6d2c0060cb74c9137d571bd660410
# engine=17709
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-01 06:07:21
# local_time=2014-04-01 08:07:21 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 11943964 148005491 0 0
# scanned=253981
# found=0
# cleaned=0
# scan_time=4879
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by KomaKuh (administrator) on KOMAKUH-PC on 01-04-2014 20:16:05
Running from C:\Users\KomaKuh\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(SlySoft, Inc.) C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\swriter.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
(Microsoft Corporation) C:\Windows\splwow64.exe
() C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ProfilerU] - C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] - C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM-x32\...\Run: [CloneCDTray] - C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKU\.DEFAULT\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\.DEFAULT\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [380928 2009-06-14] (AMD)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\MountPoints2: {0b1400c0-4adb-11e3-9f77-806e6f6e6963} - D:\SETUP.EXE
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFA610428EBDECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - DefaultScope {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/de
CHR Extension: (Google Docs) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-11]
CHR Extension: (Google Drive) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-11]
CHR Extension: (YouTube) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-11]
CHR Extension: (Adblock Plus) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-11]
CHR Extension: (Google-Suche) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-11]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2013-11-26]
CHR Extension: (Google Wallet) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-11]
CHR Extension: (Google Mail) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-11]
CHR StartMenuInternet: Google Chrome - Chrome.exe
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [766736 2014-02-18] (BlueStack Systems, Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [98560 2014-02-16] (Overwolf LTD)
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122128 2014-02-18] (BlueStack Systems)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-01] (Malwarebytes Corporation)
R3 SaiK1703; C:\Windows\System32\DRIVERS\SaiK1703.sys [180544 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
R3 SaiU1703; C:\Windows\System32\DRIVERS\SaiU1703.sys [47168 2012-09-20] (Saitek)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
U4 SR;
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-01 18:38 - 2014-04-01 18:38 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-01 18:37 - 2014-04-01 18:37 - 02347384 _____ (ESET) C:\Users\KomaKuh\Downloads\esetsmartinstaller_enu.exe
2014-04-01 18:35 - 2014-04-01 18:35 - 00014255 _____ () C:\Users\KomaKuh\Desktop\MBAM.txt
2014-04-01 18:33 - 2014-04-01 18:33 - 00023712 _____ () C:\Windows\PFRO.log
2014-04-01 18:14 - 2014-04-01 18:34 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-01 18:14 - 2014-04-01 18:34 - 00001098 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-01 18:14 - 2014-04-01 18:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-01 18:14 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-01 18:14 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-01 18:10 - 2014-04-01 18:13 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\KomaKuh\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-31 20:37 - 2014-04-01 18:33 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\GCC
2014-03-31 20:37 - 2014-03-31 20:37 - 00004534 _____ () C:\Windows\System32\Tasks\GC_Scheduler
2014-03-31 19:55 - 2014-04-01 20:16 - 00009786 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-03-31 19:30 - 2014-03-31 19:30 - 00018048 _____ () C:\Users\KomaKuh\Downloads\Benotungsschema Praktikumsmappe 9.odt
2014-03-31 19:16 - 2014-03-31 19:53 - 07376130 _____ () C:\Users\KomaKuh\Desktop\SystemLook.txt
2014-03-31 19:15 - 2014-03-31 19:15 - 00165376 _____ () C:\Users\KomaKuh\Desktop\SystemLook_x64.exe
2014-03-31 19:11 - 2014-03-31 19:14 - 00000000 ____D () C:\AdwCleaner
2014-03-31 19:09 - 2014-03-31 19:12 - 00000475 _____ () C:\Users\KomaKuh\Desktop\Neues Textdokument (4).txt
2014-03-31 19:09 - 2014-03-31 19:09 - 01950720 _____ () C:\Users\KomaKuh\Desktop\adwcleaner.exe
2014-03-31 15:48 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appadaumen.de
2014-03-31 15:47 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\Downloads\mausi 3
2014-03-31 15:47 - 2014-03-31 15:47 - 00270615 _____ () C:\Users\KomaKuh\Downloads\Mausi3.zip
2014-03-31 15:27 - 2014-03-31 15:28 - 00000000 ____D () C:\Users\KomaKuh\Desktop\saves FRST
2014-03-31 14:40 - 2014-04-01 18:33 - 00000336 _____ () C:\Windows\setupact.log
2014-03-31 14:40 - 2014-03-31 14:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-30 21:59 - 2014-04-01 20:16 - 00000000 ____D () C:\FRST
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:42 - 2014-03-30 12:43 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:45 - 2014-03-30 11:52 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:00 - 2014-03-24 22:03 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 21:01 - 2014-03-21 21:22 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 22:58 - 2014-03-17 23:05 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:04 - 2014-03-17 12:05 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-16 19:17 - 2014-03-16 22:11 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 16:37 - 2014-03-16 17:00 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-10 21:49 - 2014-04-01 19:46 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-03-08 23:07 - 2014-03-09 01:28 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-05 11:23 - 2014-03-05 11:46 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
==================== One Month Modified Files and Folders =======
2014-04-01 20:16 - 2014-03-31 19:55 - 00009786 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-04-01 20:16 - 2014-03-30 21:59 - 00000000 ____D () C:\FRST
2014-04-01 20:06 - 2013-11-11 16:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-01 19:46 - 2014-03-10 21:49 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-04-01 18:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-01 18:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-01 18:38 - 2014-04-01 18:38 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-01 18:38 - 2010-11-21 08:50 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-04-01 18:38 - 2010-11-21 08:50 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-04-01 18:38 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-01 18:37 - 2014-04-01 18:37 - 02347384 _____ (ESET) C:\Users\KomaKuh\Downloads\esetsmartinstaller_enu.exe
2014-04-01 18:36 - 2013-11-11 16:16 - 01541940 _____ () C:\Windows\WindowsUpdate.log
2014-04-01 18:35 - 2014-04-01 18:35 - 00014255 _____ () C:\Users\KomaKuh\Desktop\MBAM.txt
2014-04-01 18:34 - 2014-04-01 18:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-01 18:34 - 2014-04-01 18:14 - 00001098 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-01 18:33 - 2014-04-01 18:33 - 00023712 _____ () C:\Windows\PFRO.log
2014-04-01 18:33 - 2014-03-31 20:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\GCC
2014-04-01 18:33 - 2014-03-31 14:40 - 00000336 _____ () C:\Windows\setupact.log
2014-04-01 18:33 - 2013-11-11 16:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-01 18:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-01 18:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas
2014-04-01 18:27 - 2013-11-11 19:33 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Skype
2014-04-01 18:14 - 2014-04-01 18:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-01 18:14 - 2013-11-11 17:25 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Malwarebytes
2014-04-01 18:14 - 2013-11-11 17:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-01 18:13 - 2014-04-01 18:10 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\KomaKuh\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-31 20:37 - 2014-03-31 20:37 - 00004534 _____ () C:\Windows\System32\Tasks\GC_Scheduler
2014-03-31 19:53 - 2014-03-31 19:16 - 07376130 _____ () C:\Users\KomaKuh\Desktop\SystemLook.txt
2014-03-31 19:44 - 2013-11-27 19:46 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Bewerbung
2014-03-31 19:30 - 2014-03-31 19:30 - 00018048 _____ () C:\Users\KomaKuh\Downloads\Benotungsschema Praktikumsmappe 9.odt
2014-03-31 19:19 - 2011-06-11 02:58 - 00773680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2014-03-31 19:19 - 2011-06-11 02:58 - 00420912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2014-03-31 19:16 - 2013-11-11 16:19 - 00001201 _____ () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-31 19:15 - 2014-03-31 19:15 - 00165376 _____ () C:\Users\KomaKuh\Desktop\SystemLook_x64.exe
2014-03-31 19:14 - 2014-03-31 19:11 - 00000000 ____D () C:\AdwCleaner
2014-03-31 19:12 - 2014-03-31 19:09 - 00000475 _____ () C:\Users\KomaKuh\Desktop\Neues Textdokument (4).txt
2014-03-31 19:09 - 2014-03-31 19:09 - 01950720 _____ () C:\Users\KomaKuh\Desktop\adwcleaner.exe
2014-03-31 15:48 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appadaumen.de
2014-03-31 15:48 - 2014-03-31 15:47 - 00000000 ____D () C:\Users\KomaKuh\Downloads\mausi 3
2014-03-31 15:48 - 2013-11-17 17:32 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Deployment
2014-03-31 15:47 - 2014-03-31 15:47 - 00270615 _____ () C:\Users\KomaKuh\Downloads\Mausi3.zip
2014-03-31 15:28 - 2014-03-31 15:27 - 00000000 ____D () C:\Users\KomaKuh\Desktop\saves FRST
2014-03-31 15:23 - 2013-11-11 22:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-03-31 15:01 - 2013-11-11 16:40 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-31 15:01 - 2013-11-11 16:40 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-31 14:50 - 2013-12-08 21:17 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Battle.net
2014-03-31 14:40 - 2014-03-31 14:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 21:10 - 2014-01-16 19:46 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Media Player Classic
2014-03-30 17:47 - 2013-11-11 21:07 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\TS3Client
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:42 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:52 - 2014-03-30 11:45 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-30 08:54 - 2013-11-12 22:13 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\Spotify
2014-03-30 08:40 - 2013-11-24 15:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Overwolf
2014-03-30 03:37 - 2013-11-11 19:09 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\TS3Client
2014-03-29 23:42 - 2014-01-06 22:30 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-03-29 08:00 - 2013-11-12 22:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Spotify
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-25 17:21 - 2013-11-11 18:45 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:03 - 2014-03-24 22:00 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:51 - 2014-02-21 21:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\Users\Receful\AppData\Local\PMB Files
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-23 08:42 - 2013-11-24 15:23 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:23 - 2013-11-11 17:16 - 00000000 ____D () C:\ProgramData\AMD
2014-03-21 22:22 - 2013-11-11 16:31 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 22:18 - 2013-11-11 16:26 - 01592628 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-21 22:15 - 2013-12-08 21:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-21 21:22 - 2014-03-21 21:01 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 17:21 - 2013-11-11 17:20 - 00000000 ____D () C:\Users\KomaKuh\Desktop\hintergrund
2014-03-18 17:19 - 2014-02-12 10:51 - 00000000 ____D () C:\Users\KomaKuh\Documents\SelfMV
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 23:05 - 2014-03-17 22:58 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 22:26 - 2013-12-08 21:21 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:05 - 2014-03-17 12:04 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-17 11:30 - 2014-01-01 18:54 - 00000000 ____D () C:\Gothic II
2014-03-16 22:11 - 2014-03-16 19:17 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 17:00 - 2014-03-16 16:37 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:56 - 2014-01-01 18:54 - 00000000 ____D () C:\Program Files (x86)\JoWooD
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-09 01:28 - 2014-03-08 23:07 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-06 12:34 - 2013-11-11 19:33 - 00000000 ____D () C:\ProgramData\Skype
2014-03-05 12:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-03-05 11:46 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:24 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-03-05 09:26 - 2014-04-01 18:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-01 18:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2013-11-11 17:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
Some content of TEMP:
====================
C:\Users\KomaKuh\AppData\Local\Temp\57638uninstall.exe
C:\Users\KomaKuh\AppData\Local\Temp\93696uninstall.exe
C:\Users\KomaKuh\AppData\Local\Temp\htmlayout.dll
C:\Users\KomaKuh\AppData\Local\Temp\Quarantine.exe
C:\Users\KomaKuh\AppData\Local\Temp\Sqlite3.dll
C:\Users\KomaKuh\AppData\Local\Temp\tmp3534.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp5300.tmp.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp5552.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp6A48.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp6DE1.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmpD877.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmpD8B1.exe
C:\Users\Receful\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Receful\AppData\Local\Temp\WTFastSetupOW.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2010-11-21 05:24] - [2011-03-09 18:01] - 2872320 ____A (Microsoft Corporation) 9FF4D976D1696F114A5738842C1C45FF
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 20:15
==================== End Of Log ============================ --- --- --- |