Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Suchlauf Datum: 02.04.2014
Suchlauf-Zeit: 22:44:57
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.02.08
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: David
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 260446
Verstrichene Zeit: 28 Min, 55 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 1576, Löschen bei Neustart, [1de3f50ba858ca36ac6e94d45ba7a060]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 10
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [000012ee18e8f30d9958e02a7191e51b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [2bd504fc6c9498682d50a2ebae552ad6],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [21df6b95a25ec73965ee78e63bc7df21],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [2fd1768a758ba15f90eda1ec877c7a86],
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [1de3f50ba858ca36ac6e94d45ba7a060],
PUP.Optional.Qone8, HKU\S-1-5-21-674607549-3252579659-1989267460-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [f709da26f60a3fc1e29a7815a16215eb],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 9
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SearchProtect32.dll, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SearchProtect32.dll),Ersetzt,[1de308f8a0607d8362bb69ff24de7a86]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SearchProtect64.dll, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SearchProtect64.dll),Ersetzt,[1de308f8a0607d8362bb69ff24de7a86]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\GOOGLE CHROME\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" Webs Searches, Gut: (Chrome.exe), Schlecht: ("C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" Webs Searches,[11ef2ad6db259b65c0e0bf48f113b947]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, Webs Searches, Gut: (Google), Schlecht: (Webs Searches,[36ca0af6a15fc739e3c0a4634db7768a]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[b947817f6c94c13f147bf0212ada08f8]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\GOOGLE CHROME\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" Webs Searches, Gut: (Chrome.exe), Schlecht: ("C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" Webs Searches,[2ad60ff1d62a936d0b9527e00cf84db3]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1396272627&from=amt&uid=ST31000528AS_6VPJ9NCGXXXX6VPJ9NCG&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1396272627&from=amt&uid=ST31000528AS_6VPJ9NCGXXXX6VPJ9NCG&q={searchTerms}),Ersetzt,[52aea8586d932bd5465c45c23cc850b0]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, Webs Searches, Gut: (Google), Schlecht: (Webs Searches,[ac5419e79f6142be218095725da729d7]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, Webs Searches, Gut: (Google), Schlecht: (Webs Searches,[e11fd030d9277987198a4dba25dfd52b]
Ordner: 26
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Löschen bei Neustart, [ad533dc36a967c8484d73f16f01215eb],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [ad533dc36a967c8484d73f16f01215eb],
Dateien: 99
PUP.Optional.SupTab.A, C:\Users\David\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [ea1679872ed2768a96b5e1540cf49070],
PUP.Optional.InstallCore, C:\Users\David\Downloads\WinRAR.exe, In Quarantäne, [e61aba46e11f3bc544b80de09d66af51],
PUP.Optional.Amonetize, C:\Users\David\Downloads\DownloadSetup__2299_i363168761_il11.exe, In Quarantäne, [df2126da649ce81811c473c1ef1109f7],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [e51b39c75ea2df210917f66f69995ba5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\style.css, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\27.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\1.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\10.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\11.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\12.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\13.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\14.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\15.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\16.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\17.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\18.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\19.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\2.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\20.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\21.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\22.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\23.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\24.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\25.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\26.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\28.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\29.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\3.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\30.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\31.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\32.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\33.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\34.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\35.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\36.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\37.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\38.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\39.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\4.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\40.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\41.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\42.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\43.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\44.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\45.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\46.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\47.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\5.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\6.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\7.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\8.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\9.png, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\background.js, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-base.js, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [1de308f8a0607d8362bb69ff24de7a86],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, Löschen bei Neustart, [1de3f50ba858ca36ac6e94d45ba7a060],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [ad533dc36a967c8484d73f16f01215eb],
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.023 - Bericht erstellt am 02/04/2014 um 22:55:32
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : David - DAVID-PC
# Gestartet von : C:\Users\David\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Users\David\AppData\Local\lollipop
Ordner Gelöscht : C:\Users\David\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\David\AppData\Roaming\Systweak
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\David\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\David\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\David\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\David\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Wpm
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3300 octets] - [02/04/2014 22:54:00]
AdwCleaner[S0].txt - [2411 octets] - [02/04/2014 22:55:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2471 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by David on 02.04.2014 at 23:01:58,63
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\David\appdata\local\{3E1C4EAF-4B6B-40CD-92D6-3AB22EAE832B}
Successfully deleted: [Empty Folder] C:\Users\David\appdata\local\{A3F01CA5-F348-4A5B-94E8-B4B7F0BBDDE1}
Successfully deleted: [Empty Folder] C:\Users\David\appdata\local\{E55BAD8F-623D-4D23-A02C-9F373D9EA46D}
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.04.2014 at 23:08:46,62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by David (administrator) on DAVID-PC on 02-04-2014 23:14:25
Running from C:\Users\David\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files (x86)\watchmi\TvdService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-03-25] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [443688 2011-05-26] (CyberLink)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = Google
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-31]
CHR Extension: (Google Drive) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-31]
CHR Extension: (YouTube) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-31]
CHR Extension: (Google-Suche) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-31]
CHR Extension: (avast! Online Security) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-02-16]
CHR Extension: (Google Wallet) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-16]
CHR Extension: (Google Mail) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-31]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-03-25]
CHR StartMenuInternet: Google Chrome - Chrome.exe
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-25] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109048 2014-03-25] (AVAST Software)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
R2 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [70144 2011-10-07] ()
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-03-25] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-03-25] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [445304 2014-03-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-03-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-03-25] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-03-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-03-25] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-03-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-03-25] ()
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin)
R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-03-05] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-02] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-03-05] (Malwarebytes Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-02 23:08 - 2014-04-02 23:08 - 00001067 _____ () C:\Users\David\Desktop\JRT.txt
2014-04-02 23:01 - 2014-04-02 23:01 - 00000000 ____D () C:\Windows\ERUNT
2014-04-02 22:59 - 2014-04-02 22:59 - 01038974 _____ (Thisisu) C:\Users\David\Desktop\JRT.exe
2014-04-02 22:53 - 2014-04-02 22:55 - 00000000 ____D () C:\AdwCleaner
2014-04-02 22:51 - 2014-04-02 22:51 - 01426178 _____ () C:\Users\David\Downloads\adwcleaner.exe
2014-04-02 22:50 - 2014-04-02 22:50 - 00022254 _____ () C:\Users\David\Desktop\mbam.txt
2014-04-02 22:11 - 2014-04-02 22:57 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-02 22:11 - 2014-04-02 22:11 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-02 22:11 - 2014-04-02 22:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-02 22:11 - 2014-04-02 22:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-02 22:11 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-02 22:11 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-02 22:11 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 22:06 - 2014-04-02 22:08 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\David\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-01 16:35 - 2014-04-01 16:35 - 00028137 _____ () C:\ComboFix.txt
2014-04-01 16:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-01 16:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-01 16:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-01 16:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-01 16:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-01 16:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-01 16:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-01 16:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-01 16:21 - 2014-04-01 16:35 - 00000000 ____D () C:\Qoobox
2014-04-01 16:21 - 2014-04-01 16:34 - 00000000 ____D () C:\Windows\erdnt
2014-04-01 16:15 - 2014-04-01 16:16 - 05192353 ____R (Swearware) C:\Users\David\Downloads\ComboFix.exe
2014-04-01 15:50 - 2014-04-01 15:50 - 00001268 _____ () C:\Users\David\Desktop\Revo Uninstaller.lnk
2014-04-01 15:50 - 2014-04-01 15:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-01 15:49 - 2014-04-01 15:49 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\David\Downloads\revosetup95.exe
2014-03-31 21:33 - 2014-04-02 23:14 - 00011407 _____ () C:\Users\David\Downloads\FRST.txt
2014-03-31 21:33 - 2014-04-02 23:14 - 00000000 ____D () C:\FRST
2014-03-31 21:33 - 2014-03-31 21:38 - 00044662 _____ () C:\Users\David\Downloads\Addition.txt
2014-03-31 21:32 - 2014-03-31 21:33 - 02157056 _____ (Farbar) C:\Users\David\Downloads\FRST64.exe
2014-03-31 21:24 - 2014-04-02 22:56 - 00000392 _____ () C:\Windows\setupact.log
2014-03-31 21:24 - 2014-03-31 21:24 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-31 21:23 - 2014-04-02 22:56 - 00031122 _____ () C:\Windows\PFRO.log
2014-03-31 15:39 - 2014-03-31 15:39 - 00001541 _____ () C:\Users\David\Desktop\Avast- Antivirus.lnk
2014-03-31 15:33 - 2014-03-31 15:33 - 00000000 ____D () C:\Users\David\AppData\Roaming\Opera Software
2014-03-31 15:33 - 2014-03-31 15:33 - 00000000 ____D () C:\Users\David\AppData\Local\Opera Software
2014-03-31 15:31 - 2014-03-31 22:16 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-03-28 03:27 - 2014-03-28 03:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-28 03:27 - 2014-03-28 03:27 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-27 19:12 - 2014-03-28 03:14 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-03-27 17:07 - 2014-03-27 17:07 - 00000000 ___RD () C:\MSOCache
2014-03-27 17:02 - 2014-03-28 00:55 - 00000000 ____D () C:\Users\David\AppData\Roaming\SoftGrid Client
2014-03-27 17:02 - 2014-03-27 17:02 - 00000000 ____D () C:\Users\David\AppData\Local\SoftGrid Client
2014-03-27 17:01 - 2014-03-28 03:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-03-27 17:01 - 2014-03-27 17:02 - 00000000 ____D () C:\Users\David\AppData\Roaming\TP
2014-03-27 17:01 - 2014-03-27 17:01 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-03-27 17:01 - 2014-03-27 17:01 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-27 17:00 - 2014-03-27 17:00 - 00000000 ___RD () C:\Users\David\Documents\Notes
2014-03-26 19:13 - 2014-03-26 19:13 - 00000000 ____D () C:\Users\David\AppData\Local\Adobe
2014-03-25 17:59 - 2014-03-25 17:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-03-25 17:59 - 2014-03-25 17:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\DropboxMaster
2014-03-25 17:58 - 2014-03-25 18:00 - 00000000 ____D () C:\Users\David\AppData\Roaming\Dropbox
2014-03-25 17:50 - 2014-03-25 17:50 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-03-25 17:50 - 2014-03-25 17:49 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-03-25 17:49 - 2014-03-25 17:49 - 00445304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-03-25 16:14 - 2014-03-25 20:07 - 00000000 ____D () C:\ProgramData\PMS
2014-03-25 16:13 - 2014-03-25 16:14 - 00000000 ____D () C:\Program Files (x86)\PS3 Media Server
2014-03-25 16:13 - 2013-08-19 11:43 - 54431910 _____ () C:\Users\David\Downloads\pms-1.90.1-setup-full-x64.exe
2014-03-25 16:13 - 2013-08-19 11:43 - 53679694 _____ () C:\Users\David\Downloads\pms-1.90.1-setup-full.exe
2014-03-14 01:10 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-14 01:10 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-14 01:10 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-14 01:10 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-14 01:10 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-14 01:10 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-14 01:10 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-14 01:10 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-14 01:10 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-14 01:10 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-14 01:10 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-14 01:10 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-14 01:10 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-14 01:10 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-14 01:10 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-14 01:10 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-14 01:10 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-14 01:10 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-14 01:10 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-14 01:10 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-14 01:10 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-14 01:10 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-14 01:10 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-14 01:10 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-14 01:10 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-14 01:10 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-14 01:10 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-14 01:10 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-14 01:10 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-14 01:10 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-14 01:10 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-14 01:10 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-14 01:10 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-14 01:10 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-14 01:10 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-14 01:10 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-14 01:10 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-14 01:10 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-14 01:10 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-14 01:10 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-14 01:10 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-14 01:10 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-14 01:10 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-14 01:10 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-14 01:08 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-14 01:08 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-14 01:08 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-14 01:08 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-09 20:58 - 2014-03-09 23:37 - 00000000 ____D () C:\Users\David\AppData\Local\Windows Live
2014-03-03 05:26 - 2014-03-31 20:54 - 00000000 ____D () C:\Windows\Minidump
==================== One Month Modified Files and Folders =======
2014-04-02 23:14 - 2014-03-31 21:33 - 00011407 _____ () C:\Users\David\Downloads\FRST.txt
2014-04-02 23:14 - 2014-03-31 21:33 - 00000000 ____D () C:\FRST
2014-04-02 23:08 - 2014-04-02 23:08 - 00001067 _____ () C:\Users\David\Desktop\JRT.txt
2014-04-02 23:04 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-02 23:04 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-02 23:01 - 2014-04-02 23:01 - 00000000 ____D () C:\Windows\ERUNT
2014-04-02 22:59 - 2014-04-02 22:59 - 01038974 _____ (Thisisu) C:\Users\David\Desktop\JRT.exe
2014-04-02 22:57 - 2014-04-02 22:11 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-02 22:57 - 2014-02-16 20:52 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-02 22:56 - 2014-03-31 21:24 - 00000392 _____ () C:\Windows\setupact.log
2014-04-02 22:56 - 2014-03-31 21:23 - 00031122 _____ () C:\Windows\PFRO.log
2014-04-02 22:56 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-02 22:55 - 2014-04-02 22:53 - 00000000 ____D () C:\AdwCleaner
2014-04-02 22:55 - 2014-02-16 20:55 - 00000999 _____ () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-02 22:55 - 2014-02-16 20:51 - 01991690 _____ () C:\Windows\WindowsUpdate.log
2014-04-02 22:51 - 2014-04-02 22:51 - 01426178 _____ () C:\Users\David\Downloads\adwcleaner.exe
2014-04-02 22:50 - 2014-04-02 22:50 - 00022254 _____ () C:\Users\David\Desktop\mbam.txt
2014-04-02 22:46 - 2009-07-14 07:08 - 00032550 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-02 22:37 - 2014-02-16 20:52 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-02 22:11 - 2014-04-02 22:11 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-02 22:11 - 2014-04-02 22:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-02 22:11 - 2014-04-02 22:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-02 22:08 - 2014-04-02 22:06 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\David\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-01 22:02 - 2011-03-11 11:20 - 00699868 _____ () C:\Windows\system32\perfh007.dat
2014-04-01 22:02 - 2011-03-11 11:20 - 00149750 _____ () C:\Windows\system32\perfc007.dat
2014-04-01 22:02 - 2009-07-14 07:13 - 01622164 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-01 16:35 - 2014-04-01 16:35 - 00028137 _____ () C:\ComboFix.txt
2014-04-01 16:35 - 2014-04-01 16:21 - 00000000 ____D () C:\Qoobox
2014-04-01 16:35 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-01 16:34 - 2014-04-01 16:21 - 00000000 ____D () C:\Windows\erdnt
2014-04-01 16:34 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-01 16:16 - 2014-04-01 16:15 - 05192353 ____R (Swearware) C:\Users\David\Downloads\ComboFix.exe
2014-04-01 15:56 - 2014-02-16 20:55 - 00000000 ___RD () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-01 15:50 - 2014-04-01 15:50 - 00001268 _____ () C:\Users\David\Desktop\Revo Uninstaller.lnk
2014-04-01 15:50 - 2014-04-01 15:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-01 15:49 - 2014-04-01 15:49 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\David\Downloads\revosetup95.exe
2014-03-31 22:16 - 2014-03-31 15:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-03-31 21:38 - 2014-03-31 21:33 - 00044662 _____ () C:\Users\David\Downloads\Addition.txt
2014-03-31 21:33 - 2014-03-31 21:32 - 02157056 _____ (Farbar) C:\Users\David\Downloads\FRST64.exe
2014-03-31 21:24 - 2014-03-31 21:24 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-31 21:23 - 2014-02-16 20:52 - 00000000 ____D () C:\Program Files (x86)\Google
2014-03-31 20:54 - 2014-03-03 05:26 - 00000000 ____D () C:\Windows\Minidump
2014-03-31 20:54 - 2014-02-26 19:19 - 00000000 ____D () C:\Users\David\AppData\Local\CrashDumps
2014-03-31 15:39 - 2014-03-31 15:39 - 00001541 _____ () C:\Users\David\Desktop\Avast- Antivirus.lnk
2014-03-31 15:33 - 2014-03-31 15:33 - 00000000 ____D () C:\Users\David\AppData\Roaming\Opera Software
2014-03-31 15:33 - 2014-03-31 15:33 - 00000000 ____D () C:\Users\David\AppData\Local\Opera Software
2014-03-31 15:31 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-31 15:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-03-30 15:48 - 2014-02-16 22:18 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-28 16:21 - 2014-02-16 20:58 - 00000000 ____D () C:\Users\David\AppData\Local\Google
2014-03-28 03:28 - 2014-03-27 17:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-03-28 03:28 - 2014-02-25 01:26 - 01648846 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-28 03:27 - 2014-03-28 03:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-28 03:27 - 2014-03-28 03:27 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-28 03:14 - 2014-03-27 19:12 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-03-28 00:55 - 2014-03-27 17:02 - 00000000 ____D () C:\Users\David\AppData\Roaming\SoftGrid Client
2014-03-28 00:32 - 2014-02-16 20:52 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-28 00:32 - 2014-02-16 20:52 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-27 17:07 - 2014-03-27 17:07 - 00000000 ___RD () C:\MSOCache
2014-03-27 17:02 - 2014-03-27 17:02 - 00000000 ____D () C:\Users\David\AppData\Local\SoftGrid Client
2014-03-27 17:02 - 2014-03-27 17:01 - 00000000 ____D () C:\Users\David\AppData\Roaming\TP
2014-03-27 17:01 - 2014-03-27 17:01 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-03-27 17:01 - 2014-03-27 17:01 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-27 17:01 - 2011-08-22 19:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-27 17:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-27 17:00 - 2014-03-27 17:00 - 00000000 ___RD () C:\Users\David\Documents\Notes
2014-03-26 19:13 - 2014-03-26 19:13 - 00000000 ____D () C:\Users\David\AppData\Local\Adobe
2014-03-26 19:13 - 2014-02-16 21:16 - 00000000 ____D () C:\Users\David\AppData\Roaming\Adobe
2014-03-25 20:07 - 2014-03-25 16:14 - 00000000 ____D () C:\ProgramData\PMS
2014-03-25 18:00 - 2014-03-25 17:58 - 00000000 ____D () C:\Users\David\AppData\Roaming\Dropbox
2014-03-25 17:59 - 2014-03-25 17:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-03-25 17:59 - 2014-03-25 17:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\DropboxMaster
2014-03-25 17:50 - 2014-03-25 17:50 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-03-25 17:50 - 2014-02-16 22:18 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-03-25 17:50 - 2014-02-16 22:18 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-03-25 17:50 - 2014-02-16 22:18 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-03-25 17:50 - 2014-02-16 22:18 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-03-25 17:50 - 2014-02-16 22:18 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-03-25 17:50 - 2014-02-16 22:18 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-03-25 17:50 - 2014-02-16 22:18 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-03-25 17:50 - 2014-02-16 22:18 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-03-25 17:49 - 2014-03-25 17:50 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-03-25 17:49 - 2014-03-25 17:49 - 00445304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-03-25 17:43 - 2014-02-24 20:02 - 00000000 ____D () C:\Users\David\Installierte Programme
2014-03-25 16:14 - 2014-03-25 16:13 - 00000000 ____D () C:\Program Files (x86)\PS3 Media Server
2014-03-25 16:01 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-03-21 15:07 - 2014-02-22 02:27 - 00000000 ____D () C:\Users\David\Documents\Snagit
2014-03-19 12:40 - 2014-02-16 20:54 - 00000000 ____D () C:\Users\David
2014-03-15 09:02 - 2009-07-14 06:45 - 00361240 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-09 23:37 - 2014-03-09 20:58 - 00000000 ____D () C:\Users\David\AppData\Local\Windows Live
2014-03-05 09:26 - 2014-04-02 22:11 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-02 22:11 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-04-02 22:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-03 05:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
Some content of TEMP:
====================
C:\Users\David\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 23:26
==================== End Of Log ============================
--- --- ---