Ich habe alles durchlaufen lassen, hier die Ergebnisse: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 19.04.2014 21:03:34, SYSTEM, PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 19.04.2014 21:03:45, SYSTEM, PC, Manual, Malware Database, 2014.3.4.9, 2014.4.19.9,
(end) Code:
# AdwCleaner v3.024 - Bericht erstellt am 19/04/2014 um 22:29:48
# Aktualisiert 18/04/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Luise - PC
# Gestartet von : C:\Users\Luise\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Luise\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Luise\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Tina\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Tina\AppData\LocalLow\ConduitEngine
Ordner Gelöscht : C:\Users\Tina\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Tina\AppData\LocalLow\softonic-de3
Ordner Gelöscht : C:\Users\Robert\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Robert\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Robert\AppData\LocalLow\ConduitEngine
Ordner Gelöscht : C:\Users\Robert\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Robert\AppData\LocalLow\softonic-de3
Ordner Gelöscht : C:\Users\Robert\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\Conduit
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\ConduitEngine
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\CT2431245
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}
Ordner Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\Extensions\engine@conduit.com
Datei Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\invalidprefs.js
Datei Gelöscht : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\SaveSense
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\5e0dbdfe73bb812
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2431245
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_divx-plus_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_divx-plus_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_xrecode-ii_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_xrecode-ii_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyrixeeker
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\prefs.js ]
Zeile gelöscht : user_pref("CommunityToolbar.EngineHiddenByUser", false);
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwner", "CT2431245");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerGuid", "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerToolbarId", "softonic-de3");
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sat Mar 26 2011 09:16:19 GMT+0100");
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sat Jul 30 2011 12:14:04 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.locale", "en");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sat Jul 30 2011 12:13:57 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Zeile gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Zeile gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userId", "f9c11f00-b43c-4fab-8248-c416be468a6e");
[ Datei : C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\ayduxzca.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
[ Datei : C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\nxypc4gi.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("extensions.helperbar.BackPageActive", true);
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true);
Zeile gelöscht : user_pref("extensions.helperbar.backPageCapacity", 3);
Zeile gelöscht : user_pref("extensions.helperbar.backPageCounter", 0);
Zeile gelöscht : user_pref("extensions.helperbar.backPageDay", 29);
Zeile gelöscht : user_pref("extensions.helperbar.backPageLastEvent", "1395937211615");
Zeile gelöscht : user_pref("extensions.helperbar.backPageMinInterval", 15);
Zeile gelöscht : user_pref("extensions.helperbar.barcodeid", "127849");
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "ry_2908_ch");
Zeile gelöscht : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\"],\\\"hxxpInjection\\\":\\\"hxxp:\\\\\\/\\\\\\/www.superfish.com\\\\\\/ws\\\\\\/[...]
Zeile gelöscht : user_pref("extensions.helperbar.fromautoupdate", "false");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "7a54052d-fb87-e185-8a3e-3068ffb0c1db");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "29/03/2014");
Zeile gelöscht : user_pref("extensions.helperbar.keepAliveLastevent", "1396110012");
Zeile gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1396110043005");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "shoppinghelper");
*************************
AdwCleaner[R0].txt - [9845 octets] - [19/04/2014 22:25:08]
AdwCleaner[S0].txt - [9320 octets] - [19/04/2014 22:29:48]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9380 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Luise on 19.04.2014 at 22:42:19,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2843072593-2135467266-4033449279-1000\Software\sweetim
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Luise\AppData\Roaming\mozilla\firefox\profiles\32snpnbw.default\minidumps [146 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.04.2014 at 22:50:39,05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-04-2014
Ran by Luise (administrator) on PC on 19-04-2014 23:00:19
Running from C:\Users\Luise\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_5a0a40f129797e65\STacSV64.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_5a0a40f129797e65\AESTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe
(Creative Technology Ltd.) C:\Windows\OEM13Mon.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(MyHeritage) C:\Users\Luise\Downloads\MyHeritage\Bin\FTBCheckUpdates.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DPAgent.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Sun Microsystems, Inc.) C:\Windows\System32\jusched.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [309248 2009-06-29] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2009-11-06] (IDT, Inc.)
HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [203776 2009-11-12] (Microsoft)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)
HKLM-x32\...\Run: [PDVDDXSrv] => C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe [140520 2009-12-29] (CyberLink Corp.)
HKLM-x32\...\Run: [DpAgent] => C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe [842816 2009-05-13] (DigitalPersona, Inc.)
HKLM-x32\...\Run: [OEM13Mon.exe] => C:\Windows\OEM13Mon.exe [36864 2008-01-07] (Creative Technology Ltd.)
HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [651264 2012-04-17] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM-x32\...\Run: [Family Tree Builder Update] => C:\Users\Luise\Downloads\MyHeritage\Bin\FTBCheckUpdates.exe [2532864 2013-11-12] (MyHeritage)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-05] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2843072593-2135467266-4033449279-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-04-06] (Google Inc.)
Startup: C:\Users\Luise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\flashupdate.lnk
ShortcutTarget: flashupdate.lnk -> C:\Users\Luise\AppData\Roaming\Flash\updatesg.vbs (No File)
Startup: C:\Users\Luise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ecosia.org/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {5F3BEBD5-F6C6-A4B8-EDD2-A6F5F61813A8} URL = hxxp://www.buzqo.com/s/?q={searchTerms}&iesrc={referrer:source?}&cfg=2-401-0-2h6I8
SearchScopes: HKCU - {F8CB44D2-9135-4075-8063-E0C76DD9C488} URL =
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} C:\Users\Robert\AppData\Local\Temp\f5tmp\f5tunsrv.cab
DPF: HKLM-x32 {45B69029-F3AB-4204-92DE-D5140C3E8E74} C:\Users\Luise\AppData\Local\Temp\IXP000.TMP\InstallerControl.cab
DPF: HKLM-x32 {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} hxxp://www.myheritage.de/Genoogle/Components/ActiveX/SearchEngineQuery.dll
DPF: HKLM-x32 {E0FF21FA-B857-45C5-8621-F120A0C17FF2} C:\Users\Robert\AppData\Local\Temp\f5tmp\urxhost.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{D5502460-1F7E-4DB3-AD96-07D54DC9E7EE}: [NameServer]217.0.43.65 217.0.43.81
Tcpip\..\Interfaces\{F21869AA-F133-4CEE-8D05-0E9455A0200C}: [NameServer]94.242.222.66,8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\searchplugins\ask.uk.xml
FF SearchPlugin: C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\searchplugins\ecosia.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: F5 Networks Host Plugin - C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\Extensions\{DBBB3167-6E81-400f-BBFD-BD8921726F52} [2010-10-09]
FF Extension: GMX MailCheck - C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\Extensions\toolbar@gmx.net.xpi [2013-09-30]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Luise\AppData\Roaming\Mozilla\Firefox\Profiles\32snpnbw.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-25]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} [2014-04-12]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-04-12]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-04-12]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ []
FF HKCU\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\firefoxext
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\firefoxext [2010-04-05]
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_5a0a40f129797e65\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [910416 2014-04-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-04-05] (Avira Operations GmbH & Co. KG)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [88576 2011-09-15] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_5a0a40f129797e65\STacSV64.exe [244224 2009-11-06] (IDT, Inc.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-05] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2014-04-05] (Avira Operations GmbH & Co. KG)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-04-19] (Malwarebytes Corporation)
R3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdgx64.sys [48800 2009-05-07] (O2Micro )
R3 OEM13Vfx; C:\Windows\System32\DRIVERS\OEM13Vfx.sys [12288 2007-03-05] (EyePower Games Pte. Ltd.)
R3 OEM13Vid; C:\Windows\System32\DRIVERS\OEM13Vid.sys [267296 2008-05-28] (Creative Technology Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-19 23:00 - 2014-04-19 23:00 - 02055680 _____ (Farbar) C:\Users\Luise\Desktop\FRST64.exe
2014-04-19 23:00 - 2014-04-19 23:00 - 00016654 _____ () C:\Users\Luise\Desktop\FRST.txt
2014-04-19 22:50 - 2014-04-19 22:50 - 00000948 _____ () C:\Users\Luise\Desktop\JRT.txt
2014-04-19 22:42 - 2014-04-19 22:42 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 22:41 - 2014-04-19 22:42 - 01016261 _____ (Thisisu) C:\Users\Luise\Desktop\JRT.exe
2014-04-19 22:35 - 2014-04-19 22:35 - 00009472 _____ () C:\Users\Luise\Desktop\AdwCleaner[S0].txt
2014-04-19 22:24 - 2014-04-19 22:31 - 00000000 ____D () C:\AdwCleaner
2014-04-19 22:24 - 2014-04-19 22:24 - 01258805 _____ () C:\Users\Luise\Desktop\adwcleaner.exe
2014-04-19 22:12 - 2014-04-19 22:12 - 00000249 _____ () C:\Users\Luise\Desktop\mbam.txt.txt
2014-04-19 21:03 - 2014-04-19 21:06 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 21:03 - 2014-04-19 21:03 - 00000774 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 21:03 - 2014-04-19 21:03 - 00000000 ____D () C:\Users\Luise\Desktop\Malwarebytes Anti-Malware
2014-04-19 21:03 - 2014-04-19 21:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 21:03 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 21:03 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 21:03 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 21:00 - 2014-04-19 21:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Luise\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-19 14:13 - 2014-04-19 14:13 - 00021752 _____ () C:\ComboFix.txt
2014-04-19 12:56 - 2014-04-19 14:13 - 00000000 ____D () C:\Qoobox
2014-04-19 12:56 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-19 12:56 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-19 12:56 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-19 12:56 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-19 12:56 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-19 12:56 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-19 12:56 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-19 12:56 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-19 12:55 - 2014-04-19 14:11 - 00000000 ____D () C:\Windows\erdnt
2014-04-19 12:55 - 2014-04-19 12:55 - 05195154 ____R (Swearware) C:\Users\Luise\Desktop\ComboFix.exe
2014-04-18 17:03 - 2014-04-19 23:00 - 00000000 ____D () C:\FRST
2014-04-14 22:26 - 2014-04-14 22:26 - 00010224 _____ () C:\Users\Luise\Desktop\Stundenplan.odt
2014-04-12 13:30 - 2014-04-12 13:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-12 10:08 - 2014-04-12 10:08 - 00003038 _____ () C:\Windows\System32\Tasks\{60733D86-7424-44B5-B3FE-37E06666758D}
2014-04-11 21:01 - 2014-04-11 21:01 - 00000000 __SHD () C:\Users\Luise\AppData\Local\EmieUserList
2014-04-11 21:01 - 2014-04-11 21:01 - 00000000 __SHD () C:\Users\Luise\AppData\Local\EmieSiteList
2014-04-11 07:50 - 2014-04-11 07:50 - 00000000 __SHD () C:\Users\Tina\AppData\Local\EmieUserList
2014-04-11 07:50 - 2014-04-11 07:50 - 00000000 __SHD () C:\Users\Tina\AppData\Local\EmieSiteList
2014-04-11 00:06 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-11 00:06 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-11 00:06 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-11 00:06 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-11 00:06 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-11 00:06 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-11 00:06 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-11 00:06 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-11 00:06 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-11 00:06 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-11 00:06 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-11 00:06 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-11 00:06 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-11 00:06 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-11 00:06 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-11 00:06 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-11 00:06 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-11 00:06 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-11 00:06 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-11 00:06 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-11 00:06 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-11 00:06 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-11 00:06 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-11 00:06 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-11 00:06 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-11 00:06 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-11 00:06 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-11 00:06 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-11 00:06 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-11 00:06 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-11 00:06 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-11 00:06 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-11 00:06 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-11 00:06 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-11 00:06 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-11 00:06 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-11 00:06 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-11 00:06 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-11 00:06 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-11 00:06 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-11 00:06 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-11 00:06 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-11 00:06 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-11 00:06 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-11 00:06 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-11 00:06 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-11 00:06 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-11 00:06 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-09 16:19 - 2014-04-14 09:14 - 00000000 ____D () C:\Users\Tina\AppData\Local\{06A3EFF6-6344-24A4-D3EC-9E39B37D8624}
2014-04-09 15:51 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 15:51 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 15:51 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 15:51 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 15:51 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 15:51 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 15:51 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 15:51 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 15:51 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 15:51 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 15:51 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 15:51 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 15:51 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 15:51 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 15:51 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 15:51 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 15:51 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-09 15:41 - 2014-04-09 15:41 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Avira
2014-04-05 14:28 - 2014-04-05 14:28 - 00000000 ____D () C:\Users\Luise\AppData\Roaming\Avira
2014-04-05 09:41 - 2014-04-05 10:03 - 00004559 _____ () C:\WirelessDiagLog.csv
2014-04-05 08:13 - 2014-04-05 08:13 - 00000000 ____D () C:\Users\Robert\AppData\Roaming\Avira
2014-04-05 08:12 - 2014-04-05 08:12 - 00001996 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-04-05 08:12 - 2014-04-05 08:12 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-04-05 08:12 - 2014-04-05 08:04 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-05 08:12 - 2014-04-05 08:04 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-05 08:12 - 2014-04-05 08:04 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-05 08:12 - 2014-04-05 08:04 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-03-30 19:13 - 2014-03-30 19:17 - 148202976 _____ () C:\Users\Robert\Downloads\avira_antivirus_suite_en.exe
2014-03-30 12:23 - 2014-03-30 12:23 - 00001055 _____ () C:\Users\Luise\Desktop\Continue VuuPC Installation.lnk
2014-03-30 11:54 - 2014-03-30 11:54 - 00000000 _____ () C:\Users\Luise\daemonprocess.txt
2014-03-29 18:31 - 2014-03-29 18:32 - 00000000 ____D () C:\Users\Robert\AppData\Roaming\vlc
2014-03-29 18:28 - 2014-03-29 18:28 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-03-29 18:27 - 2014-03-29 18:27 - 00000044 _____ () C:\Users\Robert\AppData\Roaming\WB.CFG
2014-03-29 18:26 - 2014-03-29 18:28 - 25567416 _____ () C:\Users\Robert\Downloads\vlc-2.1.3-win32(1).exe
2014-03-29 18:25 - 2014-03-29 18:28 - 25567416 _____ () C:\Users\Robert\Downloads\vlc-2.1.3-win32.exe
2014-03-29 18:24 - 2014-03-29 18:28 - 00000000 ____D () C:\Users\Robert\AppData\Local\cache
2014-03-29 18:24 - 2014-03-29 18:24 - 00001975 _____ () C:\Users\Robert\Desktop\Sync Folder.lnk
2014-03-29 18:24 - 2014-03-29 18:24 - 00000000 ____D () C:\Users\Robert\.android
2014-03-29 18:24 - 2014-03-29 18:24 - 00000000 _____ () C:\Users\Robert\daemonprocess.txt
2014-03-26 10:48 - 2014-03-26 10:52 - 138607664 _____ () C:\Users\Tina\Downloads\avira_free_antivirus_de_14.0.3.350.exe
2014-03-26 10:14 - 2014-03-26 22:13 - 00000000 ____D () C:\Users\Luise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Guard Protection
2014-03-25 20:02 - 2014-04-19 22:14 - 00000000 ____D () C:\Users\Luise\AppData\Roaming\Flash
2014-03-25 20:02 - 2014-03-25 20:02 - 00000761 _____ () C:\Windows\system32\Drivers\etc\hosts.txt
==================== One Month Modified Files and Folders =======
2014-04-19 23:01 - 2014-04-19 23:00 - 00016654 _____ () C:\Users\Luise\Desktop\FRST.txt
2014-04-19 23:00 - 2014-04-19 23:00 - 02055680 _____ (Farbar) C:\Users\Luise\Desktop\FRST64.exe
2014-04-19 23:00 - 2014-04-18 17:03 - 00000000 ____D () C:\FRST
2014-04-19 23:00 - 2010-05-01 12:42 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-19 22:50 - 2014-04-19 22:50 - 00000948 _____ () C:\Users\Luise\Desktop\JRT.txt
2014-04-19 22:42 - 2014-04-19 22:42 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 22:42 - 2014-04-19 22:41 - 01016261 _____ (Thisisu) C:\Users\Luise\Desktop\JRT.exe
2014-04-19 22:42 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-19 22:42 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-19 22:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-04-19 22:35 - 2014-04-19 22:35 - 00009472 _____ () C:\Users\Luise\Desktop\AdwCleaner[S0].txt
2014-04-19 22:35 - 2012-01-16 15:51 - 00000000 ____D () C:\Users\Luise\AppData\Local\Htc
2014-04-19 22:34 - 2010-05-01 12:42 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-19 22:33 - 2014-02-20 21:44 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-04-19 22:33 - 2009-07-14 07:10 - 01519778 _____ () C:\Windows\WindowsUpdate.log
2014-04-19 22:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-19 22:33 - 2009-07-14 06:51 - 00212961 _____ () C:\Windows\setupact.log
2014-04-19 22:31 - 2014-04-19 22:24 - 00000000 ____D () C:\AdwCleaner
2014-04-19 22:28 - 2012-04-05 10:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-19 22:24 - 2014-04-19 22:24 - 01258805 _____ () C:\Users\Luise\Desktop\adwcleaner.exe
2014-04-19 22:16 - 2010-04-05 04:54 - 00747736 _____ () C:\Windows\PFRO.log
2014-04-19 22:14 - 2014-03-25 20:02 - 00000000 ____D () C:\Users\Luise\AppData\Roaming\Flash
2014-04-19 22:12 - 2014-04-19 22:12 - 00000249 _____ () C:\Users\Luise\Desktop\mbam.txt.txt
2014-04-19 21:06 - 2014-04-19 21:03 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 21:03 - 2014-04-19 21:03 - 00000774 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 21:03 - 2014-04-19 21:03 - 00000000 ____D () C:\Users\Luise\Desktop\Malwarebytes Anti-Malware
2014-04-19 21:03 - 2014-04-19 21:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 21:00 - 2014-04-19 21:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Luise\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-19 20:57 - 2012-06-26 14:32 - 00000000 ____D () C:\Users\Luise\Documents\Studium
2014-04-19 14:13 - 2014-04-19 14:13 - 00021752 _____ () C:\ComboFix.txt
2014-04-19 14:13 - 2014-04-19 12:56 - 00000000 ____D () C:\Qoobox
2014-04-19 14:13 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-19 14:11 - 2014-04-19 12:55 - 00000000 ____D () C:\Windows\erdnt
2014-04-19 14:11 - 2010-04-14 11:21 - 00000000 ___RD () C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 14:05 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-19 14:00 - 2010-04-14 11:14 - 00000000 ____D () C:\Users\Tina
2014-04-19 14:00 - 2010-04-13 21:01 - 00000000 ___RD () C:\Users\Luise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 14:00 - 2010-04-13 21:01 - 00000000 ____D () C:\Users\Luise
2014-04-19 12:55 - 2014-04-19 12:55 - 05195154 ____R (Swearware) C:\Users\Luise\Desktop\ComboFix.exe
2014-04-15 22:32 - 2010-04-24 15:33 - 00050490 _____ () C:\Users\Luise\AppData\Roaming\wklnhst.dat
2014-04-14 22:26 - 2014-04-14 22:26 - 00010224 _____ () C:\Users\Luise\Desktop\Stundenplan.odt
2014-04-14 09:14 - 2014-04-09 16:19 - 00000000 ____D () C:\Users\Tina\AppData\Local\{06A3EFF6-6344-24A4-D3EC-9E39B37D8624}
2014-04-14 09:13 - 2012-01-23 12:26 - 00000000 ____D () C:\Users\Tina\AppData\Local\Htc
2014-04-14 07:07 - 2012-12-22 10:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-13 13:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-12 13:30 - 2014-04-12 13:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-12 12:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-12 10:08 - 2014-04-12 10:08 - 00003038 _____ () C:\Windows\System32\Tasks\{60733D86-7424-44B5-B3FE-37E06666758D}
2014-04-11 22:08 - 2010-09-14 18:34 - 00024576 _____ () C:\Users\Luise\Documents\MUSIKMUSIKMUSIK.wps
2014-04-11 21:01 - 2014-04-11 21:01 - 00000000 __SHD () C:\Users\Luise\AppData\Local\EmieUserList
2014-04-11 21:01 - 2014-04-11 21:01 - 00000000 __SHD () C:\Users\Luise\AppData\Local\EmieSiteList
2014-04-11 07:50 - 2014-04-11 07:50 - 00000000 __SHD () C:\Users\Tina\AppData\Local\EmieUserList
2014-04-11 07:50 - 2014-04-11 07:50 - 00000000 __SHD () C:\Users\Tina\AppData\Local\EmieSiteList
2014-04-11 07:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-09 19:08 - 2011-12-16 19:10 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 19:06 - 2013-07-12 13:21 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 17:25 - 2010-04-17 08:18 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 15:41 - 2014-04-09 15:41 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Avira
2014-04-06 23:37 - 2010-05-01 12:42 - 00000000 ____D () C:\Program Files\Google
2014-04-06 23:37 - 2010-05-01 12:41 - 00000000 ____D () C:\ProgramData\Google
2014-04-06 23:37 - 2010-05-01 12:41 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-06 08:10 - 2012-01-28 13:10 - 00000000 ____D () C:\Users\Robert\AppData\Local\Htc
2014-04-05 14:28 - 2014-04-05 14:28 - 00000000 ____D () C:\Users\Luise\AppData\Roaming\Avira
2014-04-05 10:03 - 2014-04-05 09:41 - 00004559 _____ () C:\WirelessDiagLog.csv
2014-04-05 09:02 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-05 08:42 - 2010-05-01 12:42 - 00000000 ____D () C:\Users\Robert\AppData\Local\Google
2014-04-05 08:13 - 2014-04-05 08:13 - 00000000 ____D () C:\Users\Robert\AppData\Roaming\Avira
2014-04-05 08:12 - 2014-04-05 08:12 - 00001996 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-04-05 08:12 - 2014-04-05 08:12 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-04-05 08:12 - 2010-04-17 16:17 - 00000000 ____D () C:\ProgramData\Avira
2014-04-05 08:04 - 2014-04-05 08:12 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-05 08:04 - 2014-04-05 08:12 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-05 08:04 - 2014-04-05 08:12 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-05 08:04 - 2014-04-05 08:12 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-04-03 09:51 - 2014-04-19 21:03 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-19 21:03 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-19 21:03 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 14:55 - 2010-05-01 12:42 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-02 14:55 - 2010-05-01 12:42 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-31 13:20 - 2010-05-01 15:16 - 00000000 ____D () C:\Users\Luise\AppData\Local\Google
2014-03-31 09:35 - 2010-04-13 21:26 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-30 19:17 - 2014-03-30 19:13 - 148202976 _____ () C:\Users\Robert\Downloads\avira_antivirus_suite_en.exe
2014-03-30 12:23 - 2014-03-30 12:23 - 00001055 _____ () C:\Users\Luise\Desktop\Continue VuuPC Installation.lnk
2014-03-30 11:54 - 2014-03-30 11:54 - 00000000 _____ () C:\Users\Luise\daemonprocess.txt
2014-03-29 18:32 - 2014-03-29 18:31 - 00000000 ____D () C:\Users\Robert\AppData\Roaming\vlc
2014-03-29 18:28 - 2014-03-29 18:28 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-03-29 18:28 - 2014-03-29 18:26 - 25567416 _____ () C:\Users\Robert\Downloads\vlc-2.1.3-win32(1).exe
2014-03-29 18:28 - 2014-03-29 18:25 - 25567416 _____ () C:\Users\Robert\Downloads\vlc-2.1.3-win32.exe
2014-03-29 18:28 - 2014-03-29 18:24 - 00000000 ____D () C:\Users\Robert\AppData\Local\cache
2014-03-29 18:27 - 2014-03-29 18:27 - 00000044 _____ () C:\Users\Robert\AppData\Roaming\WB.CFG
2014-03-29 18:24 - 2014-03-29 18:24 - 00001975 _____ () C:\Users\Robert\Desktop\Sync Folder.lnk
2014-03-29 18:24 - 2014-03-29 18:24 - 00000000 ____D () C:\Users\Robert\.android
2014-03-29 18:24 - 2014-03-29 18:24 - 00000000 _____ () C:\Users\Robert\daemonprocess.txt
2014-03-29 18:24 - 2010-04-14 11:21 - 00000000 ____D () C:\Users\Robert
2014-03-29 18:13 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-03-26 22:13 - 2014-03-26 10:14 - 00000000 ____D () C:\Users\Luise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Guard Protection
2014-03-26 17:35 - 2011-02-27 11:45 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Skype
2014-03-26 15:52 - 2011-01-23 16:13 - 00001084 _____ () C:\Users\Tina\AppData\Roaming\wklnhst.dat
2014-03-26 10:52 - 2014-03-26 10:48 - 138607664 _____ () C:\Users\Tina\Downloads\avira_free_antivirus_de_14.0.3.350.exe
2014-03-25 20:02 - 2014-03-25 20:02 - 00000761 _____ () C:\Windows\system32\Drivers\etc\hosts.txt
2014-03-24 13:11 - 2013-11-29 20:24 - 00000000 ____D () C:\Users\Luise\Documents\Outlook-Dateien
Some content of TEMP:
====================
C:\Users\Luise\AppData\Local\Temp\avgnt.exe
C:\Users\Luise\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-19 21:42
==================== End Of Log ============================ --- --- --- |