Sprinkles | 05.05.2014 21:07 | So !
Endlich fertig. Tut mir leid, dass ich mich so unregelmäßig melde. Ich bin in letzter Zeit garnicht so oft am PC gewesen. u . u
Ich hab aber jetzt alles, hoffe ich !
MBAM : Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 05.05.2014 21:03:50, SYSTEM, ADMIN-PC, Protection, Malware Protection, Starting,
Protection, 05.05.2014 21:03:50, SYSTEM, ADMIN-PC, Protection, Malware Protection, Started,
Protection, 05.05.2014 21:03:50, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Starting,
Update, 05.05.2014 21:03:57, SYSTEM, ADMIN-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Protection, 05.05.2014 21:04:02, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Started,
Update, 05.05.2014 21:05:03, SYSTEM, ADMIN-PC, Manual, Malware Database, 2014.3.4.9, 2014.5.5.10,
Protection, 05.05.2014 21:05:04, SYSTEM, ADMIN-PC, Protection, Refresh, Starting,
Protection, 05.05.2014 21:05:04, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Stopping,
Protection, 05.05.2014 21:05:04, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Stopped,
Protection, 05.05.2014 21:05:10, SYSTEM, ADMIN-PC, Protection, Refresh, Success,
Protection, 05.05.2014 21:05:10, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Starting,
Protection, 05.05.2014 21:05:10, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Started,
Protection, 05.05.2014 21:26:24, SYSTEM, ADMIN-PC, Protection, Malware Protection, Starting,
Protection, 05.05.2014 21:26:24, SYSTEM, ADMIN-PC, Protection, Malware Protection, Started,
Protection, 05.05.2014 21:26:24, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Starting,
Protection, 05.05.2014 21:26:58, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, Started,
Detection, 05.05.2014 21:27:56, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, IP, 82.98.97.185, c29cef30eae4732d.dpa.download-web-shield.com, 49278, Outbound, C:\Windows\System32\tapi364.exe,
Detection, 05.05.2014 21:27:56, SYSTEM, ADMIN-PC, Protection, Malicious Website Protection, IP, 82.98.97.185, c29cef30eae4732d.dpa.download-web-shield.com, 49278, Outbound, C:\Windows\System32\tapi364.exe,
(end) ADC Cleaner : Code:
# AdwCleaner v3.207 - Bericht erstellt am 05/05/2014 um 21:37:27
# Aktualisiert 05/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Admin - ADMIN-PC
# Gestartet von : C:\Users\Admin\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Admin\AppData\Local\wwerwerwe
Ordner Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblenkmcolcdonmlfknbpbgjebabcoae
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v29.0 (de)
[ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\08qyinha.default\prefs.js ]
-\\ Google Chrome v34.0.1847.131
[ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://anisearch.de/?page=suche&mode=auswahl&qsearch={searchTerms}
Gelöscht [Search Provider] : hxxp://www.anisearch.com/anime/index/?char=all&sort=rank&q=true&text={searchTerms}
Gelöscht [Extension] : iblenkmcolcdonmlfknbpbgjebabcoae
*************************
AdwCleaner[R0].txt - [5969 octets] - [26/04/2014 22:27:21]
AdwCleaner[R1].txt - [6733 octets] - [26/04/2014 23:54:30]
AdwCleaner[R2].txt - [3257 octets] - [27/04/2014 21:24:39]
AdwCleaner[R3].txt - [1812 octets] - [28/04/2014 00:30:46]
AdwCleaner[R4].txt - [4383 octets] - [05/05/2014 21:34:00]
AdwCleaner[S0].txt - [315 octets] - [26/04/2014 22:48:56]
AdwCleaner[S1].txt - [6440 octets] - [27/04/2014 00:46:42]
AdwCleaner[S2].txt - [3144 octets] - [27/04/2014 21:33:10]
AdwCleaner[S3].txt - [4304 octets] - [05/05/2014 21:37:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [4364 octets] ##########
JRT : Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Admin on 05.05.2014 at 21:47:21,99
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\appshat-distribution_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\appshat-distribution_rasmancs
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.05.2014 at 21:56:01,28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST :
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-05-2014 02
Ran by Admin (administrator) on ADMIN-PC on 05-05-2014 22:02:43
Running from C:\Users\Admin\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Spotify Ltd) C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
() C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe
() C:\Program Files (x86)\Drakonia Black\hid.exe
(Game Inc.) C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Drakonia Black\trayicon.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Windows\System32\tapi364.exe
() C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13213840 2012-10-26] (Realtek Semiconductor)
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Black\hid.exe [247296 2013-06-26] ()
HKLM-x32\...\Run: [GamingKeyboard] => C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe [1805824 2013-10-16] (Game Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Download Protect] => C:\ProgramData\dlprotect.exe
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1833934875-2978528442-3521743640-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation)
HKU\S-1-5-21-1833934875-2978528442-3521743640-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20586656 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1833934875-2978528442-3521743640-1000\...\Run: [Spotify Web Helper] => C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-12] (Spotify Ltd)
HKU\S-1-5-21-1833934875-2978528442-3521743640-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA1100 Genie.lnk
ShortcutTarget: NETGEAR WNA1100 Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\08qyinha.default
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: raving reyven - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\08qyinha.default\Extensions\{e63d9559-e4c3-499e-867a-a3c9d0a21400}.xpi [2014-04-30]
FF HKLM-x32\...\Firefox\Extensions: [{0B0D932A-1166-4556-9E3C-99BF3D5A450D}] - C:\Windows\Installer\{0B836E91-60D5-4BE0-97F6-E12DC03B5CCB}\{0B0D932A-1166-4556-9E3C-99BF3D5A450D}.xpi
FF Extension: No Name - C:\Windows\Installer\{0B836E91-60D5-4BE0-97F6-E12DC03B5CCB}\{0B0D932A-1166-4556-9E3C-99BF3D5A450D}.xpi [2014-04-27]
Chrome:
=======
CHR HomePage:
CHR StartupUrls: "chrome://newtab/"
CHR Extension: (ProxTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2013-11-29]
CHR Extension: (reddit companion) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\algjnflpgoopkdijmkalfcifomdhmcbe [2013-11-22]
CHR Extension: (Missing e) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid [2013-11-22]
CHR Extension: (Download Protect) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkfegnnpelgenldnapeiogpfaknfdhee [2014-04-27]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-22]
CHR Extension: (Adblock Plus) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-29]
CHR Extension: (Look of Disapproval) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmomlddchhdnchpieaalgkpgaafohlbn [2013-11-22]
CHR Extension: (Poupee Helper) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllcfmkookkmkcedcnbdhcpmmeflmilc [2013-11-22]
CHR Extension: (cats) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmekamlpkbcegncocdmhnoogddkeekgn [2013-11-29]
CHR Extension: (We Heart It) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblenkmcolcdonmlfknbpbgjebabcoae [2014-04-28]
CHR Extension: (rikaikun) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jipdnfibhldikgcjhfnomkfpcebammhp [2013-11-22]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2013-11-22]
CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-22]
CHR Extension: (Hover Zoom) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl [2013-11-28]
CHR Extension: (Google Mail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-22]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 TCPSVCSd; C:\Windows\system32\tapi364.exe [118784 2014-04-24] ()
R2 WSWNA1100; C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe [297440 2011-07-28] ()
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [31232 2013-10-15] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-05-05] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [768680 2013-06-26] (Microsoft Corporation)
R3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2013-06-26] (Microsoft Corporation)
R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29352 2013-06-26] (Microsoft Corporation)
R3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2013-06-26] (Microsoft Corporation)
R1 {e63d9559-e4c3-499e-867a-a3c9d0a21400}Gw64; C:\Windows\System32\drivers\{e63d9559-e4c3-499e-867a-a3c9d0a21400}Gw64.sys [61120 2014-04-24] (StdLib)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-05 22:02 - 2014-05-05 22:02 - 00000000 ____D () C:\Users\Admin\Downloads\FRST-OlderVersion
2014-05-05 21:56 - 2014-05-05 21:56 - 00000855 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-05-05 21:47 - 2014-05-05 21:47 - 00004444 _____ () C:\Users\Admin\Documents\AdwCleaner[S3].txt
2014-05-05 21:47 - 2014-05-05 21:47 - 00000000 ____D () C:\Windows\ERUNT
2014-05-05 21:33 - 2014-05-05 21:33 - 01316991 _____ () C:\Users\Admin\Downloads\adwcleaner.exe
2014-05-05 21:29 - 2014-05-05 21:29 - 00002058 _____ () C:\Users\Admin\Documents\mbam.txt
2014-05-05 21:03 - 2014-05-05 21:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-05 21:03 - 2014-05-05 21:03 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-05 21:03 - 2014-05-05 21:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-05 21:03 - 2014-05-05 21:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-05 21:03 - 2014-05-05 21:03 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-05 21:03 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-05 21:03 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-05 21:03 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-05 20:59 - 2014-05-05 21:02 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-05-05 20:59 - 2014-05-05 20:59 - 01016261 _____ (Thisisu) C:\Users\Admin\Downloads\JRT.exe
2014-05-03 19:11 - 2014-04-29 18:00 - 23133184 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-03 19:11 - 2014-04-29 17:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-03 19:11 - 2014-04-29 16:47 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-03 19:11 - 2014-04-29 16:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-29 19:54 - 2014-04-29 19:54 - 00032286 _____ () C:\Users\Admin\Documents\frst.txt
2014-04-29 19:45 - 2014-04-29 19:50 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Mozilla
2014-04-29 19:45 - 2014-04-29 19:50 - 00000000 ____D () C:\Users\Admin\AppData\Local\Mozilla
2014-04-29 19:45 - 2014-04-29 19:45 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-29 19:45 - 2014-04-29 19:45 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-29 19:45 - 2014-04-29 19:45 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-29 19:45 - 2014-04-29 19:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-29 19:45 - 2014-04-29 19:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-29 19:44 - 2014-05-05 22:02 - 00013467 _____ () C:\Users\Admin\Downloads\FRST.txt
2014-04-29 19:44 - 2014-04-29 19:45 - 00042582 _____ () C:\Users\Admin\Downloads\Addition.txt
2014-04-29 19:43 - 2014-05-05 22:02 - 00000000 ____D () C:\FRST
2014-04-29 19:41 - 2014-05-05 22:02 - 02063872 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2014-04-29 19:40 - 2014-04-29 19:40 - 00283376 _____ (Mozilla) C:\Users\Admin\Downloads\Firefox Setup Stub 29.0.exe
2014-04-28 00:31 - 2014-04-28 00:31 - 00050477 _____ () C:\Users\Admin\Downloads\Defogger.exe
2014-04-28 00:01 - 2014-04-28 00:04 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-27 21:38 - 2014-05-05 21:43 - 00008062 _____ () C:\Windows\PFRO.log
2014-04-27 21:38 - 2014-05-05 21:43 - 00000672 _____ () C:\Windows\setupact.log
2014-04-27 21:38 - 2014-04-27 21:38 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-27 21:23 - 2014-04-27 21:23 - 00006530 _____ () C:\Users\Admin\Documents\cc_20140427_212321.reg
2014-04-27 03:19 - 2014-04-27 17:45 - 00000728 __RSH () C:\ProgramData\ntuser.pol
2014-04-26 22:28 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-04-26 22:27 - 2014-05-05 21:40 - 00000000 ____D () C:\AdwCleaner
2014-04-26 03:17 - 2014-04-26 03:17 - 00001320 _____ () C:\Windows\wininit.ini
2014-04-26 02:33 - 2014-04-30 00:30 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-26 02:33 - 2014-04-26 02:40 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-04-26 02:33 - 2014-04-26 02:33 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-04-26 02:33 - 2014-04-26 02:33 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-04-26 02:33 - 2014-04-26 02:33 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-04-26 02:33 - 2014-04-26 02:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-04-26 02:33 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-04-26 02:30 - 2014-04-27 21:24 - 00009728 ___SH () C:\Users\Admin\Documents\Thumbs.db
2014-04-26 02:12 - 2014-04-26 02:23 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Admin\Documents\spybot-2.2.25.exe
2014-04-26 02:11 - 2014-04-26 02:11 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-26 02:11 - 2014-04-26 02:11 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-04-26 02:11 - 2014-04-26 02:11 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-26 02:04 - 2014-04-26 02:08 - 04745984 _____ (Piriform Ltd) C:\Users\Admin\Documents\ccsetup413.exe
2014-04-25 03:44 - 2014-04-25 06:15 - 00002122 _____ () C:\Windows\epplauncher.mif
2014-04-25 02:28 - 2014-04-24 12:33 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\{e63d9559-e4c3-499e-867a-a3c9d0a21400}Gw64.sys
2014-04-24 01:22 - 2014-04-24 01:22 - 00000000 ____D () C:\Program Files (x86)\Elaborate Bytes
2014-04-24 01:19 - 2014-04-24 01:19 - 00118784 _____ () C:\Windows\system32\tapi364.exe
2014-04-24 00:23 - 2014-04-24 00:51 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-04-24 00:15 - 2014-04-26 02:24 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
2014-04-24 00:14 - 2014-04-24 00:15 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-04-23 23:48 - 2014-04-23 23:48 - 00004224 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-23 23:48 - 2014-04-23 23:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-23 23:48 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-23 23:48 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-23 23:48 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-23 23:48 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-23 23:48 - 2005-02-24 16:04 - 00002581 _____ () C:\Program Files (x86)\system.pak
2014-04-23 23:48 - 2005-02-24 15:20 - 00939028 _____ () C:\Program Files (x86)\script.pak
2014-04-23 23:48 - 2005-02-24 15:20 - 00034088 _____ () C:\Program Files (x86)\0cg.pak
2014-04-23 23:43 - 2014-04-23 23:43 - 00000851 _____ () C:\Users\Admin\Desktop\µTorrent.lnk
2014-04-23 18:03 - 2014-04-23 20:24 - 626729440 ____R () C:\Users\Admin\Downloads\Togainu No Chi.rar
2014-04-09 23:12 - 2014-04-09 23:12 - 00003497 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel
2014-04-09 17:08 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 17:08 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 17:08 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 17:08 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 17:08 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 17:08 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 17:08 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 17:08 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 17:08 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 17:08 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 17:08 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 17:08 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 17:08 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 17:08 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 17:08 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 17:08 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 17:08 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-05 22:24 - 2014-04-23 23:43 - 00000831 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-04-05 22:14 - 2014-04-27 21:32 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\uTorrent
2014-04-05 22:12 - 2014-04-05 22:12 - 01671248 _____ (BitTorrent Inc.) C:\Users\Admin\Documents\uTorrent.exe
==================== One Month Modified Files and Folders =======
2014-05-05 22:02 - 2014-05-05 22:02 - 00000000 ____D () C:\Users\Admin\Downloads\FRST-OlderVersion
2014-05-05 22:02 - 2014-04-29 19:44 - 00013467 _____ () C:\Users\Admin\Downloads\FRST.txt
2014-05-05 22:02 - 2014-04-29 19:43 - 00000000 ____D () C:\FRST
2014-05-05 22:02 - 2014-04-29 19:41 - 02063872 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2014-05-05 21:56 - 2014-05-05 21:56 - 00000855 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-05-05 21:51 - 2009-07-14 06:45 - 00026096 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-05 21:51 - 2009-07-14 06:45 - 00026096 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-05 21:47 - 2014-05-05 21:47 - 00004444 _____ () C:\Users\Admin\Documents\AdwCleaner[S3].txt
2014-05-05 21:47 - 2014-05-05 21:47 - 00000000 ____D () C:\Windows\ERUNT
2014-05-05 21:46 - 2013-11-22 21:52 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype
2014-05-05 21:45 - 2013-11-22 18:52 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-05 21:44 - 2014-05-05 21:03 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-05 21:43 - 2014-04-27 21:38 - 00008062 _____ () C:\Windows\PFRO.log
2014-05-05 21:43 - 2014-04-27 21:38 - 00000672 _____ () C:\Windows\setupact.log
2014-05-05 21:43 - 2013-11-22 18:52 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-05 21:43 - 2013-10-16 18:38 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-05 21:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-05 21:42 - 2013-10-16 18:24 - 01597480 _____ () C:\Windows\WindowsUpdate.log
2014-05-05 21:40 - 2014-04-26 22:27 - 00000000 ____D () C:\AdwCleaner
2014-05-05 21:33 - 2014-05-05 21:33 - 01316991 _____ () C:\Users\Admin\Downloads\adwcleaner.exe
2014-05-05 21:29 - 2014-05-05 21:29 - 00002058 _____ () C:\Users\Admin\Documents\mbam.txt
2014-05-05 21:28 - 2013-11-22 18:52 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-05 21:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-05-05 21:25 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2014-05-05 21:24 - 2013-11-23 18:38 - 00000000 ____D () C:\Users\Admin\AppData\Local\Songr
2014-05-05 21:17 - 2013-11-22 22:02 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\vlc
2014-05-05 21:07 - 2013-12-05 22:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-05 21:03 - 2014-05-05 21:03 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-05 21:03 - 2014-05-05 21:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-05 21:03 - 2014-05-05 21:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-05 21:03 - 2014-05-05 21:03 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-05 21:02 - 2014-05-05 20:59 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-05-05 20:59 - 2014-05-05 20:59 - 01016261 _____ (Thisisu) C:\Users\Admin\Downloads\JRT.exe
2014-05-04 21:34 - 2013-11-23 01:11 - 00000000 ____D () C:\Users\Admin\AppData\Local\PMB Files
2014-05-04 21:04 - 2013-11-23 01:11 - 00000000 ____D () C:\ProgramData\PMB Files
2014-05-04 21:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-04 17:51 - 2013-11-22 19:10 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Spotify
2014-04-30 00:34 - 2013-11-23 18:39 - 00001076 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Songr.lnk
2014-04-30 00:31 - 2013-11-22 18:52 - 00002175 ____H () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-30 00:30 - 2014-04-26 02:33 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-29 20:12 - 2013-12-05 22:23 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-29 20:12 - 2013-12-05 22:23 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-29 20:12 - 2013-12-05 22:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-29 19:54 - 2014-04-29 19:54 - 00032286 _____ () C:\Users\Admin\Documents\frst.txt
2014-04-29 19:50 - 2014-04-29 19:45 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Mozilla
2014-04-29 19:50 - 2014-04-29 19:45 - 00000000 ____D () C:\Users\Admin\AppData\Local\Mozilla
2014-04-29 19:45 - 2014-04-29 19:45 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-29 19:45 - 2014-04-29 19:45 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-29 19:45 - 2014-04-29 19:45 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-29 19:45 - 2014-04-29 19:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-29 19:45 - 2014-04-29 19:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-29 19:45 - 2014-04-29 19:44 - 00042582 _____ () C:\Users\Admin\Downloads\Addition.txt
2014-04-29 19:40 - 2014-04-29 19:40 - 00283376 _____ (Mozilla) C:\Users\Admin\Downloads\Firefox Setup Stub 29.0.exe
2014-04-29 18:00 - 2014-05-03 19:11 - 23133184 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 17:24 - 2014-05-03 19:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 16:47 - 2014-05-03 19:11 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 16:14 - 2014-05-03 19:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-28 23:42 - 2013-10-17 04:19 - 00699860 _____ () C:\Windows\system32\perfh007.dat
2014-04-28 23:42 - 2013-10-17 04:19 - 00149742 _____ () C:\Windows\system32\perfc007.dat
2014-04-28 23:42 - 2009-07-14 07:13 - 01622124 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-28 00:31 - 2014-04-28 00:31 - 00050477 _____ () C:\Users\Admin\Downloads\Defogger.exe
2014-04-28 00:04 - 2014-04-28 00:01 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-27 21:38 - 2014-04-27 21:38 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-27 21:32 - 2014-04-05 22:14 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\uTorrent
2014-04-27 21:24 - 2014-04-26 02:30 - 00009728 ___SH () C:\Users\Admin\Documents\Thumbs.db
2014-04-27 21:23 - 2014-04-27 21:23 - 00006530 _____ () C:\Users\Admin\Documents\cc_20140427_212321.reg
2014-04-27 21:22 - 2014-02-20 20:42 - 00000000 ____D () C:\Users\Admin\AppData\Local\CrashDumps
2014-04-27 21:20 - 2013-11-22 21:57 - 00000000 ____D () C:\Users\Admin\AppData\Local\Spotify
2014-04-27 17:45 - 2014-04-27 03:19 - 00000728 __RSH () C:\ProgramData\ntuser.pol
2014-04-27 04:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-27 03:19 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-26 03:17 - 2014-04-26 03:17 - 00001320 _____ () C:\Windows\wininit.ini
2014-04-26 02:40 - 2014-04-26 02:33 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-04-26 02:33 - 2014-04-26 02:33 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-04-26 02:33 - 2014-04-26 02:33 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-04-26 02:33 - 2014-04-26 02:33 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-04-26 02:33 - 2014-04-26 02:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-04-26 02:30 - 2014-02-23 17:16 - 00000000 ____D () C:\Users\Admin\Documents\MEMENTO2
2014-04-26 02:30 - 2013-11-24 18:07 - 00000000 ____D () C:\Users\Admin\Documents\[SCHULE]
2014-04-26 02:30 - 2013-11-24 18:04 - 00000000 ____D () C:\Users\Admin\Documents\[BOOKS]
2014-04-26 02:24 - 2014-04-24 00:15 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
2014-04-26 02:24 - 2013-10-17 04:21 - 00000000 ____D () C:\Windows\Panther
2014-04-26 02:23 - 2014-04-26 02:12 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Admin\Documents\spybot-2.2.25.exe
2014-04-26 02:11 - 2014-04-26 02:11 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-26 02:11 - 2014-04-26 02:11 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-04-26 02:11 - 2014-04-26 02:11 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-26 02:08 - 2014-04-26 02:04 - 04745984 _____ (Piriform Ltd) C:\Users\Admin\Documents\ccsetup413.exe
2014-04-25 06:15 - 2014-04-25 03:44 - 00002122 _____ () C:\Windows\epplauncher.mif
2014-04-24 12:33 - 2014-04-25 02:28 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\{e63d9559-e4c3-499e-867a-a3c9d0a21400}Gw64.sys
2014-04-24 01:22 - 2014-04-24 01:22 - 00000000 ____D () C:\Program Files (x86)\Elaborate Bytes
2014-04-24 01:19 - 2014-04-24 01:19 - 00118784 _____ () C:\Windows\system32\tapi364.exe
2014-04-24 00:51 - 2014-04-24 00:23 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-04-24 00:51 - 2013-11-24 18:05 - 00000000 ____D () C:\Users\Admin\Documents\[GAMES]
2014-04-24 00:15 - 2014-04-24 00:14 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-04-23 23:49 - 2014-02-17 00:28 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-23 23:48 - 2014-04-23 23:48 - 00004224 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-23 23:48 - 2014-04-23 23:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-23 23:48 - 2014-02-17 00:27 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-23 23:43 - 2014-04-23 23:43 - 00000851 _____ () C:\Users\Admin\Desktop\µTorrent.lnk
2014-04-23 23:43 - 2014-04-05 22:24 - 00000831 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-04-23 20:24 - 2014-04-23 18:03 - 626729440 ____R () C:\Users\Admin\Downloads\Togainu No Chi.rar
2014-04-14 20:13 - 2014-04-23 23:48 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2014-04-23 23:48 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2014-04-23 23:48 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2014-04-23 23:48 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-09 23:18 - 2013-11-23 17:33 - 00000000 ____D () C:\Users\Admin\.gimp-2.8
2014-04-09 23:12 - 2014-04-09 23:12 - 00003497 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel
2014-04-09 19:58 - 2013-11-23 17:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Mp3tag
2014-04-09 18:37 - 2013-11-25 22:52 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 18:36 - 2013-11-25 22:52 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 18:22 - 2013-11-23 17:37 - 00000000 ____D () C:\Users\Admin\AppData\Local\gtk-2.0
2014-04-07 20:28 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-05 22:12 - 2014-04-05 22:12 - 01671248 _____ (BitTorrent Inc.) C:\Users\Admin\Documents\uTorrent.exe
Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-19 00:03
==================== End Of Log ============================ --- --- ---
Danke nochmal für alles ! ★
Liebe Grüße
~ Sprinkles |