russak777 | 15.05.2014 21:03 | Hallo Schrauber, war letzte Zeit krank. Fange aber gleich wieder an...
mfg russak777
Hallo,
hier sind weitere Dateien:
mbab: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 15.05.2014 17:34:47, SYSTEM, ILJA-PC, Protection, Malware Protection, Starting,
Protection, 15.05.2014 17:34:47, SYSTEM, ILJA-PC, Protection, Malware Protection, Started,
Protection, 15.05.2014 17:34:47, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Starting,
Update, 15.05.2014 17:34:55, SYSTEM, ILJA-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 15.05.2014 17:35:09, SYSTEM, ILJA-PC, Manual, Malware Database, 2014.3.4.9, 2014.5.15.6,
Protection, 15.05.2014 17:35:15, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Started,
Protection, 15.05.2014 17:35:27, SYSTEM, ILJA-PC, Protection, Refresh, Starting,
Protection, 15.05.2014 17:35:27, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Stopping,
Protection, 15.05.2014 17:35:28, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Stopped,
Protection, 15.05.2014 17:35:42, SYSTEM, ILJA-PC, Protection, Refresh, Success,
Protection, 15.05.2014 17:35:43, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Starting,
Protection, 15.05.2014 17:35:46, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Started,
Update, 15.05.2014 18:17:42, SYSTEM, ILJA-PC, Scheduler, Malware Database, 2014.5.15.6, 2014.5.15.7,
Protection, 15.05.2014 18:17:44, SYSTEM, ILJA-PC, Protection, Refresh, Starting,
Protection, 15.05.2014 18:17:44, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Stopping,
Protection, 15.05.2014 18:17:44, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Stopped,
Protection, 15.05.2014 18:19:13, SYSTEM, ILJA-PC, Protection, Refresh, Success,
Protection, 15.05.2014 18:19:13, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Starting,
Protection, 15.05.2014 18:19:19, SYSTEM, ILJA-PC, Protection, Malicious Website Protection, Started,
(end) AdwCleaner[S1]: Code:
# AdwCleaner v3.208 - Bericht erstellt am 15/05/2014 um 19:04:54
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : ilja - ILJA-PC
# Gestartet von : C:\Users\ilja\Downloads\adwcleaner_3.208 (1).exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\Extensions\126c9ec1-e913-410f-94df-6262dd70e044@94392a4b-d7bd-4563-8bcd-ba96cf8055b2.com
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin.gif
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin.src
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-10.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-11.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-12.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-13.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-14.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-15.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-16.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-17.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-18.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-19.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-2.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-20.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-21.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-22.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-23.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-24.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-25.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-3.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-4.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-5.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-6.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-7.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-8.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-9.xml
Datei Gelöscht : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\user.js
Datei Gelöscht : C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www1.delta-search.com_0.localstorage
Datei Gelöscht : C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www1.delta-search.com_0.localstorage-journal
Datei Gelöscht : C:\Windows\System32\Tasks\BrowserDefendert
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [Tubesaver@istqt.co]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ojcdnngpmbenohhjlickdajclhbcaada
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0876CC00-6BF0-42C3-9263-7139D19141DE}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0876CC00-6BF0-42C3-9263-7139D19141DE}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{84490AA9-64AD-4971-AB96-84082798CB7A}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{84490AA9-64AD-4971-AB96-84082798CB7A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\592de8cbd35b840
Schlüssel Gelöscht : HKLM\SOFTWARE\592de8cbd35b840
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\Cr_Installer
Schlüssel Gelöscht : HKCU\Software\Grand Virtual
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\TubeSaver
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\dt soft\daemon tools toolbar
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mein Gutscheincode
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Tubesaver@istqt.co
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16545
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.internaldb.Resources_meta.value", "%7B%22css/icon_128.png%22%3A%7B%22id%22%3A155226%2C%22ver%22%3A[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.internaldb.Resources_resource_155237.value", "%22/*%21%20jQuery%20v1.8.2%20jquery.com%20%7C%20jque[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_13.name", "CrossriderAppUtils");
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_14.name", "CrossriderUtils");
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==true)&&(typeof _[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.a[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_con[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());[...]
Zeile gelöscht : user_pref("extensions.a126c9ec1e913410f94df6262dd70e04494392a4bd7bd45638bcdba96cf8055b2com29481.29481.plugins.plugin_78.name", "CrossriderInfo");
Zeile gelöscht : user_pref("extensions.enabledAddons", "ffxtlbr%40delta.com:1.5.0,%7B800b5000-a755-47e1-992b-48a1c1357f07%7D:2.0.1.6,126c9ec1-e913-410f-94df-6262dd70e044%4094392a4b-d7bd-4563-8bcd-ba96cf8055b2.com:0.94[...]
Zeile gelöscht : user_pref("icqtoolbar.allowSendURL", false);
Zeile gelöscht : user_pref("icqtoolbar.engineVerified", false);
Zeile gelöscht : user_pref("icqtoolbar.geolastmodified", 1399612352);
Zeile gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options");
Zeile gelöscht : user_pref("icqtoolbar.history", "N%20klasse%20f%C3%BChrerschein||%D0%9A%D1%83%D1%87%D0%B8%D0%BD%20%D0%98%D0%B2%D0%B0%D0%BD%20%D1%87%D0%B5%D0%BB%D0%BE%D0%B2%D0%B5%D0%BA%20%D0%B2%20%D1%82%D0%B5%D0%BB%D0[...]
Zeile gelöscht : user_pref("icqtoolbar.icqgeo", 49);
Zeile gelöscht : user_pref("icqtoolbar.installTime", "1334233214");
Zeile gelöscht : user_pref("icqtoolbar.installsource", "1");
Zeile gelöscht : user_pref("icqtoolbar.itbsitescount", 0);
Zeile gelöscht : user_pref("icqtoolbar.newtab_state", "1");
Zeile gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
Zeile gelöscht : user_pref("icqtoolbar.previousFFVersion", "28.0");
Zeile gelöscht : user_pref("icqtoolbar.removedsitescount", 28);
Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
Zeile gelöscht : user_pref("icqtoolbar.suggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "127723581612772352691277320616925");
Zeile gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1399612392);
Zeile gelöscht : user_pref("icqtoolbar.version", "2.0.1.6");
Zeile gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherWasShown", 0);
Zeile gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");
-\\ Google Chrome v34.0.1847.131
[ Datei : C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=240E001F3C568A54&affID=120692&tsp=4967
Gelöscht [Homepage] : hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=240E001F3C568A54&affID=120692&tsp=4967
Gelöscht [Extension] : eooncjejnppfjjklapaamhcdmjbilmde
*************************
AdwCleaner[R0].txt - [46125 octets] - [07/05/2014 20:52:24]
AdwCleaner[R1].txt - [46125 octets] - [07/05/2014 21:22:16]
AdwCleaner[R2].txt - [46125 octets] - [07/05/2014 21:29:37]
AdwCleaner[R3].txt - [45741 octets] - [08/05/2014 09:15:55]
AdwCleaner[R4].txt - [46644 octets] - [08/05/2014 09:22:11]
AdwCleaner[R5].txt - [40115 octets] - [15/05/2014 17:00:34]
AdwCleaner[R6].txt - [15095 octets] - [15/05/2014 18:43:06]
AdwCleaner[R7].txt - [14246 octets] - [15/05/2014 19:02:48]
AdwCleaner[S0].txt - [1339 octets] - [15/05/2014 18:47:46]
AdwCleaner[S1].txt - [14122 octets] - [15/05/2014 19:04:54]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [14183 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by ilja on 15.05.2014 at 19:59:47,29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\ilja\AppData\Roaming\mozilla\firefox\profiles\wjxcasbq.default\extensions\126
Emptied folder: C:\Users\ilja\AppData\Roaming\mozilla\firefox\profiles\wjxcasbq.default\minidumps [6 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.05.2014 at 20:16:01,25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ neue FRST-Datei:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-05-2014
Ran by ilja (administrator) on ILJA-PC on 15-05-2014 21:52:46
Running from C:\Users\ilja\Downloads
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
(Acer Inc.) C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
(Acer Inc.) C:\Acer\Empowering Technology\eNet\eNet Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Acer\Mobility Center\MobilityService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Sophos Limited) C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(acer) C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
() C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
(Realtek Semiconductor Corp.) C:\Users\ilja\AppData\Local\Temp\RtkBtMnt.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
() C:\Program Files\OpenVPN\bin\openvpn-gui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe
(FK2) C:\Windows\System32\svchospt.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Sophos Limited) C:\Program Files\Sophos\AutoUpdate\ALMon.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(PC Tools) C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
(Apple Inc.) D:\Ipod\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Nokia) C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe
() C:\VkontakteDJ\VKontakteDJ.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Logitech, Inc.) C:\Program Files\Maus\SetPoint\SetPoint.exe
(Acer Inc.) C:\Acer\Empowering Technology\eNet\eNMTray.exe
(Acer Inc.) C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
(Acer Inc.) C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\ilja\Downloads\FRST (1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-09-07] (Synaptics, Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-08] (Realtek Semiconductor)
HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [81920 2008-01-22] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] => C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [62760 2007-10-11] ()
HKLM\...\Run: [eDataSecurity Loader] => C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [521776 2008-01-03] (Egis Incorporated)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [858632 2008-01-08] (Dritek System Inc.)
HKLM\...\Run: [eRecoveryService] => [X]
HKLM\...\Run: [WarReg_PopUp] => C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe [303104 2008-01-29] (Acer Incorporated)
HKLM\...\Run: [openvpn-gui] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [99328 2005-08-18] ()
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Monitor] => C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [55824 2009-06-17] (Logitech, Inc.)
HKLM\...\Run: [svchospt] => C:\Windows\system32\svchospt.exe [962560 2009-09-01] (FK2)
HKLM\...\Run: [AppleSyncNotifier] => C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.)
HKLM\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
HKLM\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files\Sophos\AutoUpdate\almon.exe [900160 2012-10-06] (Sophos Limited)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] ()
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [SSDMonitor] => C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2011-10-25] (PC Tools)
HKLM\...\Run: [HTC Sync Loader] => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [651264 2012-04-17] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe [132496 2007-07-12] (Sun Microsystems, Inc.)
HKLM\...\Run: [iTunesHelper] => D:\Ipod\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1
HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\Run: [PC Suite Tray] => C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe [1451520 2009-11-11] (Nokia)
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\Run: [MultiCalc] => C:\Program Files\MultiCalc-Taschenrechner\MultiCalc.exe WinStart
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\Run: [VkontakteDJ] => C:\VkontakteDJ\VKontakteDJ.exe [2771280 2011-11-24] ()
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\Run: [MobileDocuments] => C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\Run: [Praetorian] => C:\Users\ilja\AppData\Local\Yandex\Updater\praetorian.exe
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\MountPoints2: {4ab25c20-1b0e-11de-bcc0-000000000000} - H:\setup.exe
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\MountPoints2: {7eb802d1-b226-11e0-ab85-000000000000} - H:\LaunchU3.exe -a
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\MountPoints2: {aaef9465-781f-11de-be56-000000000000} - G:\setup.exe
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\MountPoints2: {c5eca59a-94a3-11df-aba7-000000000000} - G:\AutoRun.exe
HKU\S-1-5-21-2905236926-120331663-3061100549-1003\...\MountPoints2: {c5eca5bc-94a3-11df-aba7-000000000000} - G:\AutoRun.exe
AppInit_DLLs: acaptuser32.dll => C:\Windows\system32\acaptuser32.dll [111992 2008-06-11] (Adobe Systems, Inc.)
AppInit_DLLs: ,C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL => C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll [221840 2012-12-08] (Sophos Limited)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
ShortcutTarget: Empowering Technology Launcher.lnk -> C:\Acer\Empowering Technology\eAPLauncher.exe (Acer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Maus\SetPoint\SetPoint.exe (Logitech, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/?ocid=ie9hp
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://de.msn.com/?pc=BB07
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.intl.acer.yahoo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.intl.acer.yahoo.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - Moikrug URL = hxxp://moikrug.ru/persons/?clid=143436&charset=utf-8&keywords={searchTerms}&submitted=1
SearchScopes: HKCU - Yandex URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-acer
SearchScopes: HKCU - {4EE790E3-D710-4D30-B222-53E335756EC2} URL = hxxp://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKCU - {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://yandex.ru/yandsearch?clid=143436&text={searchTerms}
SearchScopes: HKCU - {EC41D154-2C04-4D31-AF37-86B28CB021C7} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 21 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Code:
FireFox:
========
FF ProfilePath: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default
FF Homepage: user_pref("browser.startup.homepage", );
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\Ipod\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-26.xml
FF SearchPlugin: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\icqplugin-27.xml
FF SearchPlugin: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-04-27]
FF Extension: WEB.DE MailCheck - C:\Users\ilja\AppData\Roaming\Mozilla\Firefox\Profiles\wjxcasbq.default\Extensions\toolbar@web.de.xpi [2012-02-03]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-05]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ []
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-02-02]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.de/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll No File
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\34.0.1847.131\pdf.dll ()
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - D:\Ipod\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (YouTube) - C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-14]
CHR Extension: (Google-Suche) - C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-14]
CHR Extension: (Google Wallet) - C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-07]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 video>) - C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2011-12-14]
CHR Extension: (Google Mail) - C:\Users\ilja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-14]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
========================== Services (Whitelisted) =================
R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [506416 2008-01-03] (Egis Incorporated)
R2 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-10-01] (Acer Inc.)
R2 eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [131072 2007-12-20] (Acer Inc.)
R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.)
R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-11-27] ()
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [16384 2006-10-01] ()
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2011-10-25] (PC Tools)
R2 SAVAdminService; C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [216640 2012-12-08] (Sophos Limited)
R2 SAVService; C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe [139840 2012-10-06] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files\Sophos\AutoUpdate\ALsvc.exe [232512 2012-10-06] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2012-10-06] (Sophos Limited)
R2 swi_service; C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2869824 2012-12-08] (Sophos Limited)
S2 swi_update; C:\ProgramData\Sophos\Web Intelligence\swi_update.exe [1459264 2012-12-08] (Sophos Limited)
R2 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [167936 2007-09-20] (acer)
==================== Drivers (Whitelisted) ====================
S3 AF15BDA; C:\Windows\System32\DRIVERS\AF15BDA.sys [483200 2011-04-26] (ITETech )
S3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.Sys [40720 2009-06-17] (Logitech, Inc.)
S3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.Sys [10384 2009-06-17] (Logitech, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-05-15] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-04-03] (Malwarebytes Corporation)
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [507136 2006-12-05] (PixArt Imaging Inc.)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [123680 2012-10-06] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [33696 2012-10-06] (Sophos Limited)
S3 SilverLink; C:\Windows\System32\Drivers\SilvrLnk.sys [21456 2004-01-28] (Texas Instruments Incorporated)
R1 SKMScan; C:\Windows\System32\DRIVERS\skmscan.sys [31736 2012-10-06] (Sophos Plc)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [22536 2011-10-20] (Sophos Plc)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2009-11-30] ()
R1 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [5632 2006-07-24] ()
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [26624 2006-10-01] (The OpenVPN Project)
S2 TICalc; C:\Windows\system32\Drivers\TICalc.sys [9152 2001-01-29] ()
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U1 sysaseop; \??\C:\Windows\system32\drivers\sysaseop.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-15 21:51 - 2014-05-15 21:52 - 01056768 _____ (Farbar) C:\Users\ilja\Downloads\FRST (1).exe
2014-05-15 21:45 - 2014-05-15 21:45 - 00000000 ____D () C:\Users\ilja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
2014-05-15 21:02 - 2014-05-15 21:02 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-05-15 20:55 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 20:55 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 20:55 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 20:16 - 2014-05-15 20:16 - 00000882 _____ () C:\Users\ilja\Desktop\JRT.txt
2014-05-15 19:58 - 2014-05-15 19:32 - 01016261 _____ (Thisisu) C:\Users\ilja\Desktop\JRT (1).exe
2014-05-15 19:33 - 2014-05-15 19:33 - 00000000 ____D () C:\Windows\ERUNT
2014-05-15 19:32 - 2014-05-15 19:32 - 01016261 _____ (Thisisu) C:\Users\ilja\Downloads\JRT (1).exe
2014-05-15 19:29 - 2014-05-15 19:29 - 00000000 ____D () C:\Users\ilja\Desktop\Reinigung
2014-05-15 18:39 - 2014-05-15 18:42 - 01325827 _____ () C:\Users\ilja\Downloads\adwcleaner_3.208 (1).exe
2014-05-15 18:35 - 2014-05-15 18:37 - 01325827 _____ () C:\Users\ilja\Downloads\adwcleaner_3.208.exe
2014-05-15 17:34 - 2014-05-15 21:51 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-15 17:33 - 2014-05-15 17:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-15 17:33 - 2014-05-15 17:33 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 17:33 - 2014-05-15 17:33 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-15 17:33 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-15 17:33 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-15 17:33 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-15 17:31 - 2014-05-15 17:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\ilja\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 16:29 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 15:37 - 2014-05-15 15:37 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-05-15 15:36 - 2014-05-15 15:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ilja\Downloads\revosetup95.exe
2014-05-15 15:26 - 2014-05-15 15:26 - 210160215 _____ () C:\Windows\MEMORY.DMP
2014-05-15 15:26 - 2014-05-15 15:26 - 00143424 _____ () C:\Windows\Minidump\Mini051514-01.dmp
2014-05-08 09:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-05-08 06:43 - 2014-05-08 06:45 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
2014-05-08 06:43 - 2014-05-08 06:45 - 00001891 _____ () C:\Users\Public\Desktop\Adobe Reader 9.lnk
2014-05-07 20:52 - 2014-05-15 19:09 - 00000000 ____D () C:\AdwCleaner
2014-05-07 20:39 - 2014-05-07 20:48 - 00047566 _____ () C:\Users\ilja\Downloads\Addition.txt
2014-05-07 20:37 - 2014-05-07 20:37 - 01016261 _____ (Thisisu) C:\Users\ilja\Downloads\JRT.exe
2014-05-07 20:34 - 2014-05-07 20:34 - 01316991 _____ () C:\Users\ilja\Downloads\adwcleaner (1).exe
2014-05-07 20:28 - 2014-05-15 21:52 - 00031917 _____ () C:\Users\ilja\Downloads\FRST.txt
2014-05-07 20:26 - 2014-05-15 21:52 - 00000000 ____D () C:\FRST
2014-05-07 20:25 - 2014-05-07 20:25 - 01053184 _____ (Farbar) C:\Users\ilja\Downloads\FRST.exe
2014-05-07 20:20 - 2014-05-07 20:21 - 02063872 _____ (Farbar) C:\Users\ilja\Downloads\FRST64.exe
==================== One Month Modified Files and Folders =======
2014-05-15 21:55 - 2012-12-08 16:15 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-15 21:54 - 2014-05-07 20:28 - 00031917 _____ () C:\Users\ilja\Downloads\FRST.txt
2014-05-15 21:52 - 2014-05-15 21:51 - 01056768 _____ (Farbar) C:\Users\ilja\Downloads\FRST (1).exe
2014-05-15 21:52 - 2014-05-07 20:26 - 00000000 ____D () C:\FRST
2014-05-15 21:51 - 2014-05-15 17:34 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-15 21:49 - 2006-11-02 12:33 - 01573724 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-15 21:47 - 2011-10-20 20:46 - 00000000 ____D () C:\Users\ilja\AppData\Local\Htc
2014-05-15 21:45 - 2014-05-15 21:45 - 00000000 ____D () C:\Users\ilja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
2014-05-15 21:44 - 2010-12-23 21:33 - 00001090 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-15 21:41 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-15 21:41 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-15 21:41 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-15 21:40 - 2014-01-14 13:43 - 00229694 _____ () C:\Windows\PFRO.log
2014-05-15 21:23 - 2009-03-25 13:24 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-05-15 21:23 - 2009-03-25 13:02 - 01337537 _____ () C:\Windows\WindowsUpdate.log
2014-05-15 21:23 - 2006-11-02 15:01 - 00032586 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-15 21:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-15 21:20 - 2008-03-27 22:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 21:12 - 2010-12-23 21:33 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-15 21:04 - 2013-09-27 03:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 21:04 - 2006-11-02 12:24 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-15 21:02 - 2014-05-15 21:02 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-05-15 20:16 - 2014-05-15 20:16 - 00000882 _____ () C:\Users\ilja\Desktop\JRT.txt
2014-05-15 19:33 - 2014-05-15 19:33 - 00000000 ____D () C:\Windows\ERUNT
2014-05-15 19:32 - 2014-05-15 19:58 - 01016261 _____ (Thisisu) C:\Users\ilja\Desktop\JRT (1).exe
2014-05-15 19:32 - 2014-05-15 19:32 - 01016261 _____ (Thisisu) C:\Users\ilja\Downloads\JRT (1).exe
2014-05-15 19:29 - 2014-05-15 19:29 - 00000000 ____D () C:\Users\ilja\Desktop\Reinigung
2014-05-15 19:09 - 2014-05-07 20:52 - 00000000 ____D () C:\AdwCleaner
2014-05-15 18:47 - 2010-06-23 21:16 - 00000000 ____D () C:\ProgramData\ICQ
2014-05-15 18:42 - 2014-05-15 18:39 - 01325827 _____ () C:\Users\ilja\Downloads\adwcleaner_3.208 (1).exe
2014-05-15 18:37 - 2014-05-15 18:35 - 01325827 _____ () C:\Users\ilja\Downloads\adwcleaner_3.208.exe
2014-05-15 17:33 - 2014-05-15 17:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-15 17:33 - 2014-05-15 17:33 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 17:33 - 2014-05-15 17:33 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-15 17:31 - 2014-05-15 17:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\ilja\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 15:56 - 2012-12-08 16:14 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-05-15 15:56 - 2011-12-03 00:42 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-05-15 15:37 - 2014-05-15 15:37 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-05-15 15:37 - 2014-05-15 15:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ilja\Downloads\revosetup95.exe
2014-05-15 15:26 - 2014-05-15 15:26 - 210160215 _____ () C:\Windows\MEMORY.DMP
2014-05-15 15:26 - 2014-05-15 15:26 - 00143424 _____ () C:\Windows\Minidump\Mini051514-01.dmp
2014-05-15 15:26 - 2009-06-27 09:20 - 00000000 ____D () C:\Windows\Minidump
2014-05-08 22:47 - 2012-04-04 13:10 - 00002631 _____ () C:\Users\ilja\Desktop\Microsoft Office Word 2007.lnk
2014-05-08 06:45 - 2014-05-08 06:43 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
2014-05-08 06:45 - 2014-05-08 06:43 - 00001891 _____ () C:\Users\Public\Desktop\Adobe Reader 9.lnk
2014-05-08 06:39 - 2008-03-27 21:07 - 00000000 ____D () C:\ProgramData\Adobe
2014-05-07 22:08 - 2009-03-26 23:30 - 00000000 ____D () C:\Users\ilja\AppData\Roaming\Skype
2014-05-07 21:06 - 2014-01-07 17:24 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-07 20:48 - 2014-05-07 20:39 - 00047566 _____ () C:\Users\ilja\Downloads\Addition.txt
2014-05-07 20:37 - 2014-05-07 20:37 - 01016261 _____ (Thisisu) C:\Users\ilja\Downloads\JRT.exe
2014-05-07 20:34 - 2014-05-07 20:34 - 01316991 _____ () C:\Users\ilja\Downloads\adwcleaner (1).exe
2014-05-07 20:25 - 2014-05-07 20:25 - 01053184 _____ (Farbar) C:\Users\ilja\Downloads\FRST.exe
2014-05-07 20:22 - 2011-10-21 00:10 - 00000000 ____D () C:\Users\ilja\AppData\Local\CrashDumps
2014-05-07 20:21 - 2014-05-07 20:20 - 02063872 _____ (Farbar) C:\Users\ilja\Downloads\FRST64.exe
2014-05-06 01:32 - 2014-05-15 20:55 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 01:14 - 2014-05-15 20:55 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 20:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
Some content of TEMP:
====================
C:\Users\ilja\AppData\Local\Temp\Quarantine.exe
C:\Users\ilja\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\ilja\AppData\Local\Temp\uninst1.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-15 21:51 Code:
==================== End Of Log ============================
--- --- ---
--- --- ---
Ich glaube jetzt ist alles da. |