Ok, hier die mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.06.2014
Suchlauf-Zeit: 17:07:15
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.29.06
Rootkit Datenbank: v2014.06.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Patrick
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 275686
Verstrichene Zeit: 9 Min, 55 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 42
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344344440}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355345540}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366346640}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355345540}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366346640}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344344440}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.BHO.1, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.BHO, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.BHO, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.BHO.1, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220322342240}, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.Sandbox.1, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.Sandbox, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.Sandbox, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.Sandbox.1, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311341140}\INPROCSERVER32, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [23172f4f7308fe38a6b2e79adb272fd1],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [23172f4f7308fe38a6b2e79adb272fd1],
PUP.Optional.MoviesToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}, In Quarantäne, [80ba89f5c7b4c373f9937c06b54d2fd1],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [67d3f886d6a5280ea3fb671aa55dba46],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, In Quarantäne, [5fdb0c72e99233032f8e334e54aeec14],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, In Quarantäne, [5fdb0c72e99233032f8e334e54aeec14],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C536F080-57B7-46D6-8894-C647553F2889}, In Quarantäne, [91a9f18d017ae2546f50552cae545aa6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [a793c2bc1665af872b74cab710f27b85],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [fd3d314dd1aaea4ca3e703f063a07987],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, In Quarantäne, [8bafa0de87f44ee87df35b59f012c53b],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [db5fa0de611a1b1bdad507cb62a042be],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\Plus-HD-2.6, In Quarantäne, [1921a3db423971c596e954800df5d62a],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsProtectManger, In Quarantäne, [47f35e203744bc7a05a4eac2e51d926e],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [3307c2bc3e3d25111c5fa7559e658f71],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [5fdb7a048bf0dd59a0ea51a2887bbe42],
PUP.Optional.GreenerWeb.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Greener Web, In Quarantäne, [a29895e9a5d67cbaea52cee4d72be61a],
PUP.Optional.Iminent.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, In Quarantäne, [b08a740a83f83204c9e7a72b8a78f907],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-2.6, In Quarantäne, [77c30e7003784ee8c1213c88d32fb44c],
PUP.Optional.FilesFrog.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BI, In Quarantäne, [320889f5b7c47cba53ff965712f116ea],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [c179324c215a93a31a9e5d740101718f],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [40fa5925dd9e1224e4ebb433be4509f7],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD, In Quarantäne, [a397c1bd6714e74f43a03a8a5aa8a25e],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [47f305794437181e63169f2182807d83],
Registrierungswerte: 4
PUP.Optional.MoviesToolbar.A, HKLM\SOFTWARE\WOW6432NODE\DATAMNGR|uninstallstring, C:\Program Files (x86)\Movies Toolbar\SafetyNut\uninstall.exe, In Quarantäne, [a793cdb1abd0e1555e28716340c248b8]
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\extensions\quick_start@gmail.com, In Quarantäne, [42f8d2acaccfa3930bcde9dc837fc13f]
PUP.Optional.FilesFrog.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BI|ui_path_filesfrog, HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker, In Quarantäne, [320889f5b7c47cba53ff965712f116ea]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1148165604-3820669441-3018069665-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [40fa5925dd9e1224e4ebb433be4509f7]
Registrierungsdaten: 3
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1402836008&from=cor&uid=ST31000524AS_9VPCR8SPXXXX9VPCR8SP, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1402836008&from=cor&uid=ST31000524AS_9VPCR8SPXXXX9VPCR8SP),Ersetzt,[bd7d007ee19a7bbb25bf77144cb8c937]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[003ac6b8ee8d22144339fe8ded178a76]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[63d7205e0c6f221489f3b8d39f65837d]
Ordner: 9
Adware.InstallBrain, C:\ProgramData\IBUpdaterService, In Quarantäne, [85b5cbb33546f541cbdb328f9b6830d0],
PUP.Optional.DealPly.A, C:\Users\Patrick\AppData\Roaming\Dealply, In Quarantäne, [57e3b3cb73083df9d958860edd25a759],
PUP.Optional.DealPly.A, C:\Users\Patrick\AppData\Roaming\Dealply\UpdateProc, In Quarantäne, [57e3b3cb73083df9d958860edd25a759],
PUP.Optional.OpenCandy, C:\Users\Patrick\AppData\Roaming\OpenCandy, In Quarantäne, [2a1094ea85f67db95c0c0b89d230e41c],
PUP.Optional.OpenCandy, C:\Users\Patrick\AppData\Roaming\OpenCandy\C1BF9255D5754613B7E35E69BA927B68, In Quarantäne, [2a1094ea85f67db95c0c0b89d230e41c],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, In Quarantäne, [66d42c5223586ec837c52f7b3dc5e51b],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log, In Quarantäne, [66d42c5223586ec837c52f7b3dc5e51b],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update, In Quarantäne, [66d42c5223586ec837c52f7b3dc5e51b],
Dateien: 30
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-bho64.dll, In Quarantäne, [1f1b037b58231a1cebf7e7399e63bb45],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe, In Quarantäne, [62d8eb93116a4cead9c8bdd1cb36d62a],
PUP.Optional.Softonic, C:\Users\Patrick\Downloads\SoftonicDownloader_for_free-key-logger.exe, In Quarantäne, [43f7532b92e9cc6a41ebfa10ce3318e8],
PUP.Optional.Softonic.A, C:\Users\Patrick\Downloads\SoftonicDownloader_fuer_angry-birds-star-wars.exe, In Quarantäne, [57e3c1bd6d0e6bcb0e7b4fd610f15aa6],
PUP.Optional.Softonic, C:\Users\Patrick\Downloads\SoftonicDownloader_fuer_debut-video-capture.exe, In Quarantäne, [c377a4daea914fe73fede42659a8f40c],
PUP.Optional.Softonic, C:\Users\Patrick\Downloads\SoftonicDownloader_fuer_imageconverter.exe, In Quarantäne, [ef4bafcfbebd5bdb5ecead5d7091718f],
PUP.Optional.Softonic, C:\Users\Patrick\Downloads\SoftonicDownloader_fuer_mycam.exe, In Quarantäne, [ec4efd81097246f01319808aa25f5ca4],
PUP.Optional.Softonic, C:\Users\Patrick\Downloads\SoftonicDownloader_fuer_recuva.exe, In Quarantäne, [58e2691589f289ad2a0226e4ad5437c9],
PUP.Optional.Softonic, C:\Users\Patrick\Downloads\SoftonicDownloader_fuer_tugzip.exe, In Quarantäne, [52e897e7b1ca0036b17b8c7e9a6708f8],
PUP.Optional.RegCleanerPro, C:\Users\Patrick\Downloads\sysrc_trial_9407.exe, In Quarantäne, [2218ccb2d1aa68cef3738d83bc45a15f],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\DownloadGuide\Offers\sp-downloader.exe, In Quarantäne, [f743e8968cef999d10f34ed4a859b947],
PUP.Optional.BrowserProtect.A, C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\searchplugins\BrowserProtect.xml, In Quarantäne, [78c292ec3546270f9c42a409659df40c],
PUP.Optional.Superfish.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [d96155291e5df3430a3ed8e17191bb45],
PUP.Optional.Superfish.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [a4966c12542731056ade0eabcb3715eb],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\searchplugins\conduit-search.xml, In Quarantäne, [e9515b23a5d6ea4c10d96e587b87e41c],
Adware.InstallBrain, C:\ProgramData\IBUpdaterService\repository.xml, In Quarantäne, [85b5cbb33546f541cbdb328f9b6830d0],
PUP.Optional.SweetPage.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml, In Quarantäne, [73c7592532497abc304a629a000340c0],
PUP.Optional.DealPly.A, C:\Users\Patrick\AppData\Roaming\Dealply\UpdateProc\config.dat, In Quarantäne, [57e3b3cb73083df9d958860edd25a759],
PUP.Optional.DealPly.A, C:\Users\Patrick\AppData\Roaming\Dealply\UpdateProc\TTL.DAT, In Quarantäne, [57e3b3cb73083df9d958860edd25a759],
PUP.Optional.OpenCandy, C:\Users\Patrick\AppData\Roaming\OpenCandy\C1BF9255D5754613B7E35E69BA927B68\TuneUpUtilities2013_2200218_de-DE.exe, In Quarantäne, [2a1094ea85f67db95c0c0b89d230e41c],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-buttonutil64.exe, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\33440.crx, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\33440.xpi, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\background.html, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Installer.log, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-buttonutil64.dll, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6.ico, In Quarantäne, [102a5a2499e243f3291c8912768c916f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log\wprotectmanager_2014-06-15[14-41-40-251].log, In Quarantäne, [66d42c5223586ec837c52f7b3dc5e51b],
PUP.Optional.SweetPage.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.sweet-page.com/?type=hp&ts=1402836008&from=cor&uid=ST31000524AS_9VPCR8SPXXXX9VPCR8SP" ],), Ersetzt,[51e9770762191b1bd114c0fa887c12ee]
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "143c8fa59384c7a3491fc09586fb6cd9");), Ersetzt,[dc5e18667a01f640cefeb108ce36f907]
Physische Sektoren: 0
(No malicious items detected)
(end) dann die AdwCleaner[S0].txt Code:
# AdwCleaner v3.213 - Bericht erstellt am 29/06/2014 um 17:35:33
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Patrick - PATRICK-PC
# Gestartet von : C:\Users\Patrick\Downloads\adwcleaner_3.213.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\ProgramData\Browser Manager
Ordner Gelöscht : C:\ProgramData\BrowserProtect
Ordner Gelöscht : C:\ProgramData\AlawarWrapper
Ordner Gelöscht : C:\Program Files (x86)\file scout
Ordner Gelöscht : C:\Program Files (x86)\Greener Web
Ordner Gelöscht : C:\Program Files (x86)\GreenTree Applications
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Patrick\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Patrick\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\Patrick\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\Patrick\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Patrick\AppData\Roaming\PerformerSoft
Ordner Gelöscht : C:\Users\Patrick\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Patrick\AppData\Roaming\Windows Net Data
Ordner Gelöscht : C:\Users\Patrick\Documents\PC Speed Maximizer
Ordner Gelöscht : C:\Users\Public\Documents\AlawarWrapper
Datei Gelöscht : C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\searchplugins\Ask.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\Ask.xml
Datei Gelöscht : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\searchplugins\safesearch.xml
Datei Gelöscht : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bdephonbpjofbmmhhlhiegdokbhhccch
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKCU\Software\58538fdcbd6fbd12
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_debut-video-capture_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_debut-video-capture_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_imageconverter_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_imageconverter_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mycam_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mycam_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_recuva_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_recuva_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\filescout
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\SecuredDownload
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsWoofer
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\Software\SafetyNut
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_meta.value", "%7B%22tmp/lightbox.css%22%3A%7B%22id%22%3A354659%2C%22ver%22%3A[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.__GAM__gam_domains.value", "%7B%22gambling%22%3A%22casino.williamhill.com%7Cvegas.willi[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3322611&octid=EB_ORIGINAL_CTID&ISID=MF364084F-34F7-4B39-A29C-8C9B53F14CDB&SearchSource=58&CUI=&UM=5&UP=SP7E9BD653-68EC-4720-B365-BC72C8274F8F&q={searchTerms}&SSPV=
*************************
AdwCleaner[R0].txt - [14625 octets] - [29/06/2014 17:34:08]
AdwCleaner[S0].txt - [13808 octets] - [29/06/2014 17:35:33]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13869 octets] ########## dann die JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Patrick on 29.06.2014 at 17:41:12,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1148165604-3820669441-3018069665-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9E68EDF4-1E57-4A4A-9774-5CB79D6A09E1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\a5s72nbp.default\extensions\staged
Emptied folder: C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\a5s72nbp.default\minidumps [320 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.06.2014 at 17:59:09,68
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und nun hoff ich das Du die FRST.txt haben wolltest nachdem ich die 3 vorherigen Schritte ausgeführt hab.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by Patrick (administrator) on PATRICK-PC on 29-06-2014 18:36:21
Running from C:\Users\Patrick\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
() C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\XSManager\WTGService.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(4G Systems GmbH & Co. KG) C:\Windows\service4g.exe
(4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.70\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10806816 2010-04-30] (Realtek Semiconductor)
HKLM-x32\...\Run: [BiosNotice] => C:\Program Files (x86)\BIOSTAR\BiosNotice\BiosNotice.exe [1001984 2010-08-12] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-11-24] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [starter4g] => C:\Windows\starter4g.exe [160424 2011-03-30] (4G Systems GmbH & Co. KG)
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1724728 2013-12-19] (G Data Software AG)
HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-1148165604-3820669441-3018069665-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-14] (InstallShield Software Corporation)
==================== Internet (Whitelisted) ====================
ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {52db1893-8a90-4192-aede-08e00b8f8473} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=100&systemid=473&v=a10918-160&apn_uid=5645115192134545&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {A8D6E7CF-5694-4938-AA87-7A160F7D9A7A} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=Solo&Lan=&q={searchTerms}&gu=21f60d049a7d430cac817d313cb4e6f7&tu=11Ih000BA1B0001&sku=&tstsId=&ver=&&r=47
SearchScopes: HKCU - {B4BE2896-954D-4AF8-B08C-1AAE33B626AF} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{14EEA393-DA6F-44F2-A04D-C65D86882080}: [NameServer]193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{77ABB945-E843-4309-90F4-619FE21379AF}: [NameServer]193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{9CA8D24A-8A97-4D8A-B28C-FC201B701692}: [NameServer]193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{C9720AC4-0C04-4A85-9FD8-FF0F846BB963}: [NameServer]193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{E0C59EE5-47DD-4AF2-B3C4-BE40D2BD17C7}: [NameServer]193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{E6ABF7EF-E3D4-4280-B519-856A1FFB68C5}: [NameServer]193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{F00DD664-A6C0-4C0B-99A4-FEDD40E4BDC7}: [NameServer]193.189.244.206 193.189.244.225
FireFox:
========
FF ProfilePath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FireShot - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2014-06-05]
FF Extension: HTML5 Notifications - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\Extensions\html5notifications@paxal.net.xpi [2013-10-23]
FF Extension: Flagfox - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-08]
FF Extension: ReloadEvery - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-03-20]
FF Extension: Adblock Plus - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-18]
FF Extension: Greasemonkey - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\a5s72nbp.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-10-23]
FF HKCU\...\Firefox\Extensions: [{1ad98031-f6b8-46b7-aeb5-f0d0ae8eb0c9}] - C:\Program Files (x86)\LyricsWoofer\131.xpi
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-06-19]
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Docs) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-13]
CHR Extension: (Google Drive) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-13]
CHR Extension: (YouTube) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-13]
CHR Extension: (Google-Suche) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-13]
CHR Extension: (Google Wallet) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-13]
CHR Extension: (Google Mail) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-13]
==================== Services (Whitelisted) =================
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2244728 2014-02-12] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2723400 2014-03-25] (G Data Software AG)
R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2992760 2014-01-30] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700024 2014-02-03] (G Data Software AG)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S2 Mobile Partner. RunOuc; C:\Users\Patrick\Desktop\Mobile Partner\UpdateDog\ouc.exe [246112 2012-12-19] ()
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 Sysevnt; C:\Windows\SysWOW64\argsvc.dll [71680 2012-05-18] () [File not signed]
R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [327392 2011-03-30] ()
R2 XS Stick Service; C:\Windows\service4g.exe [145064 2011-03-30] (4G Systems GmbH & Co. KG)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 BIOS; C:\Windows\system32\drivers\BIOS64.sys [14136 2009-06-10] (BIOSTAR Group)
R1 BIOS; C:\Windows\SysWOW64\drivers\BIOS64.sys [14136 2009-06-10] (BIOSTAR Group)
R1 BS_I2cIo; C:\Windows\system32\drivers\BS_I2c64.sys [15408 2010-05-17] (BIOSTAR Group)
S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2013-01-13] (Mobile Connector)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [57344 2014-05-27] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [135168 2014-05-27] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [68608 2014-05-27] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-05-27] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-05-27] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65024 2014-05-27] (G Data Software AG)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}w64; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys [61120 2014-06-11] (StdLib)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S1 {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64; system32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys [X]
==================== NetSvcs (Whitelisted) ===================
NETSVCx32: Sysevnt -> C:\Windows\SysWOW64\argsvc.dll ()
==================== One Month Created Files and Folders ========
2014-06-29 17:59 - 2014-06-29 17:59 - 00001647 _____ () C:\Users\Patrick\Desktop\JRT.txt
2014-06-29 17:41 - 2014-06-29 17:41 - 00000000 ____D () C:\Windows\ERUNT
2014-06-29 17:40 - 2014-06-29 17:40 - 01016261 _____ (Thisisu) C:\Users\Patrick\Downloads\JRT.exe
2014-06-29 17:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-29 17:33 - 2014-06-29 17:35 - 00000000 ____D () C:\AdwCleaner
2014-06-29 17:32 - 2014-06-29 17:32 - 01342659 _____ () C:\Users\Patrick\Downloads\adwcleaner_3.213.exe
2014-06-29 17:04 - 2014-06-29 17:27 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 17:04 - 2014-06-29 17:04 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-29 17:04 - 2014-06-29 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-29 17:04 - 2014-06-29 17:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-29 17:04 - 2014-06-29 17:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-29 17:04 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-29 17:04 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-29 17:04 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-29 17:00 - 2014-06-29 17:03 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Patrick\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-29 16:52 - 2014-06-29 18:35 - 00000000 ____D () C:\Users\Patrick\Desktop\Trojaner board
2014-06-29 16:50 - 2014-06-29 16:50 - 00000000 ____D () C:\Users\Patrick\Downloads\FRST-OlderVersion
2014-06-28 19:01 - 2014-06-28 19:01 - 00054466 _____ () C:\ComboFix.txt
2014-06-28 17:16 - 2014-06-28 19:01 - 00000000 ____D () C:\ComboFix
2014-06-28 17:16 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-28 17:16 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-28 17:16 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-28 17:16 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-28 17:16 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-28 17:16 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-28 17:16 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-28 17:16 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-26 20:56 - 2014-06-28 19:01 - 00000000 ____D () C:\Qoobox
2014-06-26 20:55 - 2014-06-28 18:59 - 00000000 ____D () C:\Windows\erdnt
2014-06-26 20:51 - 2014-06-28 17:14 - 05212118 ____R (Swearware) C:\Users\Patrick\Downloads\ComboFix.exe
2014-06-23 16:15 - 2014-06-23 16:15 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Adobe
2014-06-19 18:17 - 2014-06-19 19:00 - 00000000 ____D () C:\Output
2014-06-19 17:12 - 2014-06-19 17:12 - 00001447 _____ () C:\Users\Public\Desktop\Free YouTube Download.lnk
2014-06-19 17:00 - 2014-06-19 17:08 - 32574920 _____ (DVDVideoSoft Ltd. ) C:\Users\Patrick\Downloads\FreeYouTubeDownload_3.2.39.604 (1).exe
2014-06-19 16:48 - 2014-06-19 16:48 - 00007605 _____ () C:\Users\Patrick\AppData\Local\Resmon.ResmonCfg
2014-06-19 16:28 - 2014-06-19 16:34 - 32574920 _____ (DVDVideoSoft Ltd. ) C:\Users\Patrick\Downloads\FreeYouTubeDownload_3.2.39.604.exe
2014-06-19 16:26 - 2014-06-19 16:27 - 00701808 _____ () C:\Users\Patrick\Downloads\FreeYouTubeDownload (1).exe
2014-06-19 16:25 - 2014-06-19 16:26 - 00701808 _____ () C:\Users\Patrick\Downloads\FreeYouTubeDownload.exe
2014-06-19 15:19 - 2014-06-19 15:19 - 00000634 _____ () C:\Users\Public\Desktop\MP4 To MP3 Converter.lnk
2014-06-19 15:19 - 2014-06-19 15:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP4 To MP3 Converter
2014-06-19 15:19 - 2014-06-19 15:19 - 00000000 ____D () C:\MP4ToMP3Converter
2014-06-19 15:18 - 2014-06-19 15:19 - 04640104 _____ (hxxp://www.MP4ToMP3Converter.net ) C:\Users\Patrick\Downloads\mp4tomp305.exe
2014-06-17 19:36 - 2014-06-17 19:36 - 00001275 _____ () C:\Users\Patrick\Desktop\Revo Uninstaller.lnk
2014-06-17 19:36 - 2014-06-17 19:36 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-17 19:34 - 2014-06-17 19:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Patrick\Downloads\revosetup95.exe
2014-06-16 23:51 - 2014-06-16 23:54 - 00025964 _____ () C:\Users\Patrick\Downloads\Addition.txt
2014-06-16 23:49 - 2014-06-29 18:36 - 00013209 _____ () C:\Users\Patrick\Downloads\FRST.txt
2014-06-16 23:49 - 2014-06-29 18:36 - 00000000 ____D () C:\FRST
2014-06-16 23:47 - 2014-06-29 16:50 - 02083328 _____ (Farbar) C:\Users\Patrick\Downloads\FRST64.exe
2014-06-16 19:24 - 2014-06-11 15:34 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys
2014-06-15 22:34 - 2014-06-15 22:34 - 00000132 _____ () C:\Users\Patrick\Downloads\kill.bat
2014-06-15 21:53 - 2014-06-15 21:53 - 00000756 _____ () C:\Users\Patrick\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-15 20:42 - 2014-06-15 20:42 - 01931296 _____ (Codejock Software) C:\Windows\SysWOW64\Codejock.Controls.v15.3.1.ocx
2014-06-15 20:41 - 2014-06-15 20:42 - 02390528 _____ (OldSkool) C:\Users\Patrick\Downloads\ProMod.exe
2014-06-15 15:03 - 2014-06-18 15:05 - 00003854 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1402837415
2014-06-15 15:03 - 2014-06-15 15:03 - 00018295 _____ () C:\Users\Patrick\Desktop\Opera 12 Notes.html
2014-06-15 15:03 - 2014-06-15 15:03 - 00001140 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-15 15:03 - 2014-06-15 15:03 - 00001140 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-15 15:03 - 2014-06-15 15:03 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Opera Software
2014-06-15 15:03 - 2014-06-15 15:03 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Opera Software
2014-06-15 14:50 - 2014-06-15 14:58 - 27623336 _____ (Opera Software ASA) C:\Users\Patrick\Downloads\Opera_22.0.1471.50_Setup.exe
2014-06-15 14:46 - 2014-06-15 14:46 - 00003158 _____ () C:\Windows\System32\Tasks\{8039BA54-195B-4052-BB8A-39F00B6A960B}
2014-06-15 14:44 - 2014-06-15 14:44 - 00001376 _____ () C:\Users\Patrick\Documents\cc_20140615_144403.reg
2014-06-15 14:38 - 2014-06-15 14:37 - 00223559 _____ () C:\Users\Patrick\Downloads\opera.exe
2014-06-15 14:36 - 2014-06-15 14:36 - 00748064 _____ () C:\Users\Patrick\Downloads\opera_setup.exe
2014-06-15 14:36 - 2014-06-15 14:36 - 00040924 _____ () C:\Users\Patrick\Documents\cc_20140615_143600.reg
2014-06-14 23:05 - 2014-06-14 23:05 - 00000000 ____D () C:\Users\Patrick\AppData\Local\G DATA
2014-06-14 22:43 - 2014-06-14 22:43 - 00000863 _____ () C:\Windows\SysWOW64\runrefog.lnk
2014-06-14 15:53 - 2014-06-14 15:53 - 00002950 _____ () C:\Windows\System32\Tasks\{BEDB03E7-A8F7-429A-A77C-9A91A1976E96}
2014-06-11 23:48 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 23:48 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 23:48 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-11 23:48 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 23:48 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 23:48 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 23:48 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-11 23:48 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 23:48 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 23:48 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 23:48 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 23:48 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-11 23:48 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-11 23:48 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 23:48 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-11 23:48 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 23:48 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 23:48 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 23:48 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 23:48 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 23:48 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 23:48 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-11 23:48 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 23:48 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-11 23:48 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-11 23:48 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 23:48 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 23:48 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 23:48 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-11 23:48 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-11 23:48 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 23:48 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-11 23:48 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-11 23:48 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-11 23:48 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 23:48 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 23:48 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-11 23:48 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-11 23:48 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 23:48 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 23:48 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 23:48 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 23:48 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 23:48 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-11 23:48 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 23:48 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 23:48 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 23:48 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 23:48 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 23:48 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 23:48 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-11 23:48 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-11 23:45 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 23:45 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 23:45 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 23:45 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 23:45 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 23:45 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 23:45 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 23:45 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 23:45 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 23:45 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 23:45 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 23:45 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-11 23:41 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 23:41 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-05 12:51 - 2014-06-05 12:53 - 00000000 ____D () C:\Users\Patrick\Desktop\tag der offenen Tür ( Panzer)
==================== One Month Modified Files and Folders =======
2014-06-29 18:37 - 2014-06-16 23:49 - 00013209 _____ () C:\Users\Patrick\Downloads\FRST.txt
2014-06-29 18:36 - 2014-06-16 23:49 - 00000000 ____D () C:\FRST
2014-06-29 18:35 - 2014-06-29 16:52 - 00000000 ____D () C:\Users\Patrick\Desktop\Trojaner board
2014-06-29 18:35 - 2014-03-13 20:31 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-29 17:59 - 2014-06-29 17:59 - 00001647 _____ () C:\Users\Patrick\Desktop\JRT.txt
2014-06-29 17:58 - 2012-12-19 00:40 - 01722800 _____ () C:\Windows\WindowsUpdate.log
2014-06-29 17:45 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-29 17:45 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-29 17:41 - 2014-06-29 17:41 - 00000000 ____D () C:\Windows\ERUNT
2014-06-29 17:41 - 2012-12-19 22:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-29 17:40 - 2014-06-29 17:40 - 01016261 _____ (Thisisu) C:\Users\Patrick\Downloads\JRT.exe
2014-06-29 17:37 - 2014-05-14 21:18 - 00012662 _____ () C:\Windows\setupact.log
2014-06-29 17:37 - 2014-05-14 21:17 - 00013342 _____ () C:\Windows\PFRO.log
2014-06-29 17:37 - 2014-03-13 20:31 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-29 17:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-29 17:35 - 2014-06-29 17:33 - 00000000 ____D () C:\AdwCleaner
2014-06-29 17:32 - 2014-06-29 17:32 - 01342659 _____ () C:\Users\Patrick\Downloads\adwcleaner_3.213.exe
2014-06-29 17:27 - 2014-06-29 17:04 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 17:04 - 2014-06-29 17:04 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-29 17:04 - 2014-06-29 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-29 17:04 - 2014-06-29 17:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-29 17:04 - 2014-06-29 17:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-29 17:03 - 2014-06-29 17:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Patrick\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-29 16:50 - 2014-06-29 16:50 - 00000000 ____D () C:\Users\Patrick\Downloads\FRST-OlderVersion
2014-06-29 16:50 - 2014-06-16 23:47 - 02083328 _____ (Farbar) C:\Users\Patrick\Downloads\FRST64.exe
2014-06-29 10:06 - 2013-07-18 17:00 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A3B654CF-D615-4317-8295-731BB183FE26}
2014-06-28 19:01 - 2014-06-28 19:01 - 00054466 _____ () C:\ComboFix.txt
2014-06-28 19:01 - 2014-06-28 17:16 - 00000000 ____D () C:\ComboFix
2014-06-28 19:01 - 2014-06-26 20:56 - 00000000 ____D () C:\Qoobox
2014-06-28 19:01 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-06-28 18:59 - 2014-06-26 20:55 - 00000000 ____D () C:\Windows\erdnt
2014-06-28 18:56 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-06-28 17:35 - 2009-07-14 04:34 - 55312384 _____ () C:\Windows\system32\config\software.bak
2014-06-28 17:35 - 2009-07-14 04:34 - 23855104 _____ () C:\Windows\system32\config\system.bak
2014-06-28 17:35 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\default.bak
2014-06-28 17:35 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2014-06-28 17:35 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2014-06-28 17:33 - 2012-12-19 01:15 - 00000000 ____D () C:\Users\Patrick
2014-06-28 17:30 - 2013-02-26 20:25 - 00000000 ____D () C:\ProgramData\Temp
2014-06-28 17:14 - 2014-06-26 20:51 - 05212118 ____R (Swearware) C:\Users\Patrick\Downloads\ComboFix.exe
2014-06-25 09:57 - 2013-01-15 21:29 - 00000000 ____D () C:\Users\Patrick\Desktop\Tippspiel Bundesliga
2014-06-25 09:33 - 2014-03-10 18:26 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Paint.NET
2014-06-23 16:15 - 2014-06-23 16:15 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Adobe
2014-06-23 01:03 - 2013-01-25 15:31 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\vlc
2014-06-23 01:02 - 2014-02-13 22:29 - 00000000 ____D () C:\Users\Patrick\Desktop\Bo
2014-06-19 19:00 - 2014-06-19 18:17 - 00000000 ____D () C:\Output
2014-06-19 17:12 - 2014-06-19 17:12 - 00001447 _____ () C:\Users\Public\Desktop\Free YouTube Download.lnk
2014-06-19 17:12 - 2013-03-22 04:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-06-19 17:12 - 2013-03-22 04:40 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-06-19 17:12 - 2013-01-11 19:06 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\DVDVideoSoft
2014-06-19 17:08 - 2014-06-19 17:00 - 32574920 _____ (DVDVideoSoft Ltd. ) C:\Users\Patrick\Downloads\FreeYouTubeDownload_3.2.39.604 (1).exe
2014-06-19 17:08 - 2012-12-19 22:10 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-19 17:07 - 2012-12-19 22:10 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-19 17:07 - 2012-12-19 22:10 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-19 17:06 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2014-06-19 16:48 - 2014-06-19 16:48 - 00007605 _____ () C:\Users\Patrick\AppData\Local\Resmon.ResmonCfg
2014-06-19 16:34 - 2014-06-19 16:28 - 32574920 _____ (DVDVideoSoft Ltd. ) C:\Users\Patrick\Downloads\FreeYouTubeDownload_3.2.39.604.exe
2014-06-19 16:27 - 2014-06-19 16:26 - 00701808 _____ () C:\Users\Patrick\Downloads\FreeYouTubeDownload (1).exe
2014-06-19 16:26 - 2014-06-19 16:25 - 00701808 _____ () C:\Users\Patrick\Downloads\FreeYouTubeDownload.exe
2014-06-19 15:19 - 2014-06-19 15:19 - 00000634 _____ () C:\Users\Public\Desktop\MP4 To MP3 Converter.lnk
2014-06-19 15:19 - 2014-06-19 15:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP4 To MP3 Converter
2014-06-19 15:19 - 2014-06-19 15:19 - 00000000 ____D () C:\MP4ToMP3Converter
2014-06-19 15:19 - 2014-06-19 15:18 - 04640104 _____ (hxxp://www.MP4ToMP3Converter.net ) C:\Users\Patrick\Downloads\mp4tomp305.exe
2014-06-18 15:05 - 2014-06-15 15:03 - 00003854 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1402837415
2014-06-18 15:05 - 2012-12-19 22:19 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-17 19:36 - 2014-06-17 19:36 - 00001275 _____ () C:\Users\Patrick\Desktop\Revo Uninstaller.lnk
2014-06-17 19:36 - 2014-06-17 19:36 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-17 19:35 - 2014-06-17 19:34 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Patrick\Downloads\revosetup95.exe
2014-06-16 23:54 - 2014-06-16 23:51 - 00025964 _____ () C:\Users\Patrick\Downloads\Addition.txt
2014-06-15 23:27 - 2013-02-07 14:16 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\TS3Client
2014-06-15 22:36 - 2012-12-19 13:54 - 00066112 _____ () C:\Users\Patrick\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-15 22:35 - 2009-07-14 06:45 - 00302920 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-15 22:34 - 2014-06-15 22:34 - 00000132 _____ () C:\Users\Patrick\Downloads\kill.bat
2014-06-15 21:53 - 2014-06-15 21:53 - 00000756 _____ () C:\Users\Patrick\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-15 20:43 - 2014-01-16 14:43 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll
2014-06-15 20:43 - 2014-01-16 14:43 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll
2014-06-15 20:42 - 2014-06-15 20:42 - 01931296 _____ (Codejock Software) C:\Windows\SysWOW64\Codejock.Controls.v15.3.1.ocx
2014-06-15 20:42 - 2014-06-15 20:41 - 02390528 _____ (OldSkool) C:\Users\Patrick\Downloads\ProMod.exe
2014-06-15 15:03 - 2014-06-15 15:03 - 00018295 _____ () C:\Users\Patrick\Desktop\Opera 12 Notes.html
2014-06-15 15:03 - 2014-06-15 15:03 - 00001140 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-15 15:03 - 2014-06-15 15:03 - 00001140 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-15 15:03 - 2014-06-15 15:03 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Opera Software
2014-06-15 15:03 - 2014-06-15 15:03 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Opera Software
2014-06-15 14:58 - 2014-06-15 14:50 - 27623336 _____ (Opera Software ASA) C:\Users\Patrick\Downloads\Opera_22.0.1471.50_Setup.exe
2014-06-15 14:46 - 2014-06-15 14:46 - 00003158 _____ () C:\Windows\System32\Tasks\{8039BA54-195B-4052-BB8A-39F00B6A960B}
2014-06-15 14:44 - 2014-06-15 14:44 - 00001376 _____ () C:\Users\Patrick\Documents\cc_20140615_144403.reg
2014-06-15 14:37 - 2014-06-15 14:38 - 00223559 _____ () C:\Users\Patrick\Downloads\opera.exe
2014-06-15 14:36 - 2014-06-15 14:36 - 00748064 _____ () C:\Users\Patrick\Downloads\opera_setup.exe
2014-06-15 14:36 - 2014-06-15 14:36 - 00040924 _____ () C:\Users\Patrick\Documents\cc_20140615_143600.reg
2014-06-14 23:05 - 2014-06-14 23:05 - 00000000 ____D () C:\Users\Patrick\AppData\Local\G DATA
2014-06-14 22:43 - 2014-06-14 22:43 - 00000863 _____ () C:\Windows\SysWOW64\runrefog.lnk
2014-06-14 15:53 - 2014-06-14 15:53 - 00002950 _____ () C:\Windows\System32\Tasks\{BEDB03E7-A8F7-429A-A77C-9A91A1976E96}
2014-06-14 10:20 - 2014-03-13 20:49 - 00002182 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-14 09:44 - 2014-02-16 13:14 - 00000000 ____D () C:\Users\Patrick\Desktop\12,12
2014-06-12 00:29 - 2013-07-15 00:48 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 00:27 - 2012-12-20 21:14 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 00:25 - 2014-05-07 00:44 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-11 16:10 - 2014-03-13 20:31 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-11 16:10 - 2014-03-13 20:31 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-11 15:34 - 2014-06-16 19:24 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys
2014-06-10 13:02 - 2013-11-30 14:09 - 00000000 ____D () C:\Users\Patrick\Documents\DVDVideoSoft
2014-06-08 11:13 - 2014-06-11 23:41 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-11 23:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-05 12:53 - 2014-06-05 12:51 - 00000000 ____D () C:\Users\Patrick\Desktop\tag der offenen Tür ( Panzer)
2014-05-30 12:21 - 2014-06-11 23:48 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-11 23:48 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-11 23:48 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-11 23:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-11 23:48 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-11 23:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-11 23:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-11 23:48 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-11 23:48 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-11 23:48 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-11 23:48 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-11 23:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-11 23:48 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-11 23:48 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-11 23:48 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-11 23:48 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-11 23:48 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-11 23:48 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-11 23:48 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-11 23:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-11 23:48 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-11 23:48 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-11 23:48 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-11 23:48 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-11 23:48 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-11 23:48 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-11 23:48 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-11 23:48 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-11 23:48 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-11 23:48 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-11 23:48 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-11 23:48 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-11 23:48 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-11 23:48 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-11 23:48 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-11 23:48 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-11 23:48 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-11 23:48 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-11 23:48 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-11 23:48 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-11 23:48 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-11 23:48 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-11 23:48 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-11 23:48 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-11 23:48 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-11 23:48 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-11 23:48 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-11 23:48 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-11 23:48 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-11 23:48 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-11 23:48 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-11 23:48 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
Some content of TEMP:
====================
C:\Users\Patrick\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-05-25 11:26
==================== End Of Log ============================ --- --- --- |