hier mbam. txt : Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 30.06.2014
Suchlauf-Zeit: 09:11:19
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.30.03
Rootkit Datenbank: v2014.06.23.02
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Simmal
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 326464
Verstrichene Zeit: 6 Min, 33 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Conduit.A, HKU\S-1-5-21-2669477444-2332324575-3480042970-1118-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAABD74EC-F6E7-4144-BD95-2C7C74FF880B&SearchSource=55&CUI=&UM=5&UP=SPB07B839B-7C85-442E-9F32-D440144DB09E&SSPV=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.conduit.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAABD74EC-F6E7-4144-BD95-2C7C74FF880B&SearchSource=55&CUI=&UM=5&UP=SPB07B839B-7C85-442E-9F32-D440144DB09E&SSPV=),Ersetzt,[e6b5c5b9a9d2ec4a3de4631fab59916f]
Ordner: 6
PUP.Optional.OpenCandy, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy, In Quarantäne, [aaf11a64d7a42a0c860802925ca64db3],
PUP.Optional.OpenCandy, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\9CA8097CDD324BE083C69BF3AC562534, In Quarantäne, [aaf11a64d7a42a0c860802925ca64db3],
PUP.Optional.OpenCandy, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\B0A15BC7143E45D18D22FEB1C03FA243, In Quarantäne, [aaf11a64d7a42a0c860802925ca64db3],
PUP.Optional.OpenCandy, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\E3CF05EE7A2444C2B6E0CF88D927031E, In Quarantäne, [aaf11a64d7a42a0c860802925ca64db3],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
Dateien: 49
PUP.Optional.OpenCandy.A, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\9CA8097CDD324BE083C69BF3AC562534\LatestDLMgr.exe, In Quarantäne, [25760d71f68565d1fbd7e93bd62b2bd5],
PUP.Optional.OpenCandy.A, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\9CA8097CDD324BE083C69BF3AC562534\Setupsft_chr_p1v7.exe, In Quarantäne, [55461569691239fd0a96a3d013f1b64a],
PUP.Optional.OpenCandy.A, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\B0A15BC7143E45D18D22FEB1C03FA243\dlm.exe, In Quarantäne, [702b3846403bcb6bd5fd071de41d3ac6],
PUP.Optional.Conduit.A, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\B0A15BC7143E45D18D22FEB1C03FA243\sp-downloader.exe, In Quarantäne, [6932f6886a11c86edb356fb3c041c33d],
PUP.Optional.Conduit.A, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\B0A15BC7143E45D18D22FEB1C03FA243\Whitesmoke_direct_p1v1.exe, In Quarantäne, [dbc0ec9293e837ff759b2ff3946d8779],
PUP.Optional.OpenCandy.A, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\E3CF05EE7A2444C2B6E0CF88D927031E\LatestDLMgr.exe, In Quarantäne, [b1ea2955dba03303ab27032156abc63a],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\searchplugins\softonic.xml, In Quarantäne, [b4e7e599d3a8d066e0e6fcc7956d748c],
PUP.Optional.OpenCandy, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\E3CF05EE7A2444C2B6E0CF88D927031E\Setup1004733_DE-2.exe, In Quarantäne, [aaf11a64d7a42a0c860802925ca64db3],
PUP.Optional.OpenCandy, C:\Users\Simmal.*****\AppData\Roaming\OpenCandy\E3CF05EE7A2444C2B6E0CF88D927031E\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [aaf11a64d7a42a0c860802925ca64db3],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\appCntrl.js, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.html, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.js, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\chMntz.dll, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CrmAdpt.dll, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\ct.js, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CTB.dll, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\dpk.js, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.htm, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.js, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\json2.min.js, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\logo.png, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\manifest.json, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\pref.json, In Quarantäne, [8b101f5fabd090a6cb4e6c303ec458a8],
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.admin", false);), Ersetzt,[8d0e6a1484f7340261b67f3b41c3ba46]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.aflt", "OC");), Ersetzt,[9308e6986f0c64d2af68fdbdd92b32ce]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");), Ersetzt,[514aa7d7ec8fb38315026e4c9173cd33]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.autoRvrt", "false");), Ersetzt,[c7d4c0befa81b68085928139cb393cc4]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltLng", "de");), Ersetzt,[6833245aef8c270f898efbbff60e8080]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltSrch", true);), Ersetzt,[b1ea7e006516072f3fd816a429db12ee]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dnsErr", true);), Ersetzt,[d7c445399be0a49230e79a205ea61ae6]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.excTlbr", false);), Ersetzt,[2c6f47376e0dcb6b49ce1d9d2cd82cd4]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.ffxUnstlRst", false);), Ersetzt,[7427592594e7cb6b8592e1d9eb19b14f]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpg", true);), Ersetzt,[3665aed0a6d5c5717a9d6d4db64e7888]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=e87f1526000000000000180373c0b6f2");), Ersetzt,[7e1dd9a5fe7d0f272fe8c6f4857fa65a]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.id", "e87f1526000000000000180373c0b6f2");), Ersetzt,[118ad8a68af1ec4a35e2dbdf13f1b848]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlDay", "16015");), Ersetzt,[1586c7b7314a1620d0475466b054748c]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlRef", "MOY00621");), Ersetzt,[d0cb99e5f7840a2c8a8d87331be90af6]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTab", true);), Ersetzt,[7c1f8af48af1a492ed2a15a57c88c13f]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=e87f1526000000000000180373c0b6f2");), Ersetzt,[4c4fdba35625d56140d7d8e234d06f91]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prdct", "Softonic");), Ersetzt,[19826816c2b91224ba5db60444c0c838]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prtnrId", "softonic");), Ersetzt,[4c4ff88606756acc2aede2d83fc5de22]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.rvrt", "false");), Ersetzt,[7e1d8cf235460036a4738634956fd828]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.smplGrp", "none");), Ersetzt,[3467abd31c5fb3839780b6042fd5936d]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");), Ersetzt,[8615631b7b00a294d146457506fe55ab]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrId", "opencandy2013");), Ersetzt,[ebb0225c3942b482e7309327e4208d73]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=e87f1526000000000000180373c0b6f2&q=");), Ersetzt,[8e0d82fcc1ba94a231e6b1094bb99967]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsn", "1.8.21.14");), Ersetzt,[d8c3afcf3b40e94d1bfc7d3d48bc37c9]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsnTs", "1.8.21.1411:57:29");), Ersetzt,[8d0e6c12d1aa40f6dc3b615950b4f709]
PUP.Optional.Softonic.A, C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsni", "1.8.21.14");), Ersetzt,[f0ab542ab9c23ff76bac625800047b85]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.214 - Bericht erstellt am 30/06/2014 um 09:52:14
# Aktualisiert 29/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Simmal - BALDER
# Gestartet von : C:\Users\Simmal.*****\Desktop\adwcleaner_3.214.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{065C1A21-97F8-45FB-A9F0-861B60FACEC8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3204358F-5904-46A6-841F-D6B5BE3EF4E3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AE67737-0E3E-44AA-AA5E-46A68BF017FF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3EE5B726-044A-48D2-AA7B-049BD9A0F62A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60FBBE03-57FF-49D8-B38E-053D3F489825}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6A5182F1-C0B8-42B8-96CC-7F329CD46913}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6C153418-8E4D-4FAF-AF27-5201E38463A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A26A2F05-AC4D-4A1E-9531-9125F7309B78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5D6240-7DF0-435D-9B9B-F8586A99DE86}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F343045E-E20A-46E1-82D8-9962C43EFC9E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FBB360DC-CB6C-4D6A-808A-2C773151BFFF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FFD7DDAC-EC28-42A5-8D39-917B9078604B}
Schlüssel Gelöscht : HKCU\Software\Ciuvo
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v30.0 (de)
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [2059 octets] - [30/06/2014 09:51:12]
AdwCleaner[S0].txt - [1932 octets] - [30/06/2014 09:52:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1992 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Simmal on 30.06.2014 at 9:58:21,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Simmal.AMATO\appdata\locallow\softonic"
~~~ FireFox
Successfully deleted: [File] C:\Users\Simmal.AMATO\AppData\Roaming\mozilla\firefox\profiles\dkuwcmc1.default\user.js
Successfully deleted the following from C:\Users\Simmal.AMATO\AppData\Roaming\mozilla\firefox\profiles\dkuwcmc1.default\prefs.js
user_pref("extensions.Softonic.admin", false);
user_pref("extensions.Softonic.aflt", "OC");
user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
user_pref("extensions.Softonic.autoRvrt", "false");
user_pref("extensions.Softonic.dfltLng", "de");
user_pref("extensions.Softonic.dfltSrch", true);
user_pref("extensions.Softonic.dnsErr", true);
user_pref("extensions.Softonic.excTlbr", false);
user_pref("extensions.Softonic.ffxUnstlRst", false);
user_pref("extensions.Softonic.hmpg", true);
user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=e87f1526000000000000180373c0b6f2");
user_pref("extensions.Softonic.id", "e87f1526000000000000180373c0b6f2");
user_pref("extensions.Softonic.instlDay", "16015");
user_pref("extensions.Softonic.instlRef", "MOY00621");
user_pref("extensions.Softonic.newTab", true);
user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=e87f1526000000000000180373c0b6f2");
user_pref("extensions.Softonic.prdct", "Softonic");
user_pref("extensions.Softonic.prtnrId", "softonic");
user_pref("extensions.Softonic.rvrt", "false");
user_pref("extensions.Softonic.smplGrp", "none");
user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
user_pref("extensions.Softonic.tlbrId", "opencandy2013");
user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=e87f1526000000000000180373c0b6f2&q=");
user_pref("extensions.Softonic.vrsn", "1.8.21.14");
user_pref("extensions.Softonic.vrsnTs", "1.8.21.1411:57:29");
user_pref("extensions.Softonic.vrsni", "1.8.21.14");
Emptied folder: C:\Users\Simmal.AMATO\AppData\Roaming\mozilla\firefox\profiles\dkuwcmc1.default\minidumps [44 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.06.2014 at 10:02:52,10
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by Simmal (administrator) on BALDER on 30-06-2014 10:06:52
Running from C:\Users\Simmal.*****\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\Ntrtscan.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmListen.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\HostedAgent\HostedAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe
(Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\PccNtMon.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmProxy.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\tmPfw.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\Client Server Security Agent\CNTAoSMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe [2907240 2010-10-04] (Realtek Semiconductor Corp.)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1875048 2010-08-05] ()
HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-04-29] (CyberLink Corp.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [OfficeScanNT Monitor] => c:\Program Files (x86)\Trend Micro\Client Server Security Agent\pccntmon.exe [1708048 2011-02-27] (Trend Micro Inc.)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM\...\RunOnce: [DBRMTray] - C:\Dell\DBRM\Reminder\TrayApp.exe [7168 2010-02-05] (Microsoft)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {758FAEAC-2667-44CC-9BFA-D9B28955B57F} URL =
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll (Trend Micro Inc.)
Tcpip\..\Interfaces\{2DAF9AF1-5B2B-4D77-9C5E-F348CA4E5361}: [NameServer]192.168.100.5,192.168.100.1
FireFox:
========
FF ProfilePath: C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @protomold.com/ProtomoldProtoView - C:\Program Files (x86)\Protomold\ProtoView\nppview.dll (Protomold)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Simmal.*****\AppData\Roaming\Mozilla\Firefox\Profiles\dkuwcmc1.default\searchplugins\ixquick-https.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension
FF Extension: Trend Micro NSC Firefox Extension - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension [2011-09-21]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-20] (Avira Operations GmbH & Co. KG)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 ntrtscan; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\ntrtscan.exe [1836616 2011-02-18] (Trend Micro Inc.)
R2 svcGenericHost; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe [50704 2011-04-07] (Trend Micro Inc.)
R2 tmlisten; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\tmlisten.exe [2060896 2011-02-18] (Trend Micro Inc.)
R3 TmPfw; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmPfw.exe [596032 2010-07-21] (Trend Micro Inc.)
R3 TmProxy; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmProxy.exe [917840 2010-07-21] (Trend Micro Inc.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-04-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-04-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-10] (Avira Operations GmbH & Co. KG)
R3 IntcAzAudAddService; C:\Windows\System32\drivers\RTDVHD64.sys [1980648 2010-10-04] (Realtek Semiconductor Corp.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-30] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R2 TmFilter; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmXPFlt.sys [310032 2011-03-24] (Trend Micro Inc.)
R1 tmlwf; C:\Windows\System32\DRIVERS\tmlwf.sys [196688 2010-11-08] (Trend Micro Inc.)
R2 TmPreFilter; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmPreFlt.sys [42768 2011-03-24] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [108624 2010-11-08] (Trend Micro Inc.)
R2 tmwfp; C:\Windows\System32\DRIVERS\tmwfp.sys [338000 2010-11-08] (Trend Micro Inc.)
R2 VSApiNt; c:\Program Files (x86)\Trend Micro\Client Server Security Agent\VSApiNt.sys [1988368 2011-03-24] (Trend Micro Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-30 10:02 - 2014-06-30 10:02 - 00002809 _____ () C:\Users\Simmal.*****\Desktop\JRT.txt
2014-06-30 09:58 - 2014-06-30 09:58 - 00000000 ____D () C:\Windows\ERUNT
2014-06-30 09:57 - 2014-06-30 09:57 - 01016261 _____ (Thisisu) C:\Users\Simmal.*****\Desktop\JRT.exe
2014-06-30 09:55 - 2014-06-30 09:55 - 00002072 _____ () C:\Users\Simmal.*****\Desktop\AdwCleaner[S0].txt
2014-06-30 09:53 - 2014-06-30 09:53 - 00000022 _____ () C:\Windows\S.dirmngr
2014-06-30 09:50 - 2014-06-30 09:52 - 00000000 ____D () C:\AdwCleaner
2014-06-30 09:50 - 2014-06-30 09:50 - 01346519 _____ () C:\Users\Simmal.*****\Desktop\adwcleaner_3.214.exe
2014-06-30 09:47 - 2014-06-30 09:49 - 00013611 _____ () C:\Users\Simmal.*****\Desktop\mbam.txt
2014-06-30 09:08 - 2014-06-30 09:57 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-30 09:08 - 2014-06-30 09:08 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-30 09:08 - 2014-06-30 09:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-30 09:07 - 2014-06-30 09:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-30 09:07 - 2014-06-30 09:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-30 09:07 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-30 09:07 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-30 09:07 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-30 09:06 - 2014-06-30 09:07 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Simmal.*****\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-27 15:15 - 2014-06-27 15:15 - 00019700 _____ () C:\Users\Simmal.*****\Desktop\combofix1.txt
2014-06-27 15:12 - 2014-06-27 15:12 - 00019700 _____ () C:\ComboFix.txt
2014-06-27 15:08 - 2014-06-27 15:12 - 00000000 ____D () C:\Qoobox
2014-06-27 15:08 - 2014-06-27 15:11 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 15:08 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-27 15:08 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-27 15:08 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-27 15:08 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-27 15:08 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-27 15:08 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-27 15:08 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-27 15:08 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-27 14:52 - 2014-06-27 14:52 - 05212118 ____R (Swearware) C:\Users\Simmal.*****\Desktop\ComboFix.exe
2014-06-26 17:45 - 2014-06-26 17:45 - 00001270 _____ () C:\Users\Simmal.*****\Desktop\Revo Uninstaller.lnk
2014-06-26 17:45 - 2014-06-26 17:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:43 - 2014-06-26 17:44 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Simmal.*****\Desktop\revosetup95.exe
2014-06-25 18:41 - 2014-06-30 10:06 - 00015058 _____ () C:\Users\Simmal.*****\Desktop\FRST.txt
2014-06-25 17:31 - 2014-06-25 17:35 - 00005653 _____ () C:\Users\Simmal.*****\Desktop\gmer.txt
2014-06-25 17:21 - 2014-06-25 17:21 - 00380416 _____ () C:\Users\Simmal.*****\Desktop\Gmer-19357.exe
2014-06-25 17:19 - 2014-06-25 17:19 - 00000474 _____ () C:\Users\Simmal.*****\Desktop\defogger_disable.log
2014-06-25 17:19 - 2014-06-25 17:19 - 00000000 _____ () C:\Users\Simmal.*****\defogger_reenable
2014-06-25 17:18 - 2014-06-25 17:18 - 00050477 _____ () C:\Users\Simmal.*****\Desktop\Defogger.exe
2014-06-25 16:41 - 2014-06-26 17:55 - 00043454 _____ () C:\Users\Simmal.*****\Desktop\Addition.txt
2014-06-25 16:40 - 2014-06-30 10:06 - 00000000 ____D () C:\FRST
2014-06-25 15:35 - 2014-06-25 15:35 - 02082816 _____ (Farbar) C:\Users\Simmal.*****\Desktop\FRST64.exe
2014-06-18 11:56 - 2014-06-18 11:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-17 13:28 - 2014-06-17 13:28 - 00000000 ____D () C:\Users\Simmal.*****\AppData\Local\Adobe
2014-06-11 11:07 - 2014-06-11 11:07 - 00055214 _____ () C:\Users\Simmal.*****\Desktop\Baugruppenartikel.xls
2014-06-10 23:25 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-10 23:25 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-10 23:25 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-10 23:25 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-10 23:25 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-10 23:25 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-10 23:25 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-10 23:25 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-10 23:25 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-10 23:25 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-10 23:25 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-10 23:25 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-10 23:25 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-10 23:25 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-10 23:25 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-10 23:25 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-10 23:25 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-10 23:25 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-10 23:25 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-10 23:25 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-10 23:25 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-10 23:25 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-10 23:25 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-10 23:25 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-10 23:25 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-10 23:25 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-10 23:25 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-10 23:25 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-10 23:25 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-10 23:25 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-10 23:25 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-10 23:25 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-10 23:25 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-10 23:25 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-10 23:25 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-10 23:25 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-10 23:25 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-10 23:25 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-10 23:25 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-10 23:25 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-10 23:25 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-10 23:25 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-10 23:25 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-10 23:25 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-10 23:25 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-10 23:25 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-10 23:25 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-10 23:25 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-10 23:25 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-10 23:25 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-10 23:25 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-10 23:25 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-10 23:23 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-10 23:23 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-10 23:23 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-10 23:23 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-10 23:22 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-10 23:22 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-10 23:22 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-10 23:22 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-10 23:22 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-10 23:22 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-10 23:22 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-10 23:22 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-10 23:22 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-10 23:22 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-10 23:17 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-10 23:17 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-10 16:00 - 2014-06-10 16:01 - 00004534 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
==================== One Month Modified Files and Folders =======
2014-06-30 10:06 - 2014-06-25 18:41 - 00015058 _____ () C:\Users\Simmal.*****\Desktop\FRST.txt
2014-06-30 10:06 - 2014-06-25 16:40 - 00000000 ____D () C:\FRST
2014-06-30 10:06 - 2011-09-21 13:38 - 01146752 _____ () C:\Windows\WindowsUpdate.log
2014-06-30 10:05 - 2012-11-18 12:40 - 00000120 _____ () C:\Windows\system32\config\netlogon.ftl
2014-06-30 10:02 - 2014-06-30 10:02 - 00002809 _____ () C:\Users\Simmal.*****\Desktop\JRT.txt
2014-06-30 10:00 - 2009-07-14 06:45 - 00021088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-30 10:00 - 2009-07-14 06:45 - 00021088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-30 09:58 - 2014-06-30 09:58 - 00000000 ____D () C:\Windows\ERUNT
2014-06-30 09:57 - 2014-06-30 09:57 - 01016261 _____ (Thisisu) C:\Users\Simmal.*****\Desktop\JRT.exe
2014-06-30 09:57 - 2014-06-30 09:08 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-30 09:57 - 2010-11-21 08:50 - 00710410 _____ () C:\Windows\system32\perfh007.dat
2014-06-30 09:57 - 2010-11-21 08:50 - 00153038 _____ () C:\Windows\system32\perfc007.dat
2014-06-30 09:57 - 2009-07-14 07:13 - 01650176 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-30 09:55 - 2014-06-30 09:55 - 00002072 _____ () C:\Users\Simmal.*****\Desktop\AdwCleaner[S0].txt
2014-06-30 09:55 - 2011-09-21 14:02 - 00000031 _____ () C:\tmuninst.ini
2014-06-30 09:55 - 2011-09-21 13:58 - 00000000 ____D () C:\ProgramData\Sonic
2014-06-30 09:53 - 2014-06-30 09:53 - 00000022 _____ () C:\Windows\S.dirmngr
2014-06-30 09:53 - 2010-11-21 05:47 - 01204684 _____ () C:\Windows\PFRO.log
2014-06-30 09:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-30 09:53 - 2009-07-14 06:51 - 00048648 _____ () C:\Windows\setupact.log
2014-06-30 09:52 - 2014-06-30 09:50 - 00000000 ____D () C:\AdwCleaner
2014-06-30 09:50 - 2014-06-30 09:50 - 01346519 _____ () C:\Users\Simmal.*****\Desktop\adwcleaner_3.214.exe
2014-06-30 09:49 - 2014-06-30 09:47 - 00013611 _____ () C:\Users\Simmal.*****\Desktop\mbam.txt
2014-06-30 09:08 - 2014-06-30 09:08 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-30 09:08 - 2014-06-30 09:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-30 09:08 - 2014-06-30 09:07 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-30 09:07 - 2014-06-30 09:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-30 09:07 - 2014-06-30 09:06 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Simmal.*****\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-27 15:16 - 2012-11-18 12:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-27 15:15 - 2014-06-27 15:15 - 00019700 _____ () C:\Users\Simmal.*****\Desktop\combofix1.txt
2014-06-27 15:12 - 2014-06-27 15:12 - 00019700 _____ () C:\ComboFix.txt
2014-06-27 15:12 - 2014-06-27 15:08 - 00000000 ____D () C:\Qoobox
2014-06-27 15:11 - 2014-06-27 15:08 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 15:11 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-06-27 14:52 - 2014-06-27 14:52 - 05212118 ____R (Swearware) C:\Users\Simmal.*****\Desktop\ComboFix.exe
2014-06-27 14:49 - 2012-11-20 15:38 - 00000000 ____D () C:\Users\Simmal\AppData\Local\FreePDF_XP
2014-06-26 17:55 - 2014-06-25 16:41 - 00043454 _____ () C:\Users\Simmal.*****\Desktop\Addition.txt
2014-06-26 17:48 - 2014-05-14 15:40 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-06-26 17:45 - 2014-06-26 17:45 - 00001270 _____ () C:\Users\Simmal.*****\Desktop\Revo Uninstaller.lnk
2014-06-26 17:45 - 2014-06-26 17:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:44 - 2014-06-26 17:43 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Simmal.*****\Desktop\revosetup95.exe
2014-06-25 17:35 - 2014-06-25 17:31 - 00005653 _____ () C:\Users\Simmal.*****\Desktop\gmer.txt
2014-06-25 17:21 - 2014-06-25 17:21 - 00380416 _____ () C:\Users\Simmal.*****\Desktop\Gmer-19357.exe
2014-06-25 17:19 - 2014-06-25 17:19 - 00000474 _____ () C:\Users\Simmal.*****\Desktop\defogger_disable.log
2014-06-25 17:19 - 2014-06-25 17:19 - 00000000 _____ () C:\Users\Simmal.*****\defogger_reenable
2014-06-25 17:19 - 2012-11-18 12:42 - 00000000 ____D () C:\Users\Simmal.*****
2014-06-25 17:18 - 2014-06-25 17:18 - 00050477 _____ () C:\Users\Simmal.*****\Desktop\Defogger.exe
2014-06-25 15:35 - 2014-06-25 15:35 - 02082816 _____ (Farbar) C:\Users\Simmal.*****\Desktop\FRST64.exe
2014-06-23 14:45 - 2013-07-15 19:40 - 00000000 ____D () C:\Users\Simmal.*****\AppData\Local\CrashDumps
2014-06-20 17:40 - 2014-03-24 11:29 - 00000000 ____D () C:\Users\Simmal.*****\AppData\Roaming\gnupg
2014-06-18 11:56 - 2014-06-18 11:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-17 13:28 - 2014-06-17 13:28 - 00000000 ____D () C:\Users\Simmal.*****\AppData\Local\Adobe
2014-06-17 13:24 - 2012-11-19 16:53 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-17 13:24 - 2011-09-21 13:40 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 11:07 - 2014-06-11 11:07 - 00055214 _____ () C:\Users\Simmal.*****\Desktop\Baugruppenartikel.xls
2014-06-11 03:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-11 03:37 - 2012-11-18 12:42 - 00000250 ___SH () C:\Users\Simmal.*****\ntuser.ini
2014-06-11 03:02 - 2013-07-13 03:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 03:01 - 2012-11-20 13:52 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-11 03:01 - 2012-11-18 12:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-11 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-10 16:01 - 2014-06-10 16:00 - 00004534 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-06-10 16:01 - 2014-03-03 14:47 - 00000000 ____D () C:\ProgramData\Oracle
2014-06-10 16:01 - 2013-07-01 15:30 - 00000000 ____D () C:\Program Files (x86)\Java
2014-06-10 15:57 - 2014-03-03 14:38 - 00918952 _____ (Oracle Corporation) C:\Users\Simmal.*****\Downloads\jxpiinstall.exe
2014-06-08 11:13 - 2014-06-10 23:17 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-10 23:17 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
Some content of TEMP:
====================
C:\Users\Simmal.*****\AppData\Local\Temp\avgnt.exe
C:\Users\Simmal.*****\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-28 00:41
==================== End Of Log ============================ --- --- ---
--- --- --- |