Hallo,
hier die gewünschten Dateien von meinem Rechner:
MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.07.2014
Suchlauf-Zeit: 21:12:09
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.18.08
Rootkit Datenbank: v2014.07.17.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Carmen
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 306665
Verstrichene Zeit: 5 Min, 31 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 14
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\CLSID\{33119133-0854-469d-807A-171568457991}, In Quarantäne, [37c9eab7493284b271393060738f1fe1],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, In Quarantäne, [37c9eab7493284b271393060738f1fe1],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, In Quarantäne, [37c9eab7493284b271393060738f1fe1],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\VideoDownloadConverter_4z.SkinLauncherSettings.1, In Quarantäne, [37c9eab7493284b271393060738f1fe1],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\VideoDownloadConverter_4z.SkinLauncherSettings, In Quarantäne, [37c9eab7493284b271393060738f1fe1],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw, In Quarantäne, [5ba50e93d7a43501b79375aa6e966b95],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}w, In Quarantäne, [28d8aaf75d1eb2848ac11b041aea2bd5],
Adware.EoRezo, HKLM\SOFTWARE\FrEeSoFtToDaY, In Quarantäne, [c53b614076052b0be86b2cd9d62ec43c],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\VideoDownloadConverter_4z, In Quarantäne, [738d9b061d5efe38b0b8ee2cad57ab55],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@VideoDownloadConverter_4z.com/Plugin, In Quarantäne, [de222f72057679bddad6ece7ce34ef11],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-2691091046-4108991242-2645959706-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\VideoDownloadConverter_4z, In Quarantäne, [d12fd1d0285338fe79f036e47e860df3],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-2691091046-4108991242-2645959706-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\VideoDownloadConverter_4z, In Quarantäne, [0af6e2bf96e5a29486abd6f899694fb1],
PUP.Optional.SuperFish.A, HKU\S-1-5-21-2691091046-4108991242-2645959706-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [b44c41603546fa3c5c19b5108a78ec14],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-2691091046-4108991242-2645959706-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\VideoDownloadConverter_4z, In Quarantäne, [23dd277a2e4d8aacc76a5c7258aab54b],
Registrierungswerte: 1
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|4zffxtbr@VideoDownloadConverter_4z.com, C:\Program Files\VideoDownloadConverter_4z\bar\1.bin, In Quarantäne, [52aeeab758239e98accac91258aaf010]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 11
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\History, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Settings, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\VideoDownloadConverter_4z, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\VideoDownloadConverter_4z\Cache, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.FreeSoftToday.A, C:\Users\Carmen\AppData\Local\fst_de_92, In Quarantäne, [e818e9b87cff2b0bb342e7d41fe3d32d],
PUP.Optional.FreeSoftToday.A, C:\Users\Carmen\AppData\Local\fst_de_92\fst_de_92, In Quarantäne, [e818e9b87cff2b0bb342e7d41fe3d32d],
Dateien: 86
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw.sys, In Quarantäne, [5ba50e93d7a43501b79375aa6e966b95],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}w.sys, In Quarantäne, [28d8aaf75d1eb2848ac11b041aea2bd5],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\00113C3B, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\00113DA2.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\00113E6D.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\00113F29.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\0011411D.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\001142E2.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\0011441A.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\00114591.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\0011462E.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\001146AB.bmp, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\files.ini, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\History\search3, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\ldb.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lobm.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\btmarrow.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\cancel.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\config.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\continue.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\dispatch.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\divider.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\gcancel.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\index.htm, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\infobar.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\jquery.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\la.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lbcs.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lbms.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lca.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lcfc.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lcm.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lcs.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lcso.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lctn.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\ldbg.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lddg.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lff.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lffb.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lg.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lgs.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lgw.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lha.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lhp.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lia.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\liwon.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lkazulah.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lmd.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lmfc.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lmh.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lmma.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lmosh.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lmwf.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lmws.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\loryte.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lpss.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lqc.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lrb.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lrg.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lrr.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lsc.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lscr.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lsi.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lssd.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\ltrs.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\ltvf.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lvs.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lwb.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lwf.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\lzwinky.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\ok.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\overlay.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\pid.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\qstring.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\shield.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\spacer.swf, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\toolbar.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\yelgrey.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\yellowbg.png, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\zEnable.css, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\zEnable.htm, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\ie9mesg\COMMON\zEnable.js, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\bar\Settings\prevcfg2.htm, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\VideoDownloadConverter_4z\Cache\PopupProperties212028144.html, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\VideoDownloadConverter_4z\Cache\Radio.html, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
PUP.Optional.MindSpark.A, C:\Users\Carmen\AppData\LocalLow\VideoDownloadConverter_4z\VideoDownloadConverter_4z\Cache\VideosBtn.html, In Quarantäne, [59a7cdd40e6d72c40d803c77fb071ee2],
Physische Sektoren: 0
(No malicious items detected)
(end) ADWCleaner: Code:
# AdwCleaner v3.216 - Bericht erstellt am 18/07/2014 um 21:28:04
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Carmen - CARMEN-PC
# Gestartet von : D:\Eigene\Downloads\adwcleaner_3.216.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : webinstr
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\AskPartnerNetwork
Ordner Gelöscht : C:\ProgramData\ParetoLogic
Ordner Gelöscht : C:\Program Files\predm
Ordner Gelöscht : C:\Users\Carmen\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Carmen\AppData\Local\VideoDownloadConverter_4z
Ordner Gelöscht : C:\Users\Carmen\AppData\LocalLow\iac
Ordner Gelöscht : C:\Users\Carmen\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\Carmen\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Users\Carmen\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Carmen\AppData\Roaming\Solvusoft
Datei Gelöscht : C:\Windows\system32\roboot.exe
Datei Gelöscht : D:\Eigene\Desktop\Continue VuuPC Installation.lnk
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ToolbarProtector
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ToolbarProtector.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2A1260C1-2964-453F-B0BA-FA429472EB5F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{363D5C92-10DC-4287-93E5-1832EECC48EC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3719959C-1CCD-4FA7-8EBB-7D9DED86FCCB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B41BE90-F731-4137-AFF3-2CA951E7F0D9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4128C64D-F0DD-4811-9405-D22294E8151F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66292684-B2C2-4C7C-B3D2-BF446E30744C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69407823-3494-4400-8D49-612549E8F4EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6BFF4BCB-7A73-45A7-AC4C-389A34E1D1EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{84B7B98F-E018-4DBB-AB4C-4DDD3DFCB5FB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8FCA5302-6D6D-4645-BF99-D43CF76CE474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A86782D8-7B41-452F-A217-1854F72DBA54}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD385519-22E7-4BE2-8A8D-35C66DF4858E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ED345812-2722-4DCA-9976-D01832DB44EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FF48DBA6-5DD8-4D10-9EB0-0FA968502E66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{192F487E-E812-40C0-B0DE-CB4BFA20F37B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{37923200-6887-4B44-95D4-CAE8F83ECFEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{79332472-47F3-4E32-B07F-CF8DF4C58499}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{BC153A3C-0BB7-4EED-83AE-28E6E398F56E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FB0E8A09-F08C-44CF-9E15-97ADAC016248}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF6E4B1C-DBDE-457E-9CEF-AB8ECAC8A5E8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF6E4B1C-DBDE-457E-9CEF-AB8ECAC8A5E8}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\blockAndSurf
Schlüssel Gelöscht : HKLM\Software\ParetoLogic
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoDownloadConverter_4zbar Uninstall
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Carmen\AppData\Roaming\Mozilla\Firefox\Profiles\oiqanekh.default-1405368859315\prefs.js ]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://isearch.glarysoft.com/?q={searchTerms}&src=gcsearch
Gelöscht [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo
Gelöscht [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg
Gelöscht [Extension] : hphibigbodkkohoglgfkddblldpfohjl
Gelöscht [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Gelöscht [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Gelöscht [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc
Gelöscht [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc
*************************
AdwCleaner[R0].txt - [11639 octets] - [18/07/2014 21:26:16]
AdwCleaner[S0].txt - [11529 octets] - [18/07/2014 21:28:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11590 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Professional x86
Ran by Carmen on 18.07.2014 at 21:39:39,13
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A5AAA0B7-C6C9-47D2-85F1-2EFE38162307}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Carmen\AppData\Roaming\mozilla\firefox\profiles\oiqanekh.default-1405368859315\minidumps [3 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.07.2014 at 21:43:42,79
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Neues FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by Carmen (administrator) on CARMEN-PC on 18-07-2014 21:56:26
Running from D:\Eigene\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(CANON INC.) C:\Windows\System32\CAP3RSK.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Copernic Inc.) C:\Program Files\Copernic Desktop Search - Home\DesktopSearchService.exe
(Google) C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
(CANON INC.) C:\Windows\System32\spool\drivers\w32x86\3\CAP3SWK.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\pnagent.exe
(CANON INC.) C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE
(CANON INC.) C:\Windows\System32\spool\drivers\w32x86\3\CAP3SWK.EXE
(Belkin International, Inc.) C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Farbar) D:\Eigene\Desktop\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-07-12] (AVAST Software)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [1797064 2014-03-20] (NVIDIA Corporation)
HKU\S-1-5-21-2691091046-4108991242-2645959706-1000\...\Run: [Copernic Desktop Search - Home] => C:\Program Files\Copernic Desktop Search - Home\DesktopSearchService.exe [1692200 2013-01-28] (Copernic Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Calendar Sync.lnk
ShortcutTarget: Google Calendar Sync.lnk -> C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Program Neighborhood Agent.lnk
ShortcutTarget: Program Neighborhood Agent.lnk -> C:\Windows\Installer\{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}\Icon80951CEC.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Statusfenster für Canon LASER SHOT LBP-1120.LNK
ShortcutTarget: Statusfenster für Canon LASER SHOT LBP-1120.LNK -> C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE (CANON INC.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico ()
Startup: C:\Users\Carmen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Belkin Network USB Hub Control Center.lnk
ShortcutTarget: Belkin Network USB Hub Control Center.lnk -> C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe (Belkin International, Inc.)
Startup: C:\Users\Carmen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Belkin Netzwerk USB-Hub Kontrollzentrum.lnk
ShortcutTarget: Belkin Netzwerk USB-Hub Kontrollzentrum.lnk -> C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe (Belkin International, Inc.)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF465F193F16ECC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
SearchScopes: HKCU - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - No File
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Carmen\AppData\Roaming\Mozilla\Firefox\Profiles\oiqanekh.default-1405368859315
FF Homepage: https://www.google.de/?gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin - C:\Program Files\Java\jre6\bin\npDeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKCU\...\Firefox\Extensions: [{57319509-7821-41B0-9FDF-3B58F146AE33}] - c:\program files\copernic desktop search - home\firefoxconnector
FF Extension: Copernic Desktop Search - Search Firefox content - c:\program files\copernic desktop search - home\firefoxconnector [2013-09-11]
FF HKCU\...\Firefox\Extensions: [{B88D9CE3-7EFB-E080-6B66-0996F729CACD}] - C:\Program Files\di2BlockAndSurf\175.xpi
Chrome:
=======
CHR HomePage: https://de.yahoo.com?fr=hp-avast&type=prc265
CHR RestoreOnStartup: "https://de.yahoo.com?fr=hp-avast&type=prc265"
CHR StartupUrls: "https://de.yahoo.com?fr=hp-avast&type=prc265"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (VLC Multimedia Plug-in) - C:\Program Files\VideoLAN\VLC\npvlc.dll No File
CHR Extension: (YouTube) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-05-02]
CHR Extension: (Google-Suche) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-05-02]
CHR Extension: (avast! Online Security) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-09-11]
CHR Extension: (BlockAndSurf) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbohmgpeabkdiinjpgnadfceebineoig [2014-07-12]
CHR Extension: (Chrome In-App Payments service) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-02]
CHR Extension: (Google Mail) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-05-02]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-12] (AVAST Software)
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528608 2008-08-29] (Cisco Systems, Inc.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-07-12] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-07-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-07-12] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-07-12] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-07-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-07-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [71944 2014-07-12] (AVAST Software)
R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [56080 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-07-12] ()
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306299 2008-08-29] (Cisco Systems, Inc.) [File not signed]
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [125328 2008-03-29] (Deterministic Networks, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R2 sxuptp; C:\Windows\System32\DRIVERS\sxuptp.sys [62464 2007-09-27] (silex technology, Inc.)
R0 vidsflt58; C:\Windows\System32\DRIVERS\vsflt58.sys [84512 2011-09-18] (Acronis)
S3 catchme; \??\C:\Users\Carmen\AppData\Local\Temp\catchme.sys [X]
U3 DfSdkS;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-18 21:34 - 2014-07-18 21:34 - 00000000 ____D () C:\Windows\ERUNT
2014-07-18 21:26 - 2014-07-18 21:28 - 00000000 ____D () C:\AdwCleaner
2014-07-18 21:26 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-07-18 21:08 - 2014-07-18 21:39 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 21:07 - 2014-07-18 21:07 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 21:07 - 2014-07-18 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 21:07 - 2014-07-18 21:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 21:07 - 2014-07-18 21:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-18 21:07 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-18 21:07 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-18 21:07 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-18 08:57 - 2014-07-18 08:57 - 00014911 _____ () C:\ComboFix.txt
2014-07-18 08:47 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-18 08:47 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-18 08:47 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-18 08:47 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-18 08:47 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-18 08:47 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-18 08:47 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-18 08:47 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-18 08:46 - 2014-07-18 09:06 - 00000000 ____D () C:\ComboFix
2014-07-18 08:46 - 2014-07-18 08:57 - 00000000 ____D () C:\Qoobox
2014-07-18 08:46 - 2014-07-18 08:55 - 00000000 ____D () C:\Windows\erdnt
2014-07-18 08:13 - 2014-07-18 08:13 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-16 19:39 - 2014-07-18 21:56 - 00000000 ____D () C:\FRST
2014-07-16 14:46 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-07-15 18:07 - 2014-05-08 11:06 - 02742784 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-07-15 18:07 - 2014-05-08 11:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-07-15 13:53 - 2014-07-15 13:53 - 00000000 ____D () C:\Users\Carmen\AppData\Local\NVIDIA
2014-07-14 22:24 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe
2014-07-14 22:23 - 2014-07-14 22:23 - 00000000 ____D () C:\temp
2014-07-14 22:20 - 2012-08-23 16:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-07-14 22:20 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-07-14 22:20 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-07-14 22:18 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-07-14 22:18 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-07-14 22:18 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-07-14 22:18 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-07-14 22:18 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-07-14 22:18 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-07-14 22:18 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-07-14 22:18 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-07-14 22:18 - 2013-10-02 01:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-07-14 22:18 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-07-14 22:18 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-07-14 21:50 - 2014-07-14 21:55 - 00001664 _____ () C:\Windows\system32\ASOROSet.bin
2014-07-14 21:50 - 2014-07-14 21:50 - 00000000 ____D () C:\Windows\system32\config\RCCBakup
2014-07-14 21:44 - 2014-07-14 21:44 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-07-14 21:33 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-07-14 21:33 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-07-14 21:21 - 2014-07-14 21:25 - 00000000 ____D () C:\Users\Carmen\AppData\Roaming\GlarySoft
2014-07-12 22:24 - 2014-07-18 21:37 - 00001635 _____ () C:\Windows\setupact.log
2014-07-12 22:24 - 2014-07-18 21:29 - 00040704 _____ () C:\Windows\PFRO.log
2014-07-12 22:24 - 2014-07-12 22:24 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-12 20:36 - 2014-07-12 20:36 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-12 08:03 - 2014-07-15 18:02 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-07-12 08:03 - 2014-07-12 08:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-12 08:03 - 2014-07-07 17:04 - 00051336 _____ (Corsica) C:\Windows\system32\Drivers\webinstr.sys
2014-07-11 22:37 - 2014-07-11 22:37 - 00000000 ____D () C:\Users\Carmen\AppData\Roaming\PDF Architect 2
2014-07-11 12:09 - 2014-07-12 08:13 - 00000000 ____D () C:\Program Files\PDFCreator
2014-07-11 12:09 - 2014-07-11 12:09 - 00000993 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-07-11 12:09 - 2014-07-11 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-07-11 12:09 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCT2.OCX
2014-07-11 12:09 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\system32\MSMAPI32.OCX
2014-07-11 12:09 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\MSMPIDE.DLL
2014-07-11 12:09 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\system32\VB6DE.DLL
2014-07-11 12:09 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\MSCMCDE.DLL
2014-07-11 12:09 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\MSCC2DE.DLL
2014-07-10 21:35 - 2014-07-10 21:35 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-07-10 21:35 - 2014-04-25 17:44 - 00095416 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-07-10 16:42 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 13:06 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 13:06 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 13:06 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 13:06 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 13:06 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 13:06 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 13:06 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 13:06 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 13:06 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 13:06 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 13:06 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 13:06 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 13:06 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 13:06 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 13:06 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 13:06 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 13:06 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 13:06 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 13:06 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 13:06 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 13:06 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 13:06 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 13:06 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 13:06 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 13:06 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 13:06 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 13:06 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 13:06 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 13:06 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 13:06 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 13:05 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 13:05 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 13:05 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 13:05 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 13:05 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 13:05 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 13:05 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 13:05 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 13:05 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 13:05 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 13:05 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 13:05 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 13:05 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
==================== One Month Modified Files and Folders =======
2014-07-18 21:56 - 2014-07-16 19:39 - 00000000 ____D () C:\FRST
2014-07-18 21:44 - 2009-07-14 06:34 - 00020304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-18 21:44 - 2009-07-14 06:34 - 00020304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-18 21:39 - 2014-07-18 21:08 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 21:39 - 2012-04-24 18:45 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-18 21:37 - 2014-07-12 22:24 - 00001635 _____ () C:\Windows\setupact.log
2014-07-18 21:37 - 2012-11-19 13:18 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-18 21:37 - 2012-04-24 18:45 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-18 21:37 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-18 21:36 - 2011-08-25 16:27 - 01491495 _____ () C:\Windows\WindowsUpdate.log
2014-07-18 21:34 - 2014-07-18 21:34 - 00000000 ____D () C:\Windows\ERUNT
2014-07-18 21:31 - 2013-09-18 12:06 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-18 21:29 - 2014-07-12 22:24 - 00040704 _____ () C:\Windows\PFRO.log
2014-07-18 21:28 - 2014-07-18 21:26 - 00000000 ____D () C:\AdwCleaner
2014-07-18 21:19 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Speech
2014-07-18 21:07 - 2014-07-18 21:07 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 21:07 - 2014-07-18 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 21:07 - 2014-07-18 21:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 21:07 - 2014-07-18 21:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-18 11:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-07-18 09:06 - 2014-07-18 08:46 - 00000000 ____D () C:\ComboFix
2014-07-18 08:57 - 2014-07-18 08:57 - 00014911 _____ () C:\ComboFix.txt
2014-07-18 08:57 - 2014-07-18 08:46 - 00000000 ____D () C:\Qoobox
2014-07-18 08:57 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-07-18 08:55 - 2014-07-18 08:46 - 00000000 ____D () C:\Windows\erdnt
2014-07-18 08:55 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-07-18 08:13 - 2014-07-18 08:13 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-17 03:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-07-16 10:25 - 2010-11-20 23:01 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-15 18:02 - 2014-07-12 08:03 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-07-15 13:53 - 2014-07-15 13:53 - 00000000 ____D () C:\Users\Carmen\AppData\Local\NVIDIA
2014-07-15 13:52 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-15 13:51 - 2011-04-12 03:29 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2014-07-14 22:25 - 2012-11-19 13:17 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-07-14 22:25 - 2012-11-19 13:17 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-07-14 22:23 - 2014-07-14 22:23 - 00000000 ____D () C:\temp
2014-07-14 21:55 - 2014-07-14 21:50 - 00001664 _____ () C:\Windows\system32\ASOROSet.bin
2014-07-14 21:55 - 2009-07-14 04:03 - 52690944 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-07-14 21:55 - 2009-07-14 04:03 - 15204352 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-07-14 21:55 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-07-14 21:53 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-07-14 21:50 - 2014-07-14 21:50 - 00000000 ____D () C:\Windows\system32\config\RCCBakup
2014-07-14 21:44 - 2014-07-14 21:44 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-07-14 21:26 - 2014-03-31 18:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-07-14 21:26 - 2013-08-21 21:26 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-07-14 21:26 - 2011-08-29 13:05 - 00001081 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-14 21:26 - 2011-08-29 13:05 - 00001069 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-07-14 21:25 - 2014-07-14 21:21 - 00000000 ____D () C:\Users\Carmen\AppData\Roaming\GlarySoft
2014-07-14 15:21 - 2009-07-14 04:04 - 00000580 _____ () C:\Windows\win.ini
2014-07-12 22:43 - 2012-05-23 13:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lexware
2014-07-12 22:39 - 2012-08-29 14:38 - 00000000 ____D () C:\Program Files\QuickTime
2014-07-12 22:37 - 2011-08-29 13:06 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2014-07-12 22:24 - 2014-07-12 22:24 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-12 20:36 - 2014-07-12 20:36 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-12 20:36 - 2014-04-26 17:41 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-12 20:36 - 2014-01-23 15:56 - 00071944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-07-12 20:36 - 2014-01-23 15:56 - 00002047 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-12 20:36 - 2013-09-11 21:43 - 00192352 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-07-12 20:36 - 2013-09-11 21:43 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-07-12 20:36 - 2012-04-24 17:46 - 00081768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-07-12 20:36 - 2011-08-29 10:08 - 00779536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-07-12 20:36 - 2011-08-29 10:08 - 00414520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-12 20:36 - 2011-08-29 10:08 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-07-12 08:13 - 2014-07-11 12:09 - 00000000 ____D () C:\Program Files\PDFCreator
2014-07-12 08:12 - 2014-01-13 13:53 - 00000000 ____D () C:\Windows\Minidump
2014-07-12 08:12 - 2011-08-25 17:24 - 00000000 ____D () C:\Windows\Panther
2014-07-12 08:03 - 2014-07-12 08:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-12 08:03 - 2009-07-14 04:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-07-11 22:37 - 2014-07-11 22:37 - 00000000 ____D () C:\Users\Carmen\AppData\Roaming\PDF Architect 2
2014-07-11 12:09 - 2014-07-11 12:09 - 00000993 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-07-11 12:09 - 2014-07-11 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-07-10 21:35 - 2014-07-10 21:35 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-07-10 17:31 - 2013-09-18 12:06 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-10 17:31 - 2011-08-29 13:05 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-10 16:31 - 2009-07-14 06:33 - 00408696 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 16:30 - 2011-04-12 03:39 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 21:31 - 2011-08-26 14:24 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-09 21:28 - 2013-08-14 11:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 21:26 - 2014-05-07 17:35 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-09 21:26 - 2013-08-14 11:02 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-07 17:04 - 2014-07-12 08:03 - 00051336 _____ (Corsica) C:\Windows\system32\Drivers\webinstr.sys
2014-06-30 03:40 - 2014-07-09 13:05 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 03:36 - 2014-07-09 13:05 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-20 21:39 - 2014-07-09 13:06 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-19 02:16 - 2014-07-09 13:06 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 01:56 - 2014-07-09 13:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 01:56 - 2014-07-09 13:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-19 01:38 - 2014-07-09 13:06 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-19 01:37 - 2014-07-09 13:06 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 01:36 - 2014-07-09 13:06 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-19 01:35 - 2014-07-09 13:06 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-19 01:32 - 2014-07-09 13:06 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 01:28 - 2014-07-09 13:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 01:28 - 2014-07-09 13:06 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 01:25 - 2014-07-09 13:06 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-19 01:23 - 2014-07-09 13:06 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-19 01:23 - 2014-07-09 13:06 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-19 01:22 - 2014-07-09 13:06 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-19 01:16 - 2014-07-09 13:06 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-19 01:12 - 2014-07-09 13:06 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 01:06 - 2014-07-09 13:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 01:01 - 2014-07-09 13:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-19 00:59 - 2014-07-09 13:06 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-19 00:58 - 2014-07-09 13:06 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-19 00:52 - 2014-07-09 13:06 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-19 00:52 - 2014-07-09 13:06 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-19 00:49 - 2014-07-09 13:06 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-19 00:46 - 2014-07-09 13:06 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-19 00:45 - 2014-07-09 13:06 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-19 00:35 - 2014-07-09 13:06 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-19 00:13 - 2014-07-09 13:06 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-19 00:09 - 2014-07-09 13:06 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-19 00:07 - 2014-07-09 13:06 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-18 03:51 - 2014-07-09 13:05 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-18 02:52 - 2014-07-09 13:05 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
Some content of TEMP:
====================
C:\Users\Carmen\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-18 11:16
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Muss ich jetzt noch was machen oder ist mein Rechner ist "sauber"?
VLG
Was ist mit meinem Laptop? Ist der jetzt clean? Brauchst du hier auch ein neues FRST?
Hi.
Hab meinen Laptop jetzt nochmal mit Avast überprüft und obwohl ich vorher über Avast die Bedrohung Win32:Dropper-gen gelöscht habe, ist diese wieder da. (ComboFix ist infiziert).
Was muss ich hier weiter machen oder kriegt man das Ding nicht runter? |