So alles durchgeführt :)
#Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 04.08.2014
Suchlauf-Zeit: 16:49:56
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.04.05
Rootkit Datenbank: v2014.08.01.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x86
Dateisystem: NTFS
Benutzer: Samuel
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 281367
Verstrichene Zeit: 15 Min, 10 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 3
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\LevelQualityWatcher, In Quarantäne, [3139536ee992290df14f3a9f1ee42fd1],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-171611177-3949349034-1494544249-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Rr Savings, In Quarantäne, [7af012af037825117dabd119e02224dc],
PUP.Optional.Softonic.A, HKU\S-1-5-21-171611177-3949349034-1494544249-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [6cfec0010b70bc7a55b47d6f010104fc],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 1
PUP.Optional.AdPeak.A, C:\temp, In Quarantäne, [0169c7fa245767cf5d3f528cc240c43c],
Dateien: 3
PUP.Optional.Softonic.A, C:\Users\Samuel\Downloads\SoftonicDownloader_fuer_photoscape.exe, In Quarantäne, [8ddd2e936f0ccd699542df4a5fa28878],
PUP.Optional.AdPeak.A, C:\temp\lsp2.log, In Quarantäne, [0169c7fa245767cf5d3f528cc240c43c],
PUP.Optional.AdPeak.A, C:\temp\t.txt, In Quarantäne, [0169c7fa245767cf5d3f528cc240c43c],
Physische Sektoren: 0
(No malicious items detected)
(end)
#AdwCleaner Logfile:
Code:
# AdwCleaner v3.302 - Bericht erstellt am 04/08/2014 um 17:57:10
# Aktualisiert 30/07/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Samuel - ERST-PC
# Gestartet von : C:\Users\Samuel\Downloads\adwcleaner_3.302(1).exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : PnkBstrA
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\003
Ordner Gelöscht : C:\Users\Samuel\AppData\Local\ZombieAlert
Ordner Gelöscht : C:\Users\Samuel\AppData\Roaming\InetStat
Ordner Gelöscht : C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
Datei Gelöscht : C:\Windows\system32\PnkBstrA.exe
Datei Gelöscht : C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860\foxydeal.sqlite
Datei Gelöscht : C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860\user.js
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [InetStat]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BetterDeals-11
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\suprasavings
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16561
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\Samuel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2356 octets] - [04/08/2014 17:55:27]
AdwCleaner[S0].txt - [2277 octets] - [04/08/2014 17:57:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2337 octets] ##########
--- --- ---
#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Samuel on 04.08.2014 at 18:05:38,01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Emptied folder: C:\Users\Samuel\AppData\Roaming\mozilla\firefox\profiles\wpqc1czv.default-1397160114860\minidumps [23 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.08.2014 at 18:09:15,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014
Ran by Samuel (administrator) on ERST-PC on 04-08-2014 18:10:28
Running from C:\Users\Samuel\Downloads
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
() C:\Program Files\AAVUpdateManager\aavus.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Handle) C:\Users\Samuel\AppData\Roaming\Win System\handle.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
() C:\Program Files\NETGEAR\WNA3100\WNA3100.exe
(Dropbox, Inc.) C:\Users\Samuel\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-21-171611177-3949349034-1494544249-1001\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1840424 2008-12-12] (Nero AG)
HKU\S-1-5-21-171611177-3949349034-1494544249-1001\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA3100 Genie.lnk
ShortcutTarget: NETGEAR WNA3100 Genie.lnk -> C:\Program Files\NETGEAR\WNA3100\WNA3100.exe ()
Startup: C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Samuel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Samuel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Samuel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Samuel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - {2896495D-3682-48B2-9738-9B3F41F1E321} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: No Name -> {41564952-412D-5637-00A7-7A786E7484D7} -> No File
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860
FF Homepage: https://www.google.de/?gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=15.0.4.53 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.4.53 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.709 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll No File
FF Plugin: @real.com/nprpplugin;version=15.0.4.53 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Foxy Secure - C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860\Extensions\admin@foxysecure.com [2014-06-17]
FF Extension: ProxTube - C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-30]
FF Extension: Adblock Plus - C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wpqc1czv.default-1397160114860\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-12]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-05-25]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-06-26]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AAV UpdateService; C:\Program Files\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1028688 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [165784 2014-06-23] (APN LLC.)
R2 HandleService; C:\Users\Samuel\AppData\Roaming\Win System\handle.exe [637952 2014-06-10] (Handle) [File not signed]
R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3596240 2014-07-23] (Check Point Software Technologies Ltd.)
S2 WSWNA3100; C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe [303360 2011-12-07] ()
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [93712 2014-07-03] (Check Point Software Technologies, Ltd.)
S2 NMSAccessU; C:\Users\Samuel\AppData\Local\Temp\{CBCE7B90-A710-4DFD-9AE7-92B88BCE5FFE}\NMSAccessU.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [20747 2008-10-11] (Meetinghouse Data Communications) [File not signed]
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97648 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R3 BCMH43XX; C:\Windows\System32\DRIVERS\bcmwlhigh6.sys [1074944 2011-12-12] (Broadcom Corporation)
S3 RT61; C:\Windows\System32\DRIVERS\RT61.sys [354944 2005-10-19] (Ralink Technology Inc.) [File not signed]
R0 SCMNdisP; C:\Windows\System32\DRIVERS\scmndisp.sys [21728 2007-01-19] (Windows (R) Codename Longhorn DDK provider)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-06] (Avira GmbH)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [456088 2014-07-23] (Check Point Software Technologies Ltd.)
S3 ZD1211U(Digital Data Communication); C:\Windows\System32\DRIVERS\zd1211u.sys [259584 2004-12-22] (ZyDAS Technology Corporation) [File not signed]
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 netr28u; system32\DRIVERS\netr28u.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 vsdatant7; System32\drivers\vsdatant.win7.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-04 18:09 - 2014-08-04 18:09 - 00001057 _____ () C:\Users\Samuel\Desktop\JRT.txt
2014-08-04 18:04 - 2014-08-04 18:05 - 01016261 _____ (Thisisu) C:\Users\Samuel\Downloads\JRT.exe
2014-08-04 18:03 - 2014-08-04 18:03 - 00002417 _____ () C:\Users\Samuel\Desktop\AdwCleaner[S0].txt
2014-08-04 17:56 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-08-04 17:48 - 2014-08-04 17:57 - 00000000 ____D () C:\AdwCleaner
2014-08-04 17:48 - 2014-08-04 17:48 - 01361309 _____ () C:\Users\Samuel\Downloads\adwcleaner_3.302(1).exe
2014-08-04 17:47 - 2014-08-04 17:47 - 01361309 _____ () C:\Users\Samuel\Downloads\adwcleaner_3.302.exe
2014-08-04 17:41 - 2014-08-04 17:41 - 00002014 _____ () C:\mbam.txt
2014-08-04 17:38 - 2014-08-04 17:38 - 00002014 _____ () C:\Users\Samuel\Desktop\mbam.txt
2014-08-04 16:48 - 2014-08-04 16:48 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-04 16:48 - 2014-08-04 16:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-04 16:48 - 2014-08-04 16:48 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-04 16:48 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-04 16:48 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-04 16:48 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-04 16:46 - 2014-08-04 16:47 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Samuel\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-03 19:32 - 2014-08-03 19:32 - 00013592 _____ () C:\ComboFix.txt
2014-08-03 15:03 - 2014-08-03 15:03 - 05566616 ____R (Swearware) C:\Users\Samuel\Desktop\ComboFix.exe
2014-08-03 11:53 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-03 11:53 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-03 11:53 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-03 11:53 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-03 11:53 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-03 11:53 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-03 11:53 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-03 11:53 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-03 11:50 - 2014-08-03 19:32 - 00000000 ____D () C:\Qoobox
2014-08-03 11:49 - 2014-08-03 19:31 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 09:40 - 2014-08-03 09:41 - 00181096 _____ () C:\Windows\Minidump\Mini080314-01.dmp
2014-08-03 08:51 - 2014-08-03 09:35 - 00289027 _____ () C:\Users\Samuel\Desktop\Wöchentliche Versammlung fertig.jpeg
2014-08-03 08:34 - 2014-08-03 08:43 - 00208183 _____ () C:\Users\Samuel\Desktop\Wöchentliche Versammlung.jpeg
2014-08-03 08:06 - 2014-07-06 20:48 - 00115126 _____ () C:\Users\Samuel\Desktop\Gottes Liebe in Schwierigkeiten.jpeg
2014-08-03 07:58 - 2014-08-03 08:00 - 00078421 _____ () C:\Users\Samuel\Downloads\Addition.txt
2014-08-03 07:57 - 2014-08-04 18:10 - 00013430 _____ () C:\Users\Samuel\Downloads\FRST.txt
2014-08-03 07:56 - 2014-08-04 18:10 - 00000000 ____D () C:\FRST
2014-08-03 07:56 - 2014-08-03 07:56 - 01084928 _____ (Farbar) C:\Users\Samuel\Downloads\FRST.exe
2014-08-02 17:27 - 2014-08-02 17:27 - 00142936 _____ () C:\Windows\Minidump\Mini080214-01.dmp
2014-08-01 18:15 - 2014-08-01 18:15 - 12353024 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 09711616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-08-01 18:15 - 2014-08-01 18:15 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-01 18:15 - 2014-08-01 18:15 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-01 18:15 - 2014-08-01 18:15 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00434176 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-08-01 18:15 - 2014-08-01 18:15 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00353584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\advpack.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-08-01 18:15 - 2014-08-01 18:15 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-01 18:11 - 2014-08-01 18:11 - 00826192 _____ (Chip Digital GmbH) C:\Users\Samuel\Downloads\IE9-WindowsVista-x86-deu_9.0.6 - CHIP-Installer.exe
2014-08-01 18:05 - 2014-08-01 18:07 - 65447560 _____ (Microsoft Corporation) C:\Users\Samuel\Downloads\EIE11_DE-DE_MCM_WIN764.EXE
2014-08-01 17:42 - 2014-08-01 17:43 - 00431395 _____ () C:\Windows\system32\Drivers\vsconfig.xml
2014-08-01 17:42 - 2014-08-01 17:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
2014-08-01 17:39 - 2014-08-01 17:42 - 00000000 ____D () C:\Program Files\CheckPoint
2014-08-01 17:37 - 2014-08-01 17:37 - 03394856 _____ (Check Point Software Technologies Ltd.) C:\Users\Samuel\Downloads\zaSetupWeb_132_015_000.exe
2014-08-01 17:27 - 2014-08-01 17:27 - 03401600 _____ (Check Point Software Technologies Ltd.) C:\Users\Samuel\Downloads\zafwSetupWeb_133_052_000.exe
2014-07-31 06:51 - 2014-07-31 06:56 - 00236599 _____ () C:\Users\Samuel\Desktop\Gottes unverdiente Liebe fertig.jpeg
2014-07-24 07:20 - 2014-07-24 07:20 - 00142936 _____ () C:\Windows\Minidump\Mini072414-01.dmp
2014-07-23 00:51 - 2014-07-23 00:51 - 00456088 _____ (Check Point Software Technologies Ltd.) C:\Windows\system32\Drivers\vsdatant.sys
2014-07-20 23:10 - 2014-07-20 23:10 - 00142936 _____ () C:\Windows\Minidump\Mini072014-01.dmp
2014-07-17 03:03 - 2014-07-17 03:03 - 00181520 _____ () C:\Windows\Minidump\Mini071714-01.dmp
2014-07-09 20:17 - 2014-06-07 02:19 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 20:17 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 20:17 - 2014-05-30 08:53 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-04 18:11 - 2014-08-03 07:57 - 00013430 _____ () C:\Users\Samuel\Downloads\FRST.txt
2014-08-04 18:10 - 2014-08-03 07:56 - 00000000 ____D () C:\FRST
2014-08-04 18:09 - 2014-08-04 18:09 - 00001057 _____ () C:\Users\Samuel\Desktop\JRT.txt
2014-08-04 18:05 - 2014-08-04 18:04 - 01016261 _____ (Thisisu) C:\Users\Samuel\Downloads\JRT.exe
2014-08-04 18:04 - 2008-10-02 13:48 - 01114191 _____ () C:\Windows\WindowsUpdate.log
2014-08-04 18:03 - 2014-08-04 18:03 - 00002417 _____ () C:\Users\Samuel\Desktop\AdwCleaner[S0].txt
2014-08-04 18:01 - 2013-04-29 12:38 - 00000000 ___RD () C:\Users\Samuel\Dropbox
2014-08-04 18:01 - 2013-04-29 12:35 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\Dropbox
2014-08-04 17:59 - 2012-12-07 03:00 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-04 17:59 - 2008-01-21 04:47 - 00308552 _____ () C:\Windows\PFRO.log
2014-08-04 17:59 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-04 17:59 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-04 17:59 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-04 17:58 - 2006-11-02 15:01 - 00032532 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-08-04 17:57 - 2014-08-04 17:48 - 00000000 ____D () C:\AdwCleaner
2014-08-04 17:48 - 2014-08-04 17:48 - 01361309 _____ () C:\Users\Samuel\Downloads\adwcleaner_3.302(1).exe
2014-08-04 17:47 - 2014-08-04 17:47 - 01361309 _____ () C:\Users\Samuel\Downloads\adwcleaner_3.302.exe
2014-08-04 17:41 - 2014-08-04 17:41 - 00002014 _____ () C:\mbam.txt
2014-08-04 17:38 - 2014-08-04 17:38 - 00002014 _____ () C:\Users\Samuel\Desktop\mbam.txt
2014-08-04 17:28 - 2012-08-16 07:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-04 17:23 - 2012-12-07 03:00 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-04 17:22 - 2014-04-12 10:35 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-04 17:15 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Branding
2014-08-04 16:48 - 2014-08-04 16:48 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-04 16:48 - 2014-08-04 16:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-04 16:48 - 2014-08-04 16:48 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-04 16:47 - 2014-08-04 16:46 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Samuel\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-03 19:32 - 2014-08-03 19:32 - 00013592 _____ () C:\ComboFix.txt
2014-08-03 19:32 - 2014-08-03 11:50 - 00000000 ____D () C:\Qoobox
2014-08-03 19:32 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default
2014-08-03 19:32 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public
2014-08-03 19:31 - 2014-08-03 11:49 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 19:26 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini
2014-08-03 19:25 - 2006-11-02 12:22 - 49807360 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-08-03 19:25 - 2006-11-02 12:22 - 48758784 _____ () C:\Windows\system32\config\COMPON~2.bak
2014-08-03 19:25 - 2006-11-02 12:22 - 23068672 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-08-03 19:25 - 2006-11-02 12:22 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-08-03 19:25 - 2006-11-02 12:22 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-08-03 19:25 - 2006-11-02 12:22 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-08-03 19:19 - 2008-01-21 09:16 - 01587668 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-03 15:03 - 2014-08-03 15:03 - 05566616 ____R (Swearware) C:\Users\Samuel\Desktop\ComboFix.exe
2014-08-03 09:41 - 2014-08-03 09:40 - 00181096 _____ () C:\Windows\Minidump\Mini080314-01.dmp
2014-08-03 09:40 - 2014-03-01 14:06 - 264159678 _____ () C:\Windows\MEMORY.DMP
2014-08-03 09:40 - 2014-03-01 14:06 - 00000000 ____D () C:\Windows\Minidump
2014-08-03 09:35 - 2014-08-03 08:51 - 00289027 _____ () C:\Users\Samuel\Desktop\Wöchentliche Versammlung fertig.jpeg
2014-08-03 08:58 - 2014-06-17 11:35 - 00000000 ____D () C:\Users\Samuel\Desktop\Originals
2014-08-03 08:43 - 2014-08-03 08:34 - 00208183 _____ () C:\Users\Samuel\Desktop\Wöchentliche Versammlung.jpeg
2014-08-03 08:18 - 2010-04-12 20:23 - 00000000 ____D () C:\Users\Samuel\AppData\Local\Paint.NET
2014-08-03 08:08 - 2012-12-28 18:57 - 00036864 ____H () C:\Users\Samuel\Desktop\photothumb.db
2014-08-03 08:00 - 2014-08-03 07:58 - 00078421 _____ () C:\Users\Samuel\Downloads\Addition.txt
2014-08-03 07:56 - 2014-08-03 07:56 - 01084928 _____ (Farbar) C:\Users\Samuel\Downloads\FRST.exe
2014-08-02 22:42 - 2014-06-15 18:00 - 00728576 ____H () C:\Users\Samuel\Desktop\~WRL0013.tmp
2014-08-02 17:28 - 2009-06-22 21:09 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-08-02 17:27 - 2014-08-02 17:27 - 00142936 _____ () C:\Windows\Minidump\Mini080214-01.dmp
2014-08-02 17:13 - 2014-03-01 17:18 - 00093020 _____ () C:\Users\Samuel\Desktop\Samuel Steuererklärung.ESt2013_Backup
2014-08-02 17:13 - 2014-03-01 17:18 - 00093020 _____ () C:\Users\Samuel\Desktop\Samuel Steuererklärung.ESt2013
2014-08-02 16:54 - 2014-03-01 17:00 - 00001781 _____ () C:\Users\Public\Desktop\Steuer-Sparer 2014.lnk
2014-08-02 16:54 - 2014-03-01 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer-Sparer 2014
2014-08-02 16:54 - 2014-03-01 16:58 - 00000000 ____D () C:\Program Files\Steuer-Sparer 2014
2014-08-01 18:35 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\rescache
2014-08-01 18:20 - 2008-10-02 13:52 - 00000953 _____ () C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-01 18:17 - 2006-11-02 13:18 - 00000000 ___RD () C:\Windows\Offline Web Pages
2014-08-01 18:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE
2014-08-01 18:16 - 2011-05-09 18:42 - 00005716 _____ () C:\Windows\IE9_main.log
2014-08-01 18:15 - 2014-08-01 18:15 - 12353024 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 09711616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-08-01 18:15 - 2014-08-01 18:15 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-01 18:15 - 2014-08-01 18:15 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-01 18:15 - 2014-08-01 18:15 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00434176 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-08-01 18:15 - 2014-08-01 18:15 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00353584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\advpack.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-08-01 18:15 - 2014-08-01 18:15 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-08-01 18:15 - 2014-08-01 18:15 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-01 18:15 - 2014-08-01 18:15 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-01 18:15 - 2006-11-02 08:32 - 00008798 _____ () C:\Windows\system32\icrav03.rat
2014-08-01 18:15 - 2006-11-02 08:32 - 00001988 _____ () C:\Windows\system32\ticrf.rat
2014-08-01 18:11 - 2014-08-01 18:11 - 00826192 _____ (Chip Digital GmbH) C:\Users\Samuel\Downloads\IE9-WindowsVista-x86-deu_9.0.6 - CHIP-Installer.exe
2014-08-01 18:07 - 2014-08-01 18:05 - 65447560 _____ (Microsoft Corporation) C:\Users\Samuel\Downloads\EIE11_DE-DE_MCM_WIN764.EXE
2014-08-01 17:58 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-08-01 17:43 - 2014-08-01 17:42 - 00431395 _____ () C:\Windows\system32\Drivers\vsconfig.xml
2014-08-01 17:43 - 2008-10-02 13:52 - 00000000 ____D () C:\Users\Samuel
2014-08-01 17:42 - 2014-08-01 17:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
2014-08-01 17:42 - 2014-08-01 17:39 - 00000000 ____D () C:\Program Files\CheckPoint
2014-08-01 17:37 - 2014-08-01 17:37 - 03394856 _____ (Check Point Software Technologies Ltd.) C:\Users\Samuel\Downloads\zaSetupWeb_132_015_000.exe
2014-08-01 17:27 - 2014-08-01 17:27 - 03401600 _____ (Check Point Software Technologies Ltd.) C:\Users\Samuel\Downloads\zafwSetupWeb_133_052_000.exe
2014-08-01 08:21 - 2014-06-15 18:00 - 00726528 ____H () C:\Users\Samuel\Desktop\~WRL0012.tmp
2014-07-31 06:56 - 2014-07-31 06:51 - 00236599 _____ () C:\Users\Samuel\Desktop\Gottes unverdiente Liebe fertig.jpeg
2014-07-29 22:20 - 2014-06-20 06:35 - 00000000 ____D () C:\Users\Samuel\Desktop\Samuel Fotos
2014-07-29 07:23 - 2008-08-04 11:13 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-26 03:03 - 2010-06-04 07:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-24 08:17 - 2013-04-29 12:38 - 00000963 _____ () C:\Users\Samuel\Desktop\Dropbox.lnk
2014-07-24 08:17 - 2013-04-29 12:36 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-07-24 07:20 - 2014-07-24 07:20 - 00142936 _____ () C:\Windows\Minidump\Mini072414-01.dmp
2014-07-23 00:51 - 2014-07-23 00:51 - 00456088 _____ (Check Point Software Technologies Ltd.) C:\Windows\system32\Drivers\vsdatant.sys
2014-07-20 23:10 - 2014-07-20 23:10 - 00142936 _____ () C:\Windows\Minidump\Mini072014-01.dmp
2014-07-20 14:14 - 2014-06-15 18:00 - 00720384 ____H () C:\Users\Samuel\Desktop\~WRL3911.tmp
2014-07-18 22:35 - 2014-06-15 18:00 - 00719872 ____H () C:\Users\Samuel\Desktop\~WRL0384.tmp
2014-07-17 03:03 - 2014-07-17 03:03 - 00181520 _____ () C:\Windows\Minidump\Mini071714-01.dmp
2014-07-10 03:24 - 2006-11-02 14:47 - 00333872 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 03:22 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 03:04 - 2013-08-15 10:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 03:02 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-07-09 21:15 - 2014-06-15 18:00 - 00713216 ____H () C:\Users\Samuel\Desktop\~WRL0011.tmp
2014-07-09 18:28 - 2012-06-27 09:22 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-09 18:28 - 2011-11-13 10:22 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-06 20:48 - 2014-08-03 08:06 - 00115126 _____ () C:\Users\Samuel\Desktop\Gottes Liebe in Schwierigkeiten.jpeg
Some content of TEMP:
====================
C:\Users\Samuel\AppData\Local\Temp\avgnt.exe
C:\Users\Samuel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcysoxe.dll
C:\Users\Samuel\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-04 18:05
==================== End Of Log ============================
--- --- ---