FireFox:
========
FF ProfilePath: C:\Users\doris\AppData\Roaming\Mozilla\Firefox\Profiles\9fnqnht7.default
FF SelectedSearchEngine: LEO Eng-Deu
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=1.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\doris\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\doris\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\doris\AppData\Roaming\Mozilla\Extensions\
[email protected]
FF Extension: PageRank - C:\Users\doris\AppData\Roaming\Mozilla\Firefox\Profiles\9fnqnht7.default\Extensions\
[email protected]
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google
riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\doris\AppData\Local\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\doris\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\doris\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.210.7) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U21) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Adobe Acrobat) - c:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll No File
CHR Plugin: (VLC Multimedia Plug-in) - C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\doris\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
========================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2008-12-22] ()
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 Apache2.2; c:\xampp\apache\bin\httpd.exe [18432 2011-09-10] (Apache Software Foundation)
R2 CCALib8; C:\Program Files\Canon\CAL\CALMAIN.exe [96341 2005-09-30] (Canon Inc.)
S3 FileZilla Server; c:\xampp\FileZillaFTP\FileZillaServer.exe [630272 2011-06-07] (FileZilla Project)
S3 GoogleDesktopManager-010708-104812; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [29744 2008-11-11] (Google)
R2 Lexware_Datenbank_Plus; C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [83248 2010-11-05] (iAnywhere Solutions, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 mysql; c:\xampp\mysql\bin\my.ini [5396 2012-04-17] ()
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [155648 2008-05-30] (NVIDIA)
R2 sprtsvc_DellSupportCenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-26] (SupportSoft, Inc.)
==================== Drivers (Whitelisted) ====================
R0 AFS; C:\Windows\System32\Drivers\AFS.sys [77004 2009-01-02] (Oak Technology Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-04-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-04-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-02] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-07-12] (Malwarebytes Corporation)
R3 NVR0Dev; C:\Windows\nvoclock.sys [29824 2008-05-30] (NVidia Corp.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-06] (Avira GmbH)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-12 08:37 - 2013-07-12 08:37 - 01218598 ____A (Farbar) C:\Users\doris\Downloads\FRST(1).exe
2013-07-12 08:35 - 2013-07-12 08:35 - 01218598 ____A (Farbar) C:\Users\doris\Downloads\FRST (2).exe
2013-07-12 08:33 - 2013-07-12 08:33 - 01218598 ____A (Farbar) C:\Users\doris\Downloads\FRST (1).exe
2013-07-12 07:54 - 2013-07-12 07:55 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-07-11 22:00 - 2013-07-11 22:00 - 00000000 ____D C:\Users\test\AppData\Roaming\Avira
2013-07-11 21:49 - 2013-07-11 21:49 - 00029155 ____A C:\Users\test\Desktop\FRST.txt
2013-07-11 21:48 - 2013-07-11 21:48 - 00000000 ____D C:\Users\test\AppData\Roaming\SketchUp
2013-07-11 21:02 - 2013-07-11 21:02 - 00000000 ____D C:\FRST
2013-07-11 20:58 - 2013-07-11 20:58 - 01218590 ____A (Farbar) C:\Users\test\Desktop\FRST.exe
2013-07-11 20:44 - 2013-07-11 20:44 - 00000000 ____D C:\Users\test\AppData\Roaming\Malwarebytes
2013-07-11 20:44 - 2013-07-11 20:44 - 00000000 ____D C:\Users\test\AppData\Local\Mozilla
2013-07-11 20:38 - 2013-07-11 20:38 - 01218590 ____A (Farbar) C:\Users\doris\Desktop\FRST.exe
2013-07-11 19:40 - 2013-07-11 19:40 - 00388608 ____A (Trend Micro Inc.) C:\Users\doris\Downloads\HijackThis.exe
2013-07-11 19:39 - 2013-07-11 19:39 - 00024831 ____A C:\Users\doris\Documents\download.htm
2013-07-11 17:34 - 2013-07-11 17:34 - 00000282 ____A C:\Users\doris\Desktop\Hilfe bei der Schädlingsbeseitigung.url
2013-07-11 16:46 - 2013-07-11 16:46 - 00000000 ____D C:\Users\doris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Care Antivirus
2013-07-11 14:47 - 2013-05-29 03:56 - 12333568 ____A (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 14:47 - 2013-05-29 03:50 - 01800704 ____A (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 14:47 - 2013-05-29 03:48 - 09738752 ____A (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 14:47 - 2013-05-29 03:41 - 01427968 ____A (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-11 14:47 - 2013-05-29 03:41 - 01129472 ____A (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 14:47 - 2013-05-29 03:41 - 01104384 ____A (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 14:47 - 2013-05-29 03:40 - 00231936 ____A (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-11 14:47 - 2013-05-29 03:38 - 00065024 ____A (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 14:47 - 2013-05-29 03:37 - 00142848 ____A (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-11 14:47 - 2013-05-29 03:36 - 00420864 ____A (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-11 14:47 - 2013-05-29 03:35 - 00717824 ____A (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 14:47 - 2013-05-29 03:35 - 00607744 ____A (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 14:47 - 2013-05-29 03:33 - 02382848 ____A (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 14:47 - 2013-05-29 03:33 - 01796096 ____A (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 14:47 - 2013-05-29 03:33 - 00073216 ____A (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-11 14:47 - 2013-05-29 03:29 - 00176640 ____A (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 14:18 - 2013-06-04 03:50 - 02049024 ____A (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 14:18 - 2013-06-01 06:06 - 00505344 ____A (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 14:18 - 2013-05-08 06:04 - 01548288 ____A (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 14:18 - 2013-04-17 13:28 - 01029120 ____A (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-11 14:18 - 2013-04-17 13:28 - 00219648 ____A (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-11 14:18 - 2013-04-17 13:28 - 00189952 ____A (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-11 14:18 - 2013-04-17 13:28 - 00160768 ____A (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-11 14:18 - 2013-04-17 12:34 - 01172480 ____A (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-11 14:18 - 2013-04-17 12:33 - 00486400 ____A (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-11 14:18 - 2013-04-17 12:14 - 00683008 ____A (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-11 14:18 - 2013-04-17 12:10 - 01069056 ____A (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 14:18 - 2013-04-17 12:10 - 00798208 ____A (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-07-09 11:23 - 2013-07-10 11:20 - 00013824 ____A C:\Users\doris\Documents\Entwässerung WM KG.xlr
2013-07-08 11:28 - 2013-07-08 22:56 - 00010752 ____A C:\Users\doris\Documents\zisternenberechnung.xlr
2013-07-05 14:55 - 2013-07-05 14:55 - 00000000 ____D C:\Windows\system32\20-20 Technologies
2013-07-03 11:52 - 2013-07-03 22:08 - 17314268 ____A C:\Users\doris\Documents\zauberstaude bestellung 2012.wps
2013-07-03 10:57 - 2013-07-10 07:10 - 00393216 ____A C:\Users\doris\Documents\Futterplan-Florian-07-2013.xlr
2013-06-28 17:27 - 2013-06-28 17:27 - 00000000 ____D C:\Users\doris\AppData\Roaming\SketchUp
2013-06-28 16:14 - 2013-06-28 16:14 - 00003120 ____A C:\Windows\system32\ALLFSAF13a.ocx
2013-06-28 16:14 - 2013-06-28 16:14 - 00002063 ____A C:\Users\Public\Desktop\Style Builder 2013.lnk
2013-06-28 16:14 - 2013-06-28 16:14 - 00001977 ____A C:\Users\Public\Desktop\LayOut 2013.lnk
2013-06-28 16:14 - 2013-06-28 16:14 - 00001896 ____A C:\Users\Public\Desktop\SketchUp 2013.lnk
2013-06-28 16:14 - 2013-06-28 16:14 - 00000000 ____D C:\ProgramData\SketchUp
2013-06-28 16:14 - 2013-06-28 16:14 - 00000000 ____D C:\Program Files\SketchUp
2013-06-28 14:41 - 2013-06-28 14:42 - 79487688 ____A (Trimble Navigation Limited) C:\Users\doris\Downloads\SketchUpWDE-13.exe
2013-06-28 13:47 - 2013-06-28 13:47 - 00000000 ____D C:\Users\doris\AppData\Local\freecad
2013-06-28 13:32 - 2013-06-28 13:42 - 00000000 ____D C:\Users\doris\AppData\Roaming\FreeCAD
2013-06-28 13:31 - 2013-06-28 13:31 - 00000000 ____D C:\Program Files\FreeCAD0.13
2013-06-28 13:28 - 2013-06-28 13:29 - 106101248 ____A C:\Users\doris\Downloads\FreeCAD_0.13.1828_x86_setup.msi
2013-06-27 22:13 - 2013-06-28 22:44 - 00010752 ____A C:\Users\doris\Documents\Berechnung Vollgeschoß.xlr
2013-06-27 19:20 - 2013-06-27 19:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-25 16:00 - 2013-06-25 16:00 - 00002035 ____A C:\Users\doris\AppData\Local\recently-used.xbel
2013-06-21 18:16 - 2013-06-26 23:22 - 00393728 ____A C:\Users\doris\Documents\Futterplan-Florian-06-2013.xlr
2013-06-21 13:09 - 2013-07-01 23:18 - 00014336 ____A C:\Users\doris\Documents\haushöhe neu.xlr
2013-06-21 10:07 - 2013-06-21 11:24 - 00010752 ____A C:\Users\doris\Documents\haushöhe.xlr
2013-06-20 11:40 - 2013-06-21 00:11 - 00010752 ____A C:\Users\doris\Documents\Höhenberechnung Haus Bendig.xlr
2013-06-14 09:32 - 2013-06-14 09:32 - 00126464 ____A C:\Users\doris\Documents\fotocommunity sicher.xlr
2013-06-12 18:04 - 2013-06-12 18:04 - 00000223 ____A C:\Users\doris\Documents\fc-helmut wolf.txt
2013-06-12 10:34 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-06-12 10:34 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-06-12 10:34 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-06-12 10:34 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-06-12 10:34 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\system32\printcom.dll
2013-06-12 10:34 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-06-12 10:34 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-06-12 10:34 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-06-12 10:34 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-06-12 10:34 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-06-12 10:34 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll