|
Antiviren-, Firewall- und andere Schutzprogramme: Firewall lässt sich nicht starten - "Empfohlene Einstellungen"Windows 7 Sämtliche Fragen zur Bedienung von Firewalls, Anti-Viren Programmen, Anti Malware und Anti Trojaner Software sind hier richtig. Dies ist ein Diskussionsforum für Sicherheitslösungen für Windows Rechner. Benötigst du Hilfe beim Trojaner entfernen oder weil du dir einen Virus eingefangen hast, erstelle ein Thema in den oberen Bereinigungsforen. |
14.09.2013, 13:18 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Ist schon gut. Ich wollte nur wissen, ob es wirklich nichts gefunden hat! Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
14.09.2013, 13:35 | #17 |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Hier der 1. Schritt: adwCleaner
__________________Ich fahre jetzt mit dem 2. Schritt fort. PS. Hätte nicht gedacht, dass ich doch überhaupt etwas habe, da ich doch im 2 Wochen Rhytmus immer versehentlich installiere Toolbars, Ad- und Junkware deinstalliere. Ich bin da auch sehr empfindlich - zu recht. EDIT: Schritt 2 angefügt (JRT log) EDIT2: FRST und Addition angefügt. So wie ich das verstanden habe: Der erste Scan ohne Addition. Der 2. Scan mit. adwCleaner Code:
ATTFilter # AdwCleaner v3.003 - Bericht erstellt am 14/09/2013 um 14:29:53 # Updated 07/09/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Martin - MARTIN-PC # Gestartet von : C:\Users\Martin\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : vToolbarUpdater14.2.0 ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\AVG Secure Search Ordner Gelöscht : C:\ProgramData\clsoft ltd Ordner Gelöscht : C:\ProgramData\Tarma Installer Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Program Files (x86)\SaveByClick Ordner Gelöscht : C:\Program Files (x86)\yourfiledownloader Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search Ordner Gelöscht : C:\Users\Martin\AppData\Local\AVG Secure Search Ordner Gelöscht : C:\Users\Martin\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\AVG Secure Search Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\DesktopIconForAmazon Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\OCS Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\peter\AppData\Local\AVG Secure Search Ordner Gelöscht : C:\Users\peter\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Gast\AppData\Local\AVG Secure Search Ordner Gelöscht : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Ordner Gelöscht : C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\foxydeal.sqlite Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\dvdvideosofttb-customized-web-search.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\MyStart Search.xml Datei Gelöscht : C:\Windows\System32\Tasks\YourFile Update ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}] Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\pricegong_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\pricegong_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SaveByClick_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SaveByClick_RASMANCS Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKCU\Software\1ClickDownload Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\AppDataLow\SProtector Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\Freeze.com Schlüssel Gelöscht : HKLM\Software\IB Updater Schlüssel Gelöscht : HKLM\Software\Iminent Schlüssel Gelöscht : HKLM\Software\SProtector Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\YourFileDownloader Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\IB Updater ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16686 -\\ Mozilla Firefox v22.0 (de) [ Datei : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\prefs.js ] Zeile gelöscht : user_pref("aol_toolbar.default.homepage.check", false); Zeile gelöscht : user_pref("aol_toolbar.default.search.check", false); Zeile gelöscht : user_pref("extensions.50f8330bd00a9.scode", "(function(){try{if('aol.com,mail.google.com,mystart.incredibar.com,premiumreports.info,search.babylon.com,search.funmoods.com,search.gboxapp.com,search.swe[...] Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0); Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", ""); Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.enable", ""); [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\ycz3dw5p.default\prefs.js ] -\\ Google Chrome v29.0.1547.66 [ Datei : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\preferences ] [ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [13497 octets] - [14/09/2013 14:28:02] AdwCleaner[S0].txt - [12811 octets] - [14/09/2013 14:29:53] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12872 octets] ########## JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.0 (09.12.2013:1) OS: Windows 7 Home Premium x64 Ran by Martin on 14.09.2013 at 14:36:51,39 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2693577240-4054724306-2718763821-1000\Software\IB Updater Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{007514C1-CF2F-42F5-AF79-7B06174F2B50} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{01336BB6-6817-45B0-B480-3B2989DBF795} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{014848DB-2A0A-4B5E-841F-4212EDF5E696} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0191940E-0589-46DB-8258-37E4CAC7E26A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{03B028EF-DAEA-413F-AF68-CCD480D04DFD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{03B799C1-2DE5-4874-A19D-D8F326582F9D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{057E767B-F939-4D79-9895-F6E7FE5568C6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{05F8028A-E499-4373-850F-D1E8010ABEB5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{080D123E-94CE-403C-BE7C-3AAA29493EAA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0823A8DB-48FB-4BE0-940B-79657C7E360D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0933AF80-0860-488F-A36E-95881F464374} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0AFF24F5-5FA5-44E0-BB48-A0E8F1667904} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0B801B68-FF6B-491C-B10E-932C47204319} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0CC7B070-9B94-4DE8-8A5B-4D10F1207C70} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0D90DE5B-188A-4FC8-8CFB-8B841C045BB6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{101A7CBC-D0AA-4630-A4DF-A877BFE8D26A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{10A280EB-98C1-404E-B98C-075D7DA89B50} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1263A41E-D9D6-4BB0-BBCD-AF9060C0F2D9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{127E72F5-45E9-4C28-B249-A0A281851360} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{14D2F9C5-EA5C-491C-B1AE-20B661726D91} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{152C38B8-07A0-441F-B755-504F762C13FD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{166E1F94-CAF1-4740-9FB2-7E494889C849} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{16797D61-BA96-4FE4-AF59-AE664C0B90F2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{173D0BB6-2529-48CA-AED1-01C45D02F925} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{17491D08-6A45-4921-99B5-D4A9ED74F298} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{17725ABA-8887-49BF-8DCE-847FEB044D55} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1926413D-5ACC-4D7E-85B4-7C86F0DAE356} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{192A84C7-71C8-4EF6-ACC5-8E4DEE758C6C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{193CF1FD-1698-45F2-8C76-A7F1BA64FD73} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1A9118C4-2ECB-4F74-82E2-D28742DABA44} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1AC4F2FA-620C-45EB-BAEE-DA3D4683031D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1CAD34F5-77FA-4B5B-BEF8-9FB131315045} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1CEC0CD5-343A-4CDB-915B-00CC9031290C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1D7F2C25-D338-4CDB-94F6-4E4B2765E4B3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1E57EF30-9B8A-43E2-90DB-3444483E58AA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{20928103-B0A4-4CB6-8B06-E1E54A60516D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{21118B1F-99CD-4FEC-B506-D3E2655CCA17} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{21723471-98EA-497C-BB8C-369ED57D286E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{222EF7BB-34C3-406F-B059-ED4525A5D187} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{22F3ACFB-E70D-4E55-A441-47A85291F3F9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{24B5B0A6-EC84-4D84-8611-028A9DAFE337} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{24C2771F-9FAB-47C8-8A6F-0CE10E199CE2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{25104E44-DB6A-498D-AF57-04A69F7ADB7C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{25C9BC0E-8CB1-4CD5-A08C-F6C51AD5AE31} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{280546C0-B588-4D5B-8587-6D5075704D50} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{28C29B8E-8365-47A4-AA82-FC02D3705B19} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2B3629FA-765C-4A2A-98E1-71A3B1600AAD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2B7B68A5-16C1-482B-A771-2DF18292F781} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2BA74EAF-9DE0-4522-8716-D7655FA90271} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2BE2667F-32C3-4AF9-B05F-07D284D477F1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2C0191E9-5DF7-4315-88CD-F29A294D366B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2CBC29C1-EF8E-4199-883B-34C4034CACC7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2CDC0001-59ED-411D-8B36-80E6F286B3A5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2DAC2578-567A-4EB1-8A6E-50D7084051A3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2DF2FA98-C57D-4828-826D-631ED5B564D5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2F99D82F-B337-4648-BDBD-8F230EF1761A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{305F7188-423B-4A71-8CB1-2735A83F791A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3072C3D4-859E-4162-88B3-6B29A524CA43} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3138B0B3-7133-4A9F-B809-5F967594E1A6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{316A9DC4-44DA-4DC6-9A22-03141C5EA658} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{317EFC06-9840-4225-995E-CD55422B3A0A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{32E97DDE-923A-447C-B77F-49F0D425F6F7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{33193A6D-D047-4D55-81C6-2A0EC37DA837} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{33AA1080-A3A6-4921-8224-29635AF374C7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3470968E-D346-490F-8908-AB384CCD5BC3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{34DC9100-55A3-4026-A53E-DC226BC2B448} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{37386CBE-3767-415C-A584-28E058041DA5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{39E2010F-E69F-4119-8F06-2A6DFBBF97C5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3A21844E-D2EE-41B3-B091-2EB01F080AFD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3A241B9F-29AC-42B4-8096-63CAC58EDF27} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3A33C5FC-F12E-4021-9275-8C01FBA0973E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3BDCA147-9F3D-4131-B42A-E9116DECA8D1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3C4C6897-BCCB-4DC3-B2BE-79055C290CDE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3C9B35D1-1A53-46EB-82BA-A3ACEDA86DC8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3DAFBF46-72E2-47C7-8E13-322AB46843B0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3EE620B7-F84C-4B1F-9532-EA893BF6C454} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3FECC427-4A99-4160-93CC-97646DD446C6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{418978C4-9921-4EC3-ABB3-E7DED435336A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{420C606F-1F46-46EC-87E7-40943285A599} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{42C0764C-720A-4604-8D35-DD0359B9676A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{440408AA-FB96-4845-9095-C697E8ADD260} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4446C1D9-5337-4DB1-A1E5-95CE6C34240B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4492450F-12DE-449C-8B74-2827A2FD95B2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{44FB87A9-F8D2-49A2-AF0C-FC53BCEA334A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{48070662-E26F-4570-A605-A33F24C7B656} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4826F86B-CA2F-4FF5-9CA8-D0D12DE03D80} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{48357ED5-E75F-4102-B24E-243BC5A4B79D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{49332D29-DE67-4417-B148-6E2EA4D295CB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{493467A8-6CF0-43E7-A29C-B741BCF0E065} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4D1CD743-772D-488F-89DE-E93CEF1B7524} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4D264D0E-78D3-4A84-AA28-0A3DD4624090} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4E56CE6A-367E-417E-A2DB-B7F52B65B84C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4E6B2992-1CF3-457F-872C-42AB5393F3F8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{50E39AE0-E6BA-4CEB-8FA1-50E02A8BD5C8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{511CF6B5-724C-495C-BAAD-A7D49777B1BB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{52EA3EDC-1E4A-4166-88A8-854E992E1371} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{53A353CC-E353-44A6-A0FA-624DAA386ABB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{53EF9505-2358-478A-8545-3846320755D1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{547F1A5C-DEEA-4B9D-BDD3-0C64A99F0F54} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{54910B26-2CE5-4F27-AFC5-76DD2C12D1AF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5698C46A-829D-49EF-B035-40DA0B1475A1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{56FF3163-1C7C-4010-8C99-CBB98795E3B3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5772E199-9288-42F6-9A38-0D10E047FF92} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{59308797-0F9B-4ADE-B950-2B77E4E1D1F8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5A14C411-0773-4090-AAF2-B37379B24EDF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5B2FA27C-3BF8-4DBE-BCDF-09E6B0EF0DDC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5B87D8D8-FCDA-48B5-AB11-F0EC282747C1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5DAE8C61-822C-4F95-B5B4-E98F0C3948BA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5E4DE98F-4E71-4007-B661-A887C130E7D4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{61257E3B-C9E8-44C5-B6BE-F75E04B4867C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{61D9AC9F-57E0-468A-ADDD-B643829F042B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{63637885-DE31-4905-AB76-0DC4B14A4EE2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{63CB997A-1A6F-47B0-A25E-A9C1501FECCD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{64A3A57B-E341-4BBD-883D-D6C8E8DAFEA9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{64D24686-B5B8-43C7-AC78-2756055F1B09} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{64E54AC0-6C85-425B-BF53-1C992BD1FC05} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{667FD4F4-F468-4FE9-9344-8A1B29567D56} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{66BBBB1D-F0FE-4377-911F-E1B2F6D57FA9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{673B0A85-F338-4680-8C25-E42CF5BA0800} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{67F3200A-A31A-42CF-B592-6FCEFCE0A24E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{69427788-1DB3-437C-A447-11361A0B7AF3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{69E7AE3A-7870-4EA8-9113-C884E31A24D6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6A3AD3DF-E85E-4BF1-A64F-768B48AF57E3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6BC3B2AC-EFD3-4029-9CE4-6A7564786B55} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6C51B6A0-93B8-45CD-BF2F-E53ADB98368B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6C7E27E6-CEB8-4079-9AFC-3480DE18AE75} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6C9C1996-5019-4824-850B-7682389D5456} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6CD039A1-6B6D-466C-9517-98F84C8EF3D6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6D20BA87-F39B-40E7-AAA1-EEE25B20CB18} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6F35E730-3C78-4612-969F-873753F58832} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6F928245-82DB-49A6-9477-28CE27447545} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6FDFB22D-8F2C-471F-8D76-BEDDF10D22A5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7033E5D6-5441-41EA-9735-7CA10A3AB1BA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{70B3488D-572C-4578-BAB8-DCD533DA6126} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{71DC88F9-6D62-42FB-A875-5FD9C6B26CF3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{72A7D85F-A63E-4CF7-8E5C-9A0242240C5D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{731B3FDE-23E4-4B0E-A0F4-32B163BB942F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7437E6C3-CF07-4FCA-B5D9-B81CF58054C4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{743A393F-A3E8-4280-AB91-129F987BAB99} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{743DDAA5-5D02-40A2-BB46-4F42654F7070} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7469FB06-00EA-4BB6-9806-C49E424229A7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{754F8C81-B309-40B0-B864-60AB54645560} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7689FC07-723A-4CE4-A3C8-B555C72F1DAB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{76A5720B-8FF3-4F14-9B09-DED85D6E9614} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{77380083-0669-466A-82C6-B01C2632E641} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{778C0690-EDD4-4D48-A6DC-37E4237570D1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{78B6C365-0A5F-45F9-9C34-302BCD8F0732} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{78C2D2E8-91C9-418F-9CEE-20A61368E082} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{78E32E7E-0A41-47A4-925C-F9F92FE50598} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{799072B2-22FC-4295-AAA3-B4F52DF2D8D5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{79DA3497-7E0C-42D5-AF15-91C78CF26A6E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7A30BDE7-9290-4437-9202-0B3EA386D82C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7ADC2360-5332-4914-9457-C18C2DA0A25D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7AFFE3B4-9DC0-4E36-B97C-8B38D29D5768} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7B0A04BB-7223-4468-B900-BAA49EC8554E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7B32E4C0-F340-4209-BDEC-61CEB4A40C8F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7B86EB30-74BB-43A5-91FF-ADEA62748561} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7D8C392C-897E-403E-A99A-A4CAF5E48CB4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7DA71067-4D39-47A0-A32F-6A77D6924C9E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7EECF208-53DC-4BFC-A5F9-842E2FB2A8A2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7FA8B135-89F4-4CD7-A488-AD7F1B390922} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{802E1176-4505-4E0A-BAFE-B7D0D62630B7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{80752689-95A0-412F-9E90-1462DF0750F3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{807575B9-6FF4-4330-93E0-7C1CF740DAD2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{818881A1-B871-42BF-9B52-2587BBFB55EF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{81BAFC0B-826B-467D-860F-821C946A6764} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8282606C-2023-46BD-839E-1BD7344CAF5D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8441BD98-563F-44E3-B90F-AA1C05A3AAEC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8552DFAB-77D1-4606-8D1D-5C1D7F072584} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8590D25E-D080-4370-B486-6E11091A2FC0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{862121E6-7F6C-42C2-BB21-5317E1A4236C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{865479D2-EFE4-4FF4-8D4A-A0FFF3E6BC4F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8693167E-5539-45FD-B159-E8AAA0C8DDB7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{86A0E091-22E3-49BE-AC1B-7D8BA7B18651} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{86BA38D8-3B89-4973-AC08-62BBD43C371F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{86BD3A04-AC8D-44E4-ADCB-9BAB3C74C7DE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{873AE25A-C0B4-4B50-BAA6-67C983F42BAB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{874630DA-DF79-427B-9F39-16CBCF48C638} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8868A681-1951-449A-8F3F-9FF474C3DC00} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{89551F30-500F-4F6C-969A-E604DB8F8D32} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{89E18ADD-6B0A-4E81-BE90-E6F7E80584B2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8A2BE4B5-6146-4CF0-93AA-2AE64EC269F5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8A2CDAB4-1D8A-4E80-9A00-1230AE0379D2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8C46F6D5-3440-4BC4-BCF2-65D55477073D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8C67F221-BC0B-488D-BF7D-6765757B5F37} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8D04E32B-1781-418B-8996-290C55F03AAC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8E57FD6D-392E-4A1A-9EC4-315B1AC54C65} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{90097D8C-1914-4B84-9F18-55CCF7B81AE7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9024CE5E-859E-4C2D-83EE-E69175E27179} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{90D438EE-0798-4C8F-BB55-38F0E0196CAF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{90E4FC1A-C12E-4485-8C15-31ED09C3BCB5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{919DFFF1-1EC8-489F-8E50-6F8995A93B39} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{920B73E4-D796-4104-945A-B3B67979CCA0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{92B58CA9-46A6-45C0-AB3D-0B0BB6B640D9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9359A427-AEF1-4A5E-9EC3-96DDB32B36C7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{945FDB8F-66BD-44F0-B23C-2A23DAAAA1BC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{964F2FDA-248A-4C65-8B22-CD5CD246273F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9665CF56-4581-4302-A5A6-FF7D36ED6DC4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{97CF40E1-47F0-4EB3-A898-C6C8B419BD2A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{99D55FE7-CA82-4DC4-A617-71B55584CFAC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9BC0014E-2B4C-4EF5-94FB-9858E514D0F2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9C7F711F-B3AE-4850-BA96-FE9E5C3DF780} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9E60A3FE-87A0-45A4-87B3-DC771B92F6A1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9F1983F9-B5D3-446A-9B23-CB4510E2AFF4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9FDB19C1-8F01-41D3-B17D-0E82B40723C9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A00EFCBC-3318-4720-ABB1-447CC6B88BCD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A02C75E2-E7B7-4666-886C-93DA85A8074F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A089BA03-5F02-4055-ADDD-814EF047B7FF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A26ABA58-E065-4203-804B-9DA9A9D77D6D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A2E6685E-8422-43B6-8D91-CB3E73293452} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A2FA2EF9-7EC1-48E6-8084-581D99A0CC3D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A635738E-E27F-400A-8E41-CCA61A5CA0AF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A78CAB0A-4CBA-4A89-85E7-7ABC8DA72885} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A92844B3-5356-4C27-981C-F0D01A870F52} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AA8756A4-1904-44BF-B008-518152706FED} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ABBA96C4-1DFE-4A70-9981-47909FFB6264} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AD7FDEBC-FB9E-47E7-893B-3B254AAA6DDB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ADD67239-A3F7-4A4D-AFC8-FAC0CF1885B3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AE34875F-36D6-4BD5-B7B9-950AF85BF134} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B094C018-61AB-46FF-9F0D-8D7237A14703} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B13EE301-D690-4A96-8035-D06B2E9BD6D6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B23BBAE5-7737-43C0-BE18-4A301E9406E9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B2840901-B8F6-414C-8CD1-E4D3C2C9054B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B2D53F59-30C5-45BC-8598-921105DB4AF3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B3AA25D4-3C9E-467E-9E3C-7B0751F3DCBB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B3AB2B45-1634-4CCF-B772-3F984289E19D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B4181CCD-E1D1-4B01-AC1E-0963D3262255} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B4825576-CACB-4831-B5F0-9DEC0B71200E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B575DB12-5FCD-4911-B63E-8221DB56D123} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B5B64CD5-A2E4-4655-8C6B-FEA94A3DED7E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B5C1A9C2-2BCE-4CEE-8D60-B2D379C4E3D3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B86161B3-92CD-411C-8BD4-07879EE8DD3B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B87F8153-C5AD-4747-BD5C-347ED53A6859} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B90B0A0B-0823-45F2-A8B7-32CF40AC0E1A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BA0F9FFB-BF1C-4B9C-8625-CE3306D1BCD7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BA3D28E9-BA67-4DA3-888B-ABAD915991CA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BB4BAA68-FCA0-416A-B07A-F02F8278FE58} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BDFBA279-DF7F-4962-8360-332682D2F9DD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BE41053B-BD44-477A-8E4C-6280400528BB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BFC4D225-2816-41FE-A0EF-50F17D0575D4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C09B9B3B-E981-4706-9536-98BCFD3337CE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C17EB97D-2F16-4FAD-8172-57FD3000CEAF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C227519D-8192-4906-8060-6FFB9699479F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C242C181-72FE-4F4A-8B9A-281A30AB8832} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C26FE812-5177-4594-8EA6-986BFAF3D7F5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C2BB7E5D-3955-4EB8-9A1F-829A39EAD466} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C48C55B7-6CFF-43D1-86EC-8CC3D7CFF9E4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C48F9465-F1A1-450F-9441-A89F0001ACAD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C6513041-292C-4C93-8238-D514B583C947} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C92E3466-B9D5-490C-8AC1-45DFFAD40F4A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CB7EFD0F-84A1-40A2-83E5-89323FB46F1C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CB9FAF99-9008-4745-9930-5C69EA648AE7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CD762C26-EBEF-4873-8F9E-B1182C8E2CDD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CEDCC92A-BAE1-4A72-A7ED-5F706F4DFF1A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CF8860F7-8828-40ED-83CB-065A2DCF0E56} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CFAA3BA4-B17E-45C6-8897-E4B922FA98A0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D0644D74-B74C-454E-8BE1-32FD83C864F4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D072FF9F-2F2F-4F4B-B0F3-B9DEA81EAAAA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D0D622FF-3C0F-4127-9B28-3E52E746FB3E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D1ACA81F-194B-4679-BC21-ECF8DE9F53F0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D1B34833-D5D0-46DF-9578-A56A6F4289C2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D21062CA-9EE3-479E-A8F9-7930EB7EACCD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D27E9A2E-C4A7-4CCA-B7A6-941752624D68} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D4069F3D-B771-4DEB-87DE-8DEC95E590BE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D40A94EC-28D6-4C11-B151-B0555EB7559B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D65FC3FF-510F-41A9-A041-40C9F88C4DCB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D66B128B-B079-464B-81CF-A659D18FB5F9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D7634E6F-7576-4ABC-A34C-ED44ED774FA0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D7E6A0E4-1464-482F-8796-D1BCD7DDEF1A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D85546F5-B114-4F84-B524-407834B2D4DD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D940A926-AC64-4A13-8620-D4A31FA685AE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D94FF2E8-9FFB-484C-96F5-C5FBA3D17581} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D97B2DAD-F5E4-4575-96C3-F45391FBB08B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D982F3F8-AE96-4D99-90F0-CE4C4E041216} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DA56594F-2795-4347-AB5F-0D2E4C6FC98C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DA7C3098-4454-40CF-B39C-C3C293C818D5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DA8B5741-172E-41A2-B14F-395764323195} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DA9A8649-AD23-4DE2-951E-A7E8A5828F01} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DACF38EB-44E6-4C2F-8FA4-539F01BAB87A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DB114662-6FEA-4D46-A1A0-52741E528CF0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DB4AB962-23EE-4093-92BA-59E57E4E6160} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DC0426A1-9878-419E-A781-B71573C3C52A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DC0B484C-0420-43E6-BC09-818B25D8CC89} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DC6E5D68-3172-466F-A9A7-8A1C50E2E570} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DD467B0C-2050-448C-BE6F-ABAC5BD69166} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DD84C793-E896-4CC7-A991-C5FA3D283A86} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DFA06D61-EE84-4FA7-8ADD-405163412623} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DFADB0A1-32D5-44E7-94A8-44846909F6EF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DFADB9E2-A31D-4D0C-8925-D403B8B879DD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DFD87DF6-7B41-41DC-B4A6-40CABB969C67} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DFDC05A4-65CB-4548-ABCB-67317C3769CB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E06C5F15-D3AB-484E-B1AC-0C00E9FFB520} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E1757B5F-B419-4D84-8B46-DD53B6039D9E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E1B87E6D-50A0-4B20-B1BA-2C337E13E1CE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E1D64D71-B36C-40C3-85AD-493AB99BE498} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E22CC147-E078-4CF9-BE39-D0378938110D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E22E0F7E-5DB1-4905-A7C8-E5BD7DFF3134} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E268EEE3-E68D-4688-A6F4-9A95A37294A8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E2A1BE6B-8308-4917-B915-111C981DB7F7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E333578E-8B4B-481F-99E1-8AAED5FEBC29} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E574C137-BC34-4805-91EC-7523F9402B06} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E7C59F08-EFAB-48C3-801D-B9DDE47F2B55} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E835684E-59A3-4FB7-B23B-48B9E54451B4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E9DF022D-F162-42EA-904D-3C9DBFA451EE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EA1AD5DD-6A6E-464A-9B4A-32F39101EB6E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EA437F15-0C9A-4BF4-B6C8-FF13DA5FE4FB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EAFF9D42-8B86-4B1B-9E4F-5FD0093DA72D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EBDF9B85-AB05-4E5F-99A6-85F01652A875} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EC17FB96-90BE-42AC-9454-1684A4AE3720} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ED1A5E02-5245-4E20-9DFE-CB5E14C25086} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ED5777EE-2EAC-4EC8-9A00-787CF91EA81A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EDDC184C-A70D-42CD-BDA7-0DBFC2C74A9E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EE0DAEA2-651D-4AD6-AA02-20DF07BDBA38} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EE1EB84D-EBFD-4E4E-86BE-D8887619A423} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EF470A59-B79D-4815-BAE3-6D8F5DCCFB5A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F159CBB8-C57D-44BF-8D4F-EAB7BFF11A20} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F17E13D9-0A95-42D2-85C7-0DECEFBC8B58} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F22ECB69-D19D-44DC-9B97-FD7D41F6362B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F254CB22-846B-4C7B-A586-9DC638EC5D5E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F25C26A8-0031-4971-8081-A8E0DEDD5066} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F2CBF9E5-8034-4747-9D6E-4D9EF7948C9B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F40665E4-A22D-4362-BC45-E078F491185B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F42DFE02-4ADB-494E-B22D-C961DD48A79E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F47DE224-88DD-464D-9403-2232EDBE6A72} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F576D108-506E-4317-957A-CFBF03129D6C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F8450308-E6EC-4FF1-95B9-94749165208E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F945C100-020E-4B7D-AADB-710EDC8B93B9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FAF22CA3-9DFA-4945-8C4C-0B0CC6AA8196} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FBB94A45-C88F-4D59-985D-E1876D9783EA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FEB7EFB1-5574-463A-A989-F2C61ABE3110} ~~~ FireFox Emptied folder: C:\Users\Martin\AppData\Roaming\mozilla\firefox\profiles\1m26ja9g.default\minidumps [170 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 14.09.2013 at 14:43:11,22 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST (1. Scan, ohne Addition) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-09-2013 04 Ran by Martin (administrator) on MARTIN-PC on 14-09-2013 14:51:18 Running from C:\Users\Martin\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Softwareentwicklung Remus - ArchiCrypt) C:\Program Files (x86)\ArchiCrypt\ArchiCrypt Shredder 6\ArchiCryptInjector64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\system32\inetsrv\inetinfo.exe (Microsoft Corporation) C:\Windows\system32\mqsvc.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\system32\mqtgsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CmPCIaudio] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd HKLM\...\Run: [itype] - c:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2011-08-10] (Microsoft Corporation) HKLM\...\Run: [MsmqIntCert] - regsvr32 /s mqrt.dll HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKCU\...\Run: [ccleaner] - C:\Program Files\CCleaner\CCleaner64.exe [5435744 2012-10-24] (Piriform Ltd) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-15] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.) Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: autocheck autochk * SmartDefragBootTime.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:tabs HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8074082B6BB7CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default FF NewTab: google.de FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\icq.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\rising-gods.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\ich@maltegoetz.de FF Extension: DownloadHelper - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: firebug - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: google - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\google@hitachi.com.xpi FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll No File CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (ProxTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (Angry Birds) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0 CHR Extension: (Google Docs) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Adblock Plus) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0 CHR Extension: (Google Search) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Search by Image (by Google)) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm\1.5.0_0 CHR Extension: (Webcam Toy) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade\1.5_0 CHR Extension: (Google Maps) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.7_1 CHR Extension: (Search Box) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mknehpjhljpfaghmicofickbkdagooni\1.0_0 CHR Extension: (Plants vs Zombies) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina\1.0.5_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR HKLM-x32\...\Chrome\Extension: [dkinklhnkmkhkhofcnapakaoehijaoih] - C:\Program Files (x86)\OnlineHD.TV\onhd11.crx ==================== Services (Whitelisted) ================= R2 ArchiCrypt Sichere Loeschzonen; C:\Program Files (x86)\ArchiCrypt\ArchiCrypt Shredder 6\ArchiCryptInjector64.exe [313408 2012-05-15] (Softwareentwicklung Remus - ArchiCrypt) S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3128856 2012-02-28] (devolo AG) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation) S3 MatSvc; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [343856 2011-06-13] (Microsoft Corporation) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-20] (Microsoft Corporation) S4 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [836904 2007-08-08] (Nero AG) S4 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-08-03] (Nero AG) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-31] () S3 TuneUp.Defrag; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [607048 2013-02-09] (TuneUp Software) R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [39768 2013-02-18] (AVG Technologies) R3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1154560 2009-05-19] (C-Media Inc) S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2010-06-10] (CACE Technologies) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] () R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 athur; system32\DRIVERS\athurx.sys [x] S3 BTCFilterService; system32\DRIVERS\motfilt.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-05] (Microsoft Corporation) S3 motandroidusb; System32\Drivers\motoandroid.sys [x] S3 motccgp; system32\DRIVERS\motccgp.sys [x] S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [x] S3 MotDev; system32\DRIVERS\motodrv.sys [x] S3 motmodem; system32\DRIVERS\motmodem.sys [x] S3 MotoSwitchService; system32\DRIVERS\motswch.sys [x] S3 Motousbnet; system32\DRIVERS\Motousbnet.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2099-01-13 00:05 - 2013-07-30 22:06 - 00000000 ____D C:\Users\Martin\AppData\Roaming\ICQ 2099-01-13 00:05 - 2012-05-13 11:12 - 00003248 _____ C:\Windows\System32\Tasks\SidebarExecute 2099-01-13 00:04 - 2013-01-02 15:59 - 00000000 ____D C:\Program Files (x86)\AVG 2099-01-13 00:02 - 2099-01-13 00:06 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\Users\Martin\AppData\Local\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\ProgramData\Mozilla 2099-01-13 00:02 - 2013-07-08 11:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2099-01-12 23:58 - 2013-09-14 13:32 - 00000000 ____D C:\ProgramData\MFAData 2099-01-12 23:49 - 2011-03-23 04:20 - 00077936 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\L1C62x64.sys 2099-01-12 23:48 - 2099-01-12 23:48 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e 2099-01-12 23:48 - 2013-06-10 18:16 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2099-01-12 23:46 - 2099-01-12 23:46 - 00000000 ____D C:\Program Files (x86)\Intel 2099-01-12 23:46 - 2009-08-18 07:44 - 00053248 ____R (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2099-01-12 23:40 - 2013-03-19 19:06 - 00001425 _____ C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2099-01-12 23:39 - 2099-01-12 23:39 - 00000020 ___SH C:\Users\Martin\ntuser.ini 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Favoriten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Dokumente 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Users\Martin\AppData\Local\VirtualStore 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Recovery 2099-01-12 23:39 - 2013-09-12 12:32 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2099-01-12 23:39 - 2013-07-07 16:56 - 00000000 ____D C:\Users\Martin 2099-01-12 23:39 - 2009-07-14 06:54 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2099-01-12 23:39 - 2009-07-14 06:49 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2099-01-04 14:40 - 2013-09-12 12:34 - 00000000 ____D C:\Windows\Panther 2099-01-04 14:32 - 2013-03-20 20:07 - 00000000 ____D C:\Windows.old 2013-09-14 14:51 - 2013-09-14 14:51 - 01950312 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe 2013-09-14 14:43 - 2013-09-14 14:43 - 00036444 _____ C:\Users\Martin\Desktop\JRT.txt 2013-09-14 14:36 - 2013-09-14 14:36 - 00000000 ____D C:\Windows\ERUNT 2013-09-14 14:34 - 2013-09-14 14:35 - 00016310 _____ C:\Windows\WindowsUpdate.log 2013-09-14 14:27 - 2013-09-14 14:30 - 00000000 ____D C:\AdwCleaner 2013-09-14 14:26 - 2013-09-14 14:26 - 01037278 _____ C:\Users\Martin\Desktop\adwcleaner.exe 2013-09-14 14:26 - 2013-09-14 14:26 - 01029509 _____ (Thisisu) C:\Users\Martin\Desktop\JRT.exe 2013-09-14 13:41 - 2013-09-14 14:02 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-14 13:37 - 2013-09-14 13:37 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Martin\Downloads\tdsskiller (1).exe 2013-09-12 18:09 - 2013-09-12 18:09 - 00000000 ____D C:\Users\Gast\Documents\TrackMania 2013-09-11 23:48 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 23:48 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 23:48 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 23:48 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 23:48 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 23:48 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 23:48 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 23:48 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 23:48 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 23:48 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 23:48 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 23:48 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 12:14 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 12:14 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 12:14 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 12:14 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 12:14 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 12:14 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 12:14 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 12:14 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 12:14 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 12:14 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 12:14 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 12:14 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 12:14 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 12:14 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 12:14 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 12:14 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 12:14 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 12:13 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 12:13 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 12:13 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 12:13 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 12:13 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 12:13 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 12:13 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 12:13 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 12:13 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 12:13 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-09 21:08 - 2013-09-09 21:08 - 18929080 _____ C:\Users\Martin\Desktop\b39 schrottplatz.psd 2013-09-09 19:50 - 2013-09-09 19:50 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-09-09 19:48 - 2013-09-09 19:48 - 00784840 _____ (Google Inc.) C:\Users\Martin\Downloads\GoogleEarthSetup.exe 2013-09-09 18:12 - 2013-09-09 18:12 - 00000000 ____D C:\Users\Martin\Desktop\Standalone_Neustadt_a_d_Weinstrasse 2013-09-09 18:05 - 2013-09-09 18:11 - 276437684 _____ C:\Users\Martin\Downloads\Standalone_Neustadt_a_d_Weinstrasse.rar 2013-09-09 16:54 - 2013-09-09 18:12 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-09-09 16:52 - 2013-09-09 17:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Overwolf 2013-09-08 23:46 - 2013-09-08 23:46 - 00027448 _____ C:\ComboFix.txt 2013-09-08 23:35 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-08 23:35 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-08 23:35 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-08 23:31 - 2013-09-08 23:46 - 00000000 ____D C:\Qoobox 2013-09-08 23:30 - 2013-09-08 23:44 - 00000000 ____D C:\Windows\erdnt 2013-09-08 23:01 - 2013-09-08 23:06 - 00066173 _____ C:\Users\Martin\Downloads\FRST.txt 2013-09-08 23:01 - 2013-09-08 23:05 - 00040367 _____ C:\Users\Martin\Downloads\Addition.txt 2013-09-08 23:00 - 2013-09-08 23:00 - 00000000 ____D C:\FRST 2013-09-08 21:55 - 2013-09-08 21:55 - 00628221 _____ C:\Users\Martin\Desktop\firewall.rar 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:14 - 2013-09-08 21:14 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-09-08 21:13 - 2013-09-08 21:13 - 04009167 _____ C:\Users\Martin\Downloads\ServicesRepair.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00358609 _____ (Farbar) C:\Users\Martin\Downloads\FSS.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00003606 _____ C:\Users\Martin\Downloads\FSS.txt 2013-09-08 20:29 - 2013-09-08 20:29 - 00000000 ____D C:\Users\Martin\AppData\Local\FixItCenter 2013-09-08 20:24 - 2013-09-08 20:24 - 04334752 _____ (Systweak Inc ) C:\Users\Martin\Downloads\rcpsetup_2005.exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (2).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (1).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00000931 _____ C:\Users\Public\Desktop\Microsoft Fix*it Center.lnk 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Windows\MATS 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Program Files\Microsoft Fix it Center 2013-09-08 20:18 - 2013-09-08 20:18 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run.exe 2013-09-08 20:06 - 2013-09-08 20:06 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.2.Run.exe 2013-09-08 20:05 - 2013-09-08 20:05 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.1.Run.exe 2013-09-05 01:43 - 2013-09-05 01:43 - 00045880 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2013-09-04 17:25 - 2013-09-04 17:25 - 00001367 _____ C:\Users\Martin\Downloads\project1 (1).lpr 2013-09-04 15:40 - 2013-09-04 15:40 - 00000000 ____D C:\Users\Martin\Downloads\backup 2013-09-04 15:30 - 2013-09-04 15:40 - 00001483 _____ C:\Users\Martin\Downloads\project1.lpr 2013-09-03 21:12 - 2013-09-03 21:12 - 00000000 ____D C:\Users\Martin\AppData\Local\Steppschuh 2013-09-03 16:22 - 2013-09-03 16:22 - 00000000 ____D C:\Program Files (x86)\Remote Control Server 2013-09-03 16:21 - 2013-09-03 16:21 - 02364793 _____ (Steppschuh) C:\Users\Martin\Downloads\RemoteControlServerSetup.exe 2013-09-03 13:43 - 2013-09-03 13:54 - 00090867 _____ C:\Users\Martin\Downloads\crt-120.zip 2013-09-02 23:14 - 2013-09-02 23:14 - 00021648 _____ C:\Users\Martin\Downloads\Summe.7z 2013-09-02 20:10 - 2013-09-02 20:10 - 00000988 _____ C:\Users\Martin\Desktop\Delphi 6.lnk 2013-09-02 20:08 - 2013-09-02 20:08 - 00000000 ____D C:\Program Files (x86)\Borland 2013-09-01 17:13 - 2013-09-01 17:17 - 00000000 ____D C:\Users\Martin\Desktop\catalys control center 2013-08-31 21:23 - 2013-08-31 21:23 - 00000000 ____D C:\Users\Martin\Desktop\Delphi 2013-08-31 15:13 - 2013-08-31 15:13 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-31 15:13 - 2013-08-31 15:13 - 00000000 ____D C:\Program Files\Java 2013-08-31 15:11 - 2013-08-31 15:12 - 33150376 _____ (Oracle Corporation) C:\Users\Martin\Downloads\jre-7u25-windows-x64.exe 2013-08-31 14:32 - 2013-08-31 14:32 - 00000000 ____D C:\Users\Martin\AppData\Local\PunkBuster 2013-08-31 14:31 - 2013-09-13 20:37 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-08-31 14:31 - 2013-09-12 16:53 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-08-31 14:30 - 2013-08-31 14:30 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (2).exe 2013-08-29 22:00 - 2013-09-01 13:24 - 00000000 ____D C:\Users\Martin\Desktop\venice beach 2013-08-29 17:30 - 2013-08-29 17:21 - 00840264 _____ C:\Windows\SysWOW64\pbsvc.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (1).exe 2013-08-29 17:21 - 2013-08-29 17:21 - 02211840 _____ C:\Users\Martin\Downloads\pbsetup.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 00840264 _____ C:\Users\Martin\Downloads\pbsvc.exe 2013-08-29 17:16 - 2013-08-29 17:17 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp.exe 2013-08-29 13:21 - 2013-09-08 21:54 - 00000000 ____D C:\Users\Martin\Desktop\cod 2013-08-22 19:22 - 2013-08-22 19:22 - 00000000 ____D C:\Users\Martin\Desktop\players 2013-08-22 19:18 - 2013-08-22 19:19 - 06343274 _____ C:\Users\Martin\Downloads\Fix.rar 2013-08-22 17:04 - 2013-08-22 17:04 - 00000000 ____D C:\ProgramData\ATI 2013-08-22 17:03 - 2013-08-22 17:03 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-08-22 16:45 - 2013-08-22 16:45 - 00792704 _____ (AMD) C:\Users\Martin\Downloads\amddriverdownloader (1).exe 2013-08-22 16:37 - 2013-08-22 16:37 - 00262398 _____ C:\Users\Martin\Documents\ts3_clientui-win64-1375773286-2013-08-22 16_37_39.474090.dmp 2013-08-21 16:41 - 2013-08-29 22:23 - 00015587 _____ C:\Users\Martin\Desktop\stundenplan.ods 2013-08-19 12:59 - 2013-08-19 13:00 - 00005247 _____ C:\Users\Martin\Desktop\programmliste.html 2013-08-19 11:59 - 2013-08-19 11:59 - 00000012 _____ C:\Users\Martin\Desktop\breiter.txt ==================== One Month Modified Files and Folders ======= 2099-01-13 00:06 - 2099-01-13 00:02 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\Users\Martin\AppData\Local\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\ProgramData\Mozilla 2099-01-12 23:48 - 2099-01-12 23:48 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e 2099-01-12 23:48 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\restore 2099-01-12 23:46 - 2099-01-12 23:46 - 00000000 ____D C:\Program Files (x86)\Intel 2099-01-12 23:39 - 2099-01-12 23:39 - 00000020 ___SH C:\Users\Martin\ntuser.ini 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Favoriten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Dokumente 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Users\Martin\AppData\Local\VirtualStore 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Recovery 2099-01-12 23:39 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2099-01-12 23:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2099-01-04 14:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep 2099-01-04 14:40 - 2011-09-20 05:21 - 00008192 __RSH C:\BOOTSECT.BAK 2099-01-04 14:40 - 2009-07-14 07:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2099-01-04 14:40 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-09-14 14:51 - 2013-09-14 14:51 - 01950312 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe 2013-09-14 14:43 - 2013-09-14 14:43 - 00036444 _____ C:\Users\Martin\Desktop\JRT.txt 2013-09-14 14:39 - 2009-07-14 06:45 - 00018016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-14 14:39 - 2009-07-14 06:45 - 00018016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-14 14:36 - 2013-09-14 14:36 - 00000000 ____D C:\Windows\ERUNT 2013-09-14 14:35 - 2013-09-14 14:34 - 00016310 _____ C:\Windows\WindowsUpdate.log 2013-09-14 14:34 - 2012-05-13 10:15 - 00000000 ____D C:\Users\Martin\AppData\Roaming\TS3Client 2013-09-14 14:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\inetsrv 2013-09-14 14:32 - 2012-10-09 17:57 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-14 14:32 - 2012-05-13 11:08 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Dropbox 2013-09-14 14:32 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-14 14:30 - 2013-09-14 14:27 - 00000000 ____D C:\AdwCleaner 2013-09-14 14:26 - 2013-09-14 14:26 - 01037278 _____ C:\Users\Martin\Desktop\adwcleaner.exe 2013-09-14 14:26 - 2013-09-14 14:26 - 01029509 _____ (Thisisu) C:\Users\Martin\Desktop\JRT.exe 2013-09-14 14:24 - 2012-10-28 13:26 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-14 14:03 - 2012-10-09 17:57 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-14 14:02 - 2013-09-14 13:41 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-14 13:37 - 2013-09-14 13:37 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Martin\Downloads\tdsskiller (1).exe 2013-09-14 13:36 - 2012-05-13 10:50 - 00000000 ____D C:\Users\Martin\AppData\Local\Adobe 2013-09-14 13:32 - 2099-01-12 23:58 - 00000000 ____D C:\ProgramData\MFAData 2013-09-14 13:26 - 2012-05-13 20:52 - 00000000 ___RD C:\Users\Martin\Desktop\Dropbox 2013-09-13 21:30 - 2011-12-30 18:51 - 00000000 ____D C:\Call of Duty 4 - Modern Warfare 2013-09-13 20:37 - 2013-08-31 14:31 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-09-13 20:37 - 2012-06-28 15:40 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-09-13 18:24 - 2013-05-14 23:24 - 04751752 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-09-13 18:24 - 2012-10-28 13:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-13 18:24 - 2012-10-28 13:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-13 18:24 - 2012-10-28 13:26 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-13 08:19 - 2012-12-11 17:50 - 00000981 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-09-12 19:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-12 18:18 - 2012-09-11 17:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Microsoft Games 2013-09-12 18:09 - 2013-09-12 18:09 - 00000000 ____D C:\Users\Gast\Documents\TrackMania 2013-09-12 18:09 - 2012-08-31 17:26 - 00000000 ___RD C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 18:09 - 2012-08-31 17:26 - 00000000 ___RD C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 16:53 - 2013-08-31 14:31 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-09-12 12:34 - 2099-01-04 14:40 - 00000000 ____D C:\Windows\Panther 2013-09-12 12:33 - 2009-07-14 06:45 - 05030112 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 12:32 - 2099-01-12 23:39 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 12:32 - 2012-12-06 00:32 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-11 23:49 - 2012-11-22 21:11 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-11 23:46 - 2013-08-13 22:03 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:46 - 2012-07-20 15:07 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 15:02 - 2012-05-20 11:56 - 00000069 _____ C:\Windows\NeroDigital.ini 2013-09-10 16:16 - 2012-08-07 00:06 - 00000000 ____D C:\Users\Martin\AppData\Local\CrashDumps 2013-09-09 21:08 - 2013-09-09 21:08 - 18929080 _____ C:\Users\Martin\Desktop\b39 schrottplatz.psd 2013-09-09 20:19 - 2012-06-01 00:45 - 00001456 _____ C:\Users\Martin\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2013-09-09 19:50 - 2013-09-09 19:50 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-09-09 19:48 - 2013-09-09 19:48 - 00784840 _____ (Google Inc.) C:\Users\Martin\Downloads\GoogleEarthSetup.exe 2013-09-09 18:12 - 2013-09-09 18:12 - 00000000 ____D C:\Users\Martin\Desktop\Standalone_Neustadt_a_d_Weinstrasse 2013-09-09 18:12 - 2013-09-09 16:54 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-09-09 18:11 - 2013-09-09 18:05 - 276437684 _____ C:\Users\Martin\Downloads\Standalone_Neustadt_a_d_Weinstrasse.rar 2013-09-09 17:13 - 2013-09-09 16:52 - 00000000 ____D C:\Users\Martin\AppData\Local\Overwolf 2013-09-09 16:51 - 2012-05-13 10:05 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2013-09-08 23:46 - 2013-09-08 23:46 - 00027448 _____ C:\ComboFix.txt 2013-09-08 23:46 - 2013-09-08 23:31 - 00000000 ____D C:\Qoobox 2013-09-08 23:44 - 2013-09-08 23:30 - 00000000 ____D C:\Windows\erdnt 2013-09-08 23:44 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-08 23:06 - 2013-09-08 23:01 - 00066173 _____ C:\Users\Martin\Downloads\FRST.txt 2013-09-08 23:05 - 2013-09-08 23:01 - 00040367 _____ C:\Users\Martin\Downloads\Addition.txt 2013-09-08 23:00 - 2013-09-08 23:00 - 00000000 ____D C:\FRST 2013-09-08 22:00 - 2012-05-15 23:03 - 00007662 _____ C:\Users\Martin\AppData\Local\Resmon.ResmonCfg 2013-09-08 21:58 - 2012-12-01 13:36 - 00001709 _____ C:\Users\Martin\Desktop\nXs Nuketown.lnk 2013-09-08 21:55 - 2013-09-08 21:55 - 00628221 _____ C:\Users\Martin\Desktop\firewall.rar 2013-09-08 21:54 - 2013-08-29 13:21 - 00000000 ____D C:\Users\Martin\Desktop\cod 2013-09-08 21:34 - 2013-03-24 16:13 - 00000000 ____D C:\Users\Martin\AppData\Roaming\uTorrent 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:14 - 2013-09-08 21:14 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-09-08 21:13 - 2013-09-08 21:13 - 04009167 _____ C:\Users\Martin\Downloads\ServicesRepair.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00358609 _____ (Farbar) C:\Users\Martin\Downloads\FSS.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00003606 _____ C:\Users\Martin\Downloads\FSS.txt 2013-09-08 21:08 - 2013-08-02 15:22 - 00000000 ____D C:\Users\Martin\Desktop\S3 Mukke 2013-09-08 20:58 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-08 20:29 - 2013-09-08 20:29 - 00000000 ____D C:\Users\Martin\AppData\Local\FixItCenter 2013-09-08 20:24 - 2013-09-08 20:24 - 04334752 _____ (Systweak Inc ) C:\Users\Martin\Downloads\rcpsetup_2005.exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (2).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (1).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00000931 _____ C:\Users\Public\Desktop\Microsoft Fix*it Center.lnk 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Windows\MATS 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Program Files\Microsoft Fix it Center 2013-09-08 20:18 - 2013-09-08 20:18 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run.exe 2013-09-08 20:06 - 2013-09-08 20:06 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.2.Run.exe 2013-09-08 20:05 - 2013-09-08 20:05 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.1.Run.exe 2013-09-06 17:23 - 2013-07-07 16:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-05 01:43 - 2013-09-05 01:43 - 00045880 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2013-09-04 17:25 - 2013-09-04 17:25 - 00001367 _____ C:\Users\Martin\Downloads\project1 (1).lpr 2013-09-04 15:40 - 2013-09-04 15:40 - 00000000 ____D C:\Users\Martin\Downloads\backup 2013-09-04 15:40 - 2013-09-04 15:30 - 00001483 _____ C:\Users\Martin\Downloads\project1.lpr 2013-09-03 21:12 - 2013-09-03 21:12 - 00000000 ____D C:\Users\Martin\AppData\Local\Steppschuh 2013-09-03 16:22 - 2013-09-03 16:22 - 00000000 ____D C:\Program Files (x86)\Remote Control Server 2013-09-03 16:21 - 2013-09-03 16:21 - 02364793 _____ (Steppschuh) C:\Users\Martin\Downloads\RemoteControlServerSetup.exe 2013-09-03 16:21 - 2012-05-13 10:18 - 00000000 ____D C:\Users\Martin\AppData\Local\Downloaded Installations 2013-09-03 13:54 - 2013-09-03 13:43 - 00090867 _____ C:\Users\Martin\Downloads\crt-120.zip 2013-09-02 23:14 - 2013-09-02 23:14 - 00021648 _____ C:\Users\Martin\Downloads\Summe.7z 2013-09-02 20:10 - 2013-09-02 20:10 - 00000988 _____ C:\Users\Martin\Desktop\Delphi 6.lnk 2013-09-02 20:08 - 2013-09-02 20:08 - 00000000 ____D C:\Program Files (x86)\Borland 2013-09-01 17:17 - 2013-09-01 17:13 - 00000000 ____D C:\Users\Martin\Desktop\catalys control center 2013-09-01 13:24 - 2013-08-29 22:00 - 00000000 ____D C:\Users\Martin\Desktop\venice beach 2013-08-31 21:23 - 2013-08-31 21:23 - 00000000 ____D C:\Users\Martin\Desktop\Delphi 2013-08-31 16:00 - 2012-05-13 12:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\.minecraft 2013-08-31 15:13 - 2013-08-31 15:13 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-31 15:13 - 2013-08-31 15:13 - 00000000 ____D C:\Program Files\Java 2013-08-31 15:13 - 2012-06-07 17:28 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-31 15:13 - 2012-06-07 17:28 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-31 15:12 - 2013-08-31 15:11 - 33150376 _____ (Oracle Corporation) C:\Users\Martin\Downloads\jre-7u25-windows-x64.exe 2013-08-31 14:32 - 2013-08-31 14:32 - 00000000 ____D C:\Users\Martin\AppData\Local\PunkBuster 2013-08-31 14:31 - 2012-06-28 15:40 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-08-31 14:30 - 2013-08-31 14:30 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (2).exe 2013-08-29 22:23 - 2013-08-21 16:41 - 00015587 _____ C:\Users\Martin\Desktop\stundenplan.ods 2013-08-29 22:03 - 2012-05-13 00:03 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Adobe 2013-08-29 17:21 - 2013-08-29 17:30 - 00840264 _____ C:\Windows\SysWOW64\pbsvc.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (1).exe 2013-08-29 17:21 - 2013-08-29 17:21 - 02211840 _____ C:\Users\Martin\Downloads\pbsetup.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 00840264 _____ C:\Users\Martin\Downloads\pbsvc.exe 2013-08-29 17:17 - 2013-08-29 17:16 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp.exe 2013-08-22 19:22 - 2013-08-22 19:22 - 00000000 ____D C:\Users\Martin\Desktop\players 2013-08-22 19:19 - 2013-08-22 19:18 - 06343274 _____ C:\Users\Martin\Downloads\Fix.rar 2013-08-22 17:04 - 2013-08-22 17:04 - 00000000 ____D C:\ProgramData\ATI 2013-08-22 17:03 - 2013-08-22 17:03 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-08-22 17:03 - 2012-05-13 00:04 - 00000000 ____D C:\ProgramData\AMD 2013-08-22 17:03 - 2012-05-12 23:46 - 00000000 ____D C:\Program Files\ATI Technologies 2013-08-22 16:45 - 2013-08-22 16:45 - 00792704 _____ (AMD) C:\Users\Martin\Downloads\amddriverdownloader (1).exe 2013-08-22 16:37 - 2013-08-22 16:37 - 00262398 _____ C:\Users\Martin\Documents\ts3_clientui-win64-1375773286-2013-08-22 16_37_39.474090.dmp 2013-08-21 21:52 - 2012-10-24 18:39 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Audacity 2013-08-21 17:43 - 2012-10-24 18:39 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-08-21 17:11 - 2013-06-10 17:48 - 00000000 ____D C:\Users\Martin\Desktop\Bushido 2013-08-19 13:00 - 2013-08-19 12:59 - 00005247 _____ C:\Users\Martin\Desktop\programmliste.html 2013-08-19 11:59 - 2013-08-19 11:59 - 00000012 _____ C:\Users\Martin\Desktop\breiter.txt Files to move or delete: ==================== C:\Users\Martin\AppData\Roaming\skype.ini Some content of TEMP: ==================== C:\Users\Martin\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 11:17 ==================== End Of Log ============================ Geändert von karkmar (14.09.2013 um 13:57 Uhr) |
14.09.2013, 13:58 | #18 |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Da zu viele Zeichen im Post, hier die weiteren logs.
__________________FRST (2. Scan,mit Addition) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-09-2013 04 Ran by Martin (administrator) on MARTIN-PC on 14-09-2013 14:52:36 Running from C:\Users\Martin\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Softwareentwicklung Remus - ArchiCrypt) C:\Program Files (x86)\ArchiCrypt\ArchiCrypt Shredder 6\ArchiCryptInjector64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\system32\inetsrv\inetinfo.exe (Microsoft Corporation) C:\Windows\system32\mqsvc.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\system32\mqtgsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CmPCIaudio] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd HKLM\...\Run: [itype] - c:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2011-08-10] (Microsoft Corporation) HKLM\...\Run: [MsmqIntCert] - regsvr32 /s mqrt.dll HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKCU\...\Run: [ccleaner] - C:\Program Files\CCleaner\CCleaner64.exe [5435744 2012-10-24] (Piriform Ltd) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-15] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.) Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: autocheck autochk * SmartDefragBootTime.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:tabs HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8074082B6BB7CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default FF NewTab: google.de FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\icq.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\searchplugins\rising-gods.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\ich@maltegoetz.de FF Extension: DownloadHelper - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: firebug - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: google - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\google@hitachi.com.xpi FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1m26ja9g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll No File CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (ProxTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (Angry Birds) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0 CHR Extension: (Google Docs) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Adblock Plus) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0 CHR Extension: (Google Search) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Search by Image (by Google)) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm\1.5.0_0 CHR Extension: (Webcam Toy) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade\1.5_0 CHR Extension: (Google Maps) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.7_1 CHR Extension: (Search Box) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mknehpjhljpfaghmicofickbkdagooni\1.0_0 CHR Extension: (Plants vs Zombies) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina\1.0.5_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR HKLM-x32\...\Chrome\Extension: [dkinklhnkmkhkhofcnapakaoehijaoih] - C:\Program Files (x86)\OnlineHD.TV\onhd11.crx ==================== Services (Whitelisted) ================= R2 ArchiCrypt Sichere Loeschzonen; C:\Program Files (x86)\ArchiCrypt\ArchiCrypt Shredder 6\ArchiCryptInjector64.exe [313408 2012-05-15] (Softwareentwicklung Remus - ArchiCrypt) S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3128856 2012-02-28] (devolo AG) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation) S3 MatSvc; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [343856 2011-06-13] (Microsoft Corporation) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-20] (Microsoft Corporation) S4 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [836904 2007-08-08] (Nero AG) S4 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-08-03] (Nero AG) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-31] () S3 TuneUp.Defrag; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [607048 2013-02-09] (TuneUp Software) R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [39768 2013-02-18] (AVG Technologies) R3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1154560 2009-05-19] (C-Media Inc) S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2010-06-10] (CACE Technologies) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] () R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 athur; system32\DRIVERS\athurx.sys [x] S3 BTCFilterService; system32\DRIVERS\motfilt.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-05] (Microsoft Corporation) S3 motandroidusb; System32\Drivers\motoandroid.sys [x] S3 motccgp; system32\DRIVERS\motccgp.sys [x] S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [x] S3 MotDev; system32\DRIVERS\motodrv.sys [x] S3 motmodem; system32\DRIVERS\motmodem.sys [x] S3 MotoSwitchService; system32\DRIVERS\motswch.sys [x] S3 Motousbnet; system32\DRIVERS\Motousbnet.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2099-01-13 00:05 - 2013-07-30 22:06 - 00000000 ____D C:\Users\Martin\AppData\Roaming\ICQ 2099-01-13 00:05 - 2012-05-13 11:12 - 00003248 _____ C:\Windows\System32\Tasks\SidebarExecute 2099-01-13 00:04 - 2013-01-02 15:59 - 00000000 ____D C:\Program Files (x86)\AVG 2099-01-13 00:02 - 2099-01-13 00:06 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\Users\Martin\AppData\Local\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\ProgramData\Mozilla 2099-01-13 00:02 - 2013-07-08 11:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2099-01-12 23:58 - 2013-09-14 13:32 - 00000000 ____D C:\ProgramData\MFAData 2099-01-12 23:49 - 2011-03-23 04:20 - 00077936 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\L1C62x64.sys 2099-01-12 23:48 - 2099-01-12 23:48 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e 2099-01-12 23:48 - 2013-06-10 18:16 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2099-01-12 23:46 - 2099-01-12 23:46 - 00000000 ____D C:\Program Files (x86)\Intel 2099-01-12 23:46 - 2009-08-18 07:44 - 00053248 ____R (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2099-01-12 23:40 - 2013-03-19 19:06 - 00001425 _____ C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2099-01-12 23:39 - 2099-01-12 23:39 - 00000020 ___SH C:\Users\Martin\ntuser.ini 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Favoriten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Dokumente 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Users\Martin\AppData\Local\VirtualStore 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Recovery 2099-01-12 23:39 - 2013-09-12 12:32 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2099-01-12 23:39 - 2013-07-07 16:56 - 00000000 ____D C:\Users\Martin 2099-01-12 23:39 - 2009-07-14 06:54 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2099-01-12 23:39 - 2009-07-14 06:49 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2099-01-04 14:40 - 2013-09-12 12:34 - 00000000 ____D C:\Windows\Panther 2099-01-04 14:32 - 2013-03-20 20:07 - 00000000 ____D C:\Windows.old 2013-09-14 14:51 - 2013-09-14 14:51 - 01950312 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe 2013-09-14 14:43 - 2013-09-14 14:43 - 00036444 _____ C:\Users\Martin\Desktop\JRT.txt 2013-09-14 14:36 - 2013-09-14 14:36 - 00000000 ____D C:\Windows\ERUNT 2013-09-14 14:34 - 2013-09-14 14:35 - 00016310 _____ C:\Windows\WindowsUpdate.log 2013-09-14 14:27 - 2013-09-14 14:30 - 00000000 ____D C:\AdwCleaner 2013-09-14 14:26 - 2013-09-14 14:26 - 01037278 _____ C:\Users\Martin\Desktop\adwcleaner.exe 2013-09-14 14:26 - 2013-09-14 14:26 - 01029509 _____ (Thisisu) C:\Users\Martin\Desktop\JRT.exe 2013-09-14 13:41 - 2013-09-14 14:02 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-14 13:37 - 2013-09-14 13:37 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Martin\Downloads\tdsskiller (1).exe 2013-09-12 18:09 - 2013-09-12 18:09 - 00000000 ____D C:\Users\Gast\Documents\TrackMania 2013-09-11 23:48 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 23:48 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 23:48 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 23:48 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 23:48 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 23:48 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 23:48 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 23:48 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 23:48 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 23:48 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 23:48 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 23:48 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 23:48 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 23:48 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 12:14 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 12:14 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 12:14 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 12:14 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 12:14 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 12:14 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 12:14 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 12:14 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 12:14 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 12:14 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 12:14 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 12:14 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 12:14 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 12:14 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 12:14 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 12:14 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 12:14 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 12:14 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 12:13 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 12:13 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 12:13 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 12:13 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 12:13 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 12:13 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 12:13 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 12:13 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 12:13 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 12:13 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-09 21:08 - 2013-09-09 21:08 - 18929080 _____ C:\Users\Martin\Desktop\b39 schrottplatz.psd 2013-09-09 19:50 - 2013-09-09 19:50 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-09-09 19:48 - 2013-09-09 19:48 - 00784840 _____ (Google Inc.) C:\Users\Martin\Downloads\GoogleEarthSetup.exe 2013-09-09 18:12 - 2013-09-09 18:12 - 00000000 ____D C:\Users\Martin\Desktop\Standalone_Neustadt_a_d_Weinstrasse 2013-09-09 18:05 - 2013-09-09 18:11 - 276437684 _____ C:\Users\Martin\Downloads\Standalone_Neustadt_a_d_Weinstrasse.rar 2013-09-09 16:54 - 2013-09-09 18:12 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-09-09 16:52 - 2013-09-09 17:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Overwolf 2013-09-08 23:46 - 2013-09-08 23:46 - 00027448 _____ C:\ComboFix.txt 2013-09-08 23:35 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-08 23:35 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-08 23:35 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-08 23:35 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-08 23:31 - 2013-09-08 23:46 - 00000000 ____D C:\Qoobox 2013-09-08 23:30 - 2013-09-08 23:44 - 00000000 ____D C:\Windows\erdnt 2013-09-08 23:01 - 2013-09-08 23:06 - 00066173 _____ C:\Users\Martin\Downloads\FRST.txt 2013-09-08 23:01 - 2013-09-08 23:05 - 00040367 _____ C:\Users\Martin\Downloads\Addition.txt 2013-09-08 23:00 - 2013-09-08 23:00 - 00000000 ____D C:\FRST 2013-09-08 21:55 - 2013-09-08 21:55 - 00628221 _____ C:\Users\Martin\Desktop\firewall.rar 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:14 - 2013-09-08 21:14 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-09-08 21:13 - 2013-09-08 21:13 - 04009167 _____ C:\Users\Martin\Downloads\ServicesRepair.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00358609 _____ (Farbar) C:\Users\Martin\Downloads\FSS.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00003606 _____ C:\Users\Martin\Downloads\FSS.txt 2013-09-08 20:29 - 2013-09-08 20:29 - 00000000 ____D C:\Users\Martin\AppData\Local\FixItCenter 2013-09-08 20:24 - 2013-09-08 20:24 - 04334752 _____ (Systweak Inc ) C:\Users\Martin\Downloads\rcpsetup_2005.exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (2).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (1).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00000931 _____ C:\Users\Public\Desktop\Microsoft Fix*it Center.lnk 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Windows\MATS 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Program Files\Microsoft Fix it Center 2013-09-08 20:18 - 2013-09-08 20:18 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run.exe 2013-09-08 20:06 - 2013-09-08 20:06 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.2.Run.exe 2013-09-08 20:05 - 2013-09-08 20:05 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.1.Run.exe 2013-09-05 01:43 - 2013-09-05 01:43 - 00045880 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2013-09-04 17:25 - 2013-09-04 17:25 - 00001367 _____ C:\Users\Martin\Downloads\project1 (1).lpr 2013-09-04 15:40 - 2013-09-04 15:40 - 00000000 ____D C:\Users\Martin\Downloads\backup 2013-09-04 15:30 - 2013-09-04 15:40 - 00001483 _____ C:\Users\Martin\Downloads\project1.lpr 2013-09-03 21:12 - 2013-09-03 21:12 - 00000000 ____D C:\Users\Martin\AppData\Local\Steppschuh 2013-09-03 16:22 - 2013-09-03 16:22 - 00000000 ____D C:\Program Files (x86)\Remote Control Server 2013-09-03 16:21 - 2013-09-03 16:21 - 02364793 _____ (Steppschuh) C:\Users\Martin\Downloads\RemoteControlServerSetup.exe 2013-09-03 13:43 - 2013-09-03 13:54 - 00090867 _____ C:\Users\Martin\Downloads\crt-120.zip 2013-09-02 23:14 - 2013-09-02 23:14 - 00021648 _____ C:\Users\Martin\Downloads\Summe.7z 2013-09-02 20:10 - 2013-09-02 20:10 - 00000988 _____ C:\Users\Martin\Desktop\Delphi 6.lnk 2013-09-02 20:08 - 2013-09-02 20:08 - 00000000 ____D C:\Program Files (x86)\Borland 2013-09-01 17:13 - 2013-09-01 17:17 - 00000000 ____D C:\Users\Martin\Desktop\catalys control center 2013-08-31 21:23 - 2013-08-31 21:23 - 00000000 ____D C:\Users\Martin\Desktop\Delphi 2013-08-31 15:13 - 2013-08-31 15:13 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-31 15:13 - 2013-08-31 15:13 - 00000000 ____D C:\Program Files\Java 2013-08-31 15:11 - 2013-08-31 15:12 - 33150376 _____ (Oracle Corporation) C:\Users\Martin\Downloads\jre-7u25-windows-x64.exe 2013-08-31 14:32 - 2013-08-31 14:32 - 00000000 ____D C:\Users\Martin\AppData\Local\PunkBuster 2013-08-31 14:31 - 2013-09-13 20:37 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-08-31 14:31 - 2013-09-12 16:53 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-08-31 14:30 - 2013-08-31 14:30 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (2).exe 2013-08-29 22:00 - 2013-09-01 13:24 - 00000000 ____D C:\Users\Martin\Desktop\venice beach 2013-08-29 17:30 - 2013-08-29 17:21 - 00840264 _____ C:\Windows\SysWOW64\pbsvc.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (1).exe 2013-08-29 17:21 - 2013-08-29 17:21 - 02211840 _____ C:\Users\Martin\Downloads\pbsetup.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 00840264 _____ C:\Users\Martin\Downloads\pbsvc.exe 2013-08-29 17:16 - 2013-08-29 17:17 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp.exe 2013-08-29 13:21 - 2013-09-08 21:54 - 00000000 ____D C:\Users\Martin\Desktop\cod 2013-08-22 19:22 - 2013-08-22 19:22 - 00000000 ____D C:\Users\Martin\Desktop\players 2013-08-22 19:18 - 2013-08-22 19:19 - 06343274 _____ C:\Users\Martin\Downloads\Fix.rar 2013-08-22 17:04 - 2013-08-22 17:04 - 00000000 ____D C:\ProgramData\ATI 2013-08-22 17:03 - 2013-08-22 17:03 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-08-22 16:45 - 2013-08-22 16:45 - 00792704 _____ (AMD) C:\Users\Martin\Downloads\amddriverdownloader (1).exe 2013-08-22 16:37 - 2013-08-22 16:37 - 00262398 _____ C:\Users\Martin\Documents\ts3_clientui-win64-1375773286-2013-08-22 16_37_39.474090.dmp 2013-08-21 16:41 - 2013-08-29 22:23 - 00015587 _____ C:\Users\Martin\Desktop\stundenplan.ods 2013-08-19 12:59 - 2013-08-19 13:00 - 00005247 _____ C:\Users\Martin\Desktop\programmliste.html 2013-08-19 11:59 - 2013-08-19 11:59 - 00000012 _____ C:\Users\Martin\Desktop\breiter.txt ==================== One Month Modified Files and Folders ======= 2099-01-13 00:06 - 2099-01-13 00:02 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\Users\Martin\AppData\Local\Mozilla 2099-01-13 00:02 - 2099-01-13 00:02 - 00000000 ____D C:\ProgramData\Mozilla 2099-01-12 23:48 - 2099-01-12 23:48 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e 2099-01-12 23:48 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\restore 2099-01-12 23:46 - 2099-01-12 23:46 - 00000000 ____D C:\Program Files (x86)\Intel 2099-01-12 23:39 - 2099-01-12 23:39 - 00000020 ___SH C:\Users\Martin\ntuser.ini 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Martin\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Vorlagen 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Startmenü 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Favoriten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Dokumente 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Users\Martin\AppData\Local\VirtualStore 2099-01-12 23:39 - 2099-01-12 23:39 - 00000000 ____D C:\Recovery 2099-01-12 23:39 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2099-01-12 23:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2099-01-04 14:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep 2099-01-04 14:40 - 2011-09-20 05:21 - 00008192 __RSH C:\BOOTSECT.BAK 2099-01-04 14:40 - 2009-07-14 07:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2099-01-04 14:40 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-09-14 14:51 - 2013-09-14 14:51 - 01950312 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe 2013-09-14 14:43 - 2013-09-14 14:43 - 00036444 _____ C:\Users\Martin\Desktop\JRT.txt 2013-09-14 14:39 - 2009-07-14 06:45 - 00018016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-14 14:39 - 2009-07-14 06:45 - 00018016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-14 14:36 - 2013-09-14 14:36 - 00000000 ____D C:\Windows\ERUNT 2013-09-14 14:35 - 2013-09-14 14:34 - 00016310 _____ C:\Windows\WindowsUpdate.log 2013-09-14 14:34 - 2012-05-13 10:15 - 00000000 ____D C:\Users\Martin\AppData\Roaming\TS3Client 2013-09-14 14:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\inetsrv 2013-09-14 14:32 - 2012-10-09 17:57 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-14 14:32 - 2012-05-13 11:08 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Dropbox 2013-09-14 14:32 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-14 14:30 - 2013-09-14 14:27 - 00000000 ____D C:\AdwCleaner 2013-09-14 14:26 - 2013-09-14 14:26 - 01037278 _____ C:\Users\Martin\Desktop\adwcleaner.exe 2013-09-14 14:26 - 2013-09-14 14:26 - 01029509 _____ (Thisisu) C:\Users\Martin\Desktop\JRT.exe 2013-09-14 14:24 - 2012-10-28 13:26 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-14 14:03 - 2012-10-09 17:57 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-14 14:02 - 2013-09-14 13:41 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-14 13:37 - 2013-09-14 13:37 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Martin\Downloads\tdsskiller (1).exe 2013-09-14 13:36 - 2012-05-13 10:50 - 00000000 ____D C:\Users\Martin\AppData\Local\Adobe 2013-09-14 13:32 - 2099-01-12 23:58 - 00000000 ____D C:\ProgramData\MFAData 2013-09-14 13:26 - 2012-05-13 20:52 - 00000000 ___RD C:\Users\Martin\Desktop\Dropbox 2013-09-13 21:30 - 2011-12-30 18:51 - 00000000 ____D C:\Call of Duty 4 - Modern Warfare 2013-09-13 20:37 - 2013-08-31 14:31 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-09-13 20:37 - 2012-06-28 15:40 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-09-13 18:24 - 2013-05-14 23:24 - 04751752 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-09-13 18:24 - 2012-10-28 13:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-13 18:24 - 2012-10-28 13:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-13 18:24 - 2012-10-28 13:26 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-13 08:19 - 2012-12-11 17:50 - 00000981 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-09-12 19:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-12 18:18 - 2012-09-11 17:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Microsoft Games 2013-09-12 18:09 - 2013-09-12 18:09 - 00000000 ____D C:\Users\Gast\Documents\TrackMania 2013-09-12 18:09 - 2012-08-31 17:26 - 00000000 ___RD C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 18:09 - 2012-08-31 17:26 - 00000000 ___RD C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 16:53 - 2013-08-31 14:31 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-09-12 12:34 - 2099-01-04 14:40 - 00000000 ____D C:\Windows\Panther 2013-09-12 12:33 - 2009-07-14 06:45 - 05030112 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 12:32 - 2099-01-12 23:39 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 12:32 - 2012-12-06 00:32 - 00000000 ___RD C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-11 23:49 - 2012-11-22 21:11 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-11 23:48 - 2013-08-13 22:03 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:46 - 2012-07-20 15:07 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 15:02 - 2012-05-20 11:56 - 00000069 _____ C:\Windows\NeroDigital.ini 2013-09-10 16:16 - 2012-08-07 00:06 - 00000000 ____D C:\Users\Martin\AppData\Local\CrashDumps 2013-09-09 21:08 - 2013-09-09 21:08 - 18929080 _____ C:\Users\Martin\Desktop\b39 schrottplatz.psd 2013-09-09 20:19 - 2012-06-01 00:45 - 00001456 _____ C:\Users\Martin\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2013-09-09 19:50 - 2013-09-09 19:50 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-09-09 19:48 - 2013-09-09 19:48 - 00784840 _____ (Google Inc.) C:\Users\Martin\Downloads\GoogleEarthSetup.exe 2013-09-09 18:12 - 2013-09-09 18:12 - 00000000 ____D C:\Users\Martin\Desktop\Standalone_Neustadt_a_d_Weinstrasse 2013-09-09 18:12 - 2013-09-09 16:54 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-09-09 18:11 - 2013-09-09 18:05 - 276437684 _____ C:\Users\Martin\Downloads\Standalone_Neustadt_a_d_Weinstrasse.rar 2013-09-09 17:13 - 2013-09-09 16:52 - 00000000 ____D C:\Users\Martin\AppData\Local\Overwolf 2013-09-09 16:51 - 2012-05-13 10:05 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2013-09-08 23:46 - 2013-09-08 23:46 - 00027448 _____ C:\ComboFix.txt 2013-09-08 23:46 - 2013-09-08 23:31 - 00000000 ____D C:\Qoobox 2013-09-08 23:44 - 2013-09-08 23:30 - 00000000 ____D C:\Windows\erdnt 2013-09-08 23:44 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-08 23:06 - 2013-09-08 23:01 - 00066173 _____ C:\Users\Martin\Downloads\FRST.txt 2013-09-08 23:05 - 2013-09-08 23:01 - 00040367 _____ C:\Users\Martin\Downloads\Addition.txt 2013-09-08 23:00 - 2013-09-08 23:00 - 00000000 ____D C:\FRST 2013-09-08 22:00 - 2012-05-15 23:03 - 00007662 _____ C:\Users\Martin\AppData\Local\Resmon.ResmonCfg 2013-09-08 21:58 - 2012-12-01 13:36 - 00001709 _____ C:\Users\Martin\Desktop\nXs Nuketown.lnk 2013-09-08 21:55 - 2013-09-08 21:55 - 00628221 _____ C:\Users\Martin\Desktop\firewall.rar 2013-09-08 21:54 - 2013-08-29 13:21 - 00000000 ____D C:\Users\Martin\Desktop\cod 2013-09-08 21:34 - 2013-03-24 16:13 - 00000000 ____D C:\Users\Martin\AppData\Roaming\uTorrent 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:33 - 2013-09-08 21:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-09-08 21:14 - 2013-09-08 21:14 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-09-08 21:13 - 2013-09-08 21:13 - 04009167 _____ C:\Users\Martin\Downloads\ServicesRepair.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00358609 _____ (Farbar) C:\Users\Martin\Downloads\FSS.exe 2013-09-08 21:13 - 2013-09-08 21:13 - 00003606 _____ C:\Users\Martin\Downloads\FSS.txt 2013-09-08 21:08 - 2013-08-02 15:22 - 00000000 ____D C:\Users\Martin\Desktop\S3 Mukke 2013-09-08 20:58 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-08 20:29 - 2013-09-08 20:29 - 00000000 ____D C:\Users\Martin\AppData\Local\FixItCenter 2013-09-08 20:24 - 2013-09-08 20:24 - 04334752 _____ (Systweak Inc ) C:\Users\Martin\Downloads\rcpsetup_2005.exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (2).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run (1).exe 2013-09-08 20:19 - 2013-09-08 20:19 - 00000931 _____ C:\Users\Public\Desktop\Microsoft Fix*it Center.lnk 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Windows\MATS 2013-09-08 20:19 - 2013-09-08 20:19 - 00000000 ____D C:\Program Files\Microsoft Fix it Center 2013-09-08 20:18 - 2013-09-08 20:18 - 00447792 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\FixitCenter_Run.exe 2013-09-08 20:06 - 2013-09-08 20:06 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.2.Run.exe 2013-09-08 20:05 - 2013-09-08 20:05 - 00347424 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\MicrosoftFixit.WindowsFirewall.RNP.139302094345324165.1.1.Run.exe 2013-09-06 17:23 - 2013-07-07 16:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-05 01:43 - 2013-09-05 01:43 - 00045880 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2013-09-04 17:25 - 2013-09-04 17:25 - 00001367 _____ C:\Users\Martin\Downloads\project1 (1).lpr 2013-09-04 15:40 - 2013-09-04 15:40 - 00000000 ____D C:\Users\Martin\Downloads\backup 2013-09-04 15:40 - 2013-09-04 15:30 - 00001483 _____ C:\Users\Martin\Downloads\project1.lpr 2013-09-03 21:12 - 2013-09-03 21:12 - 00000000 ____D C:\Users\Martin\AppData\Local\Steppschuh 2013-09-03 16:22 - 2013-09-03 16:22 - 00000000 ____D C:\Program Files (x86)\Remote Control Server 2013-09-03 16:21 - 2013-09-03 16:21 - 02364793 _____ (Steppschuh) C:\Users\Martin\Downloads\RemoteControlServerSetup.exe 2013-09-03 16:21 - 2012-05-13 10:18 - 00000000 ____D C:\Users\Martin\AppData\Local\Downloaded Installations 2013-09-03 13:54 - 2013-09-03 13:43 - 00090867 _____ C:\Users\Martin\Downloads\crt-120.zip 2013-09-02 23:14 - 2013-09-02 23:14 - 00021648 _____ C:\Users\Martin\Downloads\Summe.7z 2013-09-02 20:10 - 2013-09-02 20:10 - 00000988 _____ C:\Users\Martin\Desktop\Delphi 6.lnk 2013-09-02 20:08 - 2013-09-02 20:08 - 00000000 ____D C:\Program Files (x86)\Borland 2013-09-01 17:17 - 2013-09-01 17:13 - 00000000 ____D C:\Users\Martin\Desktop\catalys control center 2013-09-01 13:24 - 2013-08-29 22:00 - 00000000 ____D C:\Users\Martin\Desktop\venice beach 2013-08-31 21:23 - 2013-08-31 21:23 - 00000000 ____D C:\Users\Martin\Desktop\Delphi 2013-08-31 16:00 - 2012-05-13 12:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\.minecraft 2013-08-31 15:13 - 2013-08-31 15:13 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-31 15:13 - 2013-08-31 15:13 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-31 15:13 - 2013-08-31 15:13 - 00000000 ____D C:\Program Files\Java 2013-08-31 15:13 - 2012-06-07 17:28 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-31 15:13 - 2012-06-07 17:28 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-31 15:12 - 2013-08-31 15:11 - 33150376 _____ (Oracle Corporation) C:\Users\Martin\Downloads\jre-7u25-windows-x64.exe 2013-08-31 14:32 - 2013-08-31 14:32 - 00000000 ____D C:\Users\Martin\AppData\Local\PunkBuster 2013-08-31 14:31 - 2012-06-28 15:40 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-08-31 14:30 - 2013-08-31 14:30 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (2).exe 2013-08-29 22:23 - 2013-08-21 16:41 - 00015587 _____ C:\Users\Martin\Desktop\stundenplan.ods 2013-08-29 22:03 - 2012-05-13 00:03 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Adobe 2013-08-29 17:21 - 2013-08-29 17:30 - 00840264 _____ C:\Windows\SysWOW64\pbsvc.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp (1).exe 2013-08-29 17:21 - 2013-08-29 17:21 - 02211840 _____ C:\Users\Martin\Downloads\pbsetup.exe 2013-08-29 17:21 - 2013-08-29 17:21 - 00840264 _____ C:\Users\Martin\Downloads\pbsvc.exe 2013-08-29 17:17 - 2013-08-29 17:16 - 03330048 _____ C:\Users\Martin\Downloads\iw3mp.exe 2013-08-22 19:22 - 2013-08-22 19:22 - 00000000 ____D C:\Users\Martin\Desktop\players 2013-08-22 19:19 - 2013-08-22 19:18 - 06343274 _____ C:\Users\Martin\Downloads\Fix.rar 2013-08-22 17:04 - 2013-08-22 17:04 - 00000000 ____D C:\ProgramData\ATI 2013-08-22 17:03 - 2013-08-22 17:03 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-08-22 17:03 - 2012-05-13 00:04 - 00000000 ____D C:\ProgramData\AMD 2013-08-22 17:03 - 2012-05-12 23:46 - 00000000 ____D C:\Program Files\ATI Technologies 2013-08-22 16:45 - 2013-08-22 16:45 - 00792704 _____ (AMD) C:\Users\Martin\Downloads\amddriverdownloader (1).exe 2013-08-22 16:37 - 2013-08-22 16:37 - 00262398 _____ C:\Users\Martin\Documents\ts3_clientui-win64-1375773286-2013-08-22 16_37_39.474090.dmp 2013-08-21 21:52 - 2012-10-24 18:39 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Audacity 2013-08-21 17:43 - 2012-10-24 18:39 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-08-21 17:11 - 2013-06-10 17:48 - 00000000 ____D C:\Users\Martin\Desktop\Bushido 2013-08-19 13:00 - 2013-08-19 12:59 - 00005247 _____ C:\Users\Martin\Desktop\programmliste.html 2013-08-19 11:59 - 2013-08-19 11:59 - 00000012 _____ C:\Users\Martin\Desktop\breiter.txt Files to move or delete: ==================== C:\Users\Martin\AppData\Roaming\skype.ini Some content of TEMP: ==================== C:\Users\Martin\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 11:17 Addition (im 2. Scan) |
14.09.2013, 14:00 | #19 |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Addition scheint sehr lang zu sein.. Dann wohl hier im 3. Post, da zu viele Zeichen. Addition (im 2. Scan) Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-09-2013 04 Ran by Martin at 2013-09-14 14:53:28 Running from C:\Users\Martin\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe AIR (x32 Version: 3.5.0.1060) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.174) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168) Adobe Photoshop CS5.1 (x32 Version: 12.1) Adobe Reader X (10.1.4) - Deutsch (x32 Version: 10.1.4) AMD Accelerated Video Transcoding (Version: 12.10.100.30328) AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.911.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.80328.2204) AMD Wireless Display v3.0 (Version: 1.0.0.10) ArchiCrypt Shredder Version 6.0.9.5654 (x32 Version: 6.0.9.5654) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.2.43) Audacity 2.0.2 (x32 Version: 2.0.2) AVG 2013 (Version: 13.0.3222) AVG 2013 (Version: 13.0.3408) AVG 2013 (Version: 2013.0.3408) AVG PC TuneUp Language Pack (de-DE) (x32 Version: 12.0.4000.108) Borland Delphi 6 (x32 Version: 6.0) Canon Easy-WebPrint EX (x32) Canon MG5200 series Benutzerregistrierung (x32) Canon MG5200 series MP Drivers Canon MP Navigator EX 4.0 (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2013.0328.2218.38225) Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.2218.38225) Catalyst Control Center InstallProxy (x32 Version: 2013.0328.2218.38225) Catalyst Control Center Localization All (x32 Version: 2013.0328.2218.38225) CCC Help Chinese Standard (x32 Version: 2013.0328.2217.38225) CCC Help Chinese Traditional (x32 Version: 2013.0328.2217.38225) CCC Help Czech (x32 Version: 2013.0328.2217.38225) CCC Help Danish (x32 Version: 2013.0328.2217.38225) CCC Help Dutch (x32 Version: 2013.0328.2217.38225) CCC Help English (x32 Version: 2013.0328.2217.38225) CCC Help Finnish (x32 Version: 2013.0328.2217.38225) CCC Help French (x32 Version: 2013.0328.2217.38225) CCC Help German (x32 Version: 2013.0328.2217.38225) CCC Help Greek (x32 Version: 2013.0328.2217.38225) CCC Help Hungarian (x32 Version: 2013.0328.2217.38225) CCC Help Italian (x32 Version: 2013.0328.2217.38225) CCC Help Japanese (x32 Version: 2013.0328.2217.38225) CCC Help Korean (x32 Version: 2013.0328.2217.38225) CCC Help Norwegian (x32 Version: 2013.0328.2217.38225) CCC Help Polish (x32 Version: 2013.0328.2217.38225) CCC Help Portuguese (x32 Version: 2013.0328.2217.38225) CCC Help Russian (x32 Version: 2013.0328.2217.38225) CCC Help Spanish (x32 Version: 2013.0328.2217.38225) CCC Help Swedish (x32 Version: 2013.0328.2217.38225) CCC Help Thai (x32 Version: 2013.0328.2217.38225) CCC Help Turkish (x32 Version: 2013.0328.2217.38225) ccc-utility64 (Version: 2013.0328.2218.38225) CCleaner (Version: 3.24) C-Media PCI Audio Device D3DX10 (x32 Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition devolo dLAN Cockpit (x32 Version: 3.2.0.0) devolo dLAN-Konfigurationsassistent (x32 Version: 20.0.0.0) devolo Informer (x32 Version: 28.0.0.0) dLAN Cockpit (x32 Version: 3.2.28) Dropbox (HKCU Version: 2.0.22) FileZilla Client 3.6.0.2 (x32 Version: 3.6.0.2) Free 3GP Video Converter version 5.0.23.320 (x32 Version: 5.0.23.320) Free YouTube to MP3 Converter version 3.12.2.422 (x32 Version: 3.12.2.422) Google Chrome (x32 Version: 29.0.1547.66) Google Earth (x32 Version: 7.1.1.1888) Google Update Helper (x32 Version: 1.3.21.153) ICQ7.6 (x32 Version: 7.6) Internet Explorer (Enable DEP) Java 7 Update 21 (x32 Version: 7.0.210) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Java(TM) 6 Update 22 (x32 Version: 6.0.220) JavaFX 2.1.1 (x32 Version: 2.1.1) JDownloader 0.9 (x32 Version: 0.9) Junk Mail filter update (x32 Version: 15.4.3502.0922) LAME v3.99.3 (for Windows) (x32) Lazarus 1.0.8 (Version: 1.0.8) LogMeIn Hamachi (x32 Version: 2.1.0.294) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Fix it Center (Version: 1.0.0100) Microsoft IntelliType Pro 8.2 (Version: 8.20.469.0) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT Redists (Version: 1.0) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) MyFreeCodec (HKCU) MyPhoneExplorer (x32 Version: 1.8.4) Need For Speed™ World (x32 Version: 1.0.0.1166) Nero 8 (x32 Version: 8.0.182) Notepad++ (x32 Version: 6.2.2) OpenAL (x32) OpenOffice.org 3.3 (x32 Version: 3.3.9567) PDF Settings CS5 (x32 Version: 10.0) PunkBuster Services (x32 Version: 0.993) Remote Control Server (x32 Version: 1.8.0.0) Samsung Kies (x32 Version: 2.6.0.13064_2) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.4.0) Skype™ 6.3 (x32 Version: 6.3.107) Smart Defrag 2 (x32 Version: 2.8) Sweet Home 3D (HKCU) Sweet Home 3D version 3.5 (x32) TeamSpeak 3 Client (Version: 3.0.12) TeamViewer 7 (x32 Version: 7.0.15723) TmNationsForever (x32) TuneUp Utilities (x32 Version: 9.0.2000.15) TuneUp Utilities Language Pack (de-DE) (x32 Version: 9.0.2000.15) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553157) 64-Bit Edition Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition Update for Microsoft Office 2010 (KB2589370) 64-Bit Edition Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition Update for Microsoft Office 2010 (KB2760758) 64-Bit Edition Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition USB Storage Driver (x32) UxStyle Core Beta (Version: 0.2.1.1) Vegas Pro 12.0 (64-bit) (Version: 12.0.394) VirtualCloneDrive (x32) Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2) Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1) VLC media player 2.0.1 (x32 Version: 2.0.1) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3555.0308) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3555.0308) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) WinRAR 4.11 (64-Bit) (Version: 4.11.0) XSplit (x32 Version: 1.1.1210.3101) ==================== Restore Points ========================= 10-07-2013 22:42:35 Windows Update 18-07-2013 11:06:28 Geplanter Prüfpunkt 28-07-2013 15:13:05 Geplanter Prüfpunkt 30-07-2013 10:39:52 Installed Samsung Kies 06-08-2013 18:29:40 Geplanter Prüfpunkt 13-08-2013 19:11:01 Geplanter Prüfpunkt 13-08-2013 20:02:18 Windows Update 21-08-2013 16:41:46 Geplanter Prüfpunkt 28-08-2013 20:29:01 Windows Update 31-08-2013 13:12:31 Installed Java 7 Update 25 (64-bit) 02-09-2013 18:07:29 Borland Delphi 6 wird installiert 03-09-2013 14:22:08 Installed Remote Control Server. 08-09-2013 19:33:18 Steam wird entfernt 09-09-2013 16:10:49 Removed Overwolf 11-09-2013 21:40:31 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-09-08 23:44 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {04ABD286-62E2-4F9A-B48F-FA1C908545AE} - System32\Tasks\{C517C1EC-D5FD-4D53-B02C-0606AF65D825} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {1D911498-357F-4F4C-91A1-2CED39EFEE60} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {27254F99-F164-48A6-9EED-68D25AE0006E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe Task: {28A409A1-E2B9-4842-990F-D04AEB3CB4E1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2693577240-4054724306-2718763821-1000Core => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {2BA5B85D-ECEB-4DF3-9E57-926A73C2CA53} - System32\Tasks\{BF2817CC-4EFE-4E13-8D6D-11F9EEE56626} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {2D37590C-873C-49C3-B0A4-173F56DCEC4A} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => c:\Program Files\Microsoft IntelliType Pro\IType.exe [2011-08-10] (Microsoft Corporation) Task: {2DEA377D-FC4D-448F-96F8-5BFB4455897C} - System32\Tasks\{9312A50F-5E5F-4E03-880D-C4760896C5EC} => C:\Users\Martin\Desktop\anno\1602.EXE [2006-02-04] (MAX DESIGN) Task: {31E9BC3E-91D7-4EBA-9010-4A2C4E4A7D68} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-09] (Google Inc.) Task: {35A6C710-5F86-4C35-8C08-11D145F6BB01} - System32\Tasks\{729B9950-E6AF-4BE8-8859-BAAD11DAA1CC} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {3DB6B7D8-60CB-4451-A2E6-F78E90DC213F} - System32\Tasks\{54C6E214-EED4-4146-A1FF-E4A98AFB5497} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {43E6F094-0595-4A52-8EF3-1A6FA204B3FF} - \YourFile Update No Task File Task: {5E7238C2-AC3E-45F0-BDDA-C1F997911552} - System32\Tasks\{FCB99D6B-C4A0-44F0-BD4D-3DD86F32BAC6} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {643DAD22-8F21-4C6D-8F42-168816AAF1FC} - System32\Tasks\{A983C55A-1A7A-42ED-8347-888C47DB2A3B} => C:\Users\Martin\Desktop\anno\1602.EXE [2006-02-04] (MAX DESIGN) Task: {78AE973C-CDE8-4895-BAFB-FF92D1D8A5E9} - System32\Tasks\RDReminder => C:\Program Files (x86)\Dll-Files.com Task: {83FD3FB0-CF9C-4226-AA9D-4100C9F5C8E5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2693577240-4054724306-2718763821-1000UA => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {872E6AC2-4300-41E3-B569-2AFDFE0B2D59} - System32\Tasks\{C6B02DA7-4F1C-40BB-ACD7-E486E5DFCB89} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {894160C9-EEA4-42EA-AFB9-D956A83D2BDD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-13] (Adobe Systems Incorporated) Task: {8D72C5D6-8923-4FE9-AACA-8A59EAE2C674} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-10-24] (Piriform Ltd) Task: {90092AFC-66F1-463D-B626-315F51B4DBCE} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {9AF85E11-BCE7-4E86-A6EE-59603CDD39AF} - System32\Tasks\{AF025DCF-3C8F-4C2B-80AC-D7A1A915965F} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {9F89164D-AF14-4BCA-9867-418FCD4106B1} - System32\Tasks\{683FDBB6-20F1-4CC5-B138-6113E1D6837B} => C:\Users\Martin\Desktop\anno\1602.EXE [2006-02-04] (MAX DESIGN) Task: {A2DAA274-8C07-4FCB-AACF-373FB719A07D} - System32\Tasks\Flush DNS => C:\Users\Martin\Desktop\flushdns.bat [2012-07-28] () Task: {AF488799-85E1-4BBD-A2CF-90DAAC44895A} - System32\Tasks\SmartDefrag_Startup => C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe [2013-06-30] (IObit) Task: {B09B0CB7-9FA6-459D-A9E0-1E0DA7318FF4} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {BF44FF6F-4E4D-43A6-A76A-0CDFFCD4DE1F} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {C87A60C8-E7CF-468C-ACED-EABF21A0BCBF} - System32\Tasks\{D3DF75EC-61ED-4263-A79E-4104D5506FDF} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {CA47E233-1810-4770-A4A6-36AECCE95906} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-09] (Google Inc.) Task: {DB9EA821-F4C2-49B8-B281-F56057253195} - System32\Tasks\{70020C86-5F62-42EE-B69E-69F91F16D145} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {E70E1EB2-8BB3-459F-A218-7A99BFF9998C} - System32\Tasks\{C118DB49-F5CE-4B21-A2C0-85FF7BD7879D} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {E7FF8C4A-7CBA-43FD-8F4D-FF5DF4D4E9C3} - System32\Tasks\{5765A5E6-6D2A-4361-B2DD-FBACEDD0DD54} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {F284A250-D334-4FF7-A64B-3A5D7572C464} - System32\Tasks\SmartDefragUpdate => C:\Program Files (x86)\IObit\Smart Defrag 2\AutoUpdate.exe [2013-05-22] (IObit) Task: {F79E509E-F74A-4DFF-86E3-6B4571830DB8} - System32\Tasks\{3A969F19-73BC-4231-BA50-5EBD2C3A8E32} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: {FB8FCE8D-2DCB-486D-908E-505BB371E37B} - System32\Tasks\AdobeAAMUpdater-1.0-Martin-PC-Martin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated) Task: {FED42CE3-C7E4-4B5A-8E43-5BFFA5135408} - System32\Tasks\{263EFA6D-542E-4D3E-93A6-59D040419892} => C:\Users\Martin\Desktop\Dropbox\GYTE12 Braun\Programm\snake\bgi\EXETOBIN.EXE Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-01-09 10:07 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2009-07-14 01:37 - 2009-07-14 03:39 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\Dwm.exe 2013-03-28 22:14 - 2013-03-28 22:14 - 00217088 _____ (Advanced Mirco Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Shared.dll 2013-03-28 22:14 - 2013-03-28 22:14 - 00335872 _____ (Advanced Mirco Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Runtime.dll 2013-03-28 22:17 - 2013-03-28 22:17 - 00028672 _____ (Advanced Mirco Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.AMDHome.Graphics.Dashboard.dll 2012-05-16 13:45 - 2010-11-20 15:25 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\taskmgr.exe 2012-05-14 13:59 - 2011-02-25 08:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-05-25 02:36 - 2013-05-25 02:36 - 00164016 _____ (Dropbox, Inc.) C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll 2012-05-12 23:39 - 2012-02-17 20:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2012-08-08 14:13 - 2009-12-14 19:16 - 00107688 _____ (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll 2013-03-20 13:07 - 2013-01-02 12:38 - 00142520 _____ (Softwareentwicklung Remus - ArchiCrypt) C:\Program Files (x86)\ArchiCrypt\ArchiCrypt Shredder 6\ACShredderShellExt.dll 2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll 2013-09-14 14:51 - 2013-09-14 14:51 - 01950312 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe 2009-07-14 01:56 - 2009-07-14 03:39 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2012-05-14 13:59 - 2011-05-04 07:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2009-07-14 01:59 - 2009-07-14 03:39 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\DllHost.exe ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\Users\Martin\Documents\Anmeldung bei Schulbanker.eml:OECustomProperty ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-09-08 23:43:51.418 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-09-08 23:43:51.316 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-02-10 15:02:25.006 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\wow64_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_d6005436ad01f9a3\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 15:02:24.871 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\wow64_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_d6005436ad01f9a3\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 15:02:24.740 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\wow64_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_d6005436ad01f9a3\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 15:01:20.400 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_54ffd942dc23dbc0\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 15:01:20.264 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_54ffd942dc23dbc0\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 15:01:20.131 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_54ffd942dc23dbc0\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 14:55:36.806 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\Backup\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_54ffd942dc23dbc0_bcrypt.dll_e2f091ac" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 14:55:36.671 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows.old\Windows\winsxs\Backup\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_54ffd942dc23dbc0_bcrypt.dll_e2f091ac" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 20% Total physical RAM: 8191.12 MB Available physical RAM: 6486.53 MB Total Pagefile: 16380.42 MB Available Pagefile: 14513.31 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.76 GB) (Free:136.58 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1A295FB5) Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
15.09.2013, 19:47 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
16.09.2013, 21:37 | #21 |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Nach 6 Minuten hat Malwarebytes in der Tat im QuickScan 3 Bedrohungen gefunden, die ich jetzt allerdings nicht gefährdend finde. Hier der Log: Ps. ESET Log kommt gleich. Code:
ATTFilter Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.16.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16686 Martin :: MARTIN-PC [Administrator] Schutz: Aktiviert 16.09.2013 22:27:17 MBAM-log-2013-09-16 (22-34-25).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 302936 Laufzeit: 5 Minute(n), 56 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Users\Martin\Downloads\Brothersoft_downloader_For_RCN_Deezer_Downloader.exe (PUP.Optional.BSDownloader) -> Keine Aktion durchgeführt. C:\Users\Martin\Downloads\MyPhoneExplorer_Setup_1.8.4.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt. C:\Users\Martin\Downloads\rcpsetup_2005.exe (PUP.Optional.RegCleanerPro) -> Keine Aktion durchgeführt. (Ende) |
16.09.2013, 22:50 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Bitte mal auch auf die Pfade achten. Was im Downloadordner schlummert ist wohl kaum aktive Malware.
__________________ Logfiles bitte immer in CODE-Tags posten |
16.09.2013, 22:54 | #23 | |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen"Zitat:
Hier mal das was Eset mir nach und bei 91% ausgespuckt hat. Irgentwie verträgt der sich wohl mit Java nicht. Ich musste jetzt aber wirklich abbrechen. Muss jetzt die Kiste endlich ausmachen, hätte nicht gedacht, dass es doch solange dauert. Viellecht max. 1 Stunde. Aber das lief jetzt auch schon 1 1/2 Stunden. Finde sonst garkein Schlaf mehr :/ Code:
ATTFilter C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\556d9c4b-2f1dc5db multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\38d5a28c-207c3041 multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\32c9c812-3588dc35 multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\294385a-1b3398bd multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\694b0e23-35f79142 Java/Exploit.CVE-2013-0422.BM trojan C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\2c217004-15706537 multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\4886e86e-626487ff multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\59e0b86f-78f567b3 multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\6bdd0fb8-65dc88d4 multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\3a142c86-4fb9dcb0 Java/Exploit.Agent.NPV trojan C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\6d53a246-6c48484e Java/Exploit.Agent.NPV trojan C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\1a8aca7f-746bc346 multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\63bf9dc7-73f8953b multiple threats C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\1ac5e248-22fa9db2 Java/Exploit.CVE-2013-0422.BM trojan |
16.09.2013, 22:57 | #24 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firewall lässt sich nicht starten - "Empfohlene Einstellungen"Zitat:
"Hüllffeee Funde bei MBAM was ist das schon wieder!!!11!!11!elf" Den Reste bitte mit TFC kicken TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
17.09.2013, 19:15 | #25 |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Morgen in der Frühe gehts dann auf Studienfahrt. Ich bin dann bis Samstag nicht zu Hause. Sonntag warscheinlich auf der IAA in Frankfurt. Werde mich warscheinlich in ca. einer Woche nochmal melden und dann den vollständigen ESET-log posten. Vielleicht findet man ja noch etwas Ich danke dir auf jeden fall schonmal von ganzem Herzen. Du machst hier eine TOLLE Arbeit! Wie ich sehe, hast du schon vielen (tausenden?) Leuten geholfen (anhand deiner Beitragszahl). Im Dessen Namen auch nochmal herzlichen Dank! |
17.09.2013, 21:52 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Ok, viel Spaß bei der Studienfahrt!
__________________ Logfiles bitte immer in CODE-Tags posten |
17.09.2013, 21:58 | #27 |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen" danke :] |
26.09.2013, 20:13 | #28 |
| Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Nach 4 Stunden ESET Durchlauf, auf CPU Priorität Echtzeit endlich ein Ergebnis.. Code:
ATTFilter C:\Users\Martin\Desktop\jailbreak\iOS\[ROM] IOS V4.zip a variant of Android/Adware.Kuguo.A application C:\Users\Martin\Desktop\SDCARD BACKUp\jailbreak\iOS\[ROM] IOS V4.zip a variant of Android/Adware.Kuguo.A application C:\Users\Martin\Downloads\[ROM] IOS V4.zip a variant of Android/Adware.Kuguo.A application C:\Windows.old\Documents and Settings\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\4ebed161-67ce7343 multiple threats C:\Windows.old\Documents and Settings\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\4b8bd6f-44c4e29e Java/TrojanDownloader.Agent.NDR trojan C:\Windows.old\Documents and Settings\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\3e310347-643a480f multiple threats C:\Windows.old\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\4ebed161-67ce7343 multiple threats C:\Windows.old\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\4b8bd6f-44c4e29e Java/TrojanDownloader.Agent.NDR trojan C:\Windows.old\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\3e310347-643a480f multiple threats |
27.09.2013, 09:24 | #29 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firewall lässt sich nicht starten - "Empfohlene Einstellungen" Jailbreak/Androis Krams kann man ignorieren. Den anderen Kram mit TFC wegräumen: TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Firewall lässt sich nicht starten - "Empfohlene Einstellungen" |
arbeiten, automatisch, bild, cbs.log, ccleaner, computer, dateien, einstellungen, firewall, freund, gen, größe, herunterfahren, installieren, microsoft, netzwerk, neuste, problem, programme, schei, spiele, spielen, starte, starten, tool, versionen, wirklich |