![]() |
|
Plagegeister aller Art und deren Bekämpfung: alle Antiviren Syteme aus und alles ist extrem langsamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() alle Antiviren Syteme aus und alles ist extrem langsam Also das Problem war : Wenn ich als Admin ausführen gedrückt habe und dann den Kasten noch mit ok bestätigt habe blieb der dunklere Hintergrund noch etwas. Als er dann weg war ist allerdings nichts passiert. Im abgesicherten Modus musste ich nichts als Admin ausführen und so hats jetzt geklappt. Hier jetzt die Logs: Anti-Malware Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.26.05 Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus) Internet Explorer 10.0.9200.16721 Curdt Marcus :: CURDTMARCUS-PC [Administrator] 26.11.2013 15:18:51 mbam-log-2013-11-26 (15-18-51).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|H:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 618978 Laufzeit: 1 Stunde(n), 9 Minute(n), 1 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 14 C:\AdwCleaner\Quarantine\C\Program Files (x86)\LyricsPal\trz260.tmp.vir (PUP.LyricsAd) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\LyricsPal\Uninstall.exe.vir (PUP.Optional.LyricsAd) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Minibar\Minibar.dll.vir (PUP.Optional.MiniBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\Curdt Marcus\AppData\Local\FilesFrog Update Checker\uninstall.exe.vir (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\Curdt Marcus\AppData\Roaming\Movdap\trz731C.tmp.vir (PUP.Optional.WebCake.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\Curdt Marcus\AppData\Roaming\OpenCandy\F5DB304BE8E642AEBF48056C9811B6DC\Installer.exe.vir (PUP.Optional.Linkury.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\CURDTM~1\AppData\Local\Temp\OCS\ocs_v6r.exe.vir (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\CURDTM~1\AppData\Local\Temp\OCS\ocs_v7f.exe.vir (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Adobe\Adobe Audition CC\amtlib.dll (PUP.RiskwareTool.CK) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Curdt Marcus\AppData\Local\AppsHat Mobile Apps\Uninstall.exe (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Curdt Marcus\Downloads\gs_34075.exe (PUP.Optional.Freemium.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Curdt Marcus\Downloads\pb35setup - CHIP-Downloader.exe (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Curdt Marcus\Sony Vegas Pro 12 for Free\vegas.pro.12.-patch.exe (PUP.RiskwareTool.CK) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.013 - Bericht erstellt am 26/11/2013 um 16:41:01 # Updated 24/11/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Curdt Marcus - CURDTMARCUS-PC # Gestartet von : E:\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Curdt Marcus\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl Ordner Gelöscht : C:\Users\Curdt Marcus\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpcknfcdcgpffjddjeceioobdelceffo ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v25.0.1 (de) [ Datei : C:\Users\Curdt Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\7k6dwla6.default-1358074474981\prefs.js ] -\\ Google Chrome v31.0.1650.57 [ Datei : C:\Users\Curdt Marcus\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [13957 octets] - [28/08/2013 12:56:23] AdwCleaner[R1].txt - [11234 octets] - [26/11/2013 14:10:55] AdwCleaner[R2].txt - [1453 octets] - [26/11/2013 16:40:01] AdwCleaner[S0].txt - [13787 octets] - [28/08/2013 12:57:21] AdwCleaner[S1].txt - [9704 octets] - [26/11/2013 14:11:53] AdwCleaner[S2].txt - [1374 octets] - [26/11/2013 16:41:01] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1434 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Home Premium x64 Ran by Curdt Marcus on 26.11.2013 at 16:53:20,04 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-714820300-3119143247-1997101176-1000\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\webcakeupdater Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updatewhilokii_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updatewhilokii_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic_chr_1-8-16-10_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic_chr_1-8-16-10_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\softonic_chr_1-8-16-10_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\softonic_chr_1-8-16-10_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3943312E-28AB-47F8-A642-F30B9B08C638} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Curdt Marcus\appdata\local\appshat mobile apps" Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{124FBF9C-C163-423E-93A2-AD84BACEE582} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{2A2CF623-C3F9-4DA5-B505-3BDED21DCCAD} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{2CB6E52B-A392-467A-914D-E9968946CAFF} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{715B4C12-31B1-4090-BE1E-15E276897BA6} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{87B425FD-C278-45C3-A35F-5F4C20706A37} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{A6E9DC32-BD07-459B-A597-6FEA47C80B2B} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{AC647FC4-151C-434F-9215-A6FBDB0450C6} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{B53EA8B5-BAE6-48E6-842A-21576030D41C} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{C67CA31C-954C-47A2-8D7F-9E9CF7681D3F} Successfully deleted: [Empty Folder] C:\Users\Curdt Marcus\appdata\local\{F094A1F1-00E5-4584-832E-A6C8FFC513C8} ~~~ FireFox Successfully deleted: [File] C:\Users\Curdt Marcus\AppData\Roaming\mozilla\firefox\profiles\7k6dwla6.default-1358074474981\extensions\toolbar_avira-v7@apn.ask.com.xpi Emptied folder: C:\Users\Curdt Marcus\AppData\Roaming\mozilla\firefox\profiles\7k6dwla6.default-1358074474981\minidumps [403 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 26.11.2013 at 16:54:59,47 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-11-2013 Ran by Curdt Marcus (administrator) on CURDTMARCUS-PC on 26-11-2013 16:56:21 Running from E:\ Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) ================= (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Windows\system32\prevhost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKCU\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3561816 2013-10-18] (Electronic Arts) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_IATIINE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKCU\...\Run: [RocketDock] - C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () HKCU\...\RunOnce: [Report] - C:\AdwCleaner\AdwCleaner[S2].txt [1514 2013-11-26] () HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-26] (Intel Corporation) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\WLanGUI.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [EEventManager] - C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe [1058400 2011-10-31] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-07-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-05-15] (LogMeIn Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [20131121] - C:\Program Files\AVAST Software\Avast\Setup\emupdate\5e44d591-9d2f-46ec-9f21-702865bc2944.exe [180184 2013-11-24] (AVAST Software) Startup: C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x015989730CE2CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Curdt Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\7k6dwla6.default-1358074474981 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn/esnlaunch,version=2.1.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Battlefield Heroes Updater - C:\Users\Curdt Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\7k6dwla6.default-1358074474981\Extensions\battlefieldheroespatcher@ea.com FF Extension: Deutsches Wörterbuch - C:\Users\Curdt Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\7k6dwla6.default-1358074474981\Extensions\de-DE@dictionaries.addons.mozilla.org FF Extension: DownloadHelper - C:\Users\Curdt Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\7k6dwla6.default-1358074474981\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: stylish - C:\Users\Curdt Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\7k6dwla6.default-1358074474981\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi FF Extension: Adblock Plus - C:\Users\Curdt Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\7k6dwla6.default-1358074474981\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\CURDTM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_1 CHR Extension: (Chrome In-App Payments service) - C:\Users\CURDTM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 ==================== Services (Whitelisted) ================= S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) S2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-27] () S2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [653888 2013-10-03] (SEIKO EPSON CORPORATION) S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-03-29] (Intel Corporation) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-31] () S2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [x] ==================== Drivers (Whitelisted) ==================== S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-31] (AVAST Software) S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-31] (AVAST Software) S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-31] () S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation) S3 RTL8187B; C:\Windows\System32\DRIVERS\rtl8187B.sys [446976 2009-11-05] (Realtek Semiconductor Corporation ) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 MSICDSetup; \??\E:\CDriver64.sys [x] S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-26 16:54 - 2013-11-26 16:54 - 00003341 _____ C:\Users\Curdt Marcus\Desktop\JRT.txt 2013-11-26 16:52 - 2013-11-25 09:28 - 01034531 _____ (Thisisu) C:\Users\Curdt Marcus\Desktop\JRT.exe 2013-11-25 13:31 - 2013-11-25 09:28 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Curdt Marcus\Desktop\mbam-setup-1.75.0.1300.exe 2013-11-25 13:03 - 2013-11-25 13:03 - 00003408 ____N C:\bootsqm.dat 2013-11-24 11:08 - 2013-11-24 11:08 - 00033026 _____ C:\ComboFix.txt 2013-11-24 10:58 - 2013-11-24 11:08 - 00000000 ____D C:\Qoobox 2013-11-24 10:58 - 2013-11-24 11:07 - 00000000 ____D C:\Windows\erdnt 2013-11-24 10:58 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-11-24 10:58 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-11-24 10:58 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-11-24 10:57 - 2013-11-24 10:45 - 05149261 ____R (Swearware) C:\Users\Curdt Marcus\Desktop\ComboFix.exe 2013-11-23 12:50 - 2013-11-23 12:50 - 00000000 ____D C:\FRST 2013-11-22 15:11 - 2013-11-22 15:11 - 01957998 _____ (Farbar) C:\Users\Curdt Marcus\Downloads\FRST64.exe 2013-11-17 20:00 - 2013-11-17 21:05 - 00018180 _____ C:\Users\Curdt Marcus\Desktop\Bewerbung-1.sxw 2013-11-17 19:59 - 2013-11-17 19:59 - 00015932 _____ C:\Users\Curdt Marcus\Desktop\Lebenslauf-1.sxw 2013-11-16 10:31 - 2013-11-16 10:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-10 14:03 - 2013-11-10 14:03 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\Blizzard Entertainment 2013-11-10 13:16 - 2013-11-16 12:02 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2013-11-10 13:16 - 2013-11-10 13:16 - 00001256 _____ C:\Users\Public\Desktop\Wetin3.lnk 2013-11-10 13:02 - 2013-11-10 13:09 - 83293072 _____ (Blizzard Entertainment) C:\Users\Curdt Marcus\Downloads\World-of-Warcraft-Setup-deDE.exe 2013-11-10 11:43 - 2013-11-26 14:11 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat 2013-11-10 11:39 - 2013-11-10 11:39 - 00239064 _____ C:\Users\Curdt Marcus\Downloads\MCPatcherPro_downloader-afQyrH7m.exe 2013-11-10 11:39 - 2013-11-10 11:39 - 00003288 _____ C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart 2013-11-10 11:23 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-11-09 16:14 - 2013-11-10 13:24 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\.technic 2013-11-09 16:10 - 2013-11-10 11:45 - 02300919 _____ () C:\Users\Curdt Marcus\Desktop\TechnicLauncher.exe 2013-11-07 16:17 - 2013-11-07 16:17 - 01970848 _____ C:\Users\Curdt Marcus\Downloads\winrar-x64-500.exe 2013-11-07 16:14 - 2013-11-07 16:18 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-11-07 16:14 - 2013-11-07 16:14 - 01609146 _____ C:\Users\Curdt Marcus\Downloads\wrar420d.exe 2013-11-07 16:14 - 2013-11-07 16:14 - 00000000 ____D C:\Program Files (x86)\WinRAR 2013-11-07 16:07 - 2013-11-07 16:08 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Curdt Marcus\Downloads\AdobeAIRInstaller.exe 2013-10-31 12:56 - 2013-10-31 12:57 - 00000000 ____D C:\Users\Curdt Marcus\Crap\Documents\Battlefield Heroes 2013-10-31 12:54 - 2013-10-31 12:54 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games 2013-10-31 12:20 - 2013-10-31 12:20 - 00000000 ____D C:\Program Files (x86)\EA Games 2013-10-28 18:00 - 2013-10-29 22:02 - 00000000 ____D C:\Program Files (x86)\The Mighty Quest For Epic Loot 2013-10-28 18:00 - 2013-10-28 18:00 - 00001400 _____ C:\Users\Public\Desktop\The Mighty Quest For Epic Loot.lnk 2013-10-28 17:59 - 2013-10-28 17:59 - 28382568 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367.exe 2013-10-28 17:59 - 2013-10-28 17:59 - 03174799 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367(1).exe.part 2013-10-27 21:42 - 2013-10-27 21:42 - 00000000 ____D C:\Users\Curdt Marcus\Crap\Documents\RIFT 2013-10-27 21:33 - 2013-10-27 21:48 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\RIFT 2013-10-27 14:29 - 2013-10-27 14:29 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Guild Wars 2 2013-10-27 11:00 - 2013-10-27 11:00 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\ArmA 2 ==================== One Month Modified Files and Folders ======= 2013-11-26 16:54 - 2013-11-26 16:54 - 00003341 _____ C:\Users\Curdt Marcus\Desktop\JRT.txt 2013-11-26 16:53 - 2013-08-30 11:34 - 00000000 ____D C:\Windows\ERUNT 2013-11-26 16:42 - 2012-12-19 15:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-26 16:42 - 2009-07-14 05:51 - 00021144 _____ C:\Windows\setupact.log 2013-11-26 16:41 - 2013-08-28 12:56 - 00000000 ____D C:\AdwCleaner 2013-11-26 16:31 - 2010-11-21 04:47 - 00029282 _____ C:\Windows\PFRO.log 2013-11-26 16:29 - 2013-07-19 13:35 - 00000000 ____D C:\Users\Curdt Marcus\Sony Vegas Pro 12 for Free 2013-11-26 15:06 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-26 15:06 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-26 15:05 - 2011-04-12 08:43 - 01351010 _____ C:\Windows\system32\perfh007.dat 2013-11-26 15:05 - 2011-04-12 08:43 - 00351226 _____ C:\Windows\system32\perfc007.dat 2013-11-26 15:05 - 2009-07-14 06:13 - 00006248 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-26 15:01 - 2012-12-19 15:42 - 01597656 _____ C:\Windows\WindowsUpdate.log 2013-11-26 15:00 - 2013-01-13 14:25 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\Adobe 2013-11-26 15:00 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-11-26 14:59 - 2013-08-09 13:34 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\LogMeIn Hamachi 2013-11-26 14:59 - 2012-12-24 20:49 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-26 14:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-11-26 14:51 - 2012-12-24 20:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-26 14:47 - 2012-12-24 20:41 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-26 14:37 - 2012-12-24 20:41 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-26 14:37 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-26 14:11 - 2013-11-10 11:43 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat 2013-11-26 14:06 - 2013-08-30 09:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-25 13:21 - 2013-02-03 18:31 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\CrashDumps 2013-11-25 13:21 - 2012-12-24 21:01 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-25 13:20 - 2013-08-31 15:57 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-25 13:03 - 2013-11-25 13:03 - 00003408 ____N C:\bootsqm.dat 2013-11-25 09:28 - 2013-11-26 16:52 - 01034531 _____ (Thisisu) C:\Users\Curdt Marcus\Desktop\JRT.exe 2013-11-25 09:28 - 2013-11-25 13:31 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Curdt Marcus\Desktop\mbam-setup-1.75.0.1300.exe 2013-11-24 11:08 - 2013-11-24 11:08 - 00033026 _____ C:\ComboFix.txt 2013-11-24 11:08 - 2013-11-24 10:58 - 00000000 ____D C:\Qoobox 2013-11-24 11:07 - 2013-11-24 10:58 - 00000000 ____D C:\Windows\erdnt 2013-11-24 11:07 - 2012-12-19 15:48 - 00000000 ____D C:\Users\Curdt Marcus 2013-11-24 11:07 - 2009-07-14 03:34 - 00000243 _____ C:\Windows\system.ini 2013-11-24 10:45 - 2013-11-24 10:57 - 05149261 ____R (Swearware) C:\Users\Curdt Marcus\Desktop\ComboFix.exe 2013-11-23 12:50 - 2013-11-23 12:50 - 00000000 ____D C:\FRST 2013-11-22 15:11 - 2013-11-22 15:11 - 01957998 _____ (Farbar) C:\Users\Curdt Marcus\Downloads\FRST64.exe 2013-11-22 14:31 - 2013-02-25 16:36 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Skype 2013-11-18 18:28 - 2013-05-20 11:12 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\.minecraft 2013-11-17 21:05 - 2013-11-17 20:00 - 00018180 _____ C:\Users\Curdt Marcus\Desktop\Bewerbung-1.sxw 2013-11-17 19:59 - 2013-11-17 19:59 - 00015932 _____ C:\Users\Curdt Marcus\Desktop\Lebenslauf-1.sxw 2013-11-17 18:49 - 2012-12-27 16:54 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\TS3Client 2013-11-17 18:48 - 2012-12-27 16:53 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\TeamSpeak 3 Client 2013-11-17 00:15 - 2012-12-24 20:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-16 15:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-16 12:02 - 2013-11-10 13:16 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2013-11-16 10:31 - 2013-11-16 10:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 19:42 - 2013-06-10 16:04 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\AIMP3 2013-11-15 19:39 - 2013-03-03 21:31 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Audacity 2013-11-14 19:24 - 2013-07-20 21:03 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 19:22 - 2013-01-20 10:02 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-10 14:03 - 2013-11-10 14:03 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\Blizzard Entertainment 2013-11-10 13:24 - 2013-11-09 16:14 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\.technic 2013-11-10 13:16 - 2013-11-10 13:16 - 00001256 _____ C:\Users\Public\Desktop\Wetin3.lnk 2013-11-10 13:09 - 2013-11-10 13:02 - 83293072 _____ (Blizzard Entertainment) C:\Users\Curdt Marcus\Downloads\World-of-Warcraft-Setup-deDE.exe 2013-11-10 11:45 - 2013-11-09 16:10 - 02300919 _____ () C:\Users\Curdt Marcus\Desktop\TechnicLauncher.exe 2013-11-10 11:39 - 2013-11-10 11:39 - 00239064 _____ C:\Users\Curdt Marcus\Downloads\MCPatcherPro_downloader-afQyrH7m.exe 2013-11-10 11:39 - 2013-11-10 11:39 - 00003288 _____ C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart 2013-11-07 16:18 - 2013-11-07 16:14 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-11-07 16:17 - 2013-11-07 16:17 - 01970848 _____ C:\Users\Curdt Marcus\Downloads\winrar-x64-500.exe 2013-11-07 16:17 - 2012-12-24 21:34 - 00000000 ____D C:\Program Files\WinRAR 2013-11-07 16:14 - 2013-11-07 16:14 - 01609146 _____ C:\Users\Curdt Marcus\Downloads\wrar420d.exe 2013-11-07 16:14 - 2013-11-07 16:14 - 00000000 ____D C:\Program Files (x86)\WinRAR 2013-11-07 16:08 - 2013-11-07 16:07 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Curdt Marcus\Downloads\AdobeAIRInstaller.exe 2013-11-03 15:15 - 2013-06-19 17:16 - 00517754 _____ () C:\Users\Curdt Marcus\Downloads\FTB_Launcher.exe 2013-11-03 15:15 - 2013-06-19 17:16 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\ftblauncher 2013-11-01 15:51 - 2013-02-23 17:46 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\ArmA 2 OA 2013-10-31 13:14 - 2013-09-01 13:50 - 00282296 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-31 13:14 - 2012-12-25 10:44 - 00282296 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-10-31 13:08 - 2013-09-01 13:49 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-31 13:07 - 2012-12-24 23:00 - 00282296 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-31 13:01 - 2012-12-25 10:44 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\PunkBuster 2013-10-31 12:57 - 2013-10-31 12:56 - 00000000 ____D C:\Users\Curdt Marcus\Crap\Documents\Battlefield Heroes 2013-10-31 12:54 - 2013-10-31 12:54 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games 2013-10-31 12:20 - 2013-10-31 12:20 - 00000000 ____D C:\Program Files (x86)\EA Games 2013-10-29 22:02 - 2013-10-28 18:00 - 00000000 ____D C:\Program Files (x86)\The Mighty Quest For Epic Loot 2013-10-28 18:00 - 2013-10-28 18:00 - 00001400 _____ C:\Users\Public\Desktop\The Mighty Quest For Epic Loot.lnk 2013-10-28 17:59 - 2013-10-28 17:59 - 28382568 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367.exe 2013-10-28 17:59 - 2013-10-28 17:59 - 03174799 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367(1).exe.part 2013-10-27 22:28 - 2013-08-05 17:22 - 00005632 _____ C:\Users\Curdt Marcus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-10-27 21:48 - 2013-10-27 21:33 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\RIFT 2013-10-27 21:42 - 2013-10-27 21:42 - 00000000 ____D C:\Users\Curdt Marcus\Crap\Documents\RIFT 2013-10-27 14:29 - 2013-10-27 14:29 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Guild Wars 2 2013-10-27 14:29 - 2013-01-04 20:08 - 00000000 ____D C:\Users\Curdt Marcus\Crap\Documents\Guild Wars 2 2013-10-27 11:00 - 2013-10-27 11:00 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\ArmA 2 2013-10-27 11:00 - 2013-03-02 14:55 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2013-10-27 11:00 - 2013-02-23 17:46 - 00000000 ____D C:\Users\Curdt Marcus\Crap\Documents\ArmA 2 2013-10-27 11:00 - 2012-12-19 15:44 - 00288411 _____ C:\Windows\DirectX.log Files to move or delete: ==================== C:\Users\Curdt Marcus\Minecraft(2).exe C:\Users\Curdt Marcus\AppData\Roaming\Origin ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-22 15:52 ==================== End Of Log ============================ Bis jetzt sind noch keine Besserungen zuerkennen. Nur mal so als kleiner Zwischenstand. MfG Adan |
![]() |
Themen zu alle Antiviren Syteme aus und alles ist extrem langsam |
antiviren, avast, brauche, community, defender, extrem, extrem langsam, freezt, hoffe, keine programme, langsam, min, programme, scan, schonmal, screen, security, security scan, starte, startet, systeme, win, win7, windows, windows defender |