|
Plagegeister aller Art und deren Bekämpfung: Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.11.2013, 01:40 | #1 |
| Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Guten Abend, hoffentlich könnt ihr mir weiterhelfen. Vor einiger Zeit habe ich mir mit irgendeinem Programm Hola-Search mit runtergeladen und seit dem nervts. Benutze den Firefox/Nightly je nach dem...die Suchleiste oben hab ich manuell wieder auf "Google" umgestellt, jedoch im Home-Bildschirm geht das wohl nicht so einfach. Anscheinend doch ein sehr lästiger Parasit In letzter Zeit hab ich außerdem sehr häufig das Problem, dass mein Flash-Player abstürzt (so ziemlich bei jedem Youtube-Video z.b. - refresh hilft meistens...wenn nicht beim 1. dann beim 2. oder 3. mal ). Im Internet bin ich schon darauf gestoßen, dass man unter Programme deinstallieren dieses Hola-Search deinstallieren soll, doch bei mir scheint das dort gar nicht auf Benutze WIN 7 und möchte diesen Parasit (und ev. noch andere?!) loswerden. Edit: Hab Hola-Search aber nie benutzt, immer nur Google. Aber mit der Zeit nervt es etwas immer zu schaun, dass ich das richtige erwische Wie geh ich das am besten an? Geändert von kritiker (26.11.2013 um 01:46 Uhr) |
26.11.2013, 08:58 | #2 |
/// the machine /// TB-Ausbilder | Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
26.11.2013, 14:12 | #3 |
| Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? So alles gemacht:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-11-2013 01 Ran by Enti-Power (administrator) on ENTI-POWER-PC on 26-11-2013 14:05:10 Running from C:\Users\Enti-Power\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7Debug\mdm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe () C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe () C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Dropbox, Inc.) C:\Users\Enti-Power\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-10-18] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKCU\...\Run: [AIM for Windows] - "C:\Users\Enti-Power\AppData\Local\AOL\AIM\aim.exe" MountPoints2: {bcf1b7cf-a9a5-11e2-aa60-806e6f6e6963} - D:\.\Bin\ASSETUP.exe HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2012-08-20] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Enti-Power\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x324A91C6C53DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.holasearch.com/?q={searchTerms}&affID=121962&babsrc=SP_ss&mntrId=9ACC50465DA1BC23 BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default FF user.js: detected! => C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\user.js FF NewTab: hxxp://www.holasearch.com/?affID=121962&babsrc=NT_ss&mntrId=9ACC50465DA1BC23 FF SelectedSearchEngine: Hola Search FF Homepage: https://www.google.at/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\searchplugins\holasearch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Blue Ice Reloaded - C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\Extensions\{056f6d80-6870-11e1-b86c-0800200c9a66} FF Extension: No Name - C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\Extensions\{cbbbbcd0-3cf7-11dd-ae16-0800200c9a66}.xpi FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (Docs) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Gmail) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] () R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe [324608 2012-05-18] (ASUSTeK Computer Inc.) R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) ==================== Drivers (Whitelisted) ==================== R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2012-04-19] (ASUSTek Computer Inc.) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2012-01-06] (Asmedia Technology) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] () R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] () R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-26 14:05 - 2013-11-26 14:05 - 00016582 _____ C:\Users\Enti-PowerDesktop\FRST.txt 2013-11-26 14:04 - 2013-11-26 14:04 - 00000000 ____D C:\FRST 2013-11-26 14:03 - 2013-11-26 14:03 - 01958474 _____ (Farbar) C:\Users\Enti-Power\Desktop\FRST64.exe 2013-11-21 22:52 - 2013-11-21 22:52 - 00154564 _____ C:\Users\Enti-Power\Desktop\Zusammenfassung Öffentliches Wirtschaftsrecht.odt 2013-11-20 03:02 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-20 03:00 - 2013-11-20 03:02 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-20 03:00 - 2013-11-20 03:00 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-16 13:29 - 2013-11-16 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 04:44 - 2013-11-15 04:44 - 01071224 _____ (Solid State Networks) C:\Users\Enti-Power\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe 2013-11-13 16:55 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 16:55 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 16:55 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 16:55 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 16:55 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 16:55 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 16:55 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 16:55 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 16:55 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 16:55 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 16:55 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 16:55 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 16:55 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 16:55 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 16:55 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 16:55 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 16:55 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 16:55 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 16:55 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 16:55 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 16:55 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 16:55 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 16:55 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 16:55 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 16:55 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 16:55 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 16:55 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 16:55 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 16:55 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 16:55 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-12 00:58 - 2013-11-12 00:58 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\Program Files\iTunes 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-11-12 00:57 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iPod 2013-11-12 00:54 - 2013-11-12 00:56 - 100400976 _____ (Apple Inc.) C:\Users\Enti-Power\Downloads\iTunes64Setup.exe 2013-11-04 17:07 - 2013-11-25 19:53 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-04 17:07 - 2013-11-04 17:07 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-11-04 17:06 - 2013-11-04 17:06 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Enti-Power\Downloads\SkypeSetup(1).exe 2013-11-03 01:03 - 2013-10-18 02:36 - 01063200 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-11-03 01:03 - 2013-10-18 02:36 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-11-03 01:03 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-11-03 01:03 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-10-30 20:49 - 2013-10-30 20:49 - 00000000 ___RD C:\Users\Enti-Power\Desktop\Angewandte Betriebswirtschaft 2013-10-28 14:19 - 2013-10-28 14:19 - 14343198 _____ C:\Users\Enti-Power\Downloads\Mathe,1,4,5.rar 2013-10-28 14:11 - 2013-10-28 14:11 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\OpenOffice.org 2013-10-28 14:07 - 2013-10-28 14:07 - 00001172 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk 2013-10-28 14:07 - 2013-10-28 14:07 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2013-10-27 21:56 - 2013-11-26 13:53 - 00000000 ___RD C:\Users\Enti-Power\Dropbox 2013-10-27 21:56 - 2013-11-02 21:25 - 00001037 _____ C:\Users\Enti-Power\Desktop\Dropbox.lnk 2013-10-27 21:54 - 2013-11-26 13:53 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Dropbox 2013-10-27 21:54 - 2013-11-02 21:25 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-10-27 21:50 - 2013-10-27 21:54 - 35336112 _____ (Dropbox, Inc.) C:\Users\Enti-Power\Downloads\Dropbox 2.4.4.exe ==================== One Month Modified Files and Folders ======= 2013-11-26 14:05 - 2013-11-26 14:05 - 00016582 _____ C:\Users\Enti-Power\Desktop\FRST.txt 2013-11-26 14:04 - 2013-11-26 14:04 - 00000000 ____D C:\FRST 2013-11-26 14:03 - 2013-11-26 14:03 - 01958474 _____ (Farbar) C:\Users\Enti-Power\Desktop\FRST64.exe 2013-11-26 14:02 - 2013-04-20 11:38 - 01532746 _____ C:\Windows\WindowsUpdate.log 2013-11-26 13:58 - 2013-04-20 12:13 - 00000000 _____ C:\Windows\Path.idx 2013-11-26 13:58 - 2013-04-20 12:04 - 00003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{EC92B82A-5E2C-42BF-80B6-B610C3C9FC23} 2013-11-26 13:58 - 2009-07-14 05:45 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-26 13:58 - 2009-07-14 05:45 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-26 13:55 - 2011-04-12 08:43 - 00696848 _____ C:\Windows\system32\perfh007.dat 2013-11-26 13:55 - 2011-04-12 08:43 - 00148144 _____ C:\Windows\system32\perfc007.dat 2013-11-26 13:55 - 2009-07-14 06:13 - 01613412 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-26 13:53 - 2013-10-27 21:56 - 00000000 ___RD C:\Users\Enti-Power\Dropbox 2013-11-26 13:53 - 2013-10-27 21:54 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Dropbox 2013-11-26 13:53 - 2013-04-20 12:08 - 01048576 _____ C:\Windows\PE_Rom.dll 2013-11-26 13:51 - 2013-04-20 11:43 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-26 13:51 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-26 13:51 - 2009-07-14 05:51 - 00066882 _____ C:\Windows\setupact.log 2013-11-26 02:19 - 2013-06-09 01:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-26 00:35 - 2013-04-20 20:30 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Skype 2013-11-25 19:53 - 2013-11-04 17:07 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-25 19:53 - 2013-04-20 20:30 - 00000000 ____D C:\ProgramData\Skype 2013-11-25 15:41 - 2013-10-04 19:30 - 00000000 ____D C:\Users\Enti-Power\Desktop\Uni Wirt+Recht 2013-11-24 18:29 - 2012-12-25 16:10 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2013-11-21 22:52 - 2013-11-21 22:52 - 00154564 _____ C:\Users\Enti-Power\Desktop\Zusammenfassung Öffentliches Wirtschaftsrecht.odt 2013-11-20 21:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-20 16:08 - 2013-04-20 11:38 - 00001425 _____ C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-20 04:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-20 03:02 - 2013-11-20 03:00 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-20 03:00 - 2013-11-20 03:00 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-19 11:21 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-19 03:00 - 2013-04-20 12:13 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-19 03:00 - 2013-04-20 12:13 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-19 03:00 - 2013-04-20 12:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-11-17 17:08 - 2013-04-20 14:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-16 13:29 - 2013-11-16 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 04:44 - 2013-11-15 04:44 - 01071224 _____ (Solid State Networks) C:\Users\Enti-Power\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe 2013-11-14 03:00 - 2013-08-15 15:25 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 03:00 - 2013-04-20 13:18 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-12 00:58 - 2013-11-12 00:58 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iTunes 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-11-12 00:57 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iPod 2013-11-12 00:56 - 2013-11-12 00:54 - 100400976 _____ (Apple Inc.) C:\Users\Enti-Power\Downloads\iTunes64Setup.exe 2013-11-12 00:48 - 2013-08-18 10:51 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Apple Computer 2013-11-08 13:46 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-11-07 20:26 - 2013-08-13 13:36 - 00000000 ____D C:\Users\Enti-Power\Desktop\Bew 2013-11-05 13:44 - 2013-04-20 11:38 - 00000000 ____D C:\Users\Enti-Power 2013-11-05 12:57 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-11-05 03:14 - 2013-06-10 08:07 - 00000000 ____D C:\Users\Enti-Power\Desktop\crap 2013-11-05 03:13 - 2013-05-17 02:20 - 00000000 ____D C:\Users\Enti-Power\Desktop\- 2013-11-04 17:07 - 2013-11-04 17:07 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-11-04 17:06 - 2013-11-04 17:06 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Enti-Power\Downloads\SkypeSetup(1).exe 2013-11-03 01:03 - 2013-04-20 11:43 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-11-03 01:03 - 2013-04-20 11:43 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-11-03 01:03 - 2013-04-20 11:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-11-02 21:25 - 2013-10-27 21:56 - 00001037 _____ C:\Users\Enti-Power\Desktop\Dropbox.lnk 2013-11-02 21:25 - 2013-10-27 21:54 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-11-02 21:25 - 2013-04-20 11:38 - 00000000 ___RD C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-30 20:49 - 2013-10-30 20:49 - 00000000 ___RD C:\Users\Enti-Power\Desktop\Angewandte Betriebswirtschaft 2013-10-28 15:18 - 2009-07-14 05:45 - 00325176 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-28 14:21 - 2013-04-20 12:08 - 00070040 _____ C:\Users\Enti-Power\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-28 14:19 - 2013-10-28 14:19 - 14343198 _____ C:\Users\Enti-Power\Downloads\Mathe,1,4,5.rar 2013-10-28 14:11 - 2013-10-28 14:11 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\OpenOffice.org 2013-10-28 14:07 - 2013-10-28 14:07 - 00001172 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk 2013-10-28 14:07 - 2013-10-28 14:07 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2013-10-27 21:54 - 2013-10-27 21:50 - 35336112 _____ (Dropbox, Inc.) C:\Users\Enti-Power\Downloads\Dropbox 2.4.4.exe Some content of TEMP: ==================== C:\Users\Enti-Power\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Enti-Power\AppData\Local\Temp\msgC106.exe C:\Users\Enti-Power\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Enti-Power\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Enti-Power\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Enti-Power\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Enti-Power\AppData\Local\Temp\nvStInst.exe C:\Users\Enti-Power\AppData\Local\Temp\SkypeSetup.exe C:\Users\Enti-Power\AppData\Local\Temp\uninst1.exe C:\Users\Enti-Power\AppData\Local\Temp\_is8C28.exe C:\Users\Enti-Power\AppData\Local\Temp\_isA3EC.exe C:\Users\Enti-Power\AppData\Local\Temp\_isF20B.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 03:43 ==================== End Of Log ============================ --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-11-2013 01 Ran by Enti-Power at 2013-11-26 14:05:27 Running from C:\Users\Enti-Power\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8) AI Suite II (x32 Version: 2.00.01) Apple Application Support (x32 Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (x32 Version: 2.1.3.127) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.14.3.0) Asmedia ASM106x SATA Host Controller Driver (x32 Version: 1.3.4.000) Bonjour (Version: 3.0.0.10) Download Updater (AOL Inc.) (x32) Dropbox (HKCU Version: 2.4.6) GeForce Experience NvStream Client Components (Version: 1.6.28) Hardcopy (x32 Version: 2013.09.26) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 8.1.0.1252) Intel(R) Network Connections 17.2.154.0 (Version: 17.2.154.0) Intel(R) Rapid Storage Technology (x32 Version: 11.1.0.1006) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.5.235) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Intel® Watchdog Timer Driver (Intel® WDT) (x32) IrfanView (remove only) (x32 Version: 4.35) iTunes (Version: 11.1.3.8) Java 7 Update 21 (64-bit) (Version: 7.0.210) Logitech Gaming Software 8.45 (Version: 8.45.88) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Office XP Professional mit FrontPage (x32 Version: 10.0.6626.0) Microsoft Security Client (Version: 4.4.0304.0) Microsoft Security Essentials (Version: 4.4.304.0) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) MyMicroBalance (x32 Version: 2.5.5) Nightly 27.0a1 (x64 en-US) (Version: 27.0a1) NVIDIA 3D Vision Controller-Treiber 331.58 (Version: 331.58) NVIDIA 3D Vision Treiber 331.58 (Version: 331.58) NVIDIA GeForce Experience 1.7 (Version: 1.7) NVIDIA Grafiktreiber 331.58 (Version: 331.58) NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4) NVIDIA Install Application (Version: 2.1002.140.952) NVIDIA LED Visualizer 1.0 (Version: 1.0) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3158) NVIDIA Systemsteuerung 331.58 (Version: 331.58) NVIDIA Update 9.3.16 (Version: 9.3.16) NVIDIA Update Components (Version: 9.3.16) NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593) PDF Architect (x32 Version: 1.1.83.9982) PDFCreator (x32 Version: 1.7.1) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6657) SHIELD Streaming (Version: 1.6.34) Skype™ 6.11 (x32 Version: 6.11.102) TeamSpeak 3 Client (x32 Version: 3.0.12) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5) ==================== Restore Points ========================= 03-03-2013 10:43:04 Windows Update 07-03-2013 15:32:45 Windows Update 11-03-2013 10:50:25 Windows Update 13-03-2013 13:00:43 Windows Update 17-03-2013 11:34:35 Windows Update 20-03-2013 13:12:22 Windows Update 21-03-2013 02:00:14 Windows Update 24-03-2013 15:12:15 Windows Update 28-03-2013 09:37:17 Windows Update 29-03-2013 16:59:17 Windows Update 02-04-2013 16:23:40 Windows Update 06-04-2013 17:18:40 Windows Update 10-04-2013 20:46:30 Windows Update 12-04-2013 23:24:29 Windows Update 16-04-2013 11:18:13 Windows Update 23-11-2013 21:24:51 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {02095CF4-10E7-4496-9DC6-DEF219F808A9} - System32\Tasks\ASUS\ASUS DigiPowerControl Help => C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe [2012-07-23] (ASUSTeK Computer Inc.) Task: {1AEAD899-C809-4171-9415-D8ABB5FC5A12} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe [2011-09-09] () Task: {6AF77A7E-D408-4DF6-B41A-AE208B7B8732} - System32\Tasks\ASUS\i-Setup125023 => C:\Windows\Chipset\AsusSetup.exe [2010-09-08] (ASUSTeK Computer Inc.) Task: {80B5447B-7C09-4EB8-9DE3-ECB3EE75FB3C} - System32\Tasks\ASUS\ASUS Network iControl Help Execute => C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelpEntry.exe [2012-05-02] (ASUSTeK Computer Inc.) Task: {888B9856-7E54-412A-99E5-AE11CFE4B2D5} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {895AEA15-8A38-4CCF-95B1-E0CC189B8C39} - System32\Tasks\hcdll2_ex_x64 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe [2012-11-08] () Task: {9737C1B2-1DF4-428F-8219-6294A334E87B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated) Task: {CC087868-2503-4740-A821-CA7A2E67DCDD} - System32\Tasks\hcdll2_ex_Win32 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe [2013-07-17] () Task: {CE0411A7-C1DC-49EB-8A6B-66FAB1D1BA1E} - System32\Tasks\ASUS\ASUS AI Suite II Execute => C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe [2012-03-13] (ASUSTeK Computer Inc.) Task: {E66611DE-A53F-4757-84D4-61E69D6A829F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-10-06 01:47 - 2013-09-25 14:15 - 00125944 _____ () C:\Program Files (x86)\Hardcopy\HcDLL2_42_x64.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-04-20 12:03 - 2013-11-26 13:51 - 00030720 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.19\PEbiosinterface32.dll 2013-04-20 12:03 - 2010-06-29 03:58 - 00104448 ____R () C:\Program Files (x86)\ASUS\AXSP\1.00.19\ATKEX.dll 2013-10-06 01:47 - 2013-09-25 14:15 - 00117240 _____ () C:\Program Files (x86)\Hardcopy\HcDLL2_42_Win32.dll 2013-10-06 01:47 - 2012-07-05 14:56 - 00052800 _____ () C:\Program Files (x86)\Hardcopy\hardcopy_05.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Enti-Power\AppData\Roaming\Dropbox\bin\libcef.dll 2013-10-06 01:47 - 2013-09-14 08:20 - 02922488 _____ () C:\Program Files (x86)\Hardcopy\HcDllS.dll 2012-08-10 16:51 - 2012-08-10 16:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2013-04-20 12:06 - 2012-05-17 11:57 - 00043520 ____N () C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\HookKey32.dll 2013-04-20 12:06 - 2012-07-05 11:05 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\pngio.dll 2013-11-16 13:29 - 2013-11-16 13:29 - 03363952 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-04-20 12:03 - 2011-07-12 18:14 - 00147456 _____ () C:\Program Files (x86)\ASUS\AI Suite II\AssistFunc.dll 2013-04-20 12:03 - 2010-10-05 07:22 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite II\pngio.dll 2013-04-20 12:04 - 2011-09-26 18:36 - 00869376 _____ () C:\Program Files (x86)\ASUS\AI Suite II\AI Charger+\AIChargerPlus.dll 2013-04-20 12:03 - 2012-03-21 11:07 - 00972288 _____ () C:\Program Files (x86)\ASUS\AI Suite II\BarGadget\BarGadget.dll 2013-04-20 12:04 - 2012-06-19 11:56 - 01305600 _____ () C:\Program Files (x86)\ASUS\AI Suite II\MyLogo\MyLogo.dll 2013-04-20 12:05 - 2012-07-25 08:56 - 01124864 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\Network iControl.dll 2013-04-20 12:05 - 2012-07-20 08:39 - 01047040 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Probe_II\ProbeII.dll 2013-04-20 12:03 - 2012-05-25 09:33 - 00883712 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Sensor\Sensor.dll 2013-04-20 12:03 - 2012-05-28 20:27 - 01622528 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll 2013-04-20 12:03 - 2011-09-19 19:18 - 01243136 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Settings\Settings.dll 2013-04-20 12:03 - 2011-07-21 08:06 - 00846848 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Splitter\Splitter.dll 2013-04-20 12:03 - 2011-10-14 19:03 - 00885248 _____ () C:\Program Files (x86)\ASUS\AI Suite II\TabGadget\TabGadget.dll 2013-04-20 12:03 - 2010-08-23 03:17 - 00662016 ____R () C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMLib.dll 2013-04-20 12:03 - 2010-10-05 07:22 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite II\ImageHelper.dll 2013-04-20 12:06 - 2012-01-19 08:39 - 00028672 _____ () C:\Program Files (x86)\ASUS\AI Suite II\USB BIOS Flashback\PEInfo.dll 2013-04-20 12:06 - 2010-09-23 10:51 - 00114688 _____ () C:\Program Files (x86)\ASUS\AI Suite II\USB BIOS Flashback\AsIdxParser.dll 2013-04-20 12:06 - 2010-02-25 13:01 - 00139264 _____ () C:\Program Files (x86)\ASUS\AI Suite II\USB BIOS Flashback\Aszip.dll 2013-04-20 12:03 - 2009-08-12 19:15 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\pngio.dll 2013-10-22 07:19 - 2013-10-22 07:19 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\67f2d87ba056e1075fce76a8c50bb57e\IsdiInterop.ni.dll 2013-04-20 12:00 - 2012-02-01 15:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-04-20 11:54 - 2012-06-25 09:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-04-20 12:05 - 2012-07-31 14:21 - 00152064 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\gep.dll 2013-04-20 12:05 - 2012-08-08 15:45 - 00786432 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\func.dll 2013-04-20 12:05 - 2010-10-05 07:22 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\pngio.dll 2013-10-10 10:19 - 2013-10-10 10:19 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Netzwerkcontroller Description: Netzwerkcontroller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/26/2013 01:52:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/25/2013 06:40:27 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/25/2013 03:37:21 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/25/2013 09:34:54 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2013 11:06:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2013 01:40:37 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/23/2013 10:16:04 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2013 05:26:02 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 04:09:39 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/19/2013 03:51:54 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (11/20/2013 04:59:37 AM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/20/2013 04:59:36 AM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/20/2013 00:07:19 AM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/19/2013 10:51:35 PM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/19/2013 10:51:24 PM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/19/2013 10:51:24 PM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/19/2013 08:11:45 PM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/19/2013 07:18:24 PM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/19/2013 05:04:50 PM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Error: (11/19/2013 05:04:41 PM) (Source: DCOM) (User: Enti-Power-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Enti-Power-PCEnti-PowerS-1-5-21-1376425360-4014045650-1006204752-1000LocalHost (unter Verwendung von LRPC) Microsoft Office Sessions: ========================= Error: (11/26/2013 01:52:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/25/2013 06:40:27 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/25/2013 03:37:21 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/25/2013 09:34:54 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2013 11:06:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2013 01:40:37 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/23/2013 10:16:04 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2013 05:26:02 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 04:09:39 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/19/2013 03:51:54 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-11-26 13:51:18.177 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-25 19:32:53.874 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-25 18:38:54.006 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-25 15:51:52.967 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-25 15:35:47.740 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-25 09:33:21.286 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-24 23:05:22.099 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-24 13:44:11.371 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-24 13:39:04.614 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-23 22:26:28.164 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 59% Total physical RAM: 3020.28 MB Available physical RAM: 1233.51 MB Total Pagefile: 6038.74 MB Available Pagefile: 3954.02 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:74.43 GB) (Free:5.12 GB) NTFS Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (RECOVER) (Fixed) (Total:20 GB) (Free:10.07 GB) FAT32 Drive f: () (Fixed) (Total:911.4 GB) (Free:866.59 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 2BAB359D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=911 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: 3BE0C85F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=74 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
27.11.2013, 09:02 | #4 |
/// the machine /// TB-Ausbilder | Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.11.2013, 14:52 | #5 |
| Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Hallo Schrauber, danke für deine Hilfe! Anbei die Logfiles: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.27.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Enti-Power :: ENTI-POWER-PC [Administrator] Schutz: Aktiviert 27.11.2013 14:14:22 mbam-log-2013-11-27 (14-14-22).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 228284 Laufzeit: 2 Minute(n), 4 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 3 HKCU\SOFTWARE\BabylonToolbar (PUP.Optional.BabylonToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 2 C:\ProgramData\IBUpdaterService (Adware.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Enti-Power\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 6 C:\Users\Enti-Power\AppData\Local\Temp\9E879A63-BAB0-7891-8CE0-0E37589AE72F\Setup.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Enti-Power\AppData\Local\Temp\9E879A63-BAB0-7891-8CE0-0E37589AE72F\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Enti-Power\Downloads\AIM_Install.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Enti-Power\Downloads\SoftonicDownloader_fuer_windows-live-messenger.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\IBUpdaterService\repository.xml (Adware.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Enti-Power\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.013 - Bericht erstellt am 27/11/2013 um 14:22:42 # Updated 24/11/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Enti-Power - ENTI-POWER-PC # Gestartet von : C:\Users\Enti-Power\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\Program Files (x86)\Common Files\Software Update Utility Ordner Gelöscht : C:\Users\Enti-Power\AppData\Roaming\pdfforge Ordner Gelöscht : C:\Users\Enti-Power\AppData\Roaming\PerformerSoft Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\searchplugins\holasearch.xml Datei Gelöscht : C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdate Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\52578d8ab36fea12 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-live-messenger_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-live-messenger_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v25.0.1 (de) [ Datei : C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\prefs.js ] Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.holasearch.com/?affID=121962&babsrc=NT_ss&mntrId=9ACC50465DA1BC23"); Zeile gelöscht : user_pref("extensions.holasearch.admin", false); Zeile gelöscht : user_pref("extensions.holasearch.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.holasearch.appId", "{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}"); Zeile gelöscht : user_pref("extensions.holasearch.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.holasearch.dfltLng", "en"); Zeile gelöscht : user_pref("extensions.holasearch.excTlbr", false); Zeile gelöscht : user_pref("extensions.holasearch.ffxUnstlRst", false); Zeile gelöscht : user_pref("extensions.holasearch.id", "9acc7c6c00000000000050465da1bc23"); Zeile gelöscht : user_pref("extensions.holasearch.instlDay", "15826"); Zeile gelöscht : user_pref("extensions.holasearch.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.holasearch.newTab", false); Zeile gelöscht : user_pref("extensions.holasearch.prdct", "holasearch"); Zeile gelöscht : user_pref("extensions.holasearch.prtnrId", "holasearch"); Zeile gelöscht : user_pref("extensions.holasearch.rvrt", "false"); Zeile gelöscht : user_pref("extensions.holasearch.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.holasearch.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.holasearch.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.holasearch.vrsn", "1.8.16.16"); Zeile gelöscht : user_pref("extensions.holasearch.vrsnTs", "1.8.16.1619:14:36"); Zeile gelöscht : user_pref("extensions.holasearch.vrsni", "1.8.16.16"); -\\ Google Chrome v [ Datei : C:\Users\Enti-Power\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [6098 octets] - [27/11/2013 14:20:42] AdwCleaner[S0].txt - [5846 octets] - [27/11/2013 14:22:42] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5906 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x64 Ran by Enti-Power on 27.11.2013 at 14:39:34,52 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1376425360-4014045650-1006204752-1000\Software\sweetim ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Enti-Power\AppData\Roaming\mozilla\firefox\profiles\gghrcpkw.default\minidumps [7 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.11.2013 at 14:41:03,73 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-11-2013 Ran by Enti-Power (administrator) on ENTI-POWER-PC on 27-11-2013 14:44:34 Running from C:\Users\Enti-Power\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7Debug\mdm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Dropbox, Inc.) C:\Users\Enti-Power\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe () C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-10-18] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKCU\...\Run: [AIM for Windows] - "C:\Users\Enti-Power\AppData\Local\AOL\AIM\aim.exe" MountPoints2: {bcf1b7cf-a9a5-11e2-aa60-806e6f6e6963} - D:\.\Bin\ASSETUP.exe HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2012-08-20] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Enti-Power\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x324A91C6C53DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default FF SelectedSearchEngine: Hola Search FF Homepage: https://www.google.at/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Blue Ice Reloaded - C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\Extensions\{056f6d80-6870-11e1-b86c-0800200c9a66} FF Extension: No Name - C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\Extensions\{cbbbbcd0-3cf7-11dd-ae16-0800200c9a66}.xpi FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (Docs) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Gmail) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] () R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe [324608 2012-05-18] (ASUSTeK Computer Inc.) R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) ==================== Drivers (Whitelisted) ==================== R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2012-04-19] (ASUSTek Computer Inc.) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2012-01-06] (Asmedia Technology) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] () R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] () R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-27 14:43 - 2013-11-27 14:44 - 01958818 _____ (Farbar) C:\Users\Enti-Power\Desktop\FRST64.exe 2013-11-27 14:41 - 2013-11-27 14:41 - 00000979 _____ C:\Users\Enti-Power\Desktop\JRT.txt 2013-11-27 14:37 - 2013-11-27 14:37 - 00000000 ____D C:\Windows\ERUNT 2013-11-27 14:36 - 2013-11-27 14:36 - 01034531 _____ (Thisisu) C:\Users\Enti-Power\Desktop\JRT.exe 2013-11-27 14:20 - 2013-11-27 14:22 - 00000000 ____D C:\AdwCleaner 2013-11-27 14:20 - 2013-11-27 14:20 - 01091882 _____ C:\Users\Enti-Power\Downloads\adwcleaner.exe 2013-11-27 14:12 - 2013-11-27 14:12 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-27 14:11 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-27 14:10 - 2013-11-27 14:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Enti-Power\Downloads\mbam-setup-1.75.0.1300.exe 2013-11-26 14:05 - 2013-11-27 14:44 - 00016584 _____ C:\Users\Enti-Power\Desktop\FRST.txt 2013-11-26 14:05 - 2013-11-26 14:05 - 00024786 _____ C:\Users\Enti-Power\Desktop\Addition.txt 2013-11-26 14:04 - 2013-11-26 14:04 - 00000000 ____D C:\FRST 2013-11-21 22:52 - 2013-11-21 22:52 - 00154564 _____ C:\Users\Enti-Power\Desktop\Zusammenfassung Öffentliches Wirtschaftsrecht.odt 2013-11-20 03:02 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-20 03:00 - 2013-11-20 03:02 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-20 03:00 - 2013-11-20 03:00 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-16 13:29 - 2013-11-16 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 04:44 - 2013-11-15 04:44 - 01071224 _____ (Solid State Networks) C:\Users\Enti-Power\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe 2013-11-13 16:55 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 16:55 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 16:55 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 16:55 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 16:55 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 16:55 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 16:55 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 16:55 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 16:55 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 16:55 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 16:55 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 16:55 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 16:55 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 16:55 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 16:55 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 16:55 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 16:55 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 16:55 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 16:55 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 16:55 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 16:55 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 16:55 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 16:55 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 16:55 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 16:55 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 16:55 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 16:55 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 16:55 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 16:55 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 16:55 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-12 00:58 - 2013-11-12 00:58 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\Program Files\iTunes 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-11-12 00:57 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iPod 2013-11-12 00:54 - 2013-11-12 00:56 - 100400976 _____ (Apple Inc.) C:\Users\Enti-Power\Downloads\iTunes64Setup.exe 2013-11-04 17:07 - 2013-11-25 19:53 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-04 17:07 - 2013-11-04 17:07 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-11-04 17:06 - 2013-11-04 17:06 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Enti-Power\Downloads\SkypeSetup(1).exe 2013-11-03 01:03 - 2013-10-18 02:36 - 01063200 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-11-03 01:03 - 2013-10-18 02:36 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-11-03 01:03 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-11-03 01:03 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-10-30 20:49 - 2013-10-30 20:49 - 00000000 ___RD C:\Users\Enti-Power\Desktop\Angewandte Betriebswirtschaft 2013-10-28 14:19 - 2013-10-28 14:19 - 14343198 _____ C:\Users\Enti-Power\Downloads\Mathe,1,4,5.rar 2013-10-28 14:11 - 2013-10-28 14:11 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\OpenOffice.org 2013-10-28 14:07 - 2013-10-28 14:07 - 00001172 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk 2013-10-28 14:07 - 2013-10-28 14:07 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 ==================== One Month Modified Files and Folders ======= 2013-11-27 14:44 - 2013-11-27 14:43 - 01958818 _____ (Farbar) C:\Users\Enti-Power\Desktop\FRST64.exe 2013-11-27 14:44 - 2013-11-26 14:05 - 00016584 _____ C:\Users\Enti-Power\Desktop\FRST.txt 2013-11-27 14:41 - 2013-11-27 14:41 - 00000979 _____ C:\Users\Enti-Power\Desktop\JRT.txt 2013-11-27 14:40 - 2013-04-20 12:08 - 01048576 _____ C:\Windows\PE_Rom.dll 2013-11-27 14:39 - 2013-10-27 21:56 - 00000000 ___RD C:\Users\Enti-Power\Dropbox 2013-11-27 14:39 - 2013-10-27 21:54 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Dropbox 2013-11-27 14:39 - 2013-04-20 11:43 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-27 14:39 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-27 14:39 - 2009-07-14 05:51 - 00067666 _____ C:\Windows\setupact.log 2013-11-27 14:38 - 2013-04-20 11:38 - 01631859 _____ C:\Windows\WindowsUpdate.log 2013-11-27 14:37 - 2013-11-27 14:37 - 00000000 ____D C:\Windows\ERUNT 2013-11-27 14:36 - 2013-11-27 14:36 - 01034531 _____ (Thisisu) C:\Users\Enti-Power\Desktop\JRT.exe 2013-11-27 14:33 - 2013-04-20 12:04 - 00003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{EC92B82A-5E2C-42BF-80B6-B610C3C9FC23} 2013-11-27 14:32 - 2013-04-20 12:13 - 00000000 _____ C:\Windows\Path.idx 2013-11-27 14:30 - 2009-07-14 05:45 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-27 14:30 - 2009-07-14 05:45 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-27 14:28 - 2011-04-12 08:43 - 00696848 _____ C:\Windows\system32\perfh007.dat 2013-11-27 14:28 - 2011-04-12 08:43 - 00148144 _____ C:\Windows\system32\perfc007.dat 2013-11-27 14:28 - 2009-07-14 06:13 - 01613412 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-27 14:22 - 2013-11-27 14:20 - 00000000 ____D C:\AdwCleaner 2013-11-27 14:20 - 2013-11-27 14:20 - 01091882 _____ C:\Users\Enti-Power\Downloads\adwcleaner.exe 2013-11-27 14:19 - 2013-06-09 01:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-27 14:18 - 2010-11-21 04:47 - 00012462 _____ C:\Windows\PFRO.log 2013-11-27 14:12 - 2013-11-27 14:12 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-27 14:10 - 2013-11-27 14:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Enti-Power\Downloads\mbam-setup-1.75.0.1300.exe 2013-11-26 23:05 - 2013-04-20 20:30 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Skype 2013-11-26 14:05 - 2013-11-26 14:05 - 00024786 _____ C:\Users\Enti-Power\Desktop\Addition.txt 2013-11-26 14:04 - 2013-11-26 14:04 - 00000000 ____D C:\FRST 2013-11-25 19:53 - 2013-11-04 17:07 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-25 19:53 - 2013-04-20 20:30 - 00000000 ____D C:\ProgramData\Skype 2013-11-25 15:41 - 2013-10-04 19:30 - 00000000 ____D C:\Users\Enti-Power\Desktop\Uni Wirt+Recht 2013-11-24 18:29 - 2012-12-25 16:10 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2013-11-21 22:52 - 2013-11-21 22:52 - 00154564 _____ C:\Users\Enti-Power\Desktop\Zusammenfassung Öffentliches Wirtschaftsrecht.odt 2013-11-20 21:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-20 16:08 - 2013-04-20 11:38 - 00001425 _____ C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-20 04:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-20 03:02 - 2013-11-20 03:00 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-20 03:00 - 2013-11-20 03:00 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-19 11:21 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-19 03:00 - 2013-04-20 12:13 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-19 03:00 - 2013-04-20 12:13 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-19 03:00 - 2013-04-20 12:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-11-17 17:08 - 2013-04-20 14:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-16 13:29 - 2013-11-16 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 04:44 - 2013-11-15 04:44 - 01071224 _____ (Solid State Networks) C:\Users\Enti-Power\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe 2013-11-14 03:00 - 2013-08-15 15:25 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 03:00 - 2013-04-20 13:18 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-12 00:58 - 2013-11-12 00:58 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iTunes 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-11-12 00:57 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iPod 2013-11-12 00:56 - 2013-11-12 00:54 - 100400976 _____ (Apple Inc.) C:\Users\Enti-Power\Downloads\iTunes64Setup.exe 2013-11-12 00:48 - 2013-08-18 10:51 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Apple Computer 2013-11-08 13:46 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-11-07 20:26 - 2013-08-13 13:36 - 00000000 ____D C:\Users\Enti-Power\Desktop\Bew 2013-11-05 13:44 - 2013-04-20 11:38 - 00000000 ____D C:\Users\Enti-Power 2013-11-05 12:57 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-11-05 03:14 - 2013-06-10 08:07 - 00000000 ____D C:\Users\Enti-Power\Desktop\crap 2013-11-05 03:13 - 2013-05-17 02:20 - 00000000 ____D C:\Users\Enti-Power\Desktop\- 2013-11-04 17:07 - 2013-11-04 17:07 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-11-04 17:06 - 2013-11-04 17:06 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Enti-Power\Downloads\SkypeSetup(1).exe 2013-11-03 01:03 - 2013-04-20 11:43 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-11-03 01:03 - 2013-04-20 11:43 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-11-03 01:03 - 2013-04-20 11:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-11-02 21:25 - 2013-10-27 21:56 - 00001037 _____ C:\Users\Enti-Power\Desktop\Dropbox.lnk 2013-11-02 21:25 - 2013-10-27 21:54 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-11-02 21:25 - 2013-04-20 11:38 - 00000000 ___RD C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-30 20:49 - 2013-10-30 20:49 - 00000000 ___RD C:\Users\Enti-Power\Desktop\Angewandte Betriebswirtschaft 2013-10-28 15:18 - 2009-07-14 05:45 - 00325176 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-28 14:21 - 2013-04-20 12:08 - 00070040 _____ C:\Users\Enti-Power\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-28 14:19 - 2013-10-28 14:19 - 14343198 _____ C:\Users\Enti-Power\Downloads\Mathe,1,4,5.rar 2013-10-28 14:11 - 2013-10-28 14:11 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\OpenOffice.org 2013-10-28 14:07 - 2013-10-28 14:07 - 00001172 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk 2013-10-28 14:07 - 2013-10-28 14:07 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 Some content of TEMP: ==================== C:\Users\Enti-Power\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Enti-Power\AppData\Local\Temp\msgC106.exe C:\Users\Enti-Power\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Enti-Power\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Enti-Power\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Enti-Power\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Enti-Power\AppData\Local\Temp\nvStInst.exe C:\Users\Enti-Power\AppData\Local\Temp\Quarantine.exe C:\Users\Enti-Power\AppData\Local\Temp\SkypeSetup.exe C:\Users\Enti-Power\AppData\Local\Temp\uninst1.exe C:\Users\Enti-Power\AppData\Local\Temp\_is8C28.exe C:\Users\Enti-Power\AppData\Local\Temp\_isA3EC.exe C:\Users\Enti-Power\AppData\Local\Temp\_isF20B.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 03:43 ==================== End Of Log ============================ --- --- --- [/CODE] Hola-Search wurde auch schon erkannt und entfernt und mein Firefox ist davon schon befreit! Dank dir Schrauber, ist jetzt alles ok? LG |
28.11.2013, 09:44 | #6 |
/// the machine /// TB-Ausbilder | Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Noch nen Onlinescan auf Reste ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? |
28.11.2013, 16:40 | #7 |
| Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Hallo Schrauber, die letzten Logs: Der Online-Scanner hat nix gefunden. Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=2b20384955ba7a4b8b41086e6c2f2d82 # engine=16060 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-28 03:09:40 # local_time=2013-11-28 04:09:40 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=771 16777214 16 1 12797861 12797861 0 0 # compatibility_mode=5893 16776574 100 94 12096171 137281230 0 0 # scanned=309120 # found=0 # cleaned=0 # scan_time=9480 Code:
ATTFilter Results of screen317's Security Check version 0.99.76 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (25.0.1) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Und das frische FRST log: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-11-2013 Ran by Enti-Power (administrator) on ENTI-POWER-PC on 28-11-2013 16:16:40 Running from C:\Users\Enti-Power\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7Debug\mdm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Dropbox, Inc.) C:\Users\Enti-Power\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe () C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office10\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-10-18] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKCU\...\Run: [AIM for Windows] - "C:\Users\Enti-Power\AppData\Local\AOL\AIM\aim.exe" MountPoints2: {bcf1b7cf-a9a5-11e2-aa60-806e6f6e6963} - D:\.\Bin\ASSETUP.exe HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2012-08-20] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Enti-Power\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you) Startup: C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x324A91C6C53DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default FF SelectedSearchEngine: Hola Search FF Homepage: https://www.google.at/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Blue Ice Reloaded - C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\Extensions\{056f6d80-6870-11e1-b86c-0800200c9a66} FF Extension: No Name - C:\Users\Enti-Power\AppData\Roaming\Mozilla\Firefox\Profiles\gghrcpkw.default\Extensions\{cbbbbcd0-3cf7-11dd-ae16-0800200c9a66}.xpi FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (Docs) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Gmail) - C:\Users\ENTI-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] () R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe [324608 2012-05-18] (ASUSTeK Computer Inc.) R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) ==================== Drivers (Whitelisted) ==================== R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2012-04-19] (ASUSTek Computer Inc.) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2012-01-06] (Asmedia Technology) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] () R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] () R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-28 16:14 - 2013-11-28 16:14 - 00891184 _____ C:\Users\Enti-Power\Desktop\SecurityCheck.exe 2013-11-28 13:28 - 2013-11-28 13:28 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-27 16:24 - 2013-11-27 16:24 - 00000653 _____ C:\Users\Enti-Power\Desktop\JRT.txt 2013-11-27 14:43 - 2013-11-27 14:44 - 01958818 _____ (Farbar) C:\Users\Enti-Power\Desktop\FRST64.exe 2013-11-27 14:37 - 2013-11-27 14:37 - 00000000 ____D C:\Windows\ERUNT 2013-11-27 14:36 - 2013-11-27 14:36 - 01034531 _____ (Thisisu) C:\Users\Enti-Power\Desktop\JRT.exe 2013-11-27 14:20 - 2013-11-27 14:22 - 00000000 ____D C:\AdwCleaner 2013-11-27 14:20 - 2013-11-27 14:20 - 01091882 _____ C:\Users\Enti-Power\Downloads\adwcleaner.exe 2013-11-27 14:12 - 2013-11-27 14:12 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-27 14:11 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-27 14:10 - 2013-11-27 14:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Enti-Power\Downloads\mbam-setup-1.75.0.1300.exe 2013-11-26 14:05 - 2013-11-28 16:16 - 00016521 _____ C:\Users\Enti-Power\Desktop\FRST.txt 2013-11-26 14:05 - 2013-11-26 14:05 - 00024786 _____ C:\Users\Enti-Power\Desktop\Addition.txt 2013-11-26 14:04 - 2013-11-26 14:04 - 00000000 ____D C:\FRST 2013-11-21 22:52 - 2013-11-21 22:52 - 00154564 _____ C:\Users\Enti-Power\Desktop\Zusammenfassung Öffentliches Wirtschaftsrecht.odt 2013-11-20 03:02 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-20 03:00 - 2013-11-20 03:02 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-20 03:00 - 2013-11-20 03:00 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-16 13:29 - 2013-11-16 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 04:44 - 2013-11-15 04:44 - 01071224 _____ (Solid State Networks) C:\Users\Enti-Power\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe 2013-11-13 16:55 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 16:55 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 16:55 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 16:55 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 16:55 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 16:55 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 16:55 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 16:55 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 16:55 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 16:55 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 16:55 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 16:55 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 16:55 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 16:55 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 16:55 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 16:55 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 16:55 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 16:55 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 16:55 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 16:55 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 16:55 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 16:55 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 16:55 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 16:55 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 16:55 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 16:55 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 16:55 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 16:55 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 16:55 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 16:55 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-12 00:58 - 2013-11-12 00:58 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\Program Files\iTunes 2013-11-12 00:57 - 2013-11-12 00:58 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-11-12 00:57 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iPod 2013-11-12 00:54 - 2013-11-12 00:56 - 100400976 _____ (Apple Inc.) C:\Users\Enti-Power\Downloads\iTunes64Setup.exe 2013-11-04 17:07 - 2013-11-25 19:53 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-04 17:07 - 2013-11-04 17:07 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-11-04 17:06 - 2013-11-04 17:06 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Enti-Power\Downloads\SkypeSetup(1).exe 2013-11-03 01:03 - 2013-10-18 02:36 - 01063200 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-11-03 01:03 - 2013-10-18 02:36 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-11-03 01:03 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-11-03 01:03 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-10-30 20:49 - 2013-10-30 20:49 - 00000000 ___RD C:\Users\Enti-Power\Desktop\Angewandte Betriebswirtschaft ==================== One Month Modified Files and Folders ======= 2013-11-28 16:16 - 2013-11-26 14:05 - 00016521 _____ C:\Users\Enti-Power\Desktop\FRST.txt 2013-11-28 16:14 - 2013-11-28 16:14 - 00891184 _____ C:\Users\Enti-Power\Desktop\SecurityCheck.exe 2013-11-28 16:09 - 2013-04-20 12:04 - 00003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{EC92B82A-5E2C-42BF-80B6-B610C3C9FC23} 2013-11-28 15:19 - 2013-06-09 01:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-28 15:13 - 2013-04-20 11:38 - 01681853 _____ C:\Windows\WindowsUpdate.log 2013-11-28 15:02 - 2009-07-14 05:51 - 00068170 _____ C:\Windows\setupact.log 2013-11-28 14:52 - 2013-04-20 20:30 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Skype 2013-11-28 14:51 - 2013-10-27 21:54 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Dropbox 2013-11-28 13:28 - 2013-11-28 13:28 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-28 13:25 - 2013-04-20 12:13 - 00000000 _____ C:\Windows\Path.idx 2013-11-28 13:24 - 2009-07-14 05:45 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-28 13:24 - 2009-07-14 05:45 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-28 13:22 - 2011-04-12 08:43 - 00696848 _____ C:\Windows\system32\perfh007.dat 2013-11-28 13:22 - 2011-04-12 08:43 - 00148144 _____ C:\Windows\system32\perfc007.dat 2013-11-28 13:22 - 2009-07-14 06:13 - 01613412 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-28 13:20 - 2013-10-27 21:56 - 00000000 ___RD C:\Users\Enti-Power\Dropbox 2013-11-28 13:20 - 2013-04-20 12:08 - 01048576 _____ C:\Windows\PE_Rom.dll 2013-11-28 13:17 - 2013-04-20 11:43 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-28 13:17 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-27 16:24 - 2013-11-27 16:24 - 00000653 _____ C:\Users\Enti-Power\Desktop\JRT.txt 2013-11-27 14:44 - 2013-11-27 14:43 - 01958818 _____ (Farbar) C:\Users\Enti-Power\Desktop\FRST64.exe 2013-11-27 14:37 - 2013-11-27 14:37 - 00000000 ____D C:\Windows\ERUNT 2013-11-27 14:36 - 2013-11-27 14:36 - 01034531 _____ (Thisisu) C:\Users\Enti-Power\Desktop\JRT.exe 2013-11-27 14:22 - 2013-11-27 14:20 - 00000000 ____D C:\AdwCleaner 2013-11-27 14:20 - 2013-11-27 14:20 - 01091882 _____ C:\Users\Enti-Power\Downloads\adwcleaner.exe 2013-11-27 14:18 - 2010-11-21 04:47 - 00012462 _____ C:\Windows\PFRO.log 2013-11-27 14:12 - 2013-11-27 14:12 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-27 14:11 - 2013-11-27 14:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-27 14:10 - 2013-11-27 14:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Enti-Power\Downloads\mbam-setup-1.75.0.1300.exe 2013-11-26 14:05 - 2013-11-26 14:05 - 00024786 _____ C:\Users\Enti-Power\Desktop\Addition.txt 2013-11-26 14:04 - 2013-11-26 14:04 - 00000000 ____D C:\FRST 2013-11-25 19:53 - 2013-11-04 17:07 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-25 19:53 - 2013-04-20 20:30 - 00000000 ____D C:\ProgramData\Skype 2013-11-25 15:41 - 2013-10-04 19:30 - 00000000 ____D C:\Users\Enti-Power\Desktop\Uni Wirt+Recht 2013-11-24 18:29 - 2012-12-25 16:10 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2013-11-21 22:52 - 2013-11-21 22:52 - 00154564 _____ C:\Users\Enti-Power\Desktop\Zusammenfassung Öffentliches Wirtschaftsrecht.odt 2013-11-20 21:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-20 16:08 - 2013-04-20 11:38 - 00001425 _____ C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-20 04:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-20 03:02 - 2013-11-20 03:00 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-20 03:00 - 2013-11-20 03:00 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 03:00 - 2013-11-20 03:00 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 03:00 - 2013-11-20 03:00 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 03:00 - 2013-11-20 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 03:00 - 2013-11-20 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 03:00 - 2013-11-20 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 03:00 - 2013-11-20 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 03:00 - 2013-11-20 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-19 11:21 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-19 03:00 - 2013-04-20 12:13 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-19 03:00 - 2013-04-20 12:13 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-19 03:00 - 2013-04-20 12:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-11-17 17:08 - 2013-04-20 14:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-16 13:29 - 2013-11-16 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 04:44 - 2013-11-15 04:44 - 01071224 _____ (Solid State Networks) C:\Users\Enti-Power\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe 2013-11-14 03:00 - 2013-08-15 15:25 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 03:00 - 2013-04-20 13:18 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-12 00:58 - 2013-11-12 00:58 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iTunes 2013-11-12 00:58 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-11-12 00:57 - 2013-11-12 00:57 - 00000000 ____D C:\Program Files\iPod 2013-11-12 00:56 - 2013-11-12 00:54 - 100400976 _____ (Apple Inc.) C:\Users\Enti-Power\Downloads\iTunes64Setup.exe 2013-11-12 00:48 - 2013-08-18 10:51 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Apple Computer 2013-11-08 13:46 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-11-07 20:26 - 2013-08-13 13:36 - 00000000 ____D C:\Users\Enti-Power\Desktop\Bew 2013-11-05 13:44 - 2013-04-20 11:38 - 00000000 ____D C:\Users\Enti-Power 2013-11-05 12:57 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-11-05 03:14 - 2013-06-10 08:07 - 00000000 ____D C:\Users\Enti-Power\Desktop\crap 2013-11-05 03:13 - 2013-05-17 02:20 - 00000000 ____D C:\Users\Enti-Power\Desktop\- 2013-11-04 17:07 - 2013-11-04 17:07 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-11-04 17:06 - 2013-11-04 17:06 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Enti-Power\Downloads\SkypeSetup(1).exe 2013-11-03 01:03 - 2013-04-20 11:43 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-11-03 01:03 - 2013-04-20 11:43 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-11-03 01:03 - 2013-04-20 11:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-11-02 21:25 - 2013-10-27 21:56 - 00001037 _____ C:\Users\Enti-Power\Desktop\Dropbox.lnk 2013-11-02 21:25 - 2013-10-27 21:54 - 00000000 ____D C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-11-02 21:25 - 2013-04-20 11:38 - 00000000 ___RD C:\Users\Enti-Power\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-30 20:49 - 2013-10-30 20:49 - 00000000 ___RD C:\Users\Enti-Power\Desktop\Angewandte Betriebswirtschaft Some content of TEMP: ==================== C:\Users\Enti-Power\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Enti-Power\AppData\Local\Temp\msgC106.exe C:\Users\Enti-Power\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Enti-Power\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Enti-Power\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Enti-Power\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Enti-Power\AppData\Local\Temp\nvStInst.exe C:\Users\Enti-Power\AppData\Local\Temp\Quarantine.exe C:\Users\Enti-Power\AppData\Local\Temp\SkypeSetup.exe C:\Users\Enti-Power\AppData\Local\Temp\uninst1.exe C:\Users\Enti-Power\AppData\Local\Temp\_is8C28.exe C:\Users\Enti-Power\AppData\Local\Temp\_isA3EC.exe C:\Users\Enti-Power\AppData\Local\Temp\_isF20B.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 03:43 ==================== End Of Log ============================ --- --- --- Hola-Search ist weg. Das Problem, dass er mir die Youtube-Vids usw. mal öfters laden muss, dass sie funktionieren, besteht immer noch. Ist aber vielleicht irgendein Problem mit Firefox und Flash-Plugins etc. Perfekt! Danke für deine schnelle und kompetente Hilfe! |
29.11.2013, 08:58 | #8 |
/// the machine /// TB-Ausbilder | Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Jap, Firefox und Flash beides mal neu installieren. Adobe updaten. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.11.2013, 19:30 | #9 |
| Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Ok super danke Schrauber! Ich hab keine Fragen mir, danke für deine schnelle Hilfe! |
30.11.2013, 16:57 | #10 |
/// the machine /// TB-Ausbilder | Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Hola Search - lässt sich nicht entfernen, nichts zum deinstallieren? |
abend, adware.installbrain, andere, beste, besten, deinstalliere, deinstallieren, einiger, entfernen, google, hilft, internet, nichts, parasit, problem, programme, pup.optional.babylon.a, pup.optional.babylontoolbar.a, pup.optional.datamngr.a, pup.optional.opencandy, pup.optional.softonic, refresh, win, win 7 u, ziemlich |