![]() |
|
Log-Analyse und Auswertung: Win 7 mit 3 Problemen: Problem beim Starten von C:\Users\Admin\AppData\Local\Conduit\BackgroundContainer.dllWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #5 |
![]() | ![]() Win 7 mit 3 Problemen: Problem beim Starten von C:\Users\Admin\AppData\Local\Conduit\BackgroundContainer.dll AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 07/02/2014 um 11:21:50 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Admin - ADMIN-PC # Gestartet von : C:\Users\Admin\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Ciuvo ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v27.0 (de) [ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vy0ud23x.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [31678 octets] - [04/02/2014 20:57:10] AdwCleaner[R1].txt - [1124 octets] - [07/02/2014 11:20:17] AdwCleaner[S0].txt - [29110 octets] - [04/02/2014 21:00:45] AdwCleaner[S1].txt - [998 octets] - [07/02/2014 11:21:50] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1057 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 13/02/2014 um 19:51:18 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Admin - ADMIN-PC # Gestartet von : C:\Users\Admin\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Windows\Tasks\PC Performer_DEFAULT.job Datei Gelöscht : C:\Windows\Tasks\PC Performer_UPDATES.job ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Mozilla Firefox v -\\ Google Chrome v [ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [57627 octets] - [04/02/2014 20:57:10] AdwCleaner[R1].txt - [2231 octets] - [07/02/2014 11:20:17] AdwCleaner[S0].txt - [52466 octets] - [04/02/2014 21:00:45] AdwCleaner[S1].txt - [2105 octets] - [07/02/2014 11:21:50] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2165 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows 7 Home Premium x64 Ran by Admin on 13.02.2014 at 20:04:23,07 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.02.2014 at 20:11:33,58 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-02-2014 01 Ran by Admin (administrator) on ADMIN-PC on 13-02-2014 22:07:41 Running from C:\Users\Admin\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\iologovernor64.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (iolo technologies, LLC) C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Users\Admin\AppData\LocalLow\WOT\IE\WOTUpdater.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (TomTom) C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11369576 2010-08-11] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2586504 2010-08-05] (ELAN Microelectronics Corp.) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-24] (CANON INC.) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM-x32\...\Run: [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2010-03-02] (CANON INC.) HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q "\SearchProtect" HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\Run: [Adobe Reader Synchronizer] - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe [698760 2013-12-21] (Adobe Systems Incorporated) HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\Run: [MyDriveConnect.exe] - C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [473496 2013-11-29] (TomTom) HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: E - E:\FSetup.exe HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: F - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {07f834b9-1f13-11e1-83a1-002454de19a2} - D:\AutoRun.exe HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {07f834c6-1f13-11e1-83a1-002454de19a2} - D:\AutoRun.exe HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {113f40c1-3f62-11e1-82e2-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {113f4107-3f62-11e1-82e2-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {113f4130-3f62-11e1-82e2-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {1620fda4-2988-11e2-83cf-4cedde226fcd} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {1620fe48-2988-11e2-83cf-001e101f7f74} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {244b3c55-2178-11e1-8370-4cedde226fcd} - D:\AutoRun.exe HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {25a37d7e-6187-11e1-b279-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {3928e14d-bdf7-11e2-9a7b-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {3928e15f-bdf7-11e2-9a7b-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {3928e190-bdf7-11e2-9a7b-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {3928e19b-bdf7-11e2-9a7b-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {3928e1ab-bdf7-11e2-9a7b-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {488a0f77-4539-11e2-883f-4cedde226fcd} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {488a0ff5-4539-11e2-883f-4cedde226fcd} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {488a1018-4539-11e2-883f-4cedde226fcd} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {488a1027-4539-11e2-883f-4cedde226fcd} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {5497a038-44cc-11e2-b233-001e101fe70e} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {5497a04f-44cc-11e2-b233-001e101fe70e} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {9fc37f9d-eb8f-11e2-b1d3-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {aa50d1b7-6f0f-11e2-a9cf-806e6f6e6963} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {ad5d6f15-4b3c-11e1-82ef-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {ad5d6f9d-4b3c-11e1-82ef-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {b3055611-66b6-11e2-9930-002454de19a2} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {cb651a38-f569-11e2-b17d-4cedde226fcd} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-184453861-435592055-3614440537-1000\...\MountPoints2: {f58342a0-9aa9-11e1-88d7-002454de19a2} - D:\.\Setup.exe AUTORUN=1 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ SearchScopes: HKCU - DefaultScope {C5DEEA89-9BC1-4B78-8FA0-396C4C484222} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie SearchScopes: HKCU - {C5DEEA89-9BC1-4B78-8FA0-396C4C484222} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie SearchScopes: HKCU - {CA715ED4-91FF-4F5E-A053-EA79F72CDBD0} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} BHO: Plus-HD-2.6 - {11111111-1111-1111-1111-110311341140} - C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-bho64.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: WOT - {9E571C81-21E7-496B-9E6B-127E60263022} - C:\Users\Admin\AppData\LocalLow\WOT\IE\WOT.dll (WOT Services Oy) BHO-x32: W2PBrowser Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml Chrome: ======= CHR Extension: (Der Schnäppchenfuchs Gutscheinfinder) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\camijhkahcckljhgpgfgglbegedoepda [2014-01-13] CHR HKLM\...\Chrome\Extension: [camijhkahcckljhgpgfgglbegedoepda] - C:\Program Files (x86)\PallySoftAddon\PallySoftAddon-crx.crx [2014-01-13] CHR HKCU\...\Chrome\Extension: [camijhkahcckljhgpgfgglbegedoepda] - C:\Program Files (x86)\PallySoftAddon\PallySoftAddon-crx.crx [2014-01-13] CHR HKLM-x32\...\Chrome\Extension: [camijhkahcckljhgpgfgglbegedoepda] - C:\Program Files (x86)\PallySoftAddon\PallySoftAddon-crx.crx [2014-01-13] CHR HKLM-x32\...\Chrome\Extension: [nphjeokkkbngjpiofnfpnafjeofjomfb] - C:\Users\Admin\AppData\LocalLow\WOT\CHROME\WOT.crx [2012-01-12] ==================== Services (Whitelisted) ================= R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-08-16] () S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) S4 Brother XP spl Service; C:\Windows\SysWOW64\brsvc01a.exe [57344 2004-06-13] (brother Industries Ltd) S4 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [570368 2011-10-27] (Hauppauge Computer Works) R2 ioloSystemService; C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [1168960 2014-01-02] (iolo technologies, LLC) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 WOTUpdater; C:\Users\Admin\AppData\LocalLow\WOT\IE\WOTUpdater.exe [18432 2012-01-12] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG) R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2013-05-07] (EldoS Corporation) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [138752 2012-01-19] (Huawei Technologies Co., Ltd.) S3 ewusbnet; C:\Windows\SysWOW64\DRIVERS\ewusbnet.sys [138752 2013-05-18] (Huawei Technologies Co., Ltd.) S3 ew_hwusbdev; C:\Windows\SysWOW64\DRIVERS\ew_hwusbdev.sys [117248 2013-05-18] (Huawei Technologies Co., Ltd.) S3 hcw10bda; C:\Windows\System32\drivers\hcw10bda.sys [641920 2010-12-09] (Hauppauge Computer Works, Inc.) S2 hcw10cir; C:\Windows\System32\drivers\hcw10cir.sys [46080 2010-05-10] (Hauppauge Computer Works, Inc.) S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [121600 2013-05-18] (Huawei Technologies Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2010-10-16] (Windows (R) 2003 DDK 3790 provider) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-13 20:11 - 2014-02-13 20:11 - 00000625 ____C () C:\Users\Admin\Desktop\JRT.txt 2014-02-13 17:00 - 2014-02-13 17:44 - 00000000 ___DC () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-02-13 17:00 - 2014-02-13 17:00 - 00119000 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-02-13 16:56 - 2014-02-13 17:44 - 00000000 ___DC () C:\Users\Admin\Desktop\mbar 2014-02-13 16:56 - 2014-02-13 16:56 - 00091352 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-02-13 16:51 - 2014-02-13 16:51 - 12589848 ____C (Malwarebytes Corp.) C:\Users\Admin\Desktop\mbar-1.07.0.1009.exe 2014-02-13 13:48 - 2014-02-13 13:49 - 00026671 ____C () C:\Users\Admin\Desktop\Addition.txt 2014-02-13 13:42 - 2014-02-13 13:42 - 00002467 ____C () C:\Users\Admin\Desktop\Gmer.log 2014-02-13 13:00 - 2014-02-13 13:00 - 00380416 ____C () C:\Users\Admin\Desktop\Gmer-19357.exe 2014-02-13 12:54 - 2014-02-13 22:07 - 00016847 ____C () C:\Users\Admin\Desktop\FRST.txt 2014-02-13 12:53 - 2014-02-13 22:07 - 00000000 ___DC () C:\Users\Admin\Desktop\FRST-OlderVersion 2014-02-13 12:52 - 2014-02-13 12:52 - 00000472 ____C () C:\Users\Admin\Desktop\defogger_disable.log 2014-02-13 12:52 - 2014-02-13 12:52 - 00000000 ____C () C:\Users\Admin\defogger_reenable 2014-02-13 12:51 - 2014-02-13 12:51 - 00050477 ____C () C:\Users\Admin\Desktop\Defogger.exe 2014-02-13 12:11 - 2014-02-13 12:11 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 12:11 - 2014-02-13 12:11 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 12:10 - 2014-02-13 12:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 12:10 - 2014-02-13 12:11 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 12:10 - 2014-02-13 12:11 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 12:10 - 2014-02-13 12:11 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 12:10 - 2014-02-13 12:11 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 12:10 - 2014-02-13 12:11 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 12:10 - 2014-02-13 12:11 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 12:10 - 2014-02-13 12:11 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 12:10 - 2014-02-13 12:11 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 13:11 - 2014-02-13 12:16 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 13:11 - 2014-02-13 12:16 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 13:11 - 2014-02-13 12:15 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 13:11 - 2014-02-13 12:15 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 13:11 - 2014-02-13 12:15 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 13:10 - 2014-02-13 12:14 - 06573056 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-02-12 13:10 - 2014-02-13 12:14 - 05693440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-02-12 13:10 - 2014-02-13 12:13 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-12 13:10 - 2014-02-13 12:13 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 13:10 - 2014-02-13 12:13 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 13:10 - 2014-02-13 12:13 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-10 21:19 - 2014-02-13 22:07 - 02152960 ____C (Farbar) C:\Users\Admin\Desktop\FRST64.exe 2014-02-10 18:05 - 2014-02-10 18:05 - 00000335 ____C () C:\Users\Admin\Fixlist.txt 2014-02-10 17:33 - 2014-02-10 17:34 - 01037530 ____C (Thisisu) C:\Users\Admin\Desktop\JRT.exe 2014-02-10 17:22 - 2014-02-10 17:22 - 01166132 ____C () C:\Users\Admin\Desktop\adwcleaner.exe 2014-02-10 17:05 - 2014-02-10 17:05 - 00001105 ____C () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-10 17:05 - 2014-02-10 17:05 - 00000000 ___DC () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-10 17:05 - 2013-04-04 14:50 - 00025928 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-10 17:03 - 2014-02-10 17:03 - 10285040 ____C (Malwarebytes Corporation ) C:\Users\Admin\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-08 22:58 - 2014-02-08 22:58 - 00001912 ____C () C:\Windows\epplauncher.mif 2014-02-08 22:58 - 2014-02-08 22:58 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Security Client 2014-02-07 13:02 - 2014-02-08 22:58 - 00000000 ___DC () C:\Program Files\Microsoft Security Client 2014-02-05 22:31 - 2014-02-05 22:31 - 00000000 ___DC () C:\Users\Admin\AppData\Local\Macromedia 2014-02-05 21:59 - 2014-02-05 21:59 - 00000000 ___DC () C:\Users\Admin\AppData\Local\Mozilla 2014-02-05 21:59 - 2014-02-05 21:59 - 00000000 ___DC () C:\ProgramData\Mozilla 2014-02-04 21:14 - 2014-02-04 21:14 - 00000000 ___DC () C:\Windows\ERUNT 2014-02-04 20:56 - 2014-02-13 19:59 - 00000000 ___DC () C:\AdwCleaner 2014-02-04 20:12 - 2014-02-04 20:12 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-02-04 20:12 - 2014-02-04 20:12 - 00000000 ___DC () C:\ProgramData\Malwarebytes 2014-02-04 18:04 - 2014-02-13 22:07 - 00000000 ___DC () C:\FRST 2014-02-01 18:24 - 2014-02-01 18:24 - 00090112 ____C () C:\Users\Admin\Desktop\D- Mädchen- Spielplan.xls 2014-01-16 22:05 - 2014-01-16 22:05 - 00003118 ____C () C:\Windows\System32\Tasks\iolo Process Governor 2014-01-16 22:05 - 2014-01-16 22:05 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\ioloGovernor 2014-01-16 22:05 - 2014-01-16 22:05 - 00000000 ___DC () C:\ProgramData\ioloGovernor 2014-01-16 15:29 - 2014-02-07 22:12 - 00000000 ___DC () C:\Program Files (x86)\Avira 2014-01-16 15:29 - 2013-12-18 09:32 - 00131576 ____C (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-01-16 15:29 - 2013-12-18 09:32 - 00108440 ____C (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-01-16 15:29 - 2013-12-18 09:32 - 00028600 ____C (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-01-15 13:56 - 2014-01-15 15:16 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-15 13:56 - 2014-01-15 15:16 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 13:56 - 2013-11-27 02:41 - 00343040 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 13:56 - 2013-11-27 02:41 - 00325120 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 13:56 - 2013-11-27 02:41 - 00099840 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 13:56 - 2013-11-27 02:41 - 00053248 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 13:56 - 2013-11-27 02:41 - 00030720 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 13:56 - 2013-11-27 02:41 - 00025600 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 13:56 - 2013-11-27 02:41 - 00007808 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-14 13:06 - 2014-01-14 13:06 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\Check Point Software Technologies LTD 2014-01-14 13:04 - 2014-01-14 13:04 - 00002972 ____C () C:\Windows\System32\Tasks\{4452FA3D-120C-422A-A66D-7682A63E81E3} 2014-01-14 13:01 - 2014-01-14 13:01 - 00943872 ____C () C:\Users\Admin\Downloads\Adobe-Flash-Player-Setup.exe 2014-01-14 11:07 - 2014-01-14 11:07 - 00000000 ___DC () C:\Program Files (x86)\Google ==================== One Month Modified Files and Folders ======= 2014-02-13 22:07 - 2014-02-13 12:54 - 00016847 ____C () C:\Users\Admin\Desktop\FRST.txt 2014-02-13 22:07 - 2014-02-13 12:53 - 00000000 ___DC () C:\Users\Admin\Desktop\FRST-OlderVersion 2014-02-13 22:07 - 2014-02-10 21:19 - 02152960 ____C (Farbar) C:\Users\Admin\Desktop\FRST64.exe 2014-02-13 22:07 - 2014-02-04 18:04 - 00000000 ___DC () C:\FRST 2014-02-13 20:11 - 2014-02-13 20:11 - 00000625 ____C () C:\Users\Admin\Desktop\JRT.txt 2014-02-13 19:59 - 2014-02-04 20:56 - 00000000 ___DC () C:\AdwCleaner 2014-02-13 19:59 - 2009-07-14 05:45 - 00013936 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-13 19:59 - 2009-07-14 05:45 - 00013936 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-13 19:53 - 2012-01-16 13:43 - 00000000 ___DC () C:\Users\Admin\Desktop\Kurzfristige Datei 2014-02-13 19:52 - 2012-10-04 10:25 - 00039572 ____C () C:\Windows\setupact.log 2014-02-13 19:52 - 2009-07-14 06:08 - 00000006 ___HC () C:\Windows\Tasks\SA.DAT 2014-02-13 19:51 - 2010-09-01 00:01 - 01321064 ____C () C:\Windows\WindowsUpdate.log 2014-02-13 18:37 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-13 18:06 - 2012-01-02 15:34 - 00003930 ____C () C:\Windows\System32\Tasks\User_Feed_Synchronization-{EA6C763E-97F2-4220-93F2-531FCE4ABB8C} 2014-02-13 17:44 - 2014-02-13 17:00 - 00000000 ___DC () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-02-13 17:44 - 2014-02-13 16:56 - 00000000 ___DC () C:\Users\Admin\Desktop\mbar 2014-02-13 17:00 - 2014-02-13 17:00 - 00119000 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-02-13 16:56 - 2014-02-13 16:56 - 00091352 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-02-13 16:51 - 2014-02-13 16:51 - 12589848 ____C (Malwarebytes Corp.) C:\Users\Admin\Desktop\mbar-1.07.0.1009.exe 2014-02-13 13:49 - 2014-02-13 13:48 - 00026671 ____C () C:\Users\Admin\Desktop\Addition.txt 2014-02-13 13:42 - 2014-02-13 13:42 - 00002467 ____C () C:\Users\Admin\Desktop\Gmer.log 2014-02-13 13:00 - 2014-02-13 13:00 - 00380416 ____C () C:\Users\Admin\Desktop\Gmer-19357.exe 2014-02-13 12:52 - 2014-02-13 12:52 - 00000472 ____C () C:\Users\Admin\Desktop\defogger_disable.log 2014-02-13 12:52 - 2014-02-13 12:52 - 00000000 ____C () C:\Users\Admin\defogger_reenable 2014-02-13 12:52 - 2010-10-28 15:35 - 00000000 ___DC () C:\Users\Admin 2014-02-13 12:51 - 2014-02-13 12:51 - 00050477 ____C () C:\Users\Admin\Desktop\Defogger.exe 2014-02-13 12:24 - 2012-10-10 20:16 - 00320262 ____C () C:\Windows\PFRO.log 2014-02-13 12:17 - 2011-08-19 14:49 - 00000000 ___DC () C:\Users\Default\AppData\Local\Microsoft Help 2014-02-13 12:17 - 2011-08-19 14:49 - 00000000 ___DC () C:\Users\Default User\AppData\Local\Microsoft Help 2014-02-13 12:16 - 2014-02-12 13:11 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-13 12:16 - 2014-02-12 13:11 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-13 12:15 - 2014-02-12 13:11 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-13 12:15 - 2014-02-12 13:11 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-13 12:15 - 2014-02-12 13:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-13 12:14 - 2014-02-12 13:10 - 06573056 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-02-13 12:14 - 2014-02-12 13:10 - 05693440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-02-13 12:13 - 2014-02-12 13:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-13 12:13 - 2014-02-12 13:10 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-13 12:13 - 2014-02-12 13:10 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-13 12:13 - 2014-02-12 13:10 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-13 12:12 - 2009-07-14 03:34 - 00000478 ____C () C:\Windows\win.ini 2014-02-13 12:11 - 2014-02-13 12:11 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 12:11 - 2014-02-13 12:11 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 12:11 - 2014-02-13 12:10 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 12:11 - 2014-02-13 12:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 12:11 - 2014-02-13 12:10 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 12:11 - 2014-02-13 12:10 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 12:11 - 2014-02-13 12:10 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 12:11 - 2014-02-13 12:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 12:11 - 2014-02-13 12:10 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 12:11 - 2014-02-13 12:10 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 12:11 - 2014-02-13 12:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 15:31 - 2010-10-28 15:37 - 00000000 ___DC () C:\Users\Admin\AppData\Local\Adobe 2014-02-10 18:05 - 2014-02-10 18:05 - 00000335 ____C () C:\Users\Admin\Fixlist.txt 2014-02-10 17:34 - 2014-02-10 17:33 - 01037530 ____C (Thisisu) C:\Users\Admin\Desktop\JRT.exe 2014-02-10 17:25 - 2012-07-04 21:38 - 00000000 ___DC () C:\Program Files (x86)\Mozilla Firefox 2014-02-10 17:22 - 2014-02-10 17:22 - 01166132 ____C () C:\Users\Admin\Desktop\adwcleaner.exe 2014-02-10 17:05 - 2014-02-10 17:05 - 00001105 ____C () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-10 17:05 - 2014-02-10 17:05 - 00000000 ___DC () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-10 17:03 - 2014-02-10 17:03 - 10285040 ____C (Malwarebytes Corporation ) C:\Users\Admin\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-10 13:13 - 2010-09-01 05:23 - 00700134 ____C () C:\Windows\system32\perfh007.dat 2014-02-10 13:13 - 2010-09-01 05:23 - 00149984 ____C () C:\Windows\system32\perfc007.dat 2014-02-10 13:13 - 2009-07-14 06:13 - 01622236 ____C () C:\Windows\system32\PerfStringBackup.INI 2014-02-10 12:45 - 2010-10-28 15:35 - 00000000 _SHDC () C:\Recovery 2014-02-08 22:58 - 2014-02-08 22:58 - 00001912 ____C () C:\Windows\epplauncher.mif 2014-02-08 22:58 - 2014-02-08 22:58 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Security Client 2014-02-08 22:58 - 2014-02-07 13:02 - 00000000 ___DC () C:\Program Files\Microsoft Security Client 2014-02-07 22:20 - 2010-12-08 17:12 - 00000000 ___DC () C:\Users\Admin\AppData\Local\CrashDumps 2014-02-07 22:13 - 2011-11-12 11:13 - 00000000 ___DC () C:\Windows\system32\Macromed 2014-02-07 22:13 - 2010-11-06 18:36 - 00000000 ___DC () C:\Users\Gast 2014-02-07 22:13 - 2010-11-06 18:36 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 2014-02-07 22:13 - 2010-10-28 15:42 - 00000000 ___DC () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 2014-02-07 22:13 - 2010-10-28 15:42 - 00000000 ___DC () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 2014-02-07 22:13 - 2010-10-28 15:42 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 2014-02-07 22:13 - 2010-10-28 15:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 2014-02-07 22:13 - 2009-07-14 04:20 - 00000000 ___DC () C:\Windows\AppCompat 2014-02-07 22:12 - 2014-01-16 15:29 - 00000000 ___DC () C:\Program Files (x86)\Avira 2014-02-07 22:12 - 2014-01-09 16:59 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\iolo 2014-02-07 22:12 - 2012-10-19 19:14 - 00000000 ___DC () C:\ProgramData\Avira 2014-02-07 22:12 - 2012-09-07 21:18 - 00000000 __HDC () C:\ProgramData\CanonIJEGV 2014-02-07 22:12 - 2010-09-01 00:09 - 00000000 ___DC () C:\ProgramData\WinClon 2014-02-07 22:11 - 2010-12-12 17:02 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\Skype 2014-02-07 22:11 - 2009-07-14 04:20 - 00000000 ___DC () C:\Windows\registration 2014-02-07 22:08 - 2010-12-06 21:40 - 00000000 _RHDC () C:\MSOCache 2014-02-05 22:31 - 2014-02-05 22:31 - 00000000 ___DC () C:\Users\Admin\AppData\Local\Macromedia 2014-02-05 21:59 - 2014-02-05 21:59 - 00000000 ___DC () C:\Users\Admin\AppData\Local\Mozilla 2014-02-05 21:59 - 2014-02-05 21:59 - 00000000 ___DC () C:\ProgramData\Mozilla 2014-02-04 21:14 - 2014-02-04 21:14 - 00000000 ___DC () C:\Windows\ERUNT 2014-02-04 20:12 - 2014-02-04 20:12 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-02-04 20:12 - 2014-02-04 20:12 - 00000000 ___DC () C:\ProgramData\Malwarebytes 2014-02-01 18:24 - 2014-02-01 18:24 - 00090112 ____C () C:\Users\Admin\Desktop\D- Mädchen- Spielplan.xls 2014-01-19 08:33 - 2010-12-07 19:41 - 00270496 ____C (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-01-16 22:06 - 2014-01-09 16:59 - 00000000 ___DC () C:\ProgramData\iolo 2014-01-16 22:05 - 2014-01-16 22:05 - 00003118 ____C () C:\Windows\System32\Tasks\iolo Process Governor 2014-01-16 22:05 - 2014-01-16 22:05 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\ioloGovernor 2014-01-16 22:05 - 2014-01-16 22:05 - 00000000 ___DC () C:\ProgramData\ioloGovernor 2014-01-16 22:05 - 2014-01-09 17:03 - 00001421 ____C () C:\Users\Admin\Desktop\System Mechanic.lnk 2014-01-15 20:02 - 2009-07-14 05:45 - 00438904 ____C () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 15:16 - 2014-01-15 13:56 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-15 15:16 - 2014-01-15 13:56 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 15:16 - 2013-08-14 22:01 - 00000000 ___DC () C:\Windows\system32\MRT 2014-01-15 15:14 - 2010-12-07 17:34 - 86054176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-14 13:06 - 2014-01-14 13:06 - 00000000 ___DC () C:\Users\Admin\AppData\Roaming\Check Point Software Technologies LTD 2014-01-14 13:04 - 2014-01-14 13:04 - 00002972 ____C () C:\Windows\System32\Tasks\{4452FA3D-120C-422A-A66D-7682A63E81E3} 2014-01-14 13:01 - 2014-01-14 13:01 - 00943872 ____C () C:\Users\Admin\Downloads\Adobe-Flash-Player-Setup.exe 2014-01-14 11:07 - 2014-01-14 11:07 - 00000000 ___DC () C:\Program Files (x86)\Google 2014-01-14 11:07 - 2014-01-13 11:53 - 00000000 ___DC () C:\Users\Admin\AppData\Local\Google Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-08 14:57 ==================== End Of Log ============================ --- --- --- |
Themen zu Win 7 mit 3 Problemen: Problem beim Starten von C:\Users\Admin\AppData\Local\Conduit\BackgroundContainer.dll |
appdata, avira, backgroundcontainer, beim starten, branding, canon, control, feature, file, funktioniert, gen, hochfahren, kein update, laufwerk, leeren, meldungen, papierkorb, please, problem, probleme, scan, schonmal, setup, starten, systemwiederherstellung, update, updaten, virenscan, wildtangent games, win |