Hallo, seit ein paar Tagen öffnen sich sehr häufig - ohne ersichtlichen Grund - Hilfeseite von Windows, Thunderbird, Firexfox etc. Oft öffnet sich sehr oft die gleiche Hilfeseite, sodass das Arbeiten mit dem Rechner schwierig ist. Ich habe standardmässig Bitfender Total Security 2013 im Hintergrund laufen und habe Malewarebytes Anti-Malware Pro drüberlaufen lassen - es wurden auch einige infizierte Dateien gefunden, die ich mit dem letzten Programm gelöscht habe, aber es hat das Problem leider nicht gelöst. Bitte freundlich um Hinweise, was ich noch tun kann um den "Plagegeist" loszuwerden.
2014-02-20 09:14 - 2012-11-15 19:35 - 00000000 ____D () C:\Intel 2014-02-19 16:03 - 00000470 _____ () C:\Windows\SysWOW64\defogger_disable.log 2014-02-19 15:51 - 2014-02-19 15:51 - 00296784 _____ () C:\Windows\Minidump\021914-7562-01.dmp 2014-02-19 15:44 - 2014-02-19 15:44 - 00299816 _____ () C:\Windows\Minidump\021914-7718-01.dmp 2014-02-19 15:43 - 2014-02-19 15:43 - 00380416 _____ () C:\Users\Juga\Desktop\Gmer-19357.exe 2014-02-19 15:42 - 2014-02-19 16:19 - 00029451 _____ () C:\Users\Juga\Desktop\Addition.txt 2014-02-19 12:46 - 2014-02-19 12:46 - 01141248 _____ (Farbar) C:\Users\Juga\Downloads\FRST.exe 2014-02-19 12:46 - 2014-02-19 12:46 - 00000470 _____ () C:\Users\Juga\Downloads\defogger_disable.log 2014-02-19 12:46 - 2014-02-19 12:46 - 00000000 _____ () C:\Users\Juga\defogger_reenable 2014-02-19 12:45 - 2014-02-19 12:45 - 00050477 _____ () C:\Users\Juga\Desktop\Defogger.exe 2014-02-19 12:43 - 2014-02-19 12:43 - 00002640 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-02-19 12:43 - 2013-07-26 23:49 - 00000101 _____ () C:\Users\Juga\AppData\Roaming\WB.CFG 2014-02-19 12:06 - 2013-06-30 21:58 - 524288512 _____ () C:\Users\Juga\Desktop\Datentresor - Ruppert.bvd 2014-02-18 08:48 - 2014-02-18 08:48 - 00003142 _____ () C:\Windows\System32\Tasks\{CEEC242F-CB31-4B7C-BA41-759D23FC22A4} 2014-02-18 08:47 - 2014-02-18 08:47 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(1).exe 2014-02-17 23:03 - 2012-07-26 09:14 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-17 23:03 - 2012-07-26 09:14 - 00078304 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 20:42 - 2013-09-14 22:45 - 00000000 ____D () C:\Users\Juga\Documents\Calibre-Bibliothek 2014-02-17 20:40 - 2014-02-17 20:40 - 01816433 _____ () C:\Users\Juga\Downloads\tools_v6.0.8.zip 2014-02-17 20:29 - 2014-02-17 20:29 - 09954793 _____ () C:\Users\Juga\Downloads\Ultimate-DRM-Removal-last.zip 2014-02-17 09:25 - 2014-02-17 09:23 - 88898427 _____ () C:\Users\Juga\Desktop\Tumblr_Video.mp4 2014-02-16 22:20 - 2013-05-06 18:51 - 00000000 ____D () C:\Users\Juga\AppData\Local\VirtualStore 2014-02-16 22:08 - 2012-08-02 23:24 - 00000000 ____D () C:\Windows\Panther 2014-02-16 22:06 - 2014-02-16 22:06 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-02-16 22:06 - 2014-02-16 22:06 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-16 22:06 - 2014-02-16 22:05 - 03645064 _____ (Piriform Ltd) C:\Users\Juga\Downloads\ccsetup410_slim.exe 2014-02-16 12:59 - 2014-02-16 12:58 - 54537728 _____ () C:\Users\Juga\Downloads\calibre-1.24.0.msi 2014-02-16 07:33 - 2013-06-22 06:43 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\gnupg 2014-02-15 20:19 - 2013-11-02 21:49 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-15 20:17 - 2014-02-15 20:17 - 24490112 _____ (Mozilla) C:\Users\Juga\Downloads\Firefox Setup 27.0.1.exe 2014-02-15 15:28 - 2013-07-11 10:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-15 15:27 - 2013-05-06 19:57 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 00:49 - 2014-02-15 00:23 - 130171322 _____ () C:\Users\Juga\Desktop\1103195_white_ass_slut_fucked_twice_bare_creamed_huge_black_.flv 2014-02-14 19:21 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI(1020) 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\Downloads\Steganos-SpurenVernichter 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\ChromeExtensions 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\NVIDIA 2014-02-13 09:56 - 2014-02-13 09:56 - 01059584 _____ () C:\Users\Juga\Downloads\Steganos-SpurenVernichter-Setup.exe 2014-02-13 06:43 - 2014-02-13 06:43 - 00001237 _____ () C:\Users\Juga\Downloads\URLLink(6).acsm 2014-02-09 15:20 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-08 11:19 - 2014-02-08 11:19 - 00003576 _____ () C:\Users\Juga\Desktop\anschreibenMBWK.tex 2014-02-02 12:22 - 2014-02-02 12:22 - 00007374 _____ () C:\Users\Juga\Desktop\Preisinformation zum 1. März 2014.eml 2014-02-01 10:20 - 2014-02-13 22:03 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-01 10:19 - 2014-02-13 22:03 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-01 10:19 - 2014-02-13 22:03 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-01 10:19 - 2014-02-13 22:03 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-02-01 10:19 - 2014-02-13 22:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-01 10:18 - 2014-02-13 22:02 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-01 10:18 - 2014-02-13 22:02 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-01 08:58 - 2014-02-13 22:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-01 08:58 - 2014-02-13 22:03 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-01 08:58 - 2014-02-13 22:03 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-02-01 08:40 - 2014-02-13 22:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-01 08:34 - 2014-02-13 22:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-01 06:08 - 2014-02-13 22:03 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-01-26 10:21 - 2013-11-02 21:48 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-26 10:15 - 2014-01-26 10:15 - 00921000 _____ (Oracle Corporation) C:\Users\Juga\Downloads\jxpiinstall.exe Files to move or delete: ==================== C:\Users\Juga\AppData\Roaming\Camdata.ini C:\Users\Juga\AppData\Roaming\CamLayout.ini C:\Users\Juga\AppData\Roaming\CamShapes.ini C:\Users\Juga\AppData\Roaming\CamStudio.Producer.Data.ini Some content of TEMP: ==================== C:\Users\Juga\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-17 09:01 ==================== End Of Log ============================ --- --- --- |
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
| ![]() Windows 8: Hilfeseiten von Windows, Thunderbirg, Firefox etc. öffnen sich dauernd von selbst. ESET - ist ganz lange gelaufen log.txt Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=b4cd9c0265590f40944309abbe904af6 # engine=17208 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-25 01:24:10 # local_time=2014-02-25 02:24:10 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.2.9200 NT # compatibility_mode=5893 16776574 100 94 449061 52840761 0 0 # scanned=359835 # found=0 # cleaned=0 # scan_time=54564 SecurityCheck Code:
ATTFilter Results of screen317's Security Check version 0.99.79 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Windows Defender Bitdefender Virenschutz Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version Java 7 Update 51 Adobe Flash Player Adobe Reader XI Mozilla Firefox (27.0.1) Mozilla Thunderbird (24.3.0) Google Chrome 32.0.1700.107 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe Bitdefender Bitdefender 2013 vsserv.exe Bitdefender Bitdefender SafeBox safeboxservice.exe Bitdefender Bitdefender 2013 bdagent.exe Mobile Partner OnlineUpdate ouc.exe StarMoney 9.0 ouservice StarMoneyOnlineUpdate.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
FRST und die Antwort auf meine Frage fehlt noch
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| ![]() Windows 8: Hilfeseiten von Windows, Thunderbirg, Firefox etc. öffnen sich dauernd von selbst. Hallo, sorry, hatte das FRST File vergessen. Die letzten paar Stunden ist der Fehler nicht mehr aufgetreten. Ich hoffe, es bleibt so. Herzlichen Dank! Woran lag es? Kann ich etwas tun, um soetwas in Zukunft zu verhindern? FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-02-2014 02 Ran by Juga (administrator) on LAPTOP on 26-02-2014 18:42:33 Running from C:\Users\Juga\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe () C:\Windows\system32\DptfParticipantProcessorService.exe () C:\Windows\system32\DptfPolicyConfigTDPService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Sony Corporation) C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-30] (Realtek Semiconductor) HKLM\...\Run: [ASUSQuickGesture(x86)] - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe [20352 2012-09-11] (ASUSTeK Computer Inc.) HKLM\...\Run: [ASUSTPLoader(x64)] - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe [169856 2012-09-11] (AsusTek) HKLM\...\Run: [ASUSQuickGesture(x64)] - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe [22400 2012-09-11] (ASUSTeK Computer Inc.) HKLM\...\Run: [DptfPolicyLpmServiceHelper] - C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [21888 2012-07-30] () HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS) HKLM\...\Run: [Bdagent] - C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2013-10-25] (Bitdefender) HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [7818040 2013-09-19] (Motorola Solutions, Inc.) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Reader Application Helper] - C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-11-27] (Sony Corporation) HKLM-x32\...\Run: [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2258056 2013-09-22] (Microsoft Corp.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [] - [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: ASUS Browser Extension x64 - {78234974-0C4B-4111-BDEB-D9A104418772} - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x64\BrowserExtension64.dll (ASUSTeK Computer Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: ASUS Browser Extension x86 - {78234974-0C4B-4111-BDEB-D9A104418771} - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x86\BrowserExtension.dll (ASUSTeK Computer Inc.) BHO-x32: ividi Helper Object - {8B8B2E80-1444-451D-AC8E-EB9A847F3887} - C:\Program Files (x86)\Unitech LLC\ividi\\bh\ividi.dll No File BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{AEFBB86E-3140-48A0-A253-9D902613CC85}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Juga\AppData\Roaming\Mozilla\Firefox\Profiles\l24us74s.default-1393022713616 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @ei.FromDocToPDF_65.com/Plugin - C:\Program Files (x86)\FromDocToPDF_65EI\Installr\1.bin\NP65EISB.dll (FromDocToPDF) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @sony.com/ReaderDesktop - C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: No Name - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-21] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: No Name - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-06-30] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-19] CHR Extension: (Google Drive) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-19] CHR Extension: (YouTube) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-19] CHR Extension: (Google-Suche) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-19] CHR Extension: (Softonic Chrome Toolbar) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf [2013-10-21] CHR Extension: (Delta Toolbar) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [2014-02-19] CHR Extension: (Amazon-Icon) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [2014-02-19] CHR Extension: (Google Wallet) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-19] CHR Extension: (Google Mail) - C:\Users\Juga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-19] CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Juga\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx [2014-02-13] ==================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2013-10-25] (Bitdefender) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-09-22] (Microsoft Corp.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [515632 2013-05-21] (REINER SCT) R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-05-28] () R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [29056 2012-07-30] () R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [30592 2012-07-30] () R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [339456 2010-11-16] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 Mobile Partner. RunOuc; c:\program files (x86)\mobile partner\updatedog\ouc.exe [218624 2013-05-09] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] () R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) S2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [95184 2012-06-25] (Bitdefender) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-10-25] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-10-25] (Bitdefender) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [56704 2012-09-11] (ASUS Corporation) R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-10-25] (BitDefender) R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-10-25] (BitDefender) S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23456 2012-07-11] (Bitdefender) R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-10-25] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-10-25] (BitDefender LLC) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-10-25] (BitDefender SRL) R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-10-25] (BitDefender) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.) S3 cjusb; C:\Windows\system32\DRIVERS\cjusb.sys [35192 2012-09-04] (REINER SCT) R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107328 2012-07-13] (Intel Corporation) R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42816 2012-07-13] (Intel Corporation) R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64832 2012-07-13] (Intel Corporation) R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96064 2012-07-13] (Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [228672 2012-07-13] (Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [361792 2012-07-13] (Intel Corporation) S3 ewusbnet; C:\Windows\system32\DRIVERS\ewusbnet.sys [256000 2013-05-09] (Huawei Technologies Co., Ltd.) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-10-25] (BitDefender LLC) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-10-08] (Intel Corporation) R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) R2 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-10-25] (BitDefender S.R.L.) S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48096 2012-08-09] (Windows (R) Win 7 DDK provider) S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider) U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-26 18:42 - 2014-02-26 18:42 - 00022644 _____ () C:\Users\Juga\Desktop\FRST.txt 2014-02-26 13:59 - 2014-02-26 14:06 - 00001244 _____ () C:\Users\Juga\Desktop\Bahnfahrt-Beschwerde.txt 2014-02-24 23:07 - 2014-02-24 23:07 - 02347384 _____ (ESET) C:\Users\Juga\Downloads\esetsmartinstaller_enu.exe 2014-02-24 23:07 - 2014-02-24 23:07 - 00987425 _____ () C:\Users\Juga\Downloads\SecurityCheck.exe 2014-02-23 21:17 - 2014-02-23 21:17 - 00000000 ____D () C:\Windows\ERUNT 2014-02-23 20:35 - 2014-02-23 20:35 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-23 20:32 - 2014-02-23 20:34 - 00000000 ____D () C:\AdwCleaner 2014-02-23 20:31 - 2014-02-23 20:32 - 01241834 _____ () C:\Users\Juga\Downloads\adwcleaner(2).exe 2014-02-23 20:31 - 2014-02-23 20:31 - 01241834 _____ () C:\Users\Juga\Downloads\adwcleaner(1).exe 2014-02-23 12:43 - 2014-02-23 12:43 - 01241834 _____ () C:\Users\Juga\Downloads\adwcleaner.exe 2014-02-23 12:43 - 2014-02-23 12:43 - 01037734 _____ (Thisisu) C:\Users\Juga\Downloads\JRT.exe 2014-02-23 12:41 - 2014-02-23 23:55 - 00000000 ____D () C:\Users\Juga\Desktop\FRST-OlderVersion 2014-02-23 12:15 - 2014-02-23 12:16 - 00000000 ____D () C:\Recovery 2014-02-23 12:09 - 2014-02-23 12:10 - 00000712 _____ () C:\Windows\DtcInstall.log 2014-02-23 12:05 - 2014-02-23 12:05 - 00001564 _____ () C:\Windows\comsetup.log 2014-02-23 12:01 - 2014-02-23 12:10 - 00658599 _____ () C:\Windows\setupact.log 2014-02-23 12:01 - 2014-02-23 12:01 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-22 12:22 - 2014-02-22 12:22 - 00033083 _____ () C:\ComboFix.txt 2014-02-22 12:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-22 12:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-22 12:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-22 12:08 - 2014-02-22 12:22 - 00000000 ____D () C:\Qoobox 2014-02-22 12:08 - 2014-02-22 12:20 - 00000000 ____D () C:\Windows\erdnt 2014-02-22 12:08 - 2014-02-22 12:08 - 05183886 ____R (Swearware) C:\Users\Juga\Downloads\ComboFix.exe 2014-02-21 23:45 - 2014-02-21 23:45 - 00000000 ____D () C:\Users\Juga\Desktop\Alte Firefox-Daten 2014-02-21 23:44 - 2014-02-21 23:44 - 00019926 _____ () C:\Users\Juga\Desktop\Bestätigung Ihrer Zahlung an Rove.design GmbH.eml 2014-02-20 20:51 - 2014-02-20 21:09 - 182401458 _____ () C:\Users\Juga\Desktop\480_633_M5DAr-G182-50lo.mp4 2014-02-20 16:18 - 2014-02-20 16:22 - 00002167 _____ () C:\Users\Public\Desktop\SteuerSparErklärung 2014.lnk 2014-02-20 16:18 - 2014-02-20 16:18 - 00000000 ____D () C:\Users\Juga\AppData\Local\AAV 2014-02-20 16:16 - 2014-02-20 16:19 - 00000000 ____D () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft 2014-02-20 16:14 - 2014-02-20 16:19 - 00000000 ____D () C:\ProgramData\AAV 2014-02-20 14:27 - 2014-02-20 14:28 - 05631168 _____ (IvoSoft) C:\Users\Juga\Downloads\ClassicShellSetup_4_0_4.exe 2014-02-20 09:42 - 2014-02-20 09:42 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(2).exe 2014-02-20 09:42 - 2014-02-20 09:42 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-20 09:42 - 2014-02-20 09:42 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-20 09:40 - 2014-02-20 09:41 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Bitdefender 2014-02-19 23:33 - 2014-02-26 17:42 - 01073319 _____ () C:\Windows\WindowsUpdate.log 2014-02-19 23:19 - 2014-02-22 12:18 - 00037464 _____ () C:\Windows\PFRO.log 2014-02-19 21:24 - 2014-02-19 21:25 - 00000000 ____D () C:\Program Files (x86)\Google 2014-02-19 20:34 - 2014-02-19 20:34 - 00000000 ____D () C:\ProgramData\ClassicShell 2014-02-19 18:21 - 2014-02-19 18:21 - 00299776 _____ () C:\Windows\Minidump\021914-7500-01.dmp 2014-02-19 18:18 - 2014-02-19 18:18 - 00000470 _____ () C:\Users\Juga\Desktop\defogger_disable.log 2014-02-19 17:09 - 2014-02-19 17:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-consumer.exe 2014-02-19 16:30 - 2014-02-20 09:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-19 16:30 - 2014-02-20 09:38 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Malwarebytes 2014-02-19 16:30 - 2014-02-20 09:38 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-19 16:30 - 2014-02-19 16:30 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-19 16:30 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-19 16:29 - 2014-02-19 16:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-setup- 2014-02-19 16:19 - 2014-02-19 15:42 - 00029451 _____ () C:\Users\Juga\Desktop\Addition.txt 2014-02-19 16:03 - 2014-02-19 16:03 - 00000470 _____ () C:\Windows\SysWOW64\defogger_disable.log 2014-02-19 15:51 - 2014-02-19 15:51 - 00296784 _____ () C:\Windows\Minidump\021914-7562-01.dmp 2014-02-19 15:44 - 2014-02-19 15:44 - 00299816 _____ () C:\Windows\Minidump\021914-7718-01.dmp 2014-02-19 15:43 - 2014-02-19 15:43 - 00380416 _____ () C:\Users\Juga\Desktop\Gmer-19357.exe 2014-02-19 15:41 - 2014-02-23 23:56 - 00000000 ____D () C:\FRST 2014-02-19 12:49 - 2014-02-23 23:55 - 02155520 _____ (Farbar) C:\Users\Juga\Desktop\FRST64.exe 2014-02-19 12:46 - 2014-02-19 12:46 - 01141248 _____ (Farbar) C:\Users\Juga\Downloads\FRST.exe 2014-02-19 12:46 - 2014-02-19 12:46 - 00000470 _____ () C:\Users\Juga\Downloads\defogger_disable.log 2014-02-19 12:46 - 2014-02-19 12:46 - 00000000 _____ () C:\Users\Juga\defogger_reenable 2014-02-19 12:45 - 2014-02-19 12:45 - 00050477 _____ () C:\Users\Juga\Desktop\Defogger.exe 2014-02-19 12:43 - 2014-02-19 12:43 - 00002640 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-02-19 10:15 - 2014-02-19 19:15 - 00003586 _____ () C:\Windows\System32\Tasks\Bitdefender Auto-Scan 2014-02-18 08:48 - 2014-02-20 09:38 - 00000000 ____D () C:\Users\Juga\AppData\Local\Skype 2014-02-18 08:48 - 2014-02-18 08:48 - 00003142 _____ () C:\Windows\System32\Tasks\{CEEC242F-CB31-4B7C-BA41-759D23FC22A4} 2014-02-18 08:47 - 2014-02-18 08:47 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(1).exe 2014-02-17 20:40 - 2014-02-17 20:40 - 01816433 _____ () C:\Users\Juga\Downloads\tools_v6.0.8.zip 2014-02-17 20:29 - 2014-02-17 20:29 - 09954793 _____ () C:\Users\Juga\Downloads\Ultimate-DRM-Removal-last.zip 2014-02-17 09:23 - 2014-02-17 09:25 - 88898427 _____ () C:\Users\Juga\Desktop\Tumblr_Video.mp4 2014-02-16 22:29 - 2014-02-22 12:18 - 00323576 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-16 22:06 - 2014-02-20 09:39 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-16 22:06 - 2014-02-16 22:06 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-02-16 22:06 - 2014-02-16 22:06 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-16 22:05 - 2014-02-16 22:06 - 03645064 _____ (Piriform Ltd) C:\Users\Juga\Downloads\ccsetup410_slim.exe 2014-02-16 17:50 - 2014-02-20 09:39 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-02-16 17:50 - 2014-02-20 09:39 - 00000000 ____D () C:\Windows\system32\NV 2014-02-16 12:58 - 2014-02-16 12:59 - 54537728 _____ () C:\Users\Juga\Downloads\calibre-1.24.0.msi 2014-02-16 06:31 - 2013-12-07 07:36 - 19751936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-02-16 06:31 - 2013-12-07 06:15 - 17560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-02-15 20:17 - 2014-02-15 20:17 - 24490112 _____ (Mozilla) C:\Users\Juga\Downloads\Firefox Setup 27.0.1.exe 2014-02-15 00:23 - 2014-02-15 00:49 - 130171322 _____ () C:\Users\Juga\Desktop\1103195_white_ass_slut_fucked_twice_bare_creamed_huge_black_.flv 2014-02-14 10:11 - 2014-02-20 09:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-13 22:28 - 2013-12-05 00:43 - 00583680 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-13 22:28 - 2013-12-05 00:37 - 00451072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-13 22:04 - 2013-11-01 06:53 - 02232664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-02-13 22:03 - 2014-02-01 10:20 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 22:03 - 2014-02-01 10:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 22:03 - 2014-02-01 10:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 22:03 - 2014-02-01 10:19 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-02-13 22:03 - 2014-02-01 10:19 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 22:03 - 2014-02-01 10:18 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 22:03 - 2014-02-01 08:58 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 22:03 - 2014-02-01 08:58 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 22:03 - 2014-02-01 08:58 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-02-13 22:03 - 2014-02-01 08:57 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 22:03 - 2014-02-01 08:57 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 22:03 - 2014-02-01 08:57 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 22:03 - 2014-02-01 08:57 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-02-13 22:03 - 2014-02-01 08:57 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 22:03 - 2014-02-01 08:57 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 22:03 - 2014-02-01 08:57 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 22:03 - 2014-02-01 08:40 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 22:03 - 2014-02-01 08:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 22:03 - 2014-02-01 06:08 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-02-13 22:03 - 2013-12-09 01:45 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 22:03 - 2013-12-09 00:59 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 22:03 - 2013-12-05 00:43 - 01845248 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-13 22:03 - 2013-12-05 00:37 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-13 22:03 - 2013-11-27 01:19 - 00385614 _____ () C:\Windows\system32\ApnDatabase.xml 2014-02-13 22:03 - 2013-11-26 00:17 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2014-02-13 22:02 - 2014-02-01 10:18 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 22:02 - 2014-02-01 10:18 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 22:02 - 2014-02-01 08:57 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 22:02 - 2014-02-01 08:57 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 22:02 - 2014-02-01 08:57 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 22:02 - 2014-02-01 08:57 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-02-13 09:58 - 2014-02-20 09:39 - 00000000 ____D () C:\Users\Juga\AppData\Local\Tempfeb52be43e051bfaf4839a6935e00e42 2014-02-13 09:58 - 2014-02-20 09:39 - 00000000 ____D () C:\Users\Juga\AppData\Local\Temp12e72473eede95c369de200ff0f01ceb 2014-02-13 09:57 - 2014-02-20 09:39 - 00000000 ____D () C:\Users\Juga\AppData\Local\Temp14b5077f6956a3517aafd12a4b0ddc8f 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\Downloads\Steganos-SpurenVernichter 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\ChromeExtensions 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\NVIDIA 2014-02-13 09:56 - 2014-02-13 09:56 - 01059584 _____ () C:\Users\Juga\Downloads\Steganos-SpurenVernichter-Setup.exe 2014-02-13 06:43 - 2014-02-13 06:43 - 00001237 _____ () C:\Users\Juga\Downloads\URLLink(6).acsm 2014-02-12 11:28 - 2014-01-13 00:30 - 02238976 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 11:28 - 2014-01-13 00:30 - 02032640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 11:28 - 2013-11-20 01:15 - 03842560 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-12 11:28 - 2013-11-20 00:57 - 03288576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-08 11:19 - 2014-02-08 11:19 - 00003576 _____ () C:\Users\Juga\Desktop\anschreibenMBWK.tex 2014-02-05 13:45 - 2014-02-20 09:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-02 12:22 - 2014-02-02 12:22 - 00007374 _____ () C:\Users\Juga\Desktop\Preisinformation zum 1. März 2014.eml ==================== One Month Modified Files and Folders ======= 2014-02-26 18:43 - 2014-02-26 18:42 - 00022644 _____ () C:\Users\Juga\Desktop\FRST.txt 2014-02-26 18:43 - 2013-05-09 10:21 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Skype 2014-02-26 18:42 - 2014-02-19 15:41 - 00000000 ____D () C:\FRST 2014-02-26 18:41 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-02-26 17:47 - 2013-05-06 21:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-26 17:46 - 2013-05-11 16:41 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\vlc 2014-02-26 17:42 - 2014-02-19 23:33 - 01073319 _____ () C:\Windows\WindowsUpdate.log 2014-02-26 15:58 - 2013-06-15 14:16 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\dvdcss 2014-02-26 14:06 - 2014-02-26 13:59 - 00001244 _____ () C:\Users\Juga\Desktop\Bahnfahrt-Beschwerde.txt 2014-02-26 13:53 - 2014-01-08 10:52 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\ClassicShell 2014-02-26 12:14 - 2013-05-09 10:31 - 00000121 _____ () C:\Users\Public\LMDebug.log 2014-02-25 20:26 - 2013-05-07 18:30 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3203196741-1805427045-687499267-1002 2014-02-25 19:44 - 2013-05-06 18:53 - 00000500 _____ () C:\Users\Juga\AppData\Roaming\sp_data.sys 2014-02-25 14:12 - 2013-08-09 17:51 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 2014-02-24 23:07 - 2014-02-24 23:07 - 02347384 _____ (ESET) C:\Users\Juga\Downloads\esetsmartinstaller_enu.exe 2014-02-24 23:07 - 2014-02-24 23:07 - 00987425 _____ () C:\Users\Juga\Downloads\SecurityCheck.exe 2014-02-23 23:55 - 2014-02-23 12:41 - 00000000 ____D () C:\Users\Juga\Desktop\FRST-OlderVersion 2014-02-23 23:55 - 2014-02-19 12:49 - 02155520 _____ (Farbar) C:\Users\Juga\Desktop\FRST64.exe 2014-02-23 21:17 - 2014-02-23 21:17 - 00000000 ____D () C:\Windows\ERUNT 2014-02-23 20:40 - 2012-08-03 00:02 - 00761598 _____ () C:\Windows\system32\perfh007.dat 2014-02-23 20:40 - 2012-08-03 00:02 - 00159306 _____ () C:\Windows\system32\perfc007.dat 2014-02-23 20:40 - 2012-07-26 08:28 - 01748838 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-23 20:35 - 2014-02-23 20:35 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-23 20:35 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-23 20:35 - 2012-07-26 06:26 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-02-23 20:34 - 2014-02-23 20:32 - 00000000 ____D () C:\AdwCleaner 2014-02-23 20:32 - 2014-02-23 20:31 - 01241834 _____ () C:\Users\Juga\Downloads\adwcleaner(2).exe 2014-02-23 20:31 - 2014-02-23 20:31 - 01241834 _____ () C:\Users\Juga\Downloads\adwcleaner(1).exe 2014-02-23 12:43 - 2014-02-23 12:43 - 01241834 _____ () C:\Users\Juga\Downloads\adwcleaner.exe 2014-02-23 12:43 - 2014-02-23 12:43 - 01037734 _____ (Thisisu) C:\Users\Juga\Downloads\JRT.exe 2014-02-23 12:17 - 2013-11-14 09:24 - 00000000 ___HD () C:\$Windows.~BT 2014-02-23 12:16 - 2014-02-23 12:15 - 00000000 ____D () C:\Recovery 2014-02-23 12:10 - 2014-02-23 12:09 - 00000712 _____ () C:\Windows\DtcInstall.log 2014-02-23 12:10 - 2014-02-23 12:01 - 00658599 _____ () C:\Windows\setupact.log 2014-02-23 12:10 - 2013-05-06 18:50 - 00066678 _____ () C:\Windows\diagwrn.xml 2014-02-23 12:10 - 2013-05-06 18:50 - 00066678 _____ () C:\Windows\diagerr.xml 2014-02-23 12:10 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-02-23 12:05 - 2014-02-23 12:05 - 00001564 _____ () C:\Windows\comsetup.log 2014-02-23 12:05 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\registration 2014-02-23 12:04 - 2013-08-18 10:30 - 00008713 _____ () C:\Windows\system32\lvcoinst.log 2014-02-23 12:01 - 2014-02-23 12:01 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-23 11:37 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-02-22 15:31 - 2013-12-29 14:33 - 00000285 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2014-02-22 15:31 - 2013-05-07 21:13 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-22 12:22 - 2014-02-22 12:22 - 00033083 _____ () C:\ComboFix.txt 2014-02-22 12:22 - 2014-02-22 12:08 - 00000000 ____D () C:\Qoobox 2014-02-22 12:22 - 2012-07-26 06:37 - 00000000 __RHD () C:\Users\Default 2014-02-22 12:20 - 2014-02-22 12:08 - 00000000 ____D () C:\Windows\erdnt 2014-02-22 12:19 - 2012-07-26 06:26 - 00000215 _____ () C:\Windows\system.ini 2014-02-22 12:18 - 2014-02-19 23:19 - 00037464 _____ () C:\Windows\PFRO.log 2014-02-22 12:18 - 2014-02-16 22:29 - 00323576 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-22 12:08 - 2014-02-22 12:08 - 05183886 ____R (Swearware) C:\Users\Juga\Downloads\ComboFix.exe 2014-02-21 23:45 - 2014-02-21 23:45 - 00000000 ____D () C:\Users\Juga\Desktop\Alte Firefox-Daten 2014-02-21 23:44 - 2014-02-21 23:44 - 00019926 _____ () C:\Users\Juga\Desktop\Bestätigung Ihrer Zahlung an Rove.design GmbH.eml 2014-02-20 21:09 - 2014-02-20 20:51 - 182401458 _____ () C:\Users\Juga\Desktop\480_633_M5DAr-G182-50lo.mp4 2014-02-20 20:39 - 2013-05-08 17:53 - 00000000 ____D () C:\Users\Juga\AppData\Local\Adobe 2014-02-20 20:38 - 2013-05-06 21:41 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-20 20:38 - 2012-08-17 01:53 - 00000000 ____D () C:\ProgramData\McAfee 2014-02-20 16:22 - 2014-02-20 16:18 - 00002167 _____ () C:\Users\Public\Desktop\SteuerSparErklärung 2014.lnk 2014-02-20 16:19 - 2014-02-20 16:16 - 00000000 ____D () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft 2014-02-20 16:19 - 2014-02-20 16:14 - 00000000 ____D () C:\ProgramData\AAV 2014-02-20 16:18 - 2014-02-20 16:18 - 00000000 ____D () C:\Users\Juga\AppData\Local\AAV 2014-02-20 14:28 - 2014-02-20 14:27 - 05631168 _____ (IvoSoft) C:\Users\Juga\Downloads\ClassicShellSetup_4_0_4.exe 2014-02-20 09:42 - 2014-02-20 09:42 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(2).exe 2014-02-20 09:42 - 2014-02-20 09:42 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-20 09:42 - 2014-02-20 09:42 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-20 09:42 - 2013-05-09 10:21 - 00000000 ____D () C:\ProgramData\Skype 2014-02-20 09:41 - 2014-02-20 09:40 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Bitdefender 2014-02-20 09:41 - 2013-06-30 18:20 - 00000000 ____D () C:\ProgramData\Bitdefender 2014-02-20 09:40 - 2013-10-21 11:38 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2014-02-20 09:40 - 2013-05-24 05:45 - 00000000 ____D () C:\Windows\Minidump 2014-02-20 09:40 - 2013-05-09 17:55 - 00000000 ____D () C:\ProgramData\DatacardService 2014-02-20 09:40 - 2013-05-06 18:50 - 00000000 ____D () C:\Users\Juga 2014-02-20 09:40 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows Portable Devices 2014-02-20 09:39 - 2014-02-19 16:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-20 09:39 - 2014-02-16 22:06 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-20 09:39 - 2014-02-16 17:50 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-02-20 09:39 - 2014-02-16 17:50 - 00000000 ____D () C:\Windows\system32\NV 2014-02-20 09:39 - 2014-02-14 10:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-20 09:39 - 2014-02-13 09:58 - 00000000 ____D () C:\Users\Juga\AppData\Local\Tempfeb52be43e051bfaf4839a6935e00e42 2014-02-20 09:39 - 2014-02-13 09:58 - 00000000 ____D () C:\Users\Juga\AppData\Local\Temp12e72473eede95c369de200ff0f01ceb 2014-02-20 09:39 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\AppData\Local\Temp14b5077f6956a3517aafd12a4b0ddc8f 2014-02-20 09:39 - 2014-02-05 13:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-20 09:39 - 2014-01-08 10:52 - 00000000 ____D () C:\Program Files\Classic Shell 2014-02-20 09:39 - 2013-11-10 22:27 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\xm1 2014-02-20 09:39 - 2013-11-10 22:12 - 00000000 ____D () C:\Program Files (x86)\Texmaker 2014-02-20 09:39 - 2013-11-02 21:57 - 00000000 ____D () C:\Program Files (x86)\Tor Browser 2014-02-20 09:39 - 2013-10-21 11:46 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Scan2PDF 2014-02-20 09:39 - 2013-10-21 11:46 - 00000000 ____D () C:\Program Files (x86)\Scan2PDF 2014-02-20 09:39 - 2013-10-20 21:34 - 00000000 ____D () C:\Program Files (x86)\JonDo 2014-02-20 09:39 - 2013-10-04 09:49 - 00000000 ____D () C:\Program Files (x86)\Vidalia Relay Bundle 2014-02-20 09:39 - 2013-09-30 17:11 - 00000000 ____D () C:\totalcmd 2014-02-20 09:39 - 2013-09-29 19:33 - 00000000 ____D () C:\Program Files\WinDjView 2014-02-20 09:39 - 2013-09-28 14:18 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-02-20 09:39 - 2013-09-17 22:17 - 00000000 ____D () C:\Program Files (x86)\Audiograbber 2014-02-20 09:39 - 2013-09-14 22:45 - 00000000 ____D () C:\Program Files (x86)\Calibre2 2014-02-20 09:39 - 2013-08-29 00:41 - 00000000 ____D () C:\Program Files (x86)\StreamTransport 2014-02-20 09:39 - 2013-08-27 18:02 - 00000000 ____D () C:\Program Files (x86)\FLV Player 2014-02-20 09:39 - 2013-05-16 23:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator 2014-02-20 09:39 - 2013-05-09 17:55 - 00000000 ____D () C:\Program Files (x86)\Mobile Partner 2014-02-20 09:39 - 2013-05-07 21:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2014-02-20 09:39 - 2013-05-07 21:13 - 00000000 ____D () C:\Users\Juga\AppData\Local\Microsoft Help 2014-02-20 09:39 - 2013-05-06 18:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-20 09:39 - 2013-05-06 18:52 - 00000000 ___RD () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-20 09:39 - 2012-11-15 19:47 - 00000000 ____D () C:\ProgramData\P4G 2014-02-20 09:39 - 2012-11-15 19:39 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-20 09:39 - 2012-11-15 19:39 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-20 09:39 - 2012-08-02 14:28 - 00000000 ____D () C:\Users\Administrator 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ToastData 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\WinStore 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\SysWOW64\MSDRM 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\MSDRM 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows Defender 2014-02-20 09:39 - 2012-07-26 06:37 - 00000000 ____D () C:\Windows\servicing 2014-02-20 09:38 - 2014-02-19 16:30 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Malwarebytes 2014-02-20 09:38 - 2014-02-19 16:30 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-20 09:38 - 2014-02-18 08:48 - 00000000 ____D () C:\Users\Juga\AppData\Local\Skype 2014-02-20 09:38 - 2013-11-02 21:16 - 00000000 ____D () C:\ProgramData\Package Cache 2014-02-20 09:38 - 2013-10-03 12:01 - 00000000 ____D () C:\Users\Juga\AppData\Local\Google 2014-02-20 09:38 - 2013-05-08 06:19 - 00000000 ____D () C:\Program Files\Bitdefender 2014-02-20 09:38 - 2013-05-08 06:15 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender 2014-02-20 09:38 - 2013-05-06 18:50 - 00000000 ____D () C:\Users\Juga\AppData\Local\ASUS 2014-02-20 09:38 - 2013-04-02 14:25 - 00000000 ____D () C:\Users\Juga\AppData\Local\Packages 2014-02-20 09:38 - 2012-11-15 19:43 - 00000000 ____D () C:\Program Files\DIFX 2014-02-20 09:38 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\Help 2014-02-20 09:38 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-02-20 09:38 - 2012-07-26 06:38 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-02-20 09:37 - 2013-05-10 20:39 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-20 09:37 - 2012-11-15 19:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-20 09:37 - 2012-11-15 19:35 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-02-20 09:36 - 2014-01-03 16:19 - 00000000 ____D () C:\Users\Juga\Desktop\pics 2014-02-20 09:23 - 2013-05-08 06:20 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\QuickScan 2014-02-20 09:14 - 2012-11-15 19:35 - 00000000 ____D () C:\Intel 2014-02-19 23:36 - 2013-05-08 06:24 - 00000000 ____D () C:\ProgramData\BDLogging 2014-02-19 21:25 - 2014-02-19 21:24 - 00000000 ____D () C:\Program Files (x86)\Google 2014-02-19 20:34 - 2014-02-19 20:34 - 00000000 ____D () C:\ProgramData\ClassicShell 2014-02-19 19:15 - 2014-02-19 10:15 - 00003586 _____ () C:\Windows\System32\Tasks\Bitdefender Auto-Scan 2014-02-19 18:21 - 2014-02-19 18:21 - 00299776 _____ () C:\Windows\Minidump\021914-7500-01.dmp 2014-02-19 18:18 - 2014-02-19 18:18 - 00000470 _____ () C:\Users\Juga\Desktop\defogger_disable.log 2014-02-19 17:09 - 2014-02-19 17:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-consumer.exe 2014-02-19 16:30 - 2014-02-19 16:30 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-19 16:29 - 2014-02-19 16:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-setup- 2014-02-19 16:03 - 2014-02-19 16:03 - 00000470 _____ () C:\Windows\SysWOW64\defogger_disable.log 2014-02-19 15:51 - 2014-02-19 15:51 - 00296784 _____ () C:\Windows\Minidump\021914-7562-01.dmp 2014-02-19 15:44 - 2014-02-19 15:44 - 00299816 _____ () C:\Windows\Minidump\021914-7718-01.dmp 2014-02-19 15:43 - 2014-02-19 15:43 - 00380416 _____ () C:\Users\Juga\Desktop\Gmer-19357.exe 2014-02-19 15:42 - 2014-02-19 16:19 - 00029451 _____ () C:\Users\Juga\Desktop\Addition.txt 2014-02-19 12:46 - 2014-02-19 12:46 - 01141248 _____ (Farbar) C:\Users\Juga\Downloads\FRST.exe 2014-02-19 12:46 - 2014-02-19 12:46 - 00000470 _____ () C:\Users\Juga\Downloads\defogger_disable.log 2014-02-19 12:46 - 2014-02-19 12:46 - 00000000 _____ () C:\Users\Juga\defogger_reenable 2014-02-19 12:45 - 2014-02-19 12:45 - 00050477 _____ () C:\Users\Juga\Desktop\Defogger.exe 2014-02-19 12:43 - 2014-02-19 12:43 - 00002640 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-02-19 12:43 - 2013-07-26 23:49 - 00000101 _____ () C:\Users\Juga\AppData\Roaming\WB.CFG 2014-02-19 12:06 - 2013-06-30 21:58 - 524288512 _____ () C:\Users\Juga\Desktop\Datentresor - Ruppert.bvd 2014-02-18 08:48 - 2014-02-18 08:48 - 00003142 _____ () C:\Windows\System32\Tasks\{CEEC242F-CB31-4B7C-BA41-759D23FC22A4} 2014-02-18 08:47 - 2014-02-18 08:47 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(1).exe 2014-02-17 23:03 - 2012-07-26 09:14 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-17 23:03 - 2012-07-26 09:14 - 00078304 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 20:42 - 2013-09-14 22:45 - 00000000 ____D () C:\Users\Juga\Documents\Calibre-Bibliothek 2014-02-17 20:40 - 2014-02-17 20:40 - 01816433 _____ () C:\Users\Juga\Downloads\tools_v6.0.8.zip 2014-02-17 20:29 - 2014-02-17 20:29 - 09954793 _____ () C:\Users\Juga\Downloads\Ultimate-DRM-Removal-last.zip 2014-02-17 09:25 - 2014-02-17 09:23 - 88898427 _____ () C:\Users\Juga\Desktop\Tumblr_Video.mp4 2014-02-16 22:20 - 2013-05-06 18:51 - 00000000 ____D () C:\Users\Juga\AppData\Local\VirtualStore 2014-02-16 22:08 - 2012-08-02 23:24 - 00000000 ____D () C:\Windows\Panther 2014-02-16 22:06 - 2014-02-16 22:06 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-02-16 22:06 - 2014-02-16 22:06 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-16 22:06 - 2014-02-16 22:05 - 03645064 _____ (Piriform Ltd) C:\Users\Juga\Downloads\ccsetup410_slim.exe 2014-02-16 12:59 - 2014-02-16 12:58 - 54537728 _____ () C:\Users\Juga\Downloads\calibre-1.24.0.msi 2014-02-16 07:33 - 2013-06-22 06:43 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\gnupg 2014-02-15 20:19 - 2013-11-02 21:49 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-15 20:17 - 2014-02-15 20:17 - 24490112 _____ (Mozilla) C:\Users\Juga\Downloads\Firefox Setup 27.0.1.exe 2014-02-15 15:28 - 2013-07-11 10:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-15 15:27 - 2013-05-06 19:57 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 00:49 - 2014-02-15 00:23 - 130171322 _____ () C:\Users\Juga\Desktop\1103195_white_ass_slut_fucked_twice_bare_creamed_huge_black_.flv 2014-02-14 19:21 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI(1020) 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\Downloads\Steganos-SpurenVernichter 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\ChromeExtensions 2014-02-13 09:57 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\NVIDIA 2014-02-13 09:56 - 2014-02-13 09:56 - 01059584 _____ () C:\Users\Juga\Downloads\Steganos-SpurenVernichter-Setup.exe 2014-02-13 06:43 - 2014-02-13 06:43 - 00001237 _____ () C:\Users\Juga\Downloads\URLLink(6).acsm 2014-02-09 15:20 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-08 11:19 - 2014-02-08 11:19 - 00003576 _____ () C:\Users\Juga\Desktop\anschreibenMBWK.tex 2014-02-02 12:22 - 2014-02-02 12:22 - 00007374 _____ () C:\Users\Juga\Desktop\Preisinformation zum 1. März 2014.eml 2014-02-01 10:20 - 2014-02-13 22:03 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-01 10:19 - 2014-02-13 22:03 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-01 10:19 - 2014-02-13 22:03 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-01 10:19 - 2014-02-13 22:03 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-02-01 10:19 - 2014-02-13 22:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-01 10:18 - 2014-02-13 22:03 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-01 10:18 - 2014-02-13 22:02 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-01 10:18 - 2014-02-13 22:02 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-01 08:58 - 2014-02-13 22:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-01 08:58 - 2014-02-13 22:03 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-01 08:58 - 2014-02-13 22:03 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-01 08:57 - 2014-02-13 22:03 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-01 08:57 - 2014-02-13 22:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-02-01 08:40 - 2014-02-13 22:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-01 08:34 - 2014-02-13 22:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-01 06:08 - 2014-02-13 22:03 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll Files to move or delete: ==================== C:\Users\Juga\AppData\Roaming\Camdata.ini C:\Users\Juga\AppData\Roaming\CamLayout.ini C:\Users\Juga\AppData\Roaming\CamShapes.ini C:\Users\Juga\AppData\Roaming\CamStudio.Producer.Data.ini Some content of TEMP: ==================== C:\Users\Juga\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-26 15:30 ==================== End Of Log ============================ |
An den gefühlten 30GB Adware die wir gelöscht haben

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
ATTFilter C:\Users\Juga\AppData\Roaming\Camdata.ini C:\Users\Juga\AppData\Roaming\CamLayout.ini C:\Users\Juga\AppData\Roaming\CamShapes.ini C:\Users\Juga\AppData\Roaming\CamStudio.Producer.Data.ini Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig

Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.

Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Hallo,

danke für den Hinweis, ich habe es erst gar nicht gerafft, dass ich noch was machen soll.

Leider ist das System in den letzten Tagen wieder instabil und öffnet mitunter immernoch selbstständig Hilfeseiten - allerdings weniger als früher :-/.

Hier erstmal das fixlist.txt
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by Juga at 2014-03-16 22:22:51 Run:3 Running from C:\Users\Juga\Desktop\AdWareKiller Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Juga\AppData\Roaming\Camdata.ini C:\Users\Juga\AppData\Roaming\CamLayout.ini C:\Users\Juga\AppData\Roaming\CamShapes.ini C:\Users\Juga\AppData\Roaming\CamStudio.Producer.Data.ini ***************** "C:\Users\Juga\AppData\Roaming\Camdata.ini" => File/Directory not found. "C:\Users\Juga\AppData\Roaming\CamLayout.ini" => File/Directory not found. "C:\Users\Juga\AppData\Roaming\CamShapes.ini" => File/Directory not found. "C:\Users\Juga\AppData\Roaming\CamStudio.Producer.Data.ini" => File/Directory not found. ==== End of Fixlog ==== Daher habe ich nochmal FRST laufen lassen. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Juga (administrator) on LAPTOP on 16-03-2014 23:06:44 Running from C:\Users\Juga\Desktop\AdWareKiller Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe () C:\Windows\system32\DptfParticipantProcessorService.exe () C:\Windows\system32\DptfPolicyConfigTDPService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-30] (Realtek Semiconductor) HKLM\...\Run: [ASUSQuickGesture(x86)] - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe [20352 2012-09-11] (ASUSTeK Computer Inc.) HKLM\...\Run: [ASUSTPLoader(x64)] - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe [169856 2012-09-11] (AsusTek) HKLM\...\Run: [ASUSQuickGesture(x64)] - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe [22400 2012-09-11] (ASUSTeK Computer Inc.) HKLM\...\Run: [DptfPolicyLpmServiceHelper] - C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [21888 2012-07-30] () HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS) HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [7818040 2013-09-19] (Motorola Solutions, Inc.) HKLM\...\Run: [Bdagent] - C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1739480 2014-01-29] (Bitdefender) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Reader Application Helper] - C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-11-27] (Sony Corporation) HKLM-x32\...\Run: [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2258056 2013-09-22] (Microsoft Corp.) HKLM-x32\...\Run: [] - [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] - C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [567888 2014-02-03] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] - C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1001536 2014-02-03] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] - C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614232 2014-01-29] (Bitdefender) HKU\S-1-5-21-3203196741-1805427045-687499267-1002\...\Run: [Bitdefender-Geldbörse-Agent] - C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [567888 2014-02-03] (Bitdefender) HKU\S-1-5-21-3203196741-1805427045-687499267-1002\...\Run: [Bitdefender-Geldbörse] - C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1001536 2014-02-03] (Bitdefender) HKU\S-1-5-21-3203196741-1805427045-687499267-1002\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] - C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614232 2014-01-29] (Bitdefender) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender) BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: ASUS Browser Extension x64 - {78234974-0C4B-4111-BDEB-D9A104418772} - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x64\BrowserExtension64.dll (ASUSTeK Computer Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft) BHO-x32: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: ASUS Browser Extension x86 - {78234974-0C4B-4111-BDEB-D9A104418771} - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x86\BrowserExtension.dll (ASUSTeK Computer Inc.) BHO-x32: ividi Helper Object - {8B8B2E80-1444-451D-AC8E-EB9A847F3887} - C:\Program Files (x86)\Unitech LLC\ividi\\bh\ividi.dll No File BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{AEFBB86E-3140-48A0-A253-9D902613CC85}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Juga\AppData\Roaming\Mozilla\Firefox\Profiles\l24us74s.default-1393022713616 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @ei.FromDocToPDF_65.com/Plugin - C:\Program Files (x86)\FromDocToPDF_65EI\Installr\1.bin\NP65EISB.dll No File FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @sony.com/ReaderDesktop - C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\Juga\AppData\Roaming\Mozilla\Firefox\Profiles\l24us74s.default-1393022713616\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-16] FF Extension: aklamio CashBar - C:\Users\Juga\AppData\Roaming\Mozilla\Firefox\Profiles\l24us74s.default-1393022713616\Extensions\addon@aklamio.de.xpi [2014-03-03] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-03-15] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-21] FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ [] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-03-15] ==================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2013-11-21] (Bitdefender) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-09-22] (Microsoft Corp.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [515632 2013-05-21] (REINER SCT) R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-05-28] () R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [29056 2012-07-30] () R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [30592 2012-07-30] () R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [339456 2010-11-16] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 Mobile Partner. RunOuc; c:\program files (x86)\mobile partner\updatedog\ouc.exe [218624 2013-05-09] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] () R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) S2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-10-07] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1507248 2014-01-29] (Bitdefender) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [56704 2012-09-11] (ASUS Corporation) R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [893440 2013-12-02] (BitDefender) R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261056 2014-03-15] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [635392 2013-12-02] (BitDefender) S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender) R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-07-24] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC) S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL) R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.) S3 cjusb; C:\Windows\system32\DRIVERS\cjusb.sys [35192 2012-09-04] (REINER SCT) R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107328 2012-07-13] (Intel Corporation) R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42816 2012-07-13] (Intel Corporation) R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64832 2012-07-13] (Intel Corporation) R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96064 2012-07-13] (Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [228672 2012-07-13] (Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [361792 2012-07-13] (Intel Corporation) S3 ewusbnet; C:\Windows\system32\DRIVERS\ewusbnet.sys [256000 2013-05-09] (Huawei Technologies Co., Ltd.) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-10-08] (Intel Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-08-07] (BitDefender S.R.L.) S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48096 2012-08-09] (Windows (R) Win 7 DDK provider) S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-16 22:35 - 2014-03-16 22:35 - 00323576 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-16 22:35 - 2014-03-16 22:35 - 00000385 _____ () C:\Windows\system32\user_gensett.xml 2014-03-16 22:35 - 2014-03-16 22:35 - 00000022 _____ () C:\Windows\S.dirmngr 2014-03-16 22:30 - 2014-03-16 22:30 - 01064488 _____ (BillP Studios) C:\Users\Juga\Downloads\wpsetup(1).exe 2014-03-16 22:30 - 2014-03-16 22:30 - 00700980 _____ () C:\Users\Juga\Downloads\adblock_edge-2.0.7-sm+an+tb+fx-windows.xpi 2014-03-16 22:21 - 2014-03-16 22:21 - 00000190 _____ () C:\Users\Juga\Desktop\fixlist.txt 2014-03-16 09:51 - 2014-03-16 09:51 - 00000568 _____ () C:\Users\Public\Desktop\Biet-O-Matic.lnk 2014-03-16 09:50 - 2003-01-07 02:22 - 00015873 _____ () C:\Windows\SysWOW64\Inetde.dll 2014-03-16 09:50 - 2000-12-05 23:00 - 00109248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mswinsck.ocx 2014-03-16 09:50 - 2000-05-22 15:58 - 00115920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.ocx 2014-03-16 09:50 - 2000-04-03 19:06 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winskde.dll 2014-03-16 09:50 - 1999-07-14 13:07 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stdftde.dll 2014-03-16 09:50 - 1998-07-05 23:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Tabctde.dll 2014-03-16 09:50 - 1998-06-23 23:00 - 00209192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Tabctl32.ocx 2014-03-16 09:43 - 2014-03-16 09:43 - 04653537 _____ () C:\Users\Juga\Downloads\BOM21412_setup.exe 2014-03-15 16:50 - 2014-03-15 16:50 - 00001774 _____ () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mbam.exe - Verknüpfung.lnk 2014-03-15 16:16 - 2014-03-15 16:40 - 00009247 _____ () C:\Users\Juga\Documents\Zeitschriften-Festgeld-Gas-Strom.xlsx 2014-03-15 16:02 - 2014-03-15 16:02 - 00000195 _____ () C:\Users\Juga\Documents\jr.bwl 2014-03-15 15:04 - 2014-03-15 15:04 - 02257742 _____ () C:\ProgramData\1394891656.bdinstall.bin 2014-03-15 15:01 - 2014-03-15 15:19 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-03-15 15:01 - 2014-03-15 15:19 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll 2014-03-15 15:01 - 2014-03-15 15:01 - 00002188 _____ () C:\Users\Public\Desktop\Bitdefender Safepay.lnk 2014-03-15 15:01 - 2014-03-15 15:01 - 00002144 _____ () C:\Users\Public\Desktop\Bitdefender Total Security.lnk 2014-03-15 15:01 - 2014-03-15 15:01 - 00000299 _____ () C:\Windows\setupact.log 2014-03-15 15:01 - 2014-03-15 15:01 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-15 15:01 - 2013-12-02 11:58 - 00635392 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2014-03-15 15:01 - 2013-12-02 11:56 - 00893440 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-03-15 15:01 - 2013-11-04 15:47 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys 2014-03-15 15:01 - 2013-09-08 19:04 - 00023568 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys 2014-03-15 15:01 - 2013-07-30 17:41 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys 2014-03-15 15:01 - 2013-07-24 17:19 - 00098768 _____ (BitDefender LLC) C:\Windows\system32\Drivers\bdfndisf6.sys 2014-03-15 14:56 - 2014-03-15 15:16 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Bitdefender 2014-03-15 14:54 - 2014-03-15 15:19 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll 2014-03-15 14:54 - 2014-03-15 15:19 - 00000000 ____D () C:\ProgramData\Bitdefender 2014-03-15 14:54 - 2014-03-15 14:56 - 00000000 ____D () C:\Program Files\Bitdefender 2014-03-15 14:54 - 2014-03-15 14:54 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender 2014-03-15 14:54 - 2013-11-04 15:47 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll 2014-03-15 14:54 - 2013-11-04 15:46 - 00034384 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll 2014-03-15 14:54 - 2013-08-23 12:48 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys 2014-03-15 14:54 - 2013-08-07 12:46 - 00389240 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys 2014-03-15 14:53 - 2014-03-15 14:53 - 07304560 _____ () C:\Users\Juga\Downloads\bitdefender_tsecurity(1).exe 2014-03-15 11:29 - 2014-03-15 11:29 - 00091541 _____ () C:\ProgramData\1394879380.bdinstall.bin 2014-03-15 11:29 - 2014-03-15 11:29 - 00001549 _____ () C:\ProgramData\1394879387.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00091543 _____ () C:\ProgramData\1394879319.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00091542 _____ () C:\ProgramData\1394879295.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00091541 _____ () C:\ProgramData\1394879279.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00001549 _____ () C:\ProgramData\1394879303.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00001548 _____ () C:\ProgramData\1394879324.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00001548 _____ () C:\ProgramData\1394879284.bdinstall.bin 2014-03-15 11:27 - 2014-03-15 11:27 - 00091541 _____ () C:\ProgramData\1394879244.bdinstall.bin 2014-03-15 11:27 - 2014-03-15 11:27 - 00001548 _____ () C:\ProgramData\1394879252.bdinstall.bin 2014-03-15 11:24 - 2014-03-15 11:24 - 07302320 _____ () C:\Users\Juga\Downloads\bitdefender_tsecurity.exe 2014-03-14 23:16 - 2014-03-14 23:16 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-03-14 23:15 - 2014-03-14 23:15 - 00000745 _____ () C:\Users\Juga\Desktop\JRT.txt 2014-03-14 22:57 - 2014-03-14 22:57 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-03-14 22:57 - 2014-03-14 22:57 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-03-14 22:57 - 2014-03-14 22:57 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-03-14 22:57 - 2014-03-14 22:57 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-03-14 22:57 - 2014-03-14 22:57 - 00000000 ____D () C:\Program Files\Java 2014-03-14 22:55 - 2014-03-14 22:55 - 01064488 _____ (BillP Studios) C:\Users\Juga\Downloads\wpsetup.exe 2014-03-14 22:55 - 2014-03-14 22:55 - 00000000 ____D () C:\Users\Juga\AppData\Local\Secunia PSI 2014-03-14 22:54 - 2014-03-14 22:54 - 05329480 _____ (Secunia) C:\Users\Juga\Downloads\PSISetup_3.0.0.9016.exe 2014-03-14 22:54 - 2014-03-14 22:54 - 00000000 ____D () C:\Program Files (x86)\Secunia 2014-03-14 22:45 - 2014-03-14 22:45 - 00000834 _____ () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\adwcleaner.lnk 2014-03-14 21:26 - 2014-03-14 21:26 - 00024597 _____ () C:\ComboFix.txt 2014-03-14 21:18 - 2014-01-31 01:48 - 01339392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 21:18 - 2014-01-31 01:06 - 01628160 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 21:18 - 2013-10-25 08:34 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2014-03-14 21:18 - 2013-10-24 23:34 - 00248240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2014-03-14 17:39 - 2014-03-14 17:39 - 00987442 _____ () C:\Users\Juga\Downloads\SecurityCheck(1).exe 2014-03-14 17:20 - 2014-03-16 23:06 - 00000000 ____D () C:\Users\Juga\Desktop\AdWareKiller 2014-03-14 16:54 - 2014-03-14 16:54 - 00000414 _____ () C:\Users\Juga\Desktop\Fixlist.txt.lnk 2014-03-14 11:55 - 2014-03-16 22:35 - 00008666 _____ () C:\Windows\PFRO.log 2014-03-14 11:48 - 2014-03-14 11:48 - 03105184 _____ () C:\Users\Juga\Downloads\BitDefender_Uninstall_Tool.exe 2014-03-14 11:12 - 2014-02-08 05:34 - 04036608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 11:11 - 2014-02-23 09:13 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-14 11:11 - 2014-02-23 09:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-14 11:11 - 2014-02-23 09:13 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-03-14 11:11 - 2014-02-23 09:13 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-03-14 11:11 - 2014-02-23 09:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-14 11:11 - 2014-02-23 09:12 - 19273216 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-14 11:11 - 2014-02-23 09:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-14 11:11 - 2014-02-23 09:12 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-14 11:11 - 2014-02-23 09:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-14 11:11 - 2014-02-23 07:54 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-14 11:11 - 2014-02-23 07:54 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-14 11:11 - 2014-02-23 07:54 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 14358016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-14 11:11 - 2014-02-23 07:53 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-14 11:11 - 2014-02-23 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-14 11:11 - 2014-02-23 07:31 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-14 11:11 - 2014-02-23 05:06 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-03-13 18:25 - 2014-02-06 00:41 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 18:25 - 2014-02-06 00:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-11 13:54 - 2014-03-11 13:54 - 00001249 _____ () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpywareBlaster.lnk 2014-03-10 21:00 - 2014-03-16 22:55 - 01367404 _____ () C:\Windows\WindowsUpdate.log 2014-03-10 20:50 - 2014-03-10 22:22 - 00000000 ____D () C:\Program Files (x86)\FreeCommander XE 2014-03-10 20:50 - 2014-03-10 20:50 - 00000000 ____D () C:\Users\Juga\AppData\Local\FreeCommanderXE 2014-03-10 20:35 - 2014-03-10 21:00 - 00000000 ____D () C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZZ.Z.ZZ.Z...Z 2014-03-10 07:00 - 2014-03-10 07:00 - 00000000 ____D () C:\Users\Juga\AppData\Local\Eraser 6 2014-03-09 23:08 - 2014-03-10 22:19 - 00000000 ____D () C:\Program Files\Eraser 2014-03-08 21:32 - 2014-03-08 22:24 - 00010748 _____ () C:\Users\Juga\Documents\foto-langen.xlsx 2014-03-08 18:49 - 2014-03-10 22:21 - 00000000 ____D () C:\Program Files (x86)\IrfanView 2014-03-08 13:42 - 2014-03-12 19:08 - 00000000 ____D () C:\Users\Juga\Desktop\Münze- 2014-03-07 13:35 - 2014-03-07 14:06 - 00008570 _____ () C:\Users\Juga\Documents\Telefonkosten.xlsx 2014-03-06 18:42 - 2014-03-06 18:43 - 00000000 ____D () C:\Users\Juga\Desktop\Tor Browser 2014-03-04 17:23 - 2014-03-04 19:46 - 00000000 ____D () C:\Users\Juga\Desktop\Münzbilder - test 2014-03-04 13:36 - 2014-03-04 17:35 - 00010867 _____ () C:\Users\Juga\Documents\Münzen.xlsx 2014-03-04 13:36 - 2014-03-04 13:36 - 00000165 ____H () C:\Users\Juga\Documents\~$Münzen.xlsx 2014-02-27 19:57 - 2014-03-15 11:27 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster 2014-02-27 19:57 - 2014-03-10 22:50 - 00000000 ____D () C:\ProgramData\Licenses 2014-02-27 19:56 - 2014-02-27 19:56 - 04095448 _____ (BrightFort LLC ) C:\Users\Juga\Downloads\spywareblastersetup50.exe 2014-02-27 19:56 - 2014-02-27 19:56 - 04095448 _____ (BrightFort LLC ) C:\Users\Juga\Downloads\spywareblastersetup50(1).exe 2014-02-26 13:59 - 2014-03-01 19:50 - 00001283 _____ () C:\Users\Juga\Desktop\Bahnfahrt-Beschwerde.txt 2014-02-24 23:07 - 2014-02-24 23:07 - 00987425 _____ () C:\Users\Juga\Downloads\SecurityCheck.exe 2014-02-23 21:17 - 2014-02-23 21:17 - 00000000 ____D () C:\Windows\ERUNT 2014-02-23 20:32 - 2014-03-14 22:47 - 00000000 ____D () C:\AdwCleaner 2014-02-23 12:15 - 2014-02-23 12:16 - 00000000 ____D () C:\Recovery 2014-02-22 12:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-22 12:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-22 12:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-22 12:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-22 12:08 - 2014-03-14 21:26 - 00000000 ____D () C:\Qoobox 2014-02-22 12:08 - 2014-03-14 21:19 - 05190279 ____R (Swearware) C:\Users\Juga\Downloads\ComboFix.exe 2014-02-22 12:08 - 2014-03-10 23:07 - 00000000 ____D () C:\Windows\erdnt 2014-02-21 23:44 - 2014-02-21 23:44 - 00019926 _____ () C:\Users\Juga\Desktop\Bestätigung Ihrer Zahlung an Rove.design GmbH.eml 2014-02-20 16:18 - 2014-02-20 16:22 - 00002167 _____ () C:\Users\Public\Desktop\SteuerSparErklärung 2014.lnk 2014-02-20 16:18 - 2014-02-20 16:18 - 00000000 ____D () C:\Users\Juga\AppData\Local\AAV 2014-02-20 16:16 - 2014-02-20 16:19 - 00000000 ____D () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft 2014-02-20 16:14 - 2014-02-20 16:19 - 00000000 ____D () C:\ProgramData\AAV 2014-02-20 14:27 - 2014-02-20 14:28 - 05631168 _____ (IvoSoft) C:\Users\Juga\Downloads\ClassicShellSetup_4_0_4.exe 2014-02-20 09:42 - 2014-03-10 22:39 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-20 09:42 - 2014-02-20 09:42 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(2).exe 2014-02-20 09:42 - 2014-02-20 09:42 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-19 21:24 - 2014-03-10 20:43 - 00000000 ____D () C:\Program Files (x86)\Google 2014-02-19 20:34 - 2014-02-19 20:34 - 00000000 ____D () C:\ProgramData\ClassicShell 2014-02-19 18:21 - 2014-02-19 18:21 - 00299776 _____ () C:\Windows\Minidump\021914-7500-01.dmp 2014-02-19 17:09 - 2014-02-19 17:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-consumer.exe 2014-02-19 16:30 - 2014-03-14 21:44 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-19 16:30 - 2014-02-20 09:38 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Malwarebytes 2014-02-19 16:30 - 2014-02-20 09:38 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-19 16:30 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-19 16:29 - 2014-02-19 16:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-setup- 2014-02-19 16:03 - 2014-02-19 16:03 - 00000470 _____ () C:\Windows\SysWOW64\defogger_disable.log 2014-02-19 15:51 - 2014-02-19 15:51 - 00296784 _____ () C:\Windows\Minidump\021914-7562-01.dmp 2014-02-19 15:44 - 2014-02-19 15:44 - 00299816 _____ () C:\Windows\Minidump\021914-7718-01.dmp 2014-02-19 15:41 - 2014-03-16 23:06 - 00000000 ____D () C:\FRST 2014-02-19 12:46 - 2014-02-19 12:46 - 01141248 _____ (Farbar) C:\Users\Juga\Downloads\FRST.exe 2014-02-19 12:46 - 2014-02-19 12:46 - 00000000 _____ () C:\Users\Juga\defogger_reenable 2014-02-19 10:15 - 2014-03-15 22:39 - 00003576 _____ () C:\Windows\System32\Tasks\Bitdefender Auto-Scan 2014-02-18 08:48 - 2014-02-20 09:38 - 00000000 ____D () C:\Users\Juga\AppData\Local\Skype 2014-02-18 08:48 - 2014-02-18 08:48 - 00003142 _____ () C:\Windows\System32\Tasks\{CEEC242F-CB31-4B7C-BA41-759D23FC22A4} 2014-02-18 08:47 - 2014-02-18 08:47 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(1).exe 2014-02-16 22:06 - 2014-03-10 22:42 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-16 22:06 - 2014-02-16 22:06 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-02-16 22:05 - 2014-02-16 22:06 - 03645064 _____ (Piriform Ltd) C:\Users\Juga\Downloads\ccsetup410_slim.exe 2014-02-16 17:50 - 2014-03-10 23:50 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-02-16 17:50 - 2014-03-10 23:48 - 00000000 ____D () C:\Windows\system32\NV 2014-02-16 12:58 - 2014-02-16 12:59 - 54537728 _____ () C:\Users\Juga\Downloads\calibre-1.24.0.msi 2014-02-16 06:31 - 2013-12-07 07:36 - 19751936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-02-16 06:31 - 2013-12-07 06:15 - 17560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-02-15 20:17 - 2014-02-15 20:17 - 24490112 _____ (Mozilla) C:\Users\Juga\Downloads\Firefox Setup 27.0.1.exe 2014-02-14 10:11 - 2014-03-10 22:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-03-16 23:06 - 2014-03-14 17:20 - 00000000 ____D () C:\Users\Juga\Desktop\AdWareKiller 2014-03-16 23:06 - 2014-02-19 15:41 - 00000000 ____D () C:\FRST 2014-03-16 23:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-03-16 22:55 - 2014-03-10 21:00 - 01367404 _____ () C:\Windows\WindowsUpdate.log 2014-03-16 22:55 - 2013-05-07 18:30 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3203196741-1805427045-687499267-1002 2014-03-16 22:50 - 2013-09-16 18:17 - 00000513 _____ () C:\Windows\system32\checkdnsid.xml 2014-03-16 22:49 - 2013-09-14 22:45 - 00000000 ____D () C:\Users\Juga\Documents\Calibre-Bibliothek 2014-03-16 22:47 - 2013-05-06 21:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-16 22:40 - 2012-08-03 00:02 - 00761598 _____ () C:\Windows\system32\perfh007.dat 2014-03-16 22:40 - 2012-08-03 00:02 - 00159306 _____ () C:\Windows\system32\perfc007.dat 2014-03-16 22:40 - 2012-07-26 08:28 - 01748838 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-16 22:35 - 2014-03-16 22:35 - 00323576 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-16 22:35 - 2014-03-16 22:35 - 00000385 _____ () C:\Windows\system32\user_gensett.xml 2014-03-16 22:35 - 2014-03-16 22:35 - 00000022 _____ () C:\Windows\S.dirmngr 2014-03-16 22:35 - 2014-03-14 11:55 - 00008666 _____ () C:\Windows\PFRO.log 2014-03-16 22:35 - 2013-05-06 18:53 - 00000500 _____ () C:\Users\Juga\AppData\Roaming\sp_data.sys 2014-03-16 22:35 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-16 22:35 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-03-16 22:34 - 2013-06-30 21:58 - 524288512 _____ () C:\Users\Juga\Desktop\Datentresor - Ruppert.bvd 2014-03-16 22:34 - 2013-05-11 16:41 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\vlc 2014-03-16 22:34 - 2012-07-26 06:26 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-03-16 22:31 - 2014-01-08 10:52 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\ClassicShell 2014-03-16 22:30 - 2014-03-16 22:30 - 01064488 _____ (BillP Studios) C:\Users\Juga\Downloads\wpsetup(1).exe 2014-03-16 22:30 - 2014-03-16 22:30 - 00700980 _____ () C:\Users\Juga\Downloads\adblock_edge-2.0.7-sm+an+tb+fx-windows.xpi 2014-03-16 22:28 - 2013-05-09 10:21 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Skype 2014-03-16 22:21 - 2014-03-16 22:21 - 00000190 _____ () C:\Users\Juga\Desktop\fixlist.txt 2014-03-16 14:43 - 2013-05-09 10:31 - 00000121 _____ () C:\Users\Public\LMDebug.log 2014-03-16 12:24 - 2013-12-16 15:50 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-03-16 09:51 - 2014-03-16 09:51 - 00000568 _____ () C:\Users\Public\Desktop\Biet-O-Matic.lnk 2014-03-16 09:43 - 2014-03-16 09:43 - 04653537 _____ () C:\Users\Juga\Downloads\BOM21412_setup.exe 2014-03-15 22:39 - 2014-02-19 10:15 - 00003576 _____ () C:\Windows\System32\Tasks\Bitdefender Auto-Scan 2014-03-15 16:50 - 2014-03-15 16:50 - 00001774 _____ () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mbam.exe - Verknüpfung.lnk 2014-03-15 16:40 - 2014-03-15 16:16 - 00009247 _____ () C:\Users\Juga\Documents\Zeitschriften-Festgeld-Gas-Strom.xlsx 2014-03-15 16:02 - 2014-03-15 16:02 - 00000195 _____ () C:\Users\Juga\Documents\jr.bwl 2014-03-15 15:19 - 2014-03-15 15:01 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-03-15 15:19 - 2014-03-15 15:01 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll 2014-03-15 15:19 - 2014-03-15 14:54 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll 2014-03-15 15:19 - 2014-03-15 14:54 - 00000000 ____D () C:\ProgramData\Bitdefender 2014-03-15 15:16 - 2014-03-15 14:56 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Bitdefender 2014-03-15 15:04 - 2014-03-15 15:04 - 02257742 _____ () C:\ProgramData\1394891656.bdinstall.bin 2014-03-15 15:01 - 2014-03-15 15:01 - 00002188 _____ () C:\Users\Public\Desktop\Bitdefender Safepay.lnk 2014-03-15 15:01 - 2014-03-15 15:01 - 00002144 _____ () C:\Users\Public\Desktop\Bitdefender Total Security.lnk 2014-03-15 15:01 - 2014-03-15 15:01 - 00000299 _____ () C:\Windows\setupact.log 2014-03-15 15:01 - 2014-03-15 15:01 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-15 14:56 - 2014-03-15 14:54 - 00000000 ____D () C:\Program Files\Bitdefender 2014-03-15 14:54 - 2014-03-15 14:54 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender 2014-03-15 14:53 - 2014-03-15 14:53 - 07304560 _____ () C:\Users\Juga\Downloads\bitdefender_tsecurity(1).exe 2014-03-15 14:39 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-15 14:39 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-15 14:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows Defender 2014-03-15 14:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-03-15 11:32 - 2013-07-11 10:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-15 11:30 - 2013-05-06 19:57 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-15 11:29 - 2014-03-15 11:29 - 00091541 _____ () C:\ProgramData\1394879380.bdinstall.bin 2014-03-15 11:29 - 2014-03-15 11:29 - 00001549 _____ () C:\ProgramData\1394879387.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00091543 _____ () C:\ProgramData\1394879319.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00091542 _____ () C:\ProgramData\1394879295.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00091541 _____ () C:\ProgramData\1394879279.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00001549 _____ () C:\ProgramData\1394879303.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00001548 _____ () C:\ProgramData\1394879324.bdinstall.bin 2014-03-15 11:28 - 2014-03-15 11:28 - 00001548 _____ () C:\ProgramData\1394879284.bdinstall.bin 2014-03-15 11:27 - 2014-03-15 11:27 - 00091541 _____ () C:\ProgramData\1394879244.bdinstall.bin 2014-03-15 11:27 - 2014-03-15 11:27 - 00001548 _____ () C:\ProgramData\1394879252.bdinstall.bin 2014-03-15 11:27 - 2014-02-27 19:57 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster 2014-03-15 11:24 - 2014-03-15 11:24 - 07302320 _____ () C:\Users\Juga\Downloads\bitdefender_tsecurity.exe 2014-03-15 11:24 - 2013-06-22 06:43 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\gnupg 2014-03-15 10:22 - 2013-05-07 21:13 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-03-14 23:16 - 2014-03-14 23:16 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-03-14 23:15 - 2014-03-14 23:15 - 00000745 _____ () C:\Users\Juga\Desktop\JRT.txt 2014-03-14 22:57 - 2014-03-14 22:57 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-03-14 22:57 - 2014-03-14 22:57 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-03-14 22:57 - 2014-03-14 22:57 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-03-14 22:57 - 2014-03-14 22:57 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-03-14 22:57 - 2014-03-14 22:57 - 00000000 ____D () C:\Program Files\Java 2014-03-14 22:55 - 2014-03-14 22:55 - 01064488 _____ (BillP Studios) C:\Users\Juga\Downloads\wpsetup.exe 2014-03-14 22:55 - 2014-03-14 22:55 - 00000000 ____D () C:\Users\Juga\AppData\Local\Secunia PSI 2014-03-14 22:54 - 2014-03-14 22:54 - 05329480 _____ (Secunia) C:\Users\Juga\Downloads\PSISetup_3.0.0.9016.exe 2014-03-14 22:54 - 2014-03-14 22:54 - 00000000 ____D () C:\Program Files (x86)\Secunia 2014-03-14 22:47 - 2014-02-23 20:32 - 00000000 ____D () C:\AdwCleaner 2014-03-14 22:45 - 2014-03-14 22:45 - 00000834 _____ () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\adwcleaner.lnk 2014-03-14 21:44 - 2014-02-19 16:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-14 21:26 - 2014-03-14 21:26 - 00024597 _____ () C:\ComboFix.txt 2014-03-14 21:26 - 2014-02-22 12:08 - 00000000 ____D () C:\Qoobox 2014-03-14 21:24 - 2012-07-26 06:26 - 00000215 _____ () C:\Windows\system.ini 2014-03-14 21:19 - 2014-02-22 12:08 - 05190279 ____R (Swearware) C:\Users\Juga\Downloads\ComboFix.exe 2014-03-14 17:39 - 2014-03-14 17:39 - 00987442 _____ () C:\Users\Juga\Downloads\SecurityCheck(1).exe 2014-03-14 16:54 - 2014-03-14 16:54 - 00000414 _____ () C:\Users\Juga\Desktop\Fixlist.txt.lnk 2014-03-14 11:48 - 2014-03-14 11:48 - 03105184 _____ () C:\Users\Juga\Downloads\BitDefender_Uninstall_Tool.exe 2014-03-14 11:34 - 2013-06-10 10:11 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 11:34 - 2013-06-10 10:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-13 17:18 - 2013-08-09 17:51 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 2014-03-12 19:08 - 2014-03-08 13:42 - 00000000 ____D () C:\Users\Juga\Desktop\Münze- 2014-03-11 22:52 - 2013-05-06 18:52 - 00000000 ___RD () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-11 19:47 - 2013-05-06 21:41 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-11 19:34 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-03-11 13:54 - 2014-03-11 13:54 - 00001249 _____ () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpywareBlaster.lnk 2014-03-11 07:05 - 2013-05-06 18:50 - 00000000 ____D () C:\Users\Juga 2014-03-11 00:04 - 2013-10-21 11:38 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2014-03-11 00:04 - 2013-10-20 21:46 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JonDoFox 2014-03-11 00:04 - 2013-09-30 17:11 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander 2014-03-11 00:04 - 2013-05-24 05:45 - 00000000 ____D () C:\Windows\Minidump 2014-03-11 00:04 - 2013-05-09 17:55 - 00000000 ____D () C:\ProgramData\DatacardService 2014-03-11 00:03 - 2012-08-02 14:28 - 00000000 ____D () C:\Users\Administrator 2014-03-10 23:58 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\Offline Web Pages 2014-03-10 23:55 - 2012-11-15 20:03 - 00000000 ____D () C:\ProgramData\USBChargerPlus 2014-03-10 23:55 - 2012-11-15 19:47 - 00000000 ____D () C:\ProgramData\P4G 2014-03-10 23:55 - 2012-11-15 19:40 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-03-10 23:55 - 2012-08-02 14:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-10 23:55 - 2012-08-02 14:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-10 23:55 - 2012-08-02 14:28 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-03-10 23:55 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-10 23:55 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-10 23:55 - 2012-07-26 09:12 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-03-10 23:55 - 2012-07-26 09:12 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-03-10 23:51 - 2013-05-06 20:20 - 00000000 ___RD () C:\Windows\BrowserChoice 2014-03-10 23:51 - 2012-11-15 19:50 - 00000000 ____D () C:\Windows\ASUSProductDemoMovie 2014-03-10 23:51 - 2012-11-15 19:41 - 00000000 ____D () C:\Windows\SysWOW64\sda 2014-03-10 23:51 - 2012-11-15 19:41 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-03-10 23:51 - 2012-11-15 19:40 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-10 23:51 - 2012-11-15 19:40 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-10 23:51 - 2012-11-15 19:40 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-03-10 23:51 - 2012-08-17 01:53 - 00000000 ____D () C:\ProgramData\ChangeFolderView 2014-03-10 23:51 - 2012-08-02 14:33 - 00000000 ____D () C:\Windows\Log 2014-03-10 23:51 - 2012-08-02 14:33 - 00000000 ____D () C:\Windows\ASUS 2014-03-10 23:51 - 2012-08-02 14:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-10 23:51 - 2012-08-02 14:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-10 23:51 - 2012-08-02 14:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-03-10 23:51 - 2012-07-26 09:12 - 00000000 __RSD () C:\Windows\Media 2014-03-10 23:51 - 2012-07-26 09:12 - 00000000 __RHD () C:\Users\Public\Libraries 2014-03-10 23:51 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ToastData 2014-03-10 23:51 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\SysWOW64\Recovery 2014-03-10 23:51 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\WinMetadata 2014-03-10 23:50 - 2014-02-16 17:50 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-03-10 23:49 - 2012-07-26 06:38 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-03-10 23:48 - 2014-02-16 17:50 - 00000000 ____D () C:\Windows\system32\NV 2014-03-10 23:35 - 2012-07-26 10:45 - 00000000 ____D () C:\Windows\ShellNew 2014-03-10 23:07 - 2014-02-22 12:08 - 00000000 ____D () C:\Windows\erdnt 2014-03-10 23:03 - 2013-12-29 14:30 - 00000000 ____D () C:\Users\Juga\Downloads\Office2007PIARedist 2014-03-10 23:03 - 2013-09-22 11:12 - 00000000 ____D () C:\Users\Juga\Documents\Gutenberg-DE - Edition 12 2014-03-10 23:03 - 2013-08-29 00:50 - 00000000 ____D () C:\Users\Juga\Documents\StreamTransport 2014-03-10 23:03 - 2013-06-02 22:17 - 00000000 ___RD () C:\Users\Juga\Dropbox 2014-03-10 23:02 - 2013-11-10 22:27 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\xm1 2014-03-10 23:02 - 2013-11-10 13:00 - 00000000 ____D () C:\Users\Juga\Desktop\pib 2014-03-10 23:02 - 2013-10-21 13:16 - 00000000 ____D () C:\Users\Juga\Documents\Audible 2014-03-10 23:02 - 2013-10-21 11:46 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Scan2PDF 2014-03-10 23:02 - 2013-10-04 09:49 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\tor 2014-03-10 23:02 - 2013-05-11 16:20 - 00000000 ____D () C:\Users\Juga\Documents\a702_1.2 2014-03-10 23:02 - 2013-05-06 19:00 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Thunderbird 2014-03-10 23:01 - 2014-02-13 09:58 - 00000000 ____D () C:\Users\Juga\AppData\Local\Tempfeb52be43e051bfaf4839a6935e00e42 2014-03-10 23:01 - 2014-02-13 09:57 - 00000000 ____D () C:\Users\Juga\AppData\Local\Temp14b5077f6956a3517aafd12a4b0ddc8f 2014-03-10 23:01 - 2013-09-30 17:11 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\GHISLER 2014-03-10 23:01 - 2013-06-15 14:16 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\dvdcss 2014-03-10 23:01 - 2013-05-06 18:52 - 00000000 ___RD () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-10 23:01 - 2013-05-06 18:50 - 00000000 ___RD () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-10 23:01 - 2013-05-06 18:50 - 00000000 ___RD () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-10 23:01 - 2013-05-06 18:50 - 00000000 ___RD () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-03-10 23:01 - 2013-05-06 18:50 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-03-10 23:00 - 2014-02-13 09:58 - 00000000 ____D () C:\Users\Juga\AppData\Local\Temp12e72473eede95c369de200ff0f01ceb 2014-03-10 22:52 - 2013-11-02 21:16 - 00000000 ____D () C:\ProgramData\Package Cache 2014-03-10 22:52 - 2013-09-30 17:11 - 00000000 ____D () C:\totalcmd 2014-03-10 22:52 - 2013-09-04 07:41 - 00000000 ____D () C:\Users\Juga\AppData\Local\gtk-2.0 2014-03-10 22:52 - 2013-08-19 19:14 - 00000000 __SHD () C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2014-03-10 22:52 - 2013-05-18 10:02 - 00000000 ____D () C:\Users\Juga\AppData\Local\Downloaded Installations 2014-03-10 22:52 - 2013-05-09 10:21 - 00000000 ____D () C:\ProgramData\Skype 2014-03-10 22:52 - 2013-05-07 21:13 - 00000000 ____D () C:\Users\Juga\AppData\Local\Microsoft Help 2014-03-10 22:52 - 2013-05-06 18:50 - 00000000 ____D () C:\Users\Juga\AppData\Local\ASUS 2014-03-10 22:52 - 2012-11-15 19:48 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ASUS 2014-03-10 22:52 - 2012-11-15 19:39 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-10 22:52 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-03-10 22:52 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-03-10 22:50 - 2014-02-27 19:57 - 00000000 ____D () C:\ProgramData\Licenses 2014-03-10 22:50 - 2013-05-06 18:51 - 00000000 ____D () C:\ProgramData\FolderView 2014-03-10 22:50 - 2012-11-15 19:50 - 00000000 ____D () C:\ProgramData\ASUSVibe 2014-03-10 22:50 - 2012-08-17 01:53 - 00000000 ____D () C:\ProgramData\McAfee 2014-03-10 22:50 - 2012-08-17 01:53 - 00000000 ____D () C:\ProgramData\ASUS WebStorage 2014-03-10 22:47 - 2013-09-29 19:33 - 00000000 ____D () C:\Program Files\WinDjView 2014-03-10 22:47 - 2012-11-15 19:39 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-03-10 22:44 - 2013-09-04 07:27 - 00000000 ____D () C:\Program Files\GIMP 2 2014-03-10 22:42 - 2014-02-16 22:06 - 00000000 ____D () C:\Program Files\CCleaner 2014-03-10 22:42 - 2014-01-08 10:52 - 00000000 ____D () C:\Program Files\Classic Shell 2014-03-10 22:42 - 2013-11-11 07:12 - 00000000 ____D () C:\Program Files (x86)\wGet 2014-03-10 22:42 - 2013-08-18 10:30 - 00000000 ____D () C:\Program Files\Common Files\logishrd 2014-03-10 22:42 - 2012-11-15 19:43 - 00000000 ____D () C:\Program Files\DIFX 2014-03-10 22:42 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-03-10 22:41 - 2013-11-10 22:12 - 00000000 ____D () C:\Program Files (x86)\Texmaker 2014-03-10 22:41 - 2013-11-02 21:57 - 00000000 ____D () C:\Program Files (x86)\Tor Browser 2014-03-10 22:41 - 2013-10-04 09:49 - 00000000 ____D () C:\Program Files (x86)\Vidalia Relay Bundle 2014-03-10 22:41 - 2013-08-29 00:41 - 00000000 ____D () C:\Program Files (x86)\StreamTransport 2014-03-10 22:39 - 2014-02-20 09:42 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-10 22:39 - 2014-02-14 10:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-10 22:39 - 2014-02-05 13:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-10 22:39 - 2013-10-21 11:46 - 00000000 ____D () C:\Program Files (x86)\Scan2PDF 2014-03-10 22:39 - 2013-05-16 23:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator 2014-03-10 22:39 - 2013-05-06 18:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-10 22:39 - 2012-11-15 19:41 - 00000000 ____D () C:\Program Files (x86)\Realtek 2014-03-10 22:39 - 2012-11-15 19:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-03-10 22:38 - 2013-05-09 17:55 - 00000000 ____D () C:\Program Files (x86)\Mobile Partner 2014-03-10 22:35 - 2013-05-07 21:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2014-03-10 22:35 - 2013-05-07 21:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-03-10 22:34 - 2013-10-20 21:34 - 00000000 ____D () C:\Program Files (x86)\JonDo 2014-03-10 22:33 - 2013-11-10 21:24 - 00000000 ____D () C:\Program Files (x86)\GnuWin32 2014-03-10 22:33 - 2013-08-27 18:02 - 00000000 ____D () C:\Program Files (x86)\FLV Player 2014-03-10 22:32 - 2013-09-14 22:45 - 00000000 ____D () C:\Program Files (x86)\Calibre2 2014-03-10 22:29 - 2013-10-21 13:16 - 00000000 ____D () C:\Program Files (x86)\Audible 2014-03-10 22:29 - 2013-09-17 22:17 - 00000000 ____D () C:\Program Files (x86)\Audiograbber 2014-03-10 22:29 - 2012-08-17 01:53 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-03-10 22:28 - 2013-09-28 14:18 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-03-10 22:28 - 2013-08-15 10:47 - 00000000 ____D () C:\Fraps 2014-03-10 22:28 - 2012-11-15 19:35 - 00000000 ____D () C:\Intel 2014-03-10 22:22 - 2014-03-10 20:50 - 00000000 ____D () C:\Program Files (x86)\FreeCommander XE 2014-03-10 22:21 - 2014-03-08 18:49 - 00000000 ____D () C:\Program Files (x86)\IrfanView 2014-03-10 22:19 - 2014-03-09 23:08 - 00000000 ____D () C:\Program Files\Eraser 2014-03-10 22:15 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\registration 2014-03-10 21:00 - 2014-03-10 20:35 - 00000000 ____D () C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZZ.Z.ZZ.Z...Z 2014-03-10 20:50 - 2014-03-10 20:50 - 00000000 ____D () C:\Users\Juga\AppData\Local\FreeCommanderXE 2014-03-10 20:47 - 2013-10-21 13:16 - 00000000 ____D () C:\Users\Public\Documents\Audible 2014-03-10 20:43 - 2014-02-19 21:24 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-10 20:43 - 2013-10-03 12:01 - 00000000 ____D () C:\Users\Juga\AppData\Local\Google 2014-03-10 20:14 - 2014-01-03 16:19 - 00000000 ____D () C:\Users\Juga\Desktop\pics 2014-03-10 07:00 - 2014-03-10 07:00 - 00000000 ____D () C:\Users\Juga\AppData\Local\Eraser 6 2014-03-08 22:24 - 2014-03-08 21:32 - 00010748 _____ () C:\Users\Juga\Documents\foto-langen.xlsx 2014-03-07 14:06 - 2014-03-07 13:35 - 00008570 _____ () C:\Users\Juga\Documents\Telefonkosten.xlsx 2014-03-06 18:43 - 2014-03-06 18:42 - 00000000 ____D () C:\Users\Juga\Desktop\Tor Browser 2014-03-04 23:52 - 2012-07-26 09:14 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-04 23:52 - 2012-07-26 09:14 - 00078304 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-04 19:46 - 2014-03-04 17:23 - 00000000 ____D () C:\Users\Juga\Desktop\Münzbilder - test 2014-03-04 17:35 - 2014-03-04 13:36 - 00010867 _____ () C:\Users\Juga\Documents\Münzen.xlsx 2014-03-04 13:36 - 2014-03-04 13:36 - 00000165 ____H () C:\Users\Juga\Documents\~$Münzen.xlsx 2014-03-03 20:26 - 2013-08-26 18:00 - 00017974 _____ () C:\Users\Juga\Documents\DVD Liste.xlsx 2014-03-01 19:50 - 2014-02-26 13:59 - 00001283 _____ () C:\Users\Juga\Desktop\Bahnfahrt-Beschwerde.txt 2014-02-27 19:56 - 2014-02-27 19:56 - 04095448 _____ (BrightFort LLC ) C:\Users\Juga\Downloads\spywareblastersetup50.exe 2014-02-27 19:56 - 2014-02-27 19:56 - 04095448 _____ (BrightFort LLC ) C:\Users\Juga\Downloads\spywareblastersetup50(1).exe 2014-02-26 13:43 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-02-24 23:07 - 2014-02-24 23:07 - 00987425 _____ () C:\Users\Juga\Downloads\SecurityCheck.exe 2014-02-23 21:17 - 2014-02-23 21:17 - 00000000 ____D () C:\Windows\ERUNT 2014-02-23 12:16 - 2014-02-23 12:15 - 00000000 ____D () C:\Recovery 2014-02-23 12:10 - 2013-05-06 18:50 - 00066678 _____ () C:\Windows\diagwrn.xml 2014-02-23 12:10 - 2013-05-06 18:50 - 00066678 _____ () C:\Windows\diagerr.xml 2014-02-23 12:04 - 2013-08-18 10:30 - 00008713 _____ () C:\Windows\system32\lvcoinst.log 2014-02-23 09:13 - 2014-03-14 11:11 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-23 09:13 - 2014-03-14 11:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-23 09:13 - 2014-03-14 11:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-02-23 09:13 - 2014-03-14 11:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-02-23 09:13 - 2014-03-14 11:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-23 09:12 - 2014-03-14 11:11 - 19273216 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-23 09:12 - 2014-03-14 11:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-23 09:12 - 2014-03-14 11:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-23 09:11 - 2014-03-14 11:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-23 07:54 - 2014-03-14 11:11 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-23 07:54 - 2014-03-14 11:11 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-23 07:54 - 2014-03-14 11:11 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 14358016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-23 07:53 - 2014-03-14 11:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-23 07:35 - 2014-03-14 11:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-23 07:31 - 2014-03-14 11:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-23 05:06 - 2014-03-14 11:11 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-02-22 15:31 - 2013-12-29 14:33 - 00000285 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2014-02-22 12:22 - 2012-07-26 06:37 - 00000000 __RHD () C:\Users\Default 2014-02-21 23:44 - 2014-02-21 23:44 - 00019926 _____ () C:\Users\Juga\Desktop\Bestätigung Ihrer Zahlung an Rove.design GmbH.eml 2014-02-20 20:39 - 2013-05-08 17:53 - 00000000 ____D () C:\Users\Juga\AppData\Local\Adobe 2014-02-20 16:22 - 2014-02-20 16:18 - 00002167 _____ () C:\Users\Public\Desktop\SteuerSparErklärung 2014.lnk 2014-02-20 16:19 - 2014-02-20 16:16 - 00000000 ____D () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft 2014-02-20 16:19 - 2014-02-20 16:14 - 00000000 ____D () C:\ProgramData\AAV 2014-02-20 16:18 - 2014-02-20 16:18 - 00000000 ____D () C:\Users\Juga\AppData\Local\AAV 2014-02-20 14:28 - 2014-02-20 14:27 - 05631168 _____ (IvoSoft) C:\Users\Juga\Downloads\ClassicShellSetup_4_0_4.exe 2014-02-20 09:42 - 2014-02-20 09:42 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(2).exe 2014-02-20 09:42 - 2014-02-20 09:42 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-20 09:40 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows Portable Devices 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\WinStore 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\SysWOW64\MSDRM 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\MSDRM 2014-02-20 09:39 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache 2014-02-20 09:39 - 2012-07-26 06:37 - 00000000 ____D () C:\Windows\servicing 2014-02-20 09:38 - 2014-02-19 16:30 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\Malwarebytes 2014-02-20 09:38 - 2014-02-19 16:30 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-20 09:38 - 2014-02-18 08:48 - 00000000 ____D () C:\Users\Juga\AppData\Local\Skype 2014-02-20 09:38 - 2013-04-02 14:25 - 00000000 ____D () C:\Users\Juga\AppData\Local\Packages 2014-02-20 09:38 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\Help 2014-02-20 09:37 - 2013-05-10 20:39 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-20 09:37 - 2012-11-15 19:35 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-02-20 09:23 - 2013-05-08 06:20 - 00000000 ____D () C:\Users\Juga\AppData\Roaming\QuickScan 2014-02-19 23:36 - 2013-05-08 06:24 - 00000000 ____D () C:\ProgramData\BDLogging 2014-02-19 20:34 - 2014-02-19 20:34 - 00000000 ____D () C:\ProgramData\ClassicShell 2014-02-19 18:21 - 2014-02-19 18:21 - 00299776 _____ () C:\Windows\Minidump\021914-7500-01.dmp 2014-02-19 17:09 - 2014-02-19 17:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-consumer.exe 2014-02-19 16:29 - 2014-02-19 16:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Juga\Downloads\mbam-setup- 2014-02-19 16:03 - 2014-02-19 16:03 - 00000470 _____ () C:\Windows\SysWOW64\defogger_disable.log 2014-02-19 15:51 - 2014-02-19 15:51 - 00296784 _____ () C:\Windows\Minidump\021914-7562-01.dmp 2014-02-19 15:44 - 2014-02-19 15:44 - 00299816 _____ () C:\Windows\Minidump\021914-7718-01.dmp 2014-02-19 12:46 - 2014-02-19 12:46 - 01141248 _____ (Farbar) C:\Users\Juga\Downloads\FRST.exe 2014-02-19 12:46 - 2014-02-19 12:46 - 00000000 _____ () C:\Users\Juga\defogger_reenable 2014-02-19 12:43 - 2013-07-26 23:49 - 00000101 _____ () C:\Users\Juga\AppData\Roaming\WB.CFG 2014-02-18 08:48 - 2014-02-18 08:48 - 00003142 _____ () C:\Windows\System32\Tasks\{CEEC242F-CB31-4B7C-BA41-759D23FC22A4} 2014-02-18 08:47 - 2014-02-18 08:47 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Juga\Downloads\SkypeSetup(1).exe 2014-02-16 22:20 - 2013-05-06 18:51 - 00000000 ____D () C:\Users\Juga\AppData\Local\VirtualStore 2014-02-16 22:08 - 2012-08-02 23:24 - 00000000 ____D () C:\Windows\Panther 2014-02-16 22:06 - 2014-02-16 22:06 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-02-16 22:06 - 2014-02-16 22:05 - 03645064 _____ (Piriform Ltd) C:\Users\Juga\Downloads\ccsetup410_slim.exe 2014-02-16 12:59 - 2014-02-16 12:58 - 54537728 _____ () C:\Users\Juga\Downloads\calibre-1.24.0.msi 2014-02-15 20:19 - 2013-11-02 21:49 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-15 20:17 - 2014-02-15 20:17 - 24490112 _____ (Mozilla) C:\Users\Juga\Downloads\Firefox Setup 27.0.1.exe 2014-02-14 19:21 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI(1020) Some content of TEMP: ==================== C:\Users\Juga\AppData\Local\Temp\Quarantine.exe C:\Users\Juga\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-08 10:57 ==================== End Of Log ============================ Soll ich nochmal irgendwelche Schritte von vorher wiederholen? |
In welchem Browser?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Danke für die Nachricht!

Es ist Firefox - mein Standardbrowser. Manchmal auch die Standardhilfeseiten von Word. Besonders schlimm scheint es zu sein, wenn ich Thunderbird aufhabe. Dann werden manchmal plötzlich mehr als 50 Seiten geöffnet und ich kriege es nur noch über Task-Manager und Zwangsbeenden in den Griff.

Noch eine Anmerkung: Also oft tritt das Problem auf, wenn ich das Thunderbird mail programm geöffnet habe oder benutze. Dann öffnen sich plötzlich - für mich scheinbar unvermittelt - Hilfeseiten auf Firefox. Weiss nicht, ob as bei der Fehlerdiagnose hilft.

Das seltsame ist, dass es tatsächlich so etwa 1-2 Wochen weg war :-/.
Bevor wir jetzt tief graben mal ne ganz blöde Idee:

Ist das ein Desktop rechner oder Laptop? Keyboard intern oder extern via USB oder PS2 Anschluss?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Stimmt, das ist eine gute Idee, sich das mal anzugucken danke!!

Ich habe ein Zenbook und benutze die interne Tastatur. Ich weiss nicht, wie man in Windows die Taste zum Aufruf der "Hilfeseiten" umstellen kann, wenn man das per Software einstellen könnte, könnte man ja probieren, ob es ein Tastaturfehler ist oder?

Hallo,

ich habe folgendes gemacht: Das Programm SharpKeys installiert, mit dem einzelne Tasten in der Registry überschreiben kann und die F1 Taste abgeschaltet... Seitdem tritt der Fehler nicht mehr auf - das spricht doch für ein Hardewareproblem?

Das seltsame war allerdings bei dem Fehler, dass er nur manchmal auftrat vorher und bei einigen Programmen besonders häufig und die Taste auch nicht offensichtlich klemmte... seltsam.

Danke für den Tipp ... !!!
