|
Plagegeister aller Art und deren Bekämpfung: Avast findet Virus und Malwarebytes findet VirenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.03.2014, 17:30 | #1 |
| Avast findet Virus und Malwarebytes findet Viren Hallo, ich habe Heute mal meinen PC auf Viren gescannt. Nachdem Avast "NSIS:NextLive-A" gefunden hat, habe ich mir Malwarebytes gedownloaded und habe es auch einmal scannen lassen. Mein PC hat keine Symptome, die ich bis jetzt bemerkt habe. Das Internet und der PC haben sich nicht verlangsamt. Sever01 Malwarebytes Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.03.08.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16518 Franz :: FRANZ-PC [Administrator] 08.03.2014 13:50:37 MBAM-log-2014-03-08 (14-48-22).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 452803 Laufzeit: 53 Minute(n), 49 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 6 C:\$RECYCLE.BIN\S-1-5-21-921928476-601607189-1348779831-1000\$RKADB69.exe (PUP.Optional.Amonetize.A) -> Keine Aktion durchgeführt. C:\Users\Franz\AppData\Local\11926\a25799.exe (PUP.Optional.Amonetize.A) -> Keine Aktion durchgeführt. C:\Users\Franz\AppData\Local\Temp\awhE370.tmp (PUP.Optional.SkyTech.A) -> Keine Aktion durchgeführt. C:\Users\Franz\AppData\Local\Temp\Fraps3.5.99Setup__4940_il4040.exe (PUP.Optional.Amonetize.A) -> Keine Aktion durchgeführt. C:\Windows\Tasks\Re-markit_wd.job (PUP.Optional.ReMarkIt.A) -> Keine Aktion durchgeführt. C:\Users\Franz\AppData\Local\Temp\Re-markit_2040-4032.exe (PUP.Optional.ReMarkIT.A) -> Keine Aktion durchgeführt. (Ende) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2014 01 Ran by Franz (administrator) on FRANZ-PC on 08-03-2014 16:46:31 Running from C:\Users\Franz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe () C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.202\deploy\LoLLauncher.exe () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.75\deploy\LolClient.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-09] (AVAST Software) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [NetLimiter] - C:\Program Files\NetLimiter 3\NLClientApp.exe /tray HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1B05EBC14B4ECE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{B93B3B22-47CA-4026-BCD3-DE87FBC83548}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default FF NewTab: about:blank FF Homepage: https://www.google.de/|hxxp://www.rudolf-hildebrand-schule.de/|hxxp://nosxclan.ohost.de/index.php?news FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.20 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-28] FF Extension: Personas Plus - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\Extensions\personas@christopher.beard.xpi [2013-06-08] FF Extension: Adblock Plus - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-31] FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-05-11] FF HKCU\...\Firefox\Extensions: [{8a1a43a3-ee9f-4fff-9c5c-b3063ee1f0e0}] - C:\Program Files (x86)\Re-markit-soft\157.xpi FF Extension: No Name - C:\Program Files (x86)\Re-markit-soft\157.xpi [2014-03-08] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-09] (AVAST Software) R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-20] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-20] (Intel Corporation) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC) ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-09] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-24] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-24] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-09] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-09] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-01] () R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider) R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-22] (Intel Corporation) S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-03-14] () R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-03-20] (Intel Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments) R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-21] (Microsoft Corporation) S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X] S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X] S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-08 16:40 - 2014-03-08 16:46 - 00014466 _____ () C:\Users\Franz\Downloads\FRST.txt 2014-03-08 16:40 - 2014-03-08 16:40 - 00000000 ____D () C:\FRST 2014-03-08 16:39 - 2014-03-08 16:39 - 02156544 _____ (Farbar) C:\Users\Franz\Downloads\FRST64.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00050477 _____ () C:\Users\Franz\Downloads\Defogger.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00000472 _____ () C:\Users\Franz\Downloads\defogger_disable.log 2014-03-08 16:38 - 2014-03-08 16:38 - 00000000 _____ () C:\Users\Franz\defogger_reenable 2014-03-08 13:25 - 2014-03-08 13:25 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-08 13:25 - 2014-03-08 13:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-08 13:25 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-08 12:30 - 2014-03-08 13:58 - 00015181 _____ () C:\Users\Franz\Documents\American news.odt 2014-03-08 12:28 - 2014-03-08 13:21 - 00000390 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-03-08 12:28 - 2014-03-08 12:28 - 00002978 _____ () C:\Windows\System32\Tasks\Re-markit_wd 2014-03-08 12:28 - 2014-03-08 12:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-08 12:28 - 2014-03-08 12:28 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-03-08 12:27 - 2014-03-08 12:27 - 00000000 ____D () C:\Users\Franz\AppData\Local\11926 2014-03-08 12:19 - 2014-03-08 12:19 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 12:19 - 2014-03-08 12:19 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-06 13:33 - 2014-03-06 19:10 - 00000000 ____D () C:\Program Files\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000935 _____ () C:\Users\Franz\Desktop\Open Broadcaster Software.lnk 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-06 13:23 - 2014-03-08 11:48 - 00001306 _____ () C:\Windows\PFRO.log 2014-03-05 19:28 - 2014-03-05 19:28 - 00000000 ____D () C:\Users\Franz\AppData\Local\SplitMediaLabs 2014-03-05 19:26 - 2014-03-08 16:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-05 19:26 - 2014-03-06 14:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-05 19:26 - 2014-03-06 14:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-05 19:26 - 2014-03-06 14:28 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-05 19:17 - 2014-03-06 13:35 - 00000000 ____D () C:\Program Files (x86)\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:26 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:17 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-03-04 14:58 - 2014-03-04 14:58 - 00000000 ____D () C:\Users\Franz\AppData\Local\Skype 2014-03-04 14:57 - 2014-03-04 14:57 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-04 14:57 - 2014-03-04 14:57 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-03 17:46 - 2014-03-03 17:46 - 00000000 ____D () C:\Users\Franz\Documents\Scratch Projekte 2014-03-03 17:41 - 2014-03-08 12:18 - 00000000 ____D () C:\Users\Franz\AppData\Local\Dxtory Software 2014-03-03 17:41 - 2014-03-03 17:42 - 00000000 ____D () C:\Program Files (x86)\Dxtory Software 2014-03-03 17:39 - 2014-03-03 17:39 - 00715038 _____ () C:\Windows\unins000.exe 2014-03-03 17:39 - 2014-03-03 17:39 - 00001990 _____ () C:\Windows\unins000.dat 2014-03-03 17:39 - 2011-12-07 19:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll 2014-03-03 17:39 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll 2014-03-01 17:47 - 2014-03-01 17:47 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 17:42 - 2014-03-01 17:42 - 00001845 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-02-25 13:27 - 2014-02-25 13:28 - 00000000 ____D () C:\ef47be9d57167b970f003dc78fd13db7 2014-02-23 10:37 - 2014-02-23 10:37 - 00000646 _____ () C:\Users\Franz\Desktop\PBE.lnk 2014-02-23 10:33 - 2014-03-08 16:42 - 00000896 _____ () C:\Windows\setupact.log 2014-02-23 10:33 - 2014-02-23 10:33 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-22 19:59 - 2014-02-22 19:59 - 00000000 ____D () C:\Program Files (x86)\WinPcap 2014-02-22 19:58 - 2014-02-22 19:58 - 00003059 _____ () C:\Users\Franz\Desktop\PowerLine Utility.lnk 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TP-LINK 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-02-22 19:46 - 2014-02-22 19:46 - 00000000 ____D () C:\Users\Franz\Documents\My Weblog Posts 2014-02-22 17:35 - 2014-02-26 13:05 - 00000000 ____D () C:\Users\Franz\Tracing 2014-02-22 17:11 - 2014-02-22 17:11 - 00000000 ____D () C:\Windows\de 2014-02-22 17:09 - 2014-02-26 13:13 - 00000000 ____D () C:\Program Files\Windows Live 2014-02-22 17:09 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-02-22 17:09 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-02-22 17:09 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ___RD () C:\Users\Franz\OneDrive 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft OneDrive 2014-02-22 17:08 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-02-22 17:08 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-02-22 17:07 - 2014-02-22 17:07 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{7514B9EE-62DF-4EB7-97F7-AAAAEA715FB3} 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{5907288C-7E23-4F4F-8A0D-385823C80FDB} 2014-02-15 17:24 - 2014-02-15 17:24 - 00001274 _____ () C:\Users\Franz\Desktop\Technik Launcher.lnk 2014-02-15 15:38 - 2014-02-15 15:42 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-15 15:31 - 2014-02-20 19:37 - 00000000 ____D () C:\ProgramData\Tunngle 2014-02-15 15:31 - 2014-02-15 15:31 - 00000991 _____ () C:\Users\Public\Desktop\Tunngle beta.lnk 2014-02-15 15:31 - 2014-02-15 15:31 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2014-02-15 15:26 - 2014-02-15 15:26 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-02-15 15:14 - 2014-02-15 15:14 - 00000000 ____D () C:\Users\Franz\Documents\Tunngle 2014-02-15 15:09 - 2014-02-15 15:10 - 00000000 ____D () C:\Users\Franz\Desktop\Jakob Server 2014-02-15 12:30 - 2014-02-15 12:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-14 19:06 - 2014-02-14 19:06 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OpenOffice 2014-02-14 15:19 - 2014-02-16 13:02 - 00000000 ____D () C:\ProgramData\Soluto 2014-02-14 15:19 - 2014-02-16 13:01 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2014-02-13 15:29 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 15:29 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 15:28 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 15:28 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 15:28 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 15:28 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 15:28 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 15:28 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 15:28 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 15:28 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 15:28 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 15:28 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 15:28 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 15:28 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 15:28 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 15:28 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 15:28 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 15:28 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 15:28 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 15:28 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 15:28 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 15:28 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 15:28 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 15:28 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 15:28 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 15:28 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 15:28 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 15:28 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 15:28 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 15:28 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 15:28 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 15:28 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 15:28 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 15:28 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 15:28 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 15:28 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 15:28 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 15:28 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 15:28 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 15:28 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 15:28 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 11:49 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 11:49 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 11:48 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 11:48 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 11:48 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 11:48 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 11:48 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 11:48 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 11:48 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 11:48 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 11:48 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 11:48 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 11:48 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 11:48 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 11:48 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 16:53 - 2014-02-15 17:24 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.technic 2014-02-09 13:37 - 2014-02-09 13:37 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-06 19:47 - 2014-02-06 19:47 - 00026484 _____ () C:\Users\Franz\Documents\Koks Bio.odt ==================== One Month Modified Files and Folders ======= 2014-03-08 16:46 - 2014-03-08 16:40 - 00014466 _____ () C:\Users\Franz\Downloads\FRST.txt 2014-03-08 16:46 - 2013-05-15 19:29 - 00000000 ____D () C:\Users\Franz\AppData\Local\PMB Files 2014-03-08 16:42 - 2014-02-23 10:33 - 00000896 _____ () C:\Windows\setupact.log 2014-03-08 16:40 - 2014-03-08 16:40 - 00000000 ____D () C:\FRST 2014-03-08 16:39 - 2014-03-08 16:39 - 02156544 _____ (Farbar) C:\Users\Franz\Downloads\FRST64.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00050477 _____ () C:\Users\Franz\Downloads\Defogger.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00000472 _____ () C:\Users\Franz\Downloads\defogger_disable.log 2014-03-08 16:38 - 2014-03-08 16:38 - 00000000 _____ () C:\Users\Franz\defogger_reenable 2014-03-08 16:38 - 2013-05-11 16:15 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Skype 2014-03-08 16:38 - 2013-05-11 14:14 - 00000000 ____D () C:\Users\Franz 2014-03-08 16:28 - 2014-03-05 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-08 16:03 - 2013-05-15 19:29 - 00000000 ____D () C:\ProgramData\PMB Files 2014-03-08 14:55 - 2013-08-13 10:15 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-03-08 14:54 - 2013-05-11 15:16 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Adobe 2014-03-08 14:54 - 2013-05-11 15:13 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-08 14:52 - 2014-01-19 12:47 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-08 13:58 - 2014-03-08 12:30 - 00015181 _____ () C:\Users\Franz\Documents\American news.odt 2014-03-08 13:28 - 2009-07-14 05:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-08 13:28 - 2009-07-14 05:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-08 13:25 - 2014-03-08 13:25 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-08 13:25 - 2014-03-08 13:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-08 13:24 - 2013-08-10 12:50 - 02014112 _____ () C:\Windows\WindowsUpdate.log 2014-03-08 13:22 - 2009-07-14 05:45 - 05006784 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-08 13:21 - 2014-03-08 12:28 - 00000390 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-03-08 13:21 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-08 13:19 - 2013-09-18 18:30 - 00000000 ____D () C:\AdwCleaner 2014-03-08 13:17 - 2013-05-11 14:30 - 00069608 _____ () C:\Users\Franz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-08 12:28 - 2014-03-08 12:28 - 00002978 _____ () C:\Windows\System32\Tasks\Re-markit_wd 2014-03-08 12:28 - 2014-03-08 12:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-08 12:28 - 2014-03-08 12:28 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-03-08 12:28 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-08 12:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-03-08 12:27 - 2014-03-08 12:27 - 00000000 ____D () C:\Users\Franz\AppData\Local\11926 2014-03-08 12:19 - 2014-03-08 12:19 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 12:19 - 2014-03-08 12:19 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-08 12:18 - 2014-03-03 17:41 - 00000000 ____D () C:\Users\Franz\AppData\Local\Dxtory Software 2014-03-08 11:59 - 2013-06-18 18:44 - 00000000 ____D () C:\Users\Franz\AppData\Local\Adobe 2014-03-08 11:48 - 2014-03-06 13:23 - 00001306 _____ () C:\Windows\PFRO.log 2014-03-07 20:10 - 2013-05-17 19:11 - 00000000 ____D () C:\Users\Franz\AppData\Local\CrashDumps 2014-03-07 13:46 - 2013-05-11 15:32 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-06 19:10 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files\OBS 2014-03-06 14:28 - 2014-03-05 19:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-06 14:28 - 2014-03-05 19:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-06 14:28 - 2014-03-05 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-06 13:35 - 2014-03-05 19:17 - 00000000 ____D () C:\Program Files (x86)\SplitMediaLabs 2014-03-06 13:33 - 2014-03-06 13:33 - 00000935 _____ () C:\Users\Franz\Desktop\Open Broadcaster Software.lnk 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-05 19:28 - 2014-03-05 19:28 - 00000000 ____D () C:\Users\Franz\AppData\Local\SplitMediaLabs 2014-03-05 19:26 - 2014-03-05 19:17 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:17 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-03-05 15:42 - 2013-11-23 12:18 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-03-05 13:22 - 2013-05-11 14:14 - 00000000 ___RD () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-04 16:54 - 2013-07-03 18:09 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.minecraft 2014-03-04 14:58 - 2014-03-04 14:58 - 00000000 ____D () C:\Users\Franz\AppData\Local\Skype 2014-03-04 14:57 - 2014-03-04 14:57 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-04 14:57 - 2014-03-04 14:57 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-04 14:57 - 2013-05-11 16:15 - 00000000 ____D () C:\ProgramData\Skype 2014-03-03 17:46 - 2014-03-03 17:46 - 00000000 ____D () C:\Users\Franz\Documents\Scratch Projekte 2014-03-03 17:42 - 2014-03-03 17:41 - 00000000 ____D () C:\Program Files (x86)\Dxtory Software 2014-03-03 17:39 - 2014-03-03 17:39 - 00715038 _____ () C:\Windows\unins000.exe 2014-03-03 17:39 - 2014-03-03 17:39 - 00001990 _____ () C:\Windows\unins000.dat 2014-03-02 13:30 - 2013-05-17 19:11 - 01596822 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-02 13:30 - 2011-04-12 08:43 - 00700316 _____ () C:\Windows\system32\perfh007.dat 2014-03-02 13:30 - 2011-04-12 08:43 - 00149954 _____ () C:\Windows\system32\perfc007.dat 2014-03-02 13:30 - 2009-07-14 06:13 - 01596822 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-01 17:47 - 2014-03-01 17:47 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 17:42 - 2014-03-01 17:42 - 00001845 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-03-01 17:42 - 2013-05-12 09:29 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-02-26 13:14 - 2013-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-02-26 13:13 - 2014-02-22 17:09 - 00000000 ____D () C:\Program Files\Windows Live 2014-02-26 13:05 - 2014-02-22 17:35 - 00000000 ____D () C:\Users\Franz\Tracing 2014-02-25 13:28 - 2014-02-25 13:27 - 00000000 ____D () C:\ef47be9d57167b970f003dc78fd13db7 2014-02-25 13:23 - 2013-05-31 19:13 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\TS3Client 2014-02-23 10:37 - 2014-02-23 10:37 - 00000646 _____ () C:\Users\Franz\Desktop\PBE.lnk 2014-02-23 10:33 - 2014-02-23 10:33 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-22 21:37 - 2013-12-09 18:47 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-22 21:37 - 2013-05-11 16:03 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-22 21:11 - 2013-05-17 14:45 - 00000000 ____D () C:\Riot Games 2014-02-22 19:59 - 2014-02-22 19:59 - 00000000 ____D () C:\Program Files (x86)\WinPcap 2014-02-22 19:58 - 2014-02-22 19:58 - 00003059 _____ () C:\Users\Franz\Desktop\PowerLine Utility.lnk 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TP-LINK 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-02-22 19:46 - 2014-02-22 19:46 - 00000000 ____D () C:\Users\Franz\Documents\My Weblog Posts 2014-02-22 19:46 - 2013-09-20 19:38 - 00000000 ____D () C:\Users\Franz\AppData\Local\Windows Live Writer 2014-02-22 17:29 - 2013-05-15 19:31 - 00000000 ____D () C:\Users\Franz\AppData\Local\Windows Live 2014-02-22 17:11 - 2014-02-22 17:11 - 00000000 ____D () C:\Windows\de 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ___RD () C:\Users\Franz\OneDrive 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft OneDrive 2014-02-22 17:07 - 2014-02-22 17:07 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{7514B9EE-62DF-4EB7-97F7-AAAAEA715FB3} 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{5907288C-7E23-4F4F-8A0D-385823C80FDB} 2014-02-21 17:41 - 2013-06-22 19:27 - 00000000 ____D () C:\Windows\pss 2014-02-20 19:37 - 2014-02-15 15:31 - 00000000 ____D () C:\ProgramData\Tunngle 2014-02-20 19:37 - 2013-05-11 16:23 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Tunngle 2014-02-20 16:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-16 13:06 - 2013-12-24 10:42 - 00000000 ____D () C:\Program Files (x86)\Freemake 2014-02-16 13:02 - 2014-02-14 15:19 - 00000000 ____D () C:\ProgramData\Soluto 2014-02-16 13:01 - 2014-02-14 15:19 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2014-02-15 17:24 - 2014-02-15 17:24 - 00001274 _____ () C:\Users\Franz\Desktop\Technik Launcher.lnk 2014-02-15 17:24 - 2014-02-11 16:53 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.technic 2014-02-15 15:43 - 2013-05-11 14:20 - 00000000 ____D () C:\Program Files (x86)\REALTEK 2014-02-15 15:42 - 2014-02-15 15:38 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-15 15:32 - 2013-05-11 16:23 - 00000000 ____D () C:\Program Files (x86)\Tunngle 2014-02-15 15:31 - 2014-02-15 15:31 - 00000991 _____ () C:\Users\Public\Desktop\Tunngle beta.lnk 2014-02-15 15:31 - 2014-02-15 15:31 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2014-02-15 15:26 - 2014-02-15 15:26 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-02-15 15:25 - 2013-05-11 15:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-15 15:14 - 2014-02-15 15:14 - 00000000 ____D () C:\Users\Franz\Documents\Tunngle 2014-02-15 15:10 - 2014-02-15 15:09 - 00000000 ____D () C:\Users\Franz\Desktop\Jakob Server 2014-02-15 12:37 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-15 12:30 - 2014-02-15 12:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-14 19:06 - 2014-02-14 19:06 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OpenOffice 2014-02-14 18:59 - 2013-06-17 14:45 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Feed The Beast 2014-02-14 16:00 - 2013-08-15 10:27 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-14 15:59 - 2013-05-11 17:35 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-12 14:13 - 2013-07-10 14:23 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\FileZilla 2014-02-09 16:10 - 2014-01-24 19:02 - 00000000 ____D () C:\Users\Franz\AppData\Local\Battle.net 2014-02-09 13:37 - 2014-02-09 13:37 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-09 13:37 - 2014-01-01 15:08 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-09 13:37 - 2013-05-11 15:32 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-09 13:36 - 2013-05-11 15:32 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-06 19:47 - 2014-02-06 19:47 - 00026484 _____ () C:\Users\Franz\Documents\Koks Bio.odt 2014-02-06 13:16 - 2014-02-13 15:28 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 15:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 15:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 15:28 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 15:28 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 15:28 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 15:28 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-13 15:28 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-13 15:28 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 15:28 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 15:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 15:28 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 15:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 15:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 15:28 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 15:28 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 15:28 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 15:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 15:28 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 15:28 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 15:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 15:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 15:28 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-13 15:28 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-13 15:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 15:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 15:28 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 15:28 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 15:28 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 15:28 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 15:28 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 15:28 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 15:28 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 15:28 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 15:28 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 15:28 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 15:28 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 15:28 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Franz\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Franz\AppData\Local\Temp\Fraps3.5.99Setup__4940_il4040.exe C:\Users\Franz\AppData\Local\Temp\Quarantine.exe C:\Users\Franz\AppData\Local\Temp\Re-markit_2040-4032.exe C:\Users\Franz\AppData\Local\Temp\uninstall_flash_player.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-08 15:12 ==================== End Of Log ============================ --- --- --- --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2014 01 Ran by Franz at 2014-03-08 16:47:03 Running from C:\Users\Franz\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.10 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2013 - Avast Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Blender (HKLM\...\Blender) (Version: 2.67 - Blender Foundation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Brick-Force (HKLM-x32\...\Brick-Force) (Version: - Infernum Productions AG) Camtasia Studio 8 (HKLM-x32\...\{8F6F7194-0734-4CDA-8C04-6B766F2241A6}) (Version: 8.0.4.1060 - TechSmith Corporation) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden diclovit's mod pack 1.9.0 (HKLM-x32\...\{28B1238E-1C18-4637-A2B7-95315E94EB29}_is1) (Version: 1.9.0 - diclovit) DIE SIEDLER - Das Erbe der Könige - Gold Edition (HKLM-x32\...\{E08DE897-B6AF-4DFF-9E90-131E80C876B4}) (Version: 1.00.0000 - Blue Byte) Dokan Library 0.6.0 (HKLM-x32\...\DokanLibrary) (Version: - ) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden FileZilla Client 3.7.3 (HKCU\...\FileZilla Client) (Version: 3.7.3 - Tim Kosse) Fotogalerie (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden GIMP 2.8.8 (HKLM\...\GIMP-2_is1) (Version: 2.8.8 - The GIMP Team) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.0.1428 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.5.0.1066 - Intel Corporation) Hidden Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.27.798.1 - Intel Corporation) Hidden iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java SE Development Kit 7 Update 25 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170250}) (Version: 1.7.0.250 - Oracle) Junk Mail filter update (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - ) League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.5.2 - www.leaguereplays.com) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Expression Web 4 (HKLM-x32\...\Web_4.0.1460.0) (Version: 4.0.1460.0 - Microsoft Corporation) Microsoft Expression Web 4 (x32 Version: 4.0.1460.0 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.4.5 - Notepad++ Team) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.) Photo Gallery (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden PlanetSide 2 (HKCU\...\SOE-PlanetSide 2 PSG) (Version: 1.0.3.183 - Sony Online Entertainment) PowerLine Utility (HKLM-x32\...\{762E248A-F922-42D6-B577-A47B0AB558D2}) (Version: 1.1.810 - TP-LINK) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) Re-markit (HKLM-x32\...\1366f773-3476-4d68-acc0-219e692e6fd3) (Version: - Re-markit Software) <==== ATTENTION ROCCAT Lua Mouse Driver (HKLM-x32\...\{10E03440-9A5B-48F5-BB24-359EFE3E6C71}) (Version: 1.13 - ROCCAT GmbH) Scratch (HKLM-x32\...\Scratch) (Version: 1.4.0.0 - MIT Media Lab Lifelong Kindergarten Group) SHARKOON Skiller (HKLM-x32\...\{91C25547-9534-41A5-823A-1E54BA16EA3F}) (Version: 1.00.0000 - ) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH) Theme Resource Changer X64 v1.0 (HKLM\...\Theme Resource Changer X64 v1.0) (Version: - Bad Ass Apps) TI-Nspire(TM) CAS Student Software (HKLM-x32\...\{E8CC9064-8382-4D5C-9E55-F88D9541FFC0}) (Version: 3.2.0.1219 - Texas Instruments Inc.) TmNationsForever (HKLM-x32\...\TmNationsForever_is1) (Version: - Nadeo) Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version: - Tunngle.net GmbH) UxStyle Core Beta (HKLM\...\{8E363055-15E5-4D8A-9C69-A0A9DE9A3337}) (Version: 0.2.1.1 - The Within Network, LLC) Windows Live Communications Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) World of Tanks - Common Test (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812CT}_is1) (Version: - Wargaming.net) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) World of Warplanes (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C813EU}_is1) (Version: - Wargaming.net) ==================== Restore Points ========================= 06-03-2014 12:34:50 Removed XSplit Broadcaster 07-03-2014 13:02:20 Windows Update 08-03-2014 11:08:12 Removed OpenOffice 4.0.1 08-03-2014 11:14:18 OpenOffice 4.0.1 wird installiert 08-03-2014 11:16:45 OpenOffice 4.0.1 wird installiert 08-03-2014 11:18:14 OpenOffice 4.0.1 wird installiert ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-08-07 15:42 - 00000031 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-03-08 17:12:18 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST1000DM003-1CH162 rev.CC44 931,51GB Running: mngwvcjz.exe; Driver: C:\Users\Franz\AppData\Local\Temp\pgloypog.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\wininit.exe[672] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\winlogon.exe[708] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\services.exe[764] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\svchost.exe[912] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\atiesrxx.exe[340] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\System32\svchost.exe[444] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\System32\svchost.exe[820] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\svchost.exe[928] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1044] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\AUDIODG.EXE[1120] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\System32\spoolsv.exe[1680] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1712] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1796] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1820] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe[1900] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Windows\system32\svchost.exe[2036] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\System32\svchost.exe[1196] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1172] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\Explorer.EXE[2968] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1416] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[2480] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[3112] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3168] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[3252] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Windows\system32\SearchIndexer.exe[3364] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3808] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3884] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files\iPod\bin\iPodService.exe[2492] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4340] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4804] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000755b1465 2 bytes [5B, 75] .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000755b14bb 2 bytes [5B, 75] .text ... * 2 .text C:\Windows\system32\wbem\wmiprvse.exe[4888] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076dceecd 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[4924] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[4972] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[4972] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000755b1465 2 bytes [5B, 75] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[4972] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000755b14bb 2 bytes [5B, 75] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5012] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000755b1465 2 bytes [5B, 75] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000755b14bb 2 bytes [5B, 75] .text ... * 2 .text C:\Users\Franz\Downloads\mngwvcjz.exe[4592] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076b9a2ba 1 byte [62] ---- Threads - GMER 2.1 ---- Thread [3800:4028] 00000000770c2e65 Thread [3800:4032] 00000000770c3e85 Thread [3800:4036] 0000000072dff28e Thread [3800:4040] 000000006bd313f0 Thread [3800:4044] 0000000072310140 Thread [3800:4048] 0000000072dff28e Thread [3800:4068] 0000000072dff28e Thread [3800:4076] 0000000072dff28e Thread [3800:3772] 000000006d3da031 Thread [3800:3880] 000000006d3da031 Thread [3800:3876] 000000006df6b90f Thread [3800:3912] 000000006df6b90f Thread [3800:3916] 000000006df6b90f Thread [3800:2652] 000000006df6b90f Thread [3800:2860] 000000006df6b90f Thread [3800:4056] 000000006d3da031 Thread [3800:3396] 00000000770c3e85 Thread [3800:3716] 000000006d3da031 Thread [3800:1348] 000000006d3da031 Thread [3800:3652] 000000006d3da031 Thread [3800:5068] 00000000770c3e85 Thread [3800:3268] 00000000770c3e85 Thread [3800:2508] 00000000770c3e85 Thread [3800:1336] 000000006c8960d0 Thread [3800:5108] 000000006c8960d0 Thread [3800:3920] 000000006c8960d0 Thread [3800:3936] 000000006c8960d0 Thread [3800:3932] 000000006c8960d0 Thread [3800:2528] 00000000770c3e85 Thread [3800:4616] 00000000770c3e85 Thread [3800:4628] 00000000770c3e85 Thread [3800:4644] 00000000770c3e85 Thread [3800:4620] 000000007547d864 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [252:3688] 000007fefad22a7c Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [252:3480] 000007feedc34830 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [252:4172] 000007feedc34830 ---- EOF - GMER 2.1 ---- Geändert von sever01 (08.03.2014 um 17:36 Uhr) |
08.03.2014, 17:40 | #2 |
/// the machine /// TB-Ausbilder | Avast findet Virus und Malwarebytes findet Viren Hi,
__________________Funde von MBAM löschen lassen. Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
09.03.2014, 18:31 | #3 |
| Avast findet Virus und Malwarebytes findet Viren Hallo,
__________________danke für die schnelle Antwort. Ich habe vergessen in meiner Frage zu erwähenen, dass ich ADW Cleaner heute schonmal laufen gehabt hab. Wenn ich FRST laufen hab, gibt Windows den Fehler aus bei dem Schritt Scanning Firefox: Extensions: "Aufgrund eines unerwarteten Fehlers können Sie die Datei nicht kopieren. Wenn der Fehler weiterhin ausgegeben wird, können Sie mithilfe des Fehlercodes in der Hilfe nach diesem Problem suchen. Fehler 0x80030002: install.rdf wurde nicht gefunden" Alter log: Code:
ATTFilter # AdwCleaner v3.020 - Bericht erstellt am 08/03/2014 um 13:19:19 # Aktualisiert 27/02/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Franz - FRANZ-PC # Gestartet von : C:\Users\Franz\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\f8b34e3b5e6e337aa6491ee3f713f8f5\adwcleaner_3.0.2.0.exe # Option : Suchen ***** [ Dienste ] ***** Dienst Gefunden : Re-markit ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\user.js Datei Gefunden : C:\Windows\System32\Tasks\AmiUpdXp Datei Gefunden : C:\Windows\System32\Tasks\Re-markit Update Datei Gefunden : C:\Windows\Tasks\AmiUpdXp.job Datei Gefunden : C:\Windows\Tasks\Re-markit Update.job Ordner Gefunden C:\Users\Franz\AppData\Local\Temp\OCS Ordner Gefunden C:\Windows\SysWOW64\AI_RecycleBin ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\OCS Schlüssel Gefunden : [x64] HKCU\Software\OCS Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Updater.AmiUpd Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\prefs.js ] [ Datei : C:\Users\Youtube\AppData\Roaming\Mozilla\Firefox\Profiles\uhllyprv.default\prefs.js ] ************************* AdwCleaner[R0].txt - [2245 octets] - [18/09/2013 18:30:58] AdwCleaner[R1].txt - [2567 octets] - [08/03/2014 13:19:19] AdwCleaner[S0].txt - [2156 octets] - [18/09/2013 18:31:23] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [2687 octets] ########## Code:
ATTFilter # Aktualisiert 27/02/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Franz - FRANZ-PC # Gestartet von : C:\Users\Franz\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\prefs.js ] [ Datei : C:\Users\Youtube\AppData\Roaming\Mozilla\Firefox\Profiles\uhllyprv.default\prefs.js ] ************************* AdwCleaner[R0].txt - [2245 octets] - [18/09/2013 18:30:58] AdwCleaner[R1].txt - [2779 octets] - [08/03/2014 13:19:19] AdwCleaner[R2].txt - [1149 octets] - [08/03/2014 18:27:51] AdwCleaner[S0].txt - [2156 octets] - [18/09/2013 18:31:23] AdwCleaner[S1].txt - [2802 octets] - [08/03/2014 13:19:51] AdwCleaner[S2].txt - [1071 octets] - [08/03/2014 18:29:33] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1131 octets] ########## JRT: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.2 (02.20.2014:1) OS: Windows 7 Home Premium x64 Ran by Franz on 08.03.2014 at 18:42:56,34 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Franz\AppData\Roaming\mozilla\firefox\profiles\ufim2oib.default\minidumps [133 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.03.2014 at 18:47:11,06 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2014 01 Ran by Franz (administrator) on FRANZ-PC on 08-03-2014 18:51:13 Running from C:\Users\Franz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.202\deploy\LoLLauncher.exe () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.75\deploy\LolClient.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-09] (AVAST Software) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [NetLimiter] - C:\Program Files\NetLimiter 3\NLClientApp.exe /tray HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1B05EBC14B4ECE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{B93B3B22-47CA-4026-BCD3-DE87FBC83548}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default FF NewTab: about:blank FF Homepage: https://www.google.de/|hxxp://www.rudolf-hildebrand-schule.de/|hxxp://nosxclan.ohost.de/index.php?news FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.20 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-28] FF Extension: Personas Plus - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\Extensions\personas@christopher.beard.xpi [2013-06-08] FF Extension: Adblock Plus - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\ufim2oib.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-31] FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-05-11] FF HKCU\...\Firefox\Extensions: [{8a1a43a3-ee9f-4fff-9c5c-b3063ee1f0e0}] - C:\Program Files (x86)\Re-markit-soft\157.xpi FF Extension: No Name - C:\Program Files (x86)\Re-markit-soft\157.xpi [2014-03-08] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-09] (AVAST Software) R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-20] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-20] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC) ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-09] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-24] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-24] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-09] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-09] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-01] () R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider) R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-22] (Intel Corporation) S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-03-14] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-03-20] (Intel Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments) R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-21] (Microsoft Corporation) S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X] S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X] S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-08 18:47 - 2014-03-08 18:47 - 00000758 _____ () C:\Users\Franz\Desktop\JRT.txt 2014-03-08 18:26 - 2014-03-08 18:26 - 01244192 _____ () C:\Users\Franz\Downloads\adwcleaner.exe 2014-03-08 18:26 - 2014-03-08 18:26 - 01037734 _____ (Thisisu) C:\Users\Franz\Downloads\JRT.exe 2014-03-08 17:12 - 2014-03-08 17:12 - 00016232 _____ () C:\Users\Franz\Downloads\gmer.log 2014-03-08 16:56 - 2014-03-08 16:56 - 782529337 _____ () C:\Windows\MEMORY.DMP 2014-03-08 16:56 - 2014-03-08 16:56 - 00275128 _____ () C:\Windows\Minidump\030814-20716-01.dmp 2014-03-08 16:56 - 2014-03-08 16:56 - 00000000 ____D () C:\Windows\Minidump 2014-03-08 16:49 - 2014-03-08 16:49 - 00380416 _____ () C:\Users\Franz\Downloads\mngwvcjz.exe 2014-03-08 16:47 - 2014-03-08 16:47 - 00033383 _____ () C:\Users\Franz\Downloads\Addition.txt 2014-03-08 16:40 - 2014-03-08 18:51 - 00014846 _____ () C:\Users\Franz\Downloads\FRST.txt 2014-03-08 16:40 - 2014-03-08 18:51 - 00000000 ____D () C:\FRST 2014-03-08 16:39 - 2014-03-08 16:39 - 02156544 _____ (Farbar) C:\Users\Franz\Downloads\FRST64.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00050477 _____ () C:\Users\Franz\Downloads\Defogger.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00000472 _____ () C:\Users\Franz\Downloads\defogger_disable.log 2014-03-08 16:38 - 2014-03-08 16:38 - 00000000 _____ () C:\Users\Franz\defogger_reenable 2014-03-08 13:25 - 2014-03-08 13:25 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-08 13:25 - 2014-03-08 13:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-08 13:25 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-08 12:30 - 2014-03-08 13:58 - 00015181 _____ () C:\Users\Franz\Documents\American news.odt 2014-03-08 12:28 - 2014-03-08 18:30 - 00000390 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-03-08 12:28 - 2014-03-08 16:56 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-03-08 12:28 - 2014-03-08 12:28 - 00002978 _____ () C:\Windows\System32\Tasks\Re-markit_wd 2014-03-08 12:28 - 2014-03-08 12:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-08 12:27 - 2014-03-08 12:27 - 00000000 ____D () C:\Users\Franz\AppData\Local\11926 2014-03-08 12:19 - 2014-03-08 12:19 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 12:19 - 2014-03-08 12:19 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-06 13:33 - 2014-03-06 19:10 - 00000000 ____D () C:\Program Files\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000935 _____ () C:\Users\Franz\Desktop\Open Broadcaster Software.lnk 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-06 13:23 - 2014-03-08 11:48 - 00001306 _____ () C:\Windows\PFRO.log 2014-03-05 19:28 - 2014-03-05 19:28 - 00000000 ____D () C:\Users\Franz\AppData\Local\SplitMediaLabs 2014-03-05 19:26 - 2014-03-08 18:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-05 19:26 - 2014-03-06 14:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-05 19:26 - 2014-03-06 14:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-05 19:26 - 2014-03-06 14:28 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-05 19:17 - 2014-03-06 13:35 - 00000000 ____D () C:\Program Files (x86)\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:26 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:17 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-03-04 14:58 - 2014-03-04 14:58 - 00000000 ____D () C:\Users\Franz\AppData\Local\Skype 2014-03-04 14:57 - 2014-03-04 14:57 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-04 14:57 - 2014-03-04 14:57 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-03 17:46 - 2014-03-03 17:46 - 00000000 ____D () C:\Users\Franz\Documents\Scratch Projekte 2014-03-03 17:41 - 2014-03-08 12:18 - 00000000 ____D () C:\Users\Franz\AppData\Local\Dxtory Software 2014-03-03 17:41 - 2014-03-03 17:42 - 00000000 ____D () C:\Program Files (x86)\Dxtory Software 2014-03-03 17:39 - 2014-03-03 17:39 - 00715038 _____ () C:\Windows\unins000.exe 2014-03-03 17:39 - 2014-03-03 17:39 - 00001990 _____ () C:\Windows\unins000.dat 2014-03-03 17:39 - 2011-12-07 19:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll 2014-03-03 17:39 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll 2014-03-01 17:47 - 2014-03-01 17:47 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 17:42 - 2014-03-01 17:42 - 00001845 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-02-25 13:27 - 2014-02-25 13:28 - 00000000 ____D () C:\ef47be9d57167b970f003dc78fd13db7 2014-02-23 10:37 - 2014-02-23 10:37 - 00000646 _____ () C:\Users\Franz\Desktop\PBE.lnk 2014-02-23 10:33 - 2014-03-08 18:30 - 00001064 _____ () C:\Windows\setupact.log 2014-02-23 10:33 - 2014-02-23 10:33 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-22 19:59 - 2014-02-22 19:59 - 00000000 ____D () C:\Program Files (x86)\WinPcap 2014-02-22 19:58 - 2014-02-22 19:58 - 00003059 _____ () C:\Users\Franz\Desktop\PowerLine Utility.lnk 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TP-LINK 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-02-22 19:46 - 2014-02-22 19:46 - 00000000 ____D () C:\Users\Franz\Documents\My Weblog Posts 2014-02-22 17:35 - 2014-02-26 13:05 - 00000000 ____D () C:\Users\Franz\Tracing 2014-02-22 17:11 - 2014-02-22 17:11 - 00000000 ____D () C:\Windows\de 2014-02-22 17:09 - 2014-02-26 13:13 - 00000000 ____D () C:\Program Files\Windows Live 2014-02-22 17:09 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-02-22 17:09 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-02-22 17:09 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ___RD () C:\Users\Franz\OneDrive 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft OneDrive 2014-02-22 17:08 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-02-22 17:08 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-02-22 17:07 - 2014-02-22 17:07 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{7514B9EE-62DF-4EB7-97F7-AAAAEA715FB3} 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{5907288C-7E23-4F4F-8A0D-385823C80FDB} 2014-02-15 17:24 - 2014-02-15 17:24 - 00001274 _____ () C:\Users\Franz\Desktop\Technik Launcher.lnk 2014-02-15 15:38 - 2014-02-15 15:42 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-15 15:31 - 2014-02-20 19:37 - 00000000 ____D () C:\ProgramData\Tunngle 2014-02-15 15:31 - 2014-02-15 15:31 - 00000991 _____ () C:\Users\Public\Desktop\Tunngle beta.lnk 2014-02-15 15:31 - 2014-02-15 15:31 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2014-02-15 15:26 - 2014-02-15 15:26 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-02-15 15:14 - 2014-02-15 15:14 - 00000000 ____D () C:\Users\Franz\Documents\Tunngle 2014-02-15 15:09 - 2014-02-15 15:10 - 00000000 ____D () C:\Users\Franz\Desktop\Jakob Server 2014-02-15 12:30 - 2014-02-15 12:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-14 19:06 - 2014-02-14 19:06 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OpenOffice 2014-02-14 15:19 - 2014-02-16 13:02 - 00000000 ____D () C:\ProgramData\Soluto 2014-02-14 15:19 - 2014-02-16 13:01 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2014-02-13 15:29 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 15:29 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 15:28 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 15:28 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 15:28 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 15:28 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 15:28 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 15:28 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 15:28 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 15:28 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 15:28 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 15:28 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 15:28 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 15:28 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 15:28 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 15:28 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 15:28 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 15:28 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 15:28 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 15:28 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 15:28 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 15:28 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 15:28 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 15:28 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 15:28 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 15:28 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 15:28 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 15:28 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 15:28 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 15:28 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 15:28 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 15:28 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 15:28 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 15:28 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 15:28 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 15:28 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 15:28 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 15:28 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 15:28 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 15:28 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 15:28 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 11:49 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 11:49 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 11:48 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 11:48 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 11:48 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 11:48 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 11:48 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 11:48 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 11:48 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 11:48 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 11:48 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 11:48 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 11:48 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 11:48 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 11:48 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 16:53 - 2014-02-15 17:24 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.technic 2014-02-09 13:37 - 2014-02-09 13:37 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-06 19:47 - 2014-02-06 19:47 - 00026484 _____ () C:\Users\Franz\Documents\Koks Bio.odt ==================== One Month Modified Files and Folders ======= 2014-03-08 18:51 - 2014-03-08 16:40 - 00014846 _____ () C:\Users\Franz\Downloads\FRST.txt 2014-03-08 18:51 - 2014-03-08 16:40 - 00000000 ____D () C:\FRST 2014-03-08 18:51 - 2013-05-15 19:29 - 00000000 ____D () C:\Users\Franz\AppData\Local\PMB Files 2014-03-08 18:48 - 2013-05-11 16:15 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Skype 2014-03-08 18:47 - 2014-03-08 18:47 - 00000758 _____ () C:\Users\Franz\Desktop\JRT.txt 2014-03-08 18:45 - 2013-05-15 19:29 - 00000000 ____D () C:\ProgramData\PMB Files 2014-03-08 18:42 - 2013-06-24 15:51 - 00000000 ____D () C:\Windows\ERUNT 2014-03-08 18:37 - 2009-07-14 05:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-08 18:37 - 2009-07-14 05:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-08 18:33 - 2013-08-10 12:50 - 02022800 _____ () C:\Windows\WindowsUpdate.log 2014-03-08 18:30 - 2014-03-08 12:28 - 00000390 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-03-08 18:30 - 2014-02-23 10:33 - 00001064 _____ () C:\Windows\setupact.log 2014-03-08 18:30 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-08 18:29 - 2013-09-18 18:30 - 00000000 ____D () C:\AdwCleaner 2014-03-08 18:28 - 2014-03-05 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-08 18:26 - 2014-03-08 18:26 - 01244192 _____ () C:\Users\Franz\Downloads\adwcleaner.exe 2014-03-08 18:26 - 2014-03-08 18:26 - 01037734 _____ (Thisisu) C:\Users\Franz\Downloads\JRT.exe 2014-03-08 17:12 - 2014-03-08 17:12 - 00016232 _____ () C:\Users\Franz\Downloads\gmer.log 2014-03-08 16:56 - 2014-03-08 16:56 - 782529337 _____ () C:\Windows\MEMORY.DMP 2014-03-08 16:56 - 2014-03-08 16:56 - 00275128 _____ () C:\Windows\Minidump\030814-20716-01.dmp 2014-03-08 16:56 - 2014-03-08 16:56 - 00000000 ____D () C:\Windows\Minidump 2014-03-08 16:56 - 2014-03-08 12:28 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-03-08 16:49 - 2014-03-08 16:49 - 00380416 _____ () C:\Users\Franz\Downloads\mngwvcjz.exe 2014-03-08 16:47 - 2014-03-08 16:47 - 00033383 _____ () C:\Users\Franz\Downloads\Addition.txt 2014-03-08 16:39 - 2014-03-08 16:39 - 02156544 _____ (Farbar) C:\Users\Franz\Downloads\FRST64.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00050477 _____ () C:\Users\Franz\Downloads\Defogger.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00000472 _____ () C:\Users\Franz\Downloads\defogger_disable.log 2014-03-08 16:38 - 2014-03-08 16:38 - 00000000 _____ () C:\Users\Franz\defogger_reenable 2014-03-08 16:38 - 2013-05-11 14:14 - 00000000 ____D () C:\Users\Franz 2014-03-08 14:55 - 2013-08-13 10:15 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-03-08 14:54 - 2013-05-11 15:16 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Adobe 2014-03-08 14:54 - 2013-05-11 15:13 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-08 14:52 - 2014-01-19 12:47 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-08 13:58 - 2014-03-08 12:30 - 00015181 _____ () C:\Users\Franz\Documents\American news.odt 2014-03-08 13:25 - 2014-03-08 13:25 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-08 13:25 - 2014-03-08 13:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-08 13:22 - 2009-07-14 05:45 - 05006784 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-08 13:17 - 2013-05-11 14:30 - 00069608 _____ () C:\Users\Franz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-08 12:28 - 2014-03-08 12:28 - 00002978 _____ () C:\Windows\System32\Tasks\Re-markit_wd 2014-03-08 12:28 - 2014-03-08 12:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-08 12:28 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-08 12:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-03-08 12:27 - 2014-03-08 12:27 - 00000000 ____D () C:\Users\Franz\AppData\Local\11926 2014-03-08 12:19 - 2014-03-08 12:19 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 12:19 - 2014-03-08 12:19 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-08 12:18 - 2014-03-03 17:41 - 00000000 ____D () C:\Users\Franz\AppData\Local\Dxtory Software 2014-03-08 11:59 - 2013-06-18 18:44 - 00000000 ____D () C:\Users\Franz\AppData\Local\Adobe 2014-03-08 11:48 - 2014-03-06 13:23 - 00001306 _____ () C:\Windows\PFRO.log 2014-03-07 20:10 - 2013-05-17 19:11 - 00000000 ____D () C:\Users\Franz\AppData\Local\CrashDumps 2014-03-07 13:46 - 2013-05-11 15:32 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-06 19:10 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files\OBS 2014-03-06 14:28 - 2014-03-05 19:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-06 14:28 - 2014-03-05 19:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-06 14:28 - 2014-03-05 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-06 13:35 - 2014-03-05 19:17 - 00000000 ____D () C:\Program Files (x86)\SplitMediaLabs 2014-03-06 13:33 - 2014-03-06 13:33 - 00000935 _____ () C:\Users\Franz\Desktop\Open Broadcaster Software.lnk 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-05 19:28 - 2014-03-05 19:28 - 00000000 ____D () C:\Users\Franz\AppData\Local\SplitMediaLabs 2014-03-05 19:26 - 2014-03-05 19:17 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:17 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-03-05 15:42 - 2013-11-23 12:18 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-03-05 13:22 - 2013-05-11 14:14 - 00000000 ___RD () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-04 16:54 - 2013-07-03 18:09 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.minecraft 2014-03-04 14:58 - 2014-03-04 14:58 - 00000000 ____D () C:\Users\Franz\AppData\Local\Skype 2014-03-04 14:57 - 2014-03-04 14:57 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-04 14:57 - 2014-03-04 14:57 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-04 14:57 - 2013-05-11 16:15 - 00000000 ____D () C:\ProgramData\Skype 2014-03-03 17:46 - 2014-03-03 17:46 - 00000000 ____D () C:\Users\Franz\Documents\Scratch Projekte 2014-03-03 17:42 - 2014-03-03 17:41 - 00000000 ____D () C:\Program Files (x86)\Dxtory Software 2014-03-03 17:39 - 2014-03-03 17:39 - 00715038 _____ () C:\Windows\unins000.exe 2014-03-03 17:39 - 2014-03-03 17:39 - 00001990 _____ () C:\Windows\unins000.dat 2014-03-02 13:30 - 2013-05-17 19:11 - 01596822 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-02 13:30 - 2011-04-12 08:43 - 00700316 _____ () C:\Windows\system32\perfh007.dat 2014-03-02 13:30 - 2011-04-12 08:43 - 00149954 _____ () C:\Windows\system32\perfc007.dat 2014-03-02 13:30 - 2009-07-14 06:13 - 01596822 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-01 17:47 - 2014-03-01 17:47 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 17:42 - 2014-03-01 17:42 - 00001845 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-03-01 17:42 - 2013-05-12 09:29 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-02-26 13:14 - 2013-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-02-26 13:13 - 2014-02-22 17:09 - 00000000 ____D () C:\Program Files\Windows Live 2014-02-26 13:05 - 2014-02-22 17:35 - 00000000 ____D () C:\Users\Franz\Tracing 2014-02-25 13:28 - 2014-02-25 13:27 - 00000000 ____D () C:\ef47be9d57167b970f003dc78fd13db7 2014-02-25 13:23 - 2013-05-31 19:13 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\TS3Client 2014-02-23 10:37 - 2014-02-23 10:37 - 00000646 _____ () C:\Users\Franz\Desktop\PBE.lnk 2014-02-23 10:33 - 2014-02-23 10:33 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-22 21:37 - 2013-12-09 18:47 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-22 21:37 - 2013-05-11 16:03 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-22 21:11 - 2013-05-17 14:45 - 00000000 ____D () C:\Riot Games 2014-02-22 19:59 - 2014-02-22 19:59 - 00000000 ____D () C:\Program Files (x86)\WinPcap 2014-02-22 19:58 - 2014-02-22 19:58 - 00003059 _____ () C:\Users\Franz\Desktop\PowerLine Utility.lnk 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TP-LINK 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-02-22 19:46 - 2014-02-22 19:46 - 00000000 ____D () C:\Users\Franz\Documents\My Weblog Posts 2014-02-22 19:46 - 2013-09-20 19:38 - 00000000 ____D () C:\Users\Franz\AppData\Local\Windows Live Writer 2014-02-22 17:29 - 2013-05-15 19:31 - 00000000 ____D () C:\Users\Franz\AppData\Local\Windows Live 2014-02-22 17:11 - 2014-02-22 17:11 - 00000000 ____D () C:\Windows\de 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ___RD () C:\Users\Franz\OneDrive 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft OneDrive 2014-02-22 17:07 - 2014-02-22 17:07 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{7514B9EE-62DF-4EB7-97F7-AAAAEA715FB3} 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{5907288C-7E23-4F4F-8A0D-385823C80FDB} 2014-02-21 17:41 - 2013-06-22 19:27 - 00000000 ____D () C:\Windows\pss 2014-02-20 19:37 - 2014-02-15 15:31 - 00000000 ____D () C:\ProgramData\Tunngle 2014-02-20 19:37 - 2013-05-11 16:23 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Tunngle 2014-02-20 16:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-16 13:06 - 2013-12-24 10:42 - 00000000 ____D () C:\Program Files (x86)\Freemake 2014-02-16 13:02 - 2014-02-14 15:19 - 00000000 ____D () C:\ProgramData\Soluto 2014-02-16 13:01 - 2014-02-14 15:19 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2014-02-15 17:24 - 2014-02-15 17:24 - 00001274 _____ () C:\Users\Franz\Desktop\Technik Launcher.lnk 2014-02-15 17:24 - 2014-02-11 16:53 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.technic 2014-02-15 15:43 - 2013-05-11 14:20 - 00000000 ____D () C:\Program Files (x86)\REALTEK 2014-02-15 15:42 - 2014-02-15 15:38 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-15 15:32 - 2013-05-11 16:23 - 00000000 ____D () C:\Program Files (x86)\Tunngle 2014-02-15 15:31 - 2014-02-15 15:31 - 00000991 _____ () C:\Users\Public\Desktop\Tunngle beta.lnk 2014-02-15 15:31 - 2014-02-15 15:31 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2014-02-15 15:26 - 2014-02-15 15:26 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-02-15 15:25 - 2013-05-11 15:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-15 15:14 - 2014-02-15 15:14 - 00000000 ____D () C:\Users\Franz\Documents\Tunngle 2014-02-15 15:10 - 2014-02-15 15:09 - 00000000 ____D () C:\Users\Franz\Desktop\Jakob Server 2014-02-15 12:37 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-15 12:30 - 2014-02-15 12:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-14 19:06 - 2014-02-14 19:06 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OpenOffice 2014-02-14 18:59 - 2013-06-17 14:45 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Feed The Beast 2014-02-14 16:00 - 2013-08-15 10:27 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-14 15:59 - 2013-05-11 17:35 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-12 14:13 - 2013-07-10 14:23 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\FileZilla 2014-02-09 16:10 - 2014-01-24 19:02 - 00000000 ____D () C:\Users\Franz\AppData\Local\Battle.net 2014-02-09 13:37 - 2014-02-09 13:37 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-09 13:37 - 2014-01-01 15:08 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-09 13:37 - 2013-05-11 15:32 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-09 13:36 - 2013-05-11 15:32 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-06 19:47 - 2014-02-06 19:47 - 00026484 _____ () C:\Users\Franz\Documents\Koks Bio.odt 2014-02-06 13:16 - 2014-02-13 15:28 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 15:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 15:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 15:28 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 15:28 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 15:28 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 15:28 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-13 15:28 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-13 15:28 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 15:28 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 15:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 15:28 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 15:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 15:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 15:28 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 15:28 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 15:28 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 15:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 15:28 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 15:28 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 15:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 15:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 15:28 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-13 15:28 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-13 15:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 15:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 15:28 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 15:28 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 15:28 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 15:28 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 15:28 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 15:28 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 15:28 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 15:28 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 15:28 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 15:28 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 15:28 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 15:28 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Franz\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Franz\AppData\Local\Temp\Fraps3.5.99Setup__4940_il4040.exe C:\Users\Franz\AppData\Local\Temp\Quarantine.exe C:\Users\Franz\AppData\Local\Temp\Re-markit_2040-4032.exe C:\Users\Franz\AppData\Local\Temp\uninstall_flash_player.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-08 15:12 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- Sever01 Hallo, ich habe jetzt ein bisschen im Internet gesurft. Bei zufälligen Internetseiten öffnet sich einfach Werbung in einem neuen Fenster. Unten rechts ist auch manchmal Werbung. Sever01 Zum beispiel solche Treiberseiten: hxxp://gir.driveropti.net/sd/dw31.html?u=http%3A%2F%2Fdlvr.readserver.net%2Fbp%3Fsection%3D2455%26type%3D2&p=Remarkit&a=&c=2040-4033&b=firefox&bv=27&t1=1394385898556&tt=1394385898556&r=www.google.de&ua=1&n=apptv&sn=&mpa=0&mp=0 |
10.03.2014, 14:27 | #4 |
/// the machine /// TB-Ausbilder | Avast findet Virus und Malwarebytes findet Viren Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.03.2014, 19:48 | #5 |
| Avast findet Virus und Malwarebytes findet Viren Hier die Checkup.txt. Der Rest kommt noch Code:
ATTFilter Results of screen317's Security Check version 0.99.80 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 51 Adobe Flash Player 12.0.0.70 Adobe Reader XI Mozilla Firefox (27.0.1) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Av `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-03-2014 02 Ran by Franz (administrator) on FRANZ-PC on 10-03-2014 19:04:35 Running from C:\Users\Franz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ROCCAT) C:\Program Files (x86)\ROCCAT\Lua Mouse\Lua Config.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe (ESET) C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe () C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe () C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.202\deploy\LoLLauncher.exe () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.75\deploy\LolClient.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-09] (AVAST Software) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [NetLimiter] - C:\Program Files\NetLimiter 3\NLClientApp.exe /tray HKU\S-1-5-21-921928476-601607189-1348779831-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1B05EBC14B4ECE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{B93B3B22-47CA-4026-BCD3-DE87FBC83548}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\o5qb79m0.default-1394461475543 FF Homepage: https://www.google.de/|hxxp://www.rudolf-hildebrand-schule.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.20 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\o5qb79m0.default-1394461475543\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-03-10] FF Extension: Personas Plus - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\o5qb79m0.default-1394461475543\Extensions\personas@christopher.beard.xpi [2014-03-10] FF Extension: Adblock Plus - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\o5qb79m0.default-1394461475543\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-10] FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-05-11] FF HKCU\...\Firefox\Extensions: [{8a1a43a3-ee9f-4fff-9c5c-b3063ee1f0e0}] - C:\Program Files (x86)\Re-markit-soft\157.xpi FF Extension: No Name - C:\Program Files (x86)\Re-markit-soft\157.xpi [2014-03-08] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-09] (AVAST Software) R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-20] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-20] (Intel Corporation) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC) ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-09] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-24] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-24] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-09] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-09] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-01] () R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider) R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-22] (Intel Corporation) S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-03-14] () R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-03-20] (Intel Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments) R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-21] (Microsoft Corporation) S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X] S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X] S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-10 19:04 - 2014-03-10 19:04 - 00000000 ____D () C:\Users\Franz\Downloads\FRST-OlderVersion 2014-03-10 16:39 - 2014-03-10 16:39 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-03-10 16:38 - 2014-03-10 16:38 - 02347384 _____ (ESET) C:\Users\Franz\Downloads\esetsmartinstaller_enu.exe 2014-03-10 16:37 - 2014-03-10 16:37 - 00987442 _____ () C:\Users\Franz\Downloads\SecurityCheck.exe 2014-03-10 15:24 - 2014-03-10 15:24 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-10 15:24 - 2014-03-10 15:24 - 00000000 ____D () C:\Users\Franz\Desktop\Alte Firefox-Daten 2014-03-10 15:24 - 2014-03-10 15:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-10 15:24 - 2014-03-10 15:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-10 14:37 - 2014-03-10 14:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Franz\Downloads\revosetup95.exe 2014-03-10 14:37 - 2014-03-10 14:37 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-03-09 18:39 - 2014-03-09 19:46 - 00039761 _____ () C:\Users\Franz\Documents\Bilder american news.odt 2014-03-08 18:47 - 2014-03-08 18:47 - 00000758 _____ () C:\Users\Franz\Desktop\JRT.txt 2014-03-08 18:26 - 2014-03-08 18:26 - 01244192 _____ () C:\Users\Franz\Downloads\adwcleaner.exe 2014-03-08 18:26 - 2014-03-08 18:26 - 01037734 _____ (Thisisu) C:\Users\Franz\Downloads\JRT.exe 2014-03-08 17:12 - 2014-03-08 17:12 - 00016232 _____ () C:\Users\Franz\Downloads\gmer.log 2014-03-08 16:56 - 2014-03-09 19:15 - 00000000 ____D () C:\Windows\Minidump 2014-03-08 16:49 - 2014-03-08 16:49 - 00380416 _____ () C:\Users\Franz\Downloads\mngwvcjz.exe 2014-03-08 16:47 - 2014-03-08 16:47 - 00033383 _____ () C:\Users\Franz\Downloads\Addition.txt 2014-03-08 16:40 - 2014-03-10 19:04 - 00014507 _____ () C:\Users\Franz\Downloads\FRST.txt 2014-03-08 16:40 - 2014-03-10 19:04 - 00000000 ____D () C:\FRST 2014-03-08 16:39 - 2014-03-10 19:04 - 02157056 _____ (Farbar) C:\Users\Franz\Downloads\FRST64.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00050477 _____ () C:\Users\Franz\Downloads\Defogger.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00000472 _____ () C:\Users\Franz\Downloads\defogger_disable.log 2014-03-08 16:38 - 2014-03-08 16:38 - 00000000 _____ () C:\Users\Franz\defogger_reenable 2014-03-08 12:30 - 2014-03-09 19:46 - 00018066 _____ () C:\Users\Franz\Documents\American news.odt 2014-03-08 12:28 - 2014-03-10 14:31 - 00000390 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-03-08 12:28 - 2014-03-08 16:56 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-03-08 12:28 - 2014-03-08 12:28 - 00002978 _____ () C:\Windows\System32\Tasks\Re-markit_wd 2014-03-08 12:28 - 2014-03-08 12:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-08 12:27 - 2014-03-08 12:27 - 00000000 ____D () C:\Users\Franz\AppData\Local\11926 2014-03-08 12:19 - 2014-03-08 12:19 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 12:19 - 2014-03-08 12:19 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-06 13:33 - 2014-03-06 19:10 - 00000000 ____D () C:\Program Files\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000935 _____ () C:\Users\Franz\Desktop\Open Broadcaster Software.lnk 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-05 19:28 - 2014-03-05 19:28 - 00000000 ____D () C:\Users\Franz\AppData\Local\SplitMediaLabs 2014-03-05 19:26 - 2014-03-10 18:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-05 19:26 - 2014-03-06 14:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-05 19:26 - 2014-03-06 14:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-05 19:26 - 2014-03-06 14:28 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-05 19:17 - 2014-03-06 13:35 - 00000000 ____D () C:\Program Files (x86)\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:26 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:17 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-03-04 14:58 - 2014-03-04 14:58 - 00000000 ____D () C:\Users\Franz\AppData\Local\Skype 2014-03-04 14:57 - 2014-03-04 14:57 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-04 14:57 - 2014-03-04 14:57 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-03 17:46 - 2014-03-03 17:46 - 00000000 ____D () C:\Users\Franz\Documents\Scratch Projekte 2014-03-03 17:41 - 2014-03-08 12:18 - 00000000 ____D () C:\Users\Franz\AppData\Local\Dxtory Software 2014-03-03 17:41 - 2014-03-03 17:42 - 00000000 ____D () C:\Program Files (x86)\Dxtory Software 2014-03-03 17:39 - 2014-03-03 17:39 - 00715038 _____ () C:\Windows\unins000.exe 2014-03-03 17:39 - 2014-03-03 17:39 - 00001990 _____ () C:\Windows\unins000.dat 2014-03-03 17:39 - 2011-12-07 19:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll 2014-03-03 17:39 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll 2014-03-01 17:47 - 2014-03-01 17:47 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 17:42 - 2014-03-01 17:42 - 00001845 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-02-25 13:27 - 2014-02-25 13:28 - 00000000 ____D () C:\ef47be9d57167b970f003dc78fd13db7 2014-02-23 10:37 - 2014-02-23 10:37 - 00000646 _____ () C:\Users\Franz\Desktop\PBE.lnk 2014-02-22 19:59 - 2014-02-22 19:59 - 00000000 ____D () C:\Program Files (x86)\WinPcap 2014-02-22 19:58 - 2014-02-22 19:58 - 00003059 _____ () C:\Users\Franz\Desktop\PowerLine Utility.lnk 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TP-LINK 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-02-22 19:46 - 2014-02-22 19:46 - 00000000 ____D () C:\Users\Franz\Documents\My Weblog Posts 2014-02-22 17:35 - 2014-03-09 19:15 - 00000000 ____D () C:\Users\Franz\Tracing 2014-02-22 17:11 - 2014-02-22 17:11 - 00000000 ____D () C:\Windows\de 2014-02-22 17:09 - 2014-02-26 13:13 - 00000000 ____D () C:\Program Files\Windows Live 2014-02-22 17:09 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-02-22 17:09 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-02-22 17:09 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-02-22 17:09 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-02-22 17:09 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ___RD () C:\Users\Franz\OneDrive 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft OneDrive 2014-02-22 17:08 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-02-22 17:08 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-02-22 17:07 - 2014-02-22 17:07 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{7514B9EE-62DF-4EB7-97F7-AAAAEA715FB3} 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{5907288C-7E23-4F4F-8A0D-385823C80FDB} 2014-02-15 17:24 - 2014-02-15 17:24 - 00001274 _____ () C:\Users\Franz\Desktop\Technik Launcher.lnk 2014-02-15 15:38 - 2014-02-15 15:42 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-15 15:31 - 2014-02-20 19:37 - 00000000 ____D () C:\ProgramData\Tunngle 2014-02-15 15:31 - 2014-02-15 15:31 - 00000991 _____ () C:\Users\Public\Desktop\Tunngle beta.lnk 2014-02-15 15:31 - 2014-02-15 15:31 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2014-02-15 15:26 - 2014-02-15 15:26 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-02-15 15:14 - 2014-02-15 15:14 - 00000000 ____D () C:\Users\Franz\Documents\Tunngle 2014-02-15 15:09 - 2014-02-15 15:10 - 00000000 ____D () C:\Users\Franz\Desktop\Jakob Server 2014-02-14 19:06 - 2014-02-14 19:06 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OpenOffice 2014-02-14 15:19 - 2014-02-16 13:02 - 00000000 ____D () C:\ProgramData\Soluto 2014-02-14 15:19 - 2014-02-16 13:01 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2014-02-13 15:29 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 15:29 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 15:28 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 15:28 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 15:28 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 15:28 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 15:28 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 15:28 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 15:28 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 15:28 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 15:28 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 15:28 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 15:28 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 15:28 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 15:28 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 15:28 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 15:28 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 15:28 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 15:28 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 15:28 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 15:28 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 15:28 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 15:28 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 15:28 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 15:28 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 15:28 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 15:28 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 15:28 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 15:28 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 15:28 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 15:28 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 15:28 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 15:28 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 15:28 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 15:28 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 15:28 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 15:28 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 15:28 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 15:28 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 15:28 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 15:28 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 11:49 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 11:49 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 11:48 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 11:48 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 11:48 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 11:48 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 11:48 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 11:48 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 11:48 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 11:48 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 11:48 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 11:48 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 11:48 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 11:48 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 11:48 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 11:48 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 11:48 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 11:48 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 11:48 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 16:53 - 2014-02-15 17:24 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.technic 2014-02-09 13:37 - 2014-02-09 13:37 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk ==================== One Month Modified Files and Folders ======= 2014-03-10 19:05 - 2014-03-10 14:37 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-03-10 19:05 - 2014-03-08 16:40 - 00014507 _____ () C:\Users\Franz\Downloads\FRST.txt 2014-03-10 19:05 - 2013-05-15 19:29 - 00000000 ____D () C:\Users\Franz\AppData\Local\PMB Files 2014-03-10 19:04 - 2014-03-10 19:04 - 00000000 ____D () C:\Users\Franz\Downloads\FRST-OlderVersion 2014-03-10 19:04 - 2014-03-08 16:40 - 00000000 ____D () C:\FRST 2014-03-10 19:04 - 2014-03-08 16:39 - 02157056 _____ (Farbar) C:\Users\Franz\Downloads\FRST64.exe 2014-03-10 19:01 - 2013-05-11 16:15 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Skype 2014-03-10 18:28 - 2014-03-05 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-10 18:00 - 2013-05-15 19:29 - 00000000 ____D () C:\ProgramData\PMB Files 2014-03-10 17:44 - 2013-05-17 19:11 - 00000000 ____D () C:\Users\Franz\AppData\Local\CrashDumps 2014-03-10 16:39 - 2014-03-10 16:39 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-03-10 16:38 - 2014-03-10 16:38 - 02347384 _____ (ESET) C:\Users\Franz\Downloads\esetsmartinstaller_enu.exe 2014-03-10 16:37 - 2014-03-10 16:37 - 00987442 _____ () C:\Users\Franz\Downloads\SecurityCheck.exe 2014-03-10 15:24 - 2014-03-10 15:24 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-10 15:24 - 2014-03-10 15:24 - 00000000 ____D () C:\Users\Franz\Desktop\Alte Firefox-Daten 2014-03-10 15:24 - 2014-03-10 15:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-10 15:24 - 2014-03-10 15:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-10 14:42 - 2013-08-10 12:50 - 02046918 _____ () C:\Windows\WindowsUpdate.log 2014-03-10 14:37 - 2014-03-10 14:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Franz\Downloads\revosetup95.exe 2014-03-10 14:31 - 2014-03-08 12:28 - 00000390 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-03-09 20:26 - 2013-05-11 18:40 - 00000000 ____D () C:\Users\Franz\Documents\Schule 2014-03-09 19:46 - 2014-03-09 18:39 - 00039761 _____ () C:\Users\Franz\Documents\Bilder american news.odt 2014-03-09 19:46 - 2014-03-08 12:30 - 00018066 _____ () C:\Users\Franz\Documents\American news.odt 2014-03-09 19:15 - 2014-03-08 16:56 - 00000000 ____D () C:\Windows\Minidump 2014-03-09 19:15 - 2014-02-22 17:35 - 00000000 ____D () C:\Users\Franz\Tracing 2014-03-09 19:15 - 2013-05-31 19:13 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\TS3Client 2014-03-09 09:17 - 2009-07-14 05:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-09 09:17 - 2009-07-14 05:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-09 09:10 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-08 18:47 - 2014-03-08 18:47 - 00000758 _____ () C:\Users\Franz\Desktop\JRT.txt 2014-03-08 18:42 - 2013-06-24 15:51 - 00000000 ____D () C:\Windows\ERUNT 2014-03-08 18:29 - 2013-09-18 18:30 - 00000000 ____D () C:\AdwCleaner 2014-03-08 18:26 - 2014-03-08 18:26 - 01244192 _____ () C:\Users\Franz\Downloads\adwcleaner.exe 2014-03-08 18:26 - 2014-03-08 18:26 - 01037734 _____ (Thisisu) C:\Users\Franz\Downloads\JRT.exe 2014-03-08 17:12 - 2014-03-08 17:12 - 00016232 _____ () C:\Users\Franz\Downloads\gmer.log 2014-03-08 16:56 - 2014-03-08 12:28 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-03-08 16:49 - 2014-03-08 16:49 - 00380416 _____ () C:\Users\Franz\Downloads\mngwvcjz.exe 2014-03-08 16:47 - 2014-03-08 16:47 - 00033383 _____ () C:\Users\Franz\Downloads\Addition.txt 2014-03-08 16:38 - 2014-03-08 16:38 - 00050477 _____ () C:\Users\Franz\Downloads\Defogger.exe 2014-03-08 16:38 - 2014-03-08 16:38 - 00000472 _____ () C:\Users\Franz\Downloads\defogger_disable.log 2014-03-08 16:38 - 2014-03-08 16:38 - 00000000 _____ () C:\Users\Franz\defogger_reenable 2014-03-08 16:38 - 2013-05-11 14:14 - 00000000 ____D () C:\Users\Franz 2014-03-08 14:55 - 2013-08-13 10:15 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-03-08 14:54 - 2013-05-11 15:16 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Adobe 2014-03-08 14:54 - 2013-05-11 15:13 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-08 14:52 - 2014-01-19 12:47 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-08 13:22 - 2009-07-14 05:45 - 05006784 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-08 13:17 - 2013-05-11 14:30 - 00069608 _____ () C:\Users\Franz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-08 12:28 - 2014-03-08 12:28 - 00002978 _____ () C:\Windows\System32\Tasks\Re-markit_wd 2014-03-08 12:28 - 2014-03-08 12:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-08 12:28 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-08 12:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-03-08 12:27 - 2014-03-08 12:27 - 00000000 ____D () C:\Users\Franz\AppData\Local\11926 2014-03-08 12:19 - 2014-03-08 12:19 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 12:19 - 2014-03-08 12:19 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-08 12:18 - 2014-03-03 17:41 - 00000000 ____D () C:\Users\Franz\AppData\Local\Dxtory Software 2014-03-08 11:59 - 2013-06-18 18:44 - 00000000 ____D () C:\Users\Franz\AppData\Local\Adobe 2014-03-07 13:46 - 2013-05-11 15:32 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-06 19:10 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files\OBS 2014-03-06 14:28 - 2014-03-05 19:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-06 14:28 - 2014-03-05 19:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-06 14:28 - 2014-03-05 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-06 13:35 - 2014-03-05 19:17 - 00000000 ____D () C:\Program Files (x86)\SplitMediaLabs 2014-03-06 13:33 - 2014-03-06 13:33 - 00000935 _____ () C:\Users\Franz\Desktop\Open Broadcaster Software.lnk 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OBS 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-06 13:33 - 2014-03-06 13:33 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-05 19:28 - 2014-03-05 19:28 - 00000000 ____D () C:\Users\Franz\AppData\Local\SplitMediaLabs 2014-03-05 19:26 - 2014-03-05 19:17 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\SplitMediaLabs 2014-03-05 19:17 - 2014-03-05 19:17 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-03-05 15:42 - 2013-11-23 12:18 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-03-05 13:22 - 2013-05-11 14:14 - 00000000 ___RD () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-04 16:54 - 2013-07-03 18:09 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.minecraft 2014-03-04 14:58 - 2014-03-04 14:58 - 00000000 ____D () C:\Users\Franz\AppData\Local\Skype 2014-03-04 14:57 - 2014-03-04 14:57 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-04 14:57 - 2014-03-04 14:57 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-04 14:57 - 2013-05-11 16:15 - 00000000 ____D () C:\ProgramData\Skype 2014-03-03 17:46 - 2014-03-03 17:46 - 00000000 ____D () C:\Users\Franz\Documents\Scratch Projekte 2014-03-03 17:42 - 2014-03-03 17:41 - 00000000 ____D () C:\Program Files (x86)\Dxtory Software 2014-03-03 17:39 - 2014-03-03 17:39 - 00715038 _____ () C:\Windows\unins000.exe 2014-03-03 17:39 - 2014-03-03 17:39 - 00001990 _____ () C:\Windows\unins000.dat 2014-03-02 13:30 - 2013-05-17 19:11 - 01596822 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-02 13:30 - 2011-04-12 08:43 - 00700316 _____ () C:\Windows\system32\perfh007.dat 2014-03-02 13:30 - 2011-04-12 08:43 - 00149954 _____ () C:\Windows\system32\perfc007.dat 2014-03-02 13:30 - 2009-07-14 06:13 - 01596822 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-01 17:47 - 2014-03-01 17:47 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 17:47 - 2014-03-01 17:47 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 17:42 - 2014-03-01 17:42 - 00001845 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-03-01 17:42 - 2013-05-12 09:29 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-02-26 13:14 - 2013-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-02-26 13:13 - 2014-02-22 17:09 - 00000000 ____D () C:\Program Files\Windows Live 2014-02-25 13:28 - 2014-02-25 13:27 - 00000000 ____D () C:\ef47be9d57167b970f003dc78fd13db7 2014-02-23 10:37 - 2014-02-23 10:37 - 00000646 _____ () C:\Users\Franz\Desktop\PBE.lnk 2014-02-22 21:37 - 2013-12-09 18:47 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-22 21:37 - 2013-05-11 16:03 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-22 21:11 - 2013-05-17 14:45 - 00000000 ____D () C:\Riot Games 2014-02-22 19:59 - 2014-02-22 19:59 - 00000000 ____D () C:\Program Files (x86)\WinPcap 2014-02-22 19:58 - 2014-02-22 19:58 - 00003059 _____ () C:\Users\Franz\Desktop\PowerLine Utility.lnk 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TP-LINK 2014-02-22 19:58 - 2014-02-22 19:58 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-02-22 19:46 - 2014-02-22 19:46 - 00000000 ____D () C:\Users\Franz\Documents\My Weblog Posts 2014-02-22 19:46 - 2013-09-20 19:38 - 00000000 ____D () C:\Users\Franz\AppData\Local\Windows Live Writer 2014-02-22 17:29 - 2013-05-15 19:31 - 00000000 ____D () C:\Users\Franz\AppData\Local\Windows Live 2014-02-22 17:11 - 2014-02-22 17:11 - 00000000 ____D () C:\Windows\de 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ___RD () C:\Users\Franz\OneDrive 2014-02-22 17:08 - 2014-02-22 17:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft OneDrive 2014-02-22 17:07 - 2014-02-22 17:07 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{7514B9EE-62DF-4EB7-97F7-AAAAEA715FB3} 2014-02-22 17:06 - 2014-02-22 17:06 - 00003130 _____ () C:\Windows\System32\Tasks\{5907288C-7E23-4F4F-8A0D-385823C80FDB} 2014-02-21 17:41 - 2013-06-22 19:27 - 00000000 ____D () C:\Windows\pss 2014-02-20 19:37 - 2014-02-15 15:31 - 00000000 ____D () C:\ProgramData\Tunngle 2014-02-20 19:37 - 2013-05-11 16:23 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Tunngle 2014-02-20 16:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-16 13:06 - 2013-12-24 10:42 - 00000000 ____D () C:\Program Files (x86)\Freemake 2014-02-16 13:02 - 2014-02-14 15:19 - 00000000 ____D () C:\ProgramData\Soluto 2014-02-16 13:01 - 2014-02-14 15:19 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2014-02-15 17:24 - 2014-02-15 17:24 - 00001274 _____ () C:\Users\Franz\Desktop\Technik Launcher.lnk 2014-02-15 17:24 - 2014-02-11 16:53 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\.technic 2014-02-15 15:43 - 2013-05-11 14:20 - 00000000 ____D () C:\Program Files (x86)\REALTEK 2014-02-15 15:42 - 2014-02-15 15:38 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-15 15:32 - 2013-05-11 16:23 - 00000000 ____D () C:\Program Files (x86)\Tunngle 2014-02-15 15:31 - 2014-02-15 15:31 - 00000991 _____ () C:\Users\Public\Desktop\Tunngle beta.lnk 2014-02-15 15:31 - 2014-02-15 15:31 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2014-02-15 15:26 - 2014-02-15 15:26 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-02-15 15:14 - 2014-02-15 15:14 - 00000000 ____D () C:\Users\Franz\Documents\Tunngle 2014-02-15 15:10 - 2014-02-15 15:09 - 00000000 ____D () C:\Users\Franz\Desktop\Jakob Server 2014-02-15 12:37 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-14 19:06 - 2014-02-14 19:06 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\OpenOffice 2014-02-14 18:59 - 2013-06-17 14:45 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\Feed The Beast 2014-02-14 16:00 - 2013-08-15 10:27 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-14 15:59 - 2013-05-11 17:35 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-12 14:13 - 2013-07-10 14:23 - 00000000 ____D () C:\Users\Franz\AppData\Roaming\FileZilla 2014-02-09 16:10 - 2014-01-24 19:02 - 00000000 ____D () C:\Users\Franz\AppData\Local\Battle.net 2014-02-09 13:37 - 2014-02-09 13:37 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-09 13:37 - 2014-01-01 15:08 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-09 13:37 - 2013-05-11 15:32 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-09 13:36 - 2013-05-11 15:32 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-09 13:36 - 2013-05-11 15:32 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-08 15:12 ==================== End Of Log ============================ --- --- --- --- --- --- Eset kommt gleich. So hab jetzt Eset mal durchlaufen lassen und es danch gleich gelöscht... (diesen Haken reingemacht). Also hab ich jetzt kein Logfile, aber Eset hat nichts gefunden, dass kann ich sagen. Ich hab auch keine Probleme mehr im Internet mit Werbeeinblendungen. |
11.03.2014, 13:15 | #6 |
/// the machine /// TB-Ausbilder | Avast findet Virus und Malwarebytes findet Viren Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Avast findet Virus und Malwarebytes findet Viren |
11.03.2014, 15:10 | #7 |
| Avast findet Virus und Malwarebytes findet VirenCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-03-2014 02 Ran by Franz at 2014-03-11 14:21:15 Run:1 Running from C:\Users\Franz\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ***************** C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== |
12.03.2014, 12:06 | #8 |
/// the machine /// TB-Ausbilder | Avast findet Virus und Malwarebytes findet Viren Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Avast findet Virus und Malwarebytes findet Viren |
adobe, bonjour, branding, defender, firefox, fontcache, homepage, iexplore.exe, league of legends, mozilla, newtab, pup.optional.amonetize.a, pup.optional.remarkit.a, pup.optional.skytech.a, security, services.exe, svchost.exe, temp, virus |