![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Langsames Internet und hoher PingWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #7 |
| | Langsames Internet und hoher Ping Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 18.04.2014 Scan Time: 18:25:57 Logfile: Log2.txt Administrator: Yes Version: 2.00.1.1004 Malware Database: v2014.04.18.06 Rootkit Database: v2014.03.27.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Chameleon: Disabled OS: Windows 8 CPU: x64 File System: NTFS User: Maximilian Scan Type: Threat Scan Result: Completed Objects Scanned: 258621 Time Elapsed: 7 min, 0 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Shuriken: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 18/04/2014 um 19:28:24
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Maximilian - CYBERBEAGLE
# Gestartet von : C:\Users\Maximilian\Desktop\adwcleaner.exe
# Option : Loschen
***** [ Dienste ] *****
Dienst Geloscht : APNMCP
***** [ Dateien / Ordner ] *****
Ordner Geloscht : C:\ProgramData\apn
Ordner Geloscht : C:\ProgramData\AskPartnerNetwork
Ordner Geloscht : C:\Program Files (x86)\AskPartnerNetwork
Ordner Geloscht : C:\Windows\SysWOW64\AI_RecycleBin
Ordner Geloscht : C:\Users\MAXIMI~1\AppData\Local\Temp\apn
Ordner Geloscht : C:\Users\Maximilian\AppData\Local\AskPartnerNetwork
Ordner Geloscht : C:\Users\Maximilian\Documents\Optimizer Pro
***** [ Verknupfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlussel Geloscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
Wert Geloscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}
Schlussel Geloscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41564952-412D-5637-00A7-7A786E7484D7}
Schlussel Geloscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41564952-412D-5637-00A7-7A786E7484D7}
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Wert Geloscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}]
Wert Geloscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{41564952-412D-5637-00A7-7A786E7484D7}]
Schlussel Geloscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Schlussel Geloscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}
Wert Geloscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}]
Schlussel Geloscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Schlussel Geloscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Schlussel Geloscht : HKCU\Software\AskPartnerNetwork
Schlussel Geloscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlussel Geloscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlussel Geloscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlussel Geloscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlussel Geloscht : HKLM\Software\AskPartnerNetwork
Schlussel Geloscht : [x64] HKLM\SOFTWARE\AskPartnerNetwork
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\mo6flo9x.default\prefs.js ]
Zeile geloscht : user_pref("iminent.enabledAds", "false");
*************************
AdwCleaner[R0].txt - [4219 octets] - [16/04/2014 00:42:36]
AdwCleaner[R1].txt - [4277 octets] - [18/04/2014 19:26:28]
AdwCleaner[S0].txt - [4012 octets] - [18/04/2014 19:28:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4072 octets] ##########
Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 8 x64
Ran by Maximilian on 18.04.2014 at 20:33:24,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.04.2014 at 20:34:14,10
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by Maximilian (administrator) on CYBERBEAGLE on 18-04-2014 22:17:18
Running from C:\Users\Maximilian\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) D:\Programme\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) D:\Programme\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Avira Operations GmbH & Co. KG) D:\Programme\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) D:\Programme\Avira\AntiVir Desktop\avwebg7.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Alienware) C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
( Inc.) C:\Program Files\Alienware\Alienware TactX Mouse CI\AWMouseCI.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Avira Operations GmbH & Co. KG) D:\Programme\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) D:\Programme\PDF24\pdf24.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) D:\Programme\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Valve Corporation) D:\Programme\Steam\Steam.exe
(Avira Operations GmbH & Co. KG) D:\Programme\Avira\AntiVir Desktop\avcenter.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(TeamSpeak Systems GmbH) D:\Programme\Teamspeak3\ts3client_win64.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7174728 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [Launch Keyboard CI] => C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe [3439928 2012-07-11] (Alienware)
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12656 2012-07-24] (Alienware)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation)
HKLM-x32\...\Run: [avgnt] => D:\Programme\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [185896 2013-10-28] (Geek Software GmbH)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-04-15] (LogMeIn Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1794192025-2275051285-2623997292-1002\...\Run: [Steam] => D:\Programme\Steam\steam.exe [1821888 2014-02-25] (Valve Corporation)
HKU\S-1-5-21-1794192025-2275051285-2623997292-1002\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-1794192025-2275051285-2623997292-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xDB253AC7E85ACF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.7,ja;q=0.3
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.3.1
FireFox:
========
FF ProfilePath: C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\mo6flo9x.default
FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", "");
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - D:\Programme\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\mo6flo9x.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2013-07-26]
FF Extension: Adblock Plus - C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\mo6flo9x.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-11]
FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; D:\Programme\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; D:\Programme\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; D:\Programme\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [927232 2012-10-29] ()
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-04-08] (LogMeIn, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-21] ()
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek )
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-27] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-09-12] (DT Soft Ltd)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-04-15] (LogMeIn Inc.)
S3 LADF_DHP2; C:\Windows\system32\DRIVERS\ladfDHP2amd64.sys [62168 2010-09-29] (Logitech)
S3 LADF_SBVM; C:\Windows\system32\DRIVERS\ladfSBVMamd64.sys [377176 2010-09-29] (Logitech)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [129856 2012-10-20] (Ray Hinchliffe)
S3 Asushwio; \??\E:\Bin\64bit\Asushwio.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 e1edc438-f640-4184-a443-d2a7c37a01dc; \??\c:\OA3_Scripts\MB_Tools\ASUS\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X]
S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X]
S3 X6va016; \??\C:\Windows\SysWOW64\Drivers\X6va016 [X]
S3 X6va017; \??\C:\Windows\SysWOW64\Drivers\X6va017 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 22:17 - 2014-04-18 22:17 - 00014022 _____ () C:\Users\Maximilian\Desktop\FRST.txt
2014-04-18 22:16 - 2014-04-18 22:16 - 00000000 ____D () C:\Users\Maximilian\Desktop\FRST-OlderVersion
2014-04-18 20:34 - 2014-04-18 20:34 - 00000640 _____ () C:\Users\Maximilian\Desktop\JRT.txt
2014-04-18 20:31 - 2014-04-18 20:31 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 19:46 - 2014-04-18 19:47 - 01016261 _____ (Thisisu) C:\Users\Maximilian\Downloads\JRT.exe
2014-04-18 00:19 - 2014-04-18 00:19 - 00024965 _____ () C:\ComboFix.txt
2014-04-18 00:16 - 2014-04-18 00:19 - 00000000 ____D () C:\Qoobox
2014-04-18 00:16 - 2014-04-18 00:18 - 00000000 ____D () C:\Windows\erdnt
2014-04-18 00:16 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-18 00:16 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-18 00:16 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-18 00:16 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-18 00:16 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-18 00:16 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-04-18 00:16 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-18 00:16 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-18 00:16 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-18 00:13 - 2014-04-18 00:13 - 05195154 ____R (Swearware) C:\Users\Maximilian\Desktop\ComboFix.exe
2014-04-16 14:24 - 2014-04-16 14:25 - 00036976 _____ () C:\Users\Maximilian\Downloads\FRST.txt
2014-04-16 14:22 - 2014-04-16 14:22 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-04-16 00:44 - 2014-04-18 22:16 - 00000000 ____D () C:\FRST
2014-04-16 00:42 - 2014-04-18 19:28 - 00000000 ____D () C:\AdwCleaner
2014-04-16 00:42 - 2014-04-16 00:42 - 01426178 _____ () C:\Users\Maximilian\Desktop\adwcleaner.exe
2014-04-15 21:48 - 2014-04-18 22:16 - 02158592 _____ (Farbar) C:\Users\Maximilian\Desktop\FRST64.exe
2014-04-15 21:13 - 2014-04-18 18:18 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-15 21:13 - 2014-04-15 21:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-15 21:13 - 2014-04-15 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-04-15 21:13 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-15 21:13 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-15 21:13 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-15 21:01 - 2014-04-15 21:13 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Maximilian\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-15 10:46 - 2014-04-15 10:46 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-04-14 01:56 - 2014-04-14 01:56 - 00000446 _____ () C:\Users\Maximilian\Desktop\Bewertung.txt
2014-04-13 21:27 - 2014-02-04 01:56 - 00332632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-13 21:27 - 2014-02-04 01:56 - 00278872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-13 21:27 - 2014-01-31 05:55 - 00209712 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-04-13 21:27 - 2014-01-31 02:48 - 00564736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-04-13 21:27 - 2014-01-31 02:48 - 00485888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSDApi.dll
2014-04-13 21:27 - 2014-01-31 02:48 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2014-04-13 21:27 - 2014-01-31 02:48 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-13 21:27 - 2014-01-31 02:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-04-13 21:27 - 2014-01-31 02:06 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2014-04-13 21:27 - 2014-01-31 02:06 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-13 21:27 - 2014-01-27 05:42 - 02232664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-04-13 21:27 - 2014-01-27 05:39 - 01939288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-13 21:27 - 2014-01-27 02:52 - 17561088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-04-13 21:27 - 2014-01-27 02:31 - 19752448 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-04-13 21:27 - 2014-01-27 01:17 - 00386722 _____ () C:\Windows\system32\ApnDatabase.xml
2014-04-13 21:27 - 2014-01-16 01:42 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-04-13 21:27 - 2014-01-11 08:48 - 05979648 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-04-13 21:27 - 2014-01-11 07:06 - 05092352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-04-13 21:27 - 2014-01-03 01:35 - 00365568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-04-13 21:27 - 2014-01-03 01:32 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-04-13 21:26 - 2014-03-07 02:48 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-13 21:26 - 2014-03-07 02:48 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-13 21:26 - 2014-03-07 02:47 - 14357504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-13 21:26 - 2014-03-07 02:47 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-13 21:26 - 2014-03-07 02:47 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-13 21:26 - 2014-03-07 02:47 - 02049536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-13 21:26 - 2014-03-07 02:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-04-13 21:26 - 2014-03-07 02:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-13 21:26 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 19273216 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 02240000 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-13 21:26 - 2014-03-07 02:08 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-13 21:26 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-04-13 21:26 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-04-13 21:26 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-13 21:26 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-13 21:26 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-04-13 21:26 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-13 21:26 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-13 21:26 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-13 21:26 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-04-13 21:26 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-13 21:26 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-04-13 21:26 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-13 21:26 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-13 21:26 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-12 02:20 - 2014-04-12 02:20 - 00007683 _____ () C:\Users\Maximilian\Desktop\Mai 2.0.txt
2014-04-10 19:49 - 2014-04-10 19:49 - 01344918 _____ () C:\Users\Maximilian\Desktop\test.psd
2014-04-10 19:42 - 2014-04-10 19:42 - 00196136 _____ () C:\Users\Maximilian\Desktop\Schrift.psd
2014-04-09 23:33 - 2014-02-06 01:41 - 01257984 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 23:33 - 2014-02-06 01:41 - 00978432 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-04-09 23:33 - 2014-02-06 01:26 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-04-09 23:33 - 2014-02-06 01:19 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 16:54 - 2014-04-09 16:54 - 00018606 _____ () C:\Users\Maximilian\Downloads\bleach_best_trax_b875f.zip
2014-04-08 00:46 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-04-08 00:46 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-04-06 19:14 - 2014-04-06 19:14 - 00000857 _____ () C:\Users\Maximilian\Desktop\NP.txt
2014-04-05 20:29 - 2014-04-05 20:29 - 00000748 _____ () C:\Users\Maximilian\Desktop\as.txt
2014-04-04 12:42 - 2014-04-04 12:45 - 44929303 _____ () C:\Users\Maximilian\Downloads\Highschool DxD NEW OP Single.zip
2014-04-01 13:19 - 2014-04-01 13:21 - 24300402 _____ () C:\Users\Maximilian\Downloads\Magi S2 OP2 Single.zip
2014-04-01 11:59 - 2014-04-01 12:08 - 00004729 _____ () C:\Users\Maximilian\Desktop\le_text.txt
2014-03-28 16:33 - 2014-03-28 16:33 - 02254936 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-26 23:10 - 2014-03-26 23:11 - 00019936 _____ () C:\Users\Maximilian\Desktop\Merlin.odt
2014-03-26 21:25 - 2014-02-08 06:34 - 04036608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-26 21:25 - 2013-10-25 09:34 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-03-26 21:25 - 2013-10-25 00:34 - 00248240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-03-26 21:23 - 2014-02-06 01:41 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-26 21:23 - 2014-02-06 01:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-26 21:23 - 2014-01-31 02:48 - 01339392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-26 21:23 - 2014-01-31 02:06 - 01628160 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-25 02:27 - 2014-03-25 02:27 - 00636944 _____ () C:\Users\Maximilian\Desktop\Unbenannt-2.psd
2014-03-22 13:47 - 2014-03-22 13:47 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-22 13:47 - 2014-03-22 13:47 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-22 13:47 - 2014-03-22 13:47 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Skype
2014-03-21 18:20 - 2014-03-21 18:20 - 00000000 ____D () C:\Users\Maximilian\Desktop\[ASL] Aoi Eir - Fate/Zero Image Song Album - Prayer [MP3] [w Scans]
2014-03-21 17:39 - 2014-03-21 18:14 - 101194917 _____ () C:\Users\Maximilian\Downloads\[ASL]_Aoi_Eir_-_Fate_Zero_Image_Song_Album_-_Prayer_[MP3]_[w_Scans].rar
2014-03-21 01:05 - 2014-03-21 01:05 - 02297316 _____ () C:\Users\Maximilian\Desktop\Saber03.psd
==================== One Month Modified Files and Folders =======
2014-04-18 22:17 - 2014-04-18 22:17 - 00014022 _____ () C:\Users\Maximilian\Desktop\FRST.txt
2014-04-18 22:17 - 2014-04-16 00:44 - 00000000 ____D () C:\FRST
2014-04-18 22:16 - 2014-04-18 22:16 - 00000000 ____D () C:\Users\Maximilian\Desktop\FRST-OlderVersion
2014-04-18 22:16 - 2014-04-15 21:48 - 02158592 _____ (Farbar) C:\Users\Maximilian\Desktop\FRST64.exe
2014-04-18 22:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-04-18 21:51 - 2013-09-11 20:34 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Skype
2014-04-18 21:36 - 2013-09-11 20:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-18 21:19 - 2013-09-11 19:28 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1794192025-2275051285-2623997292-1002
2014-04-18 20:45 - 2013-09-11 18:39 - 01473646 _____ () C:\Windows\WindowsUpdate.log
2014-04-18 20:38 - 2013-04-23 21:21 - 00742640 _____ () C:\Windows\system32\perfh007.dat
2014-04-18 20:38 - 2013-04-23 21:21 - 00155698 _____ () C:\Windows\system32\perfc007.dat
2014-04-18 20:38 - 2012-07-26 09:28 - 01748838 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-18 20:36 - 2014-01-02 16:00 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\LogMeIn Hamachi
2014-04-18 20:34 - 2014-04-18 20:34 - 00000640 _____ () C:\Users\Maximilian\Desktop\JRT.txt
2014-04-18 20:33 - 2014-01-08 12:36 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\TSVNCache
2014-04-18 20:32 - 2013-08-29 11:16 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-18 20:32 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-18 20:31 - 2014-04-18 20:31 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 19:47 - 2014-04-18 19:46 - 01016261 _____ (Thisisu) C:\Users\Maximilian\Downloads\JRT.exe
2014-04-18 19:28 - 2014-04-16 00:42 - 00000000 ____D () C:\AdwCleaner
2014-04-18 18:18 - 2014-04-15 21:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-18 00:24 - 2013-04-23 10:48 - 00018620 _____ () C:\Windows\PFRO.log
2014-04-18 00:19 - 2014-04-18 00:19 - 00024965 _____ () C:\ComboFix.txt
2014-04-18 00:19 - 2014-04-18 00:16 - 00000000 ____D () C:\Qoobox
2014-04-18 00:19 - 2013-09-15 17:51 - 05687808 ___SH () C:\Users\Maximilian\Desktop\Thumbs.db
2014-04-18 00:18 - 2014-04-18 00:16 - 00000000 ____D () C:\Windows\erdnt
2014-04-18 00:18 - 2013-09-11 18:40 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-18 00:18 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-04-18 00:13 - 2014-04-18 00:13 - 05195154 ____R (Swearware) C:\Users\Maximilian\Desktop\ComboFix.exe
2014-04-17 16:51 - 2013-09-11 22:52 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\PMB Files
2014-04-17 16:51 - 2013-09-11 22:52 - 00000000 ____D () C:\ProgramData\PMB Files
2014-04-16 14:25 - 2014-04-16 14:24 - 00036976 _____ () C:\Users\Maximilian\Downloads\FRST.txt
2014-04-16 14:22 - 2014-04-16 14:22 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-04-16 00:42 - 2014-04-16 00:42 - 01426178 _____ () C:\Users\Maximilian\Desktop\adwcleaner.exe
2014-04-15 21:30 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-04-15 21:13 - 2014-04-15 21:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-15 21:13 - 2014-04-15 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-04-15 21:13 - 2014-04-15 21:01 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Maximilian\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-15 20:57 - 2013-09-11 18:40 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Adobe
2014-04-15 10:46 - 2014-04-15 10:46 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-04-14 23:45 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-04-14 11:24 - 2013-09-11 18:40 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-14 02:08 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-04-14 02:08 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-04-14 01:56 - 2014-04-14 01:56 - 00000446 _____ () C:\Users\Maximilian\Desktop\Bewertung.txt
2014-04-13 11:36 - 2013-10-07 10:13 - 00067584 ___SH () C:\Users\Maximilian\Downloads\Thumbs.db
2014-04-12 02:20 - 2014-04-12 02:20 - 00007683 _____ () C:\Users\Maximilian\Desktop\Mai 2.0.txt
2014-04-11 22:00 - 2013-09-11 21:14 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\CrashDumps
2014-04-11 10:54 - 2013-09-29 18:39 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 19:49 - 2014-04-10 19:49 - 01344918 _____ () C:\Users\Maximilian\Desktop\test.psd
2014-04-10 19:42 - 2014-04-10 19:42 - 00196136 _____ () C:\Users\Maximilian\Desktop\Schrift.psd
2014-04-10 14:47 - 2013-08-29 11:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 14:46 - 2013-04-23 11:49 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 16:54 - 2014-04-09 16:54 - 00018606 _____ () C:\Users\Maximilian\Downloads\bleach_best_trax_b875f.zip
2014-04-08 00:46 - 2013-12-18 23:36 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\NVIDIA Corporation
2014-04-08 00:46 - 2013-08-29 11:16 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-04-08 00:46 - 2013-08-29 11:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-04-08 00:46 - 2012-07-26 09:21 - 00036603 _____ () C:\Windows\setupact.log
2014-04-07 20:40 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-04-06 19:14 - 2014-04-06 19:14 - 00000857 _____ () C:\Users\Maximilian\Desktop\NP.txt
2014-04-05 20:29 - 2014-04-05 20:29 - 00000748 _____ () C:\Users\Maximilian\Desktop\as.txt
2014-04-04 12:45 - 2014-04-04 12:42 - 44929303 _____ () C:\Users\Maximilian\Downloads\Highschool DxD NEW OP Single.zip
2014-04-03 09:51 - 2014-04-15 21:13 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-15 21:13 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-15 21:13 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 15:27 - 2013-10-28 19:11 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-04-02 15:27 - 2013-10-28 19:11 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-04-01 13:21 - 2014-04-01 13:19 - 24300402 _____ () C:\Users\Maximilian\Downloads\Magi S2 OP2 Single.zip
2014-04-01 12:08 - 2014-04-01 11:59 - 00004729 _____ () C:\Users\Maximilian\Desktop\le_text.txt
2014-03-31 23:18 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-31 23:18 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-28 16:33 - 2014-03-28 16:33 - 02254936 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-27 02:33 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-27 02:33 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-27 02:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-27 02:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-03-26 23:11 - 2014-03-26 23:10 - 00019936 _____ () C:\Users\Maximilian\Desktop\Merlin.odt
2014-03-26 21:29 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-03-26 19:29 - 2014-02-22 12:16 - 00000718 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fate.lnk
2014-03-25 02:27 - 2014-03-25 02:27 - 00636944 _____ () C:\Users\Maximilian\Desktop\Unbenannt-2.psd
2014-03-22 13:47 - 2014-03-22 13:47 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-22 13:47 - 2014-03-22 13:47 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-22 13:47 - 2014-03-22 13:47 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Skype
2014-03-22 13:47 - 2013-09-11 20:34 - 00000000 ____D () C:\ProgramData\Skype
2014-03-21 21:43 - 2014-04-08 00:46 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-03-21 21:43 - 2014-04-08 00:46 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-03-21 21:43 - 2013-09-12 23:34 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2014-03-21 18:20 - 2014-03-21 18:20 - 00000000 ____D () C:\Users\Maximilian\Desktop\[ASL] Aoi Eir - Fate/Zero Image Song Album - Prayer [MP3] [w Scans]
2014-03-21 18:14 - 2014-03-21 17:39 - 101194917 _____ () C:\Users\Maximilian\Downloads\[ASL]_Aoi_Eir_-_Fate_Zero_Image_Song_Album_-_Prayer_[MP3]_[w_Scans].rar
2014-03-21 01:05 - 2014-03-21 01:05 - 02297316 _____ () C:\Users\Maximilian\Desktop\Saber03.psd
Some content of TEMP:
====================
C:\Users\Maximilian\AppData\Local\Temp\avgnt.exe
C:\Users\Maximilian\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-18 17:36
==================== End Of Log ============================
|
| Themen zu Langsames Internet und hoher Ping |
| antivir, code, ergebnis, grundlos, internet, internet explorer, langsames internet, malwarebytes, microsoft, pup.optional.iminent, pup.optional.iminent.a, pup.optional.opencandy, pup.optional.optimizerpro.a, pup.optional.somoto, pup.optional.spigot.a, rechner, system, temp, windows, woche |