Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 19.04.2014, 11:47   #1
Spender0815
 
Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden - Standard

Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden



Hallo zusammen,

wie oben beschrieben habe ich SUPER2014 installiert, die Installation dann abgebrochen, da ich gesehen habe, was alles an Müll installiert wird. Leider hatte ich dann Programme wie V-bates 2.0.0.438 und Search Protect installiert. Ebenfalls erscheinen nur noch 7 Programme in der Übersicht, die installiert sind, was definitiv zu wenif sind.
Systemwiederherstellung ist leider deaktiviert (warum auch immer).
Firefox hatte auch "conduit" als Standardsuche. Seit dem stürzt FF auch immer mal wieder ab.
Was tun sprach Zeus?
Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Alexander on 19.04.2014 at 12:31:19,61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Alexander\AppData\Roaming\mozilla\firefox\profiles\y9w336l0.default\minidumps [3 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.04.2014 at 12:35:33,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by Alexander (administrator) on SAUVIEH on 19-04-2014 12:29:33
Running from C:\Users\Alexander\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-19] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6FFAA25E6C4DCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default
FF NewTab: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Homepage: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\ich@maltegoetz.de [2014-04-18]
FF Extension: NoScript - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30]
FF Extension: Adblock Plus - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-30]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-03-13] ()
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R0 Pnp680r; C:\Windows\System32\DRIVERS\pnp680r.sys [125992 2007-07-24] (Silicon Image, Inc)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-19 12:14 - 2014-04-19 12:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 12:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 12:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:12 - 2014-04-19 12:29 - 00011061 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-19 12:12 - 2014-04-19 12:29 - 00000000 ____D () C:\FRST
2014-04-19 12:12 - 2014-04-19 12:13 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 10:14 - 2014-04-19 12:08 - 00000000 ____D () C:\AdwCleaner
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-19 12:27 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:39 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-04-18 21:39 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:33 - 2014-04-18 21:34 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:33 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-18 21:33 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:25 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-18 21:25 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-18 21:25 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-18 21:25 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-18 21:25 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-18 21:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-18 21:25 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-18 21:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-18 21:25 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-18 21:25 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-18 21:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-18 21:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-18 21:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-18 21:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-18 21:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-18 21:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-18 21:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-18 21:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-18 21:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-18 21:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-18 21:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-18 21:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-18 21:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-18 21:25 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-18 21:25 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-18 21:25 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-18 21:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-04-18 21:25 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-04-18 21:25 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-18 21:25 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-04-18 21:25 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-04-18 21:25 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-04-18 21:25 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-04-18 21:25 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-04-18 21:25 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-04-18 21:25 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-04-18 21:25 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-04-18 21:25 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-04-18 21:25 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-04-18 21:25 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-04-18 21:25 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-04-18 21:25 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-04-18 21:25 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-04-18 21:25 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-04-18 21:25 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-04-18 21:25 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-04-18 21:25 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-04-18 21:25 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-04-18 21:25 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-04-19 12:29 - 2014-04-19 12:12 - 00011061 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-19 12:29 - 2014-04-19 12:12 - 00000000 ____D () C:\FRST
2014-04-19 12:29 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-19 12:29 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-19 12:27 - 2014-04-19 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-19 12:26 - 2009-07-14 19:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-04-19 12:26 - 2009-07-14 19:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-04-19 12:26 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-19 12:22 - 2014-04-19 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 12:22 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-04-19 12:21 - 2012-12-31 21:16 - 00212804 _____ () C:\Windows\PFRO.log
2014-04-19 12:21 - 2012-12-09 20:35 - 01392025 _____ () C:\Windows\WindowsUpdate.log
2014-04-19 12:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-19 12:21 - 2009-07-14 06:51 - 00046315 _____ () C:\Windows\setupact.log
2014-04-19 12:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:13 - 2014-04-19 12:12 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-19 12:08 - 2014-04-19 10:14 - 00000000 ____D () C:\AdwCleaner
2014-04-19 12:07 - 2013-01-07 23:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-19 11:49 - 2013-07-08 15:59 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\vlc
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 11:38 - 2013-04-04 12:21 - 00000000 ____D () C:\Windows\rescache
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-19 10:07 - 2013-01-07 23:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 09:47 - 2013-07-12 13:51 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-19 09:47 - 2013-06-30 12:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-19 09:45 - 2013-12-27 11:39 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\dvdcss
2014-04-19 09:43 - 2013-06-30 12:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-19 00:22 - 2013-03-04 23:08 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 23:00 - 2013-04-04 18:26 - 00000000 ____D () C:\Users\Alexander\Documents\StarCraft II
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:43 - 2009-07-14 06:45 - 00342952 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-18 21:39 - 2013-07-08 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:33 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:34 - 2013-11-30 20:21 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-03 09:51 - 2014-04-19 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-19 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-19 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:51 - 2013-04-04 08:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Alexander\AppData\Local\Temp\avgnt.exe
C:\Users\Alexander\AppData\Local\Temp\BackupSetup.exe
C:\Users\Alexander\AppData\Local\Temp\MP3_German_Launcher_1_27_0_0.exe
C:\Users\Alexander\AppData\Local\Temp\MP3_German_Patch_Update_1_0_0_78.exe
C:\Users\Alexander\AppData\Local\Temp\ose00000.exe
C:\Users\Alexander\AppData\Local\Temp\Quarantine.exe
C:\Users\Alexander\AppData\Local\Temp\uninst1.exe
C:\Users\Alexander\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Alexander\AppData\Local\Temp\_isABF7.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-19 11:31

==================== End Of Log ============================
         
--- --- ---


Sodele dann noch mal eine Log!

GMER Logfile:
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-19 12:45:22
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.CXM0 59,63GB
Running: Gmer-19357.exe; Driver: C:\Users\ALEXAN~1\AppData\Local\Temp\pwtdypob.sys


---- User code sections - GMER 2.1 ----

.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                       0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                      00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                         0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                        00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                               00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2

---- EOF - GMER 2.1 ----
         
--- --- ---


Zitat:
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 19.04.2014
Scan Time: 12:19:36
Logfile: Malwarebytes_log.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.04.19.05
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Alexander

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 246406
Time Elapsed: 4 min, 25 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 7
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\V-bates, Quarantined, [c071101c3a41c0761b50b0d047bb4db3],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\WOW6432NODE\V-bates, Quarantined, [ea47ae7e473480b6412acbb55aa8d32d],
PUP.Optional.VbatesHelper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\V-bates Updater, Quarantined, [3100f735d2a9d46294d4512f5ca6d927],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 11
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsn3FC1.exe, Quarantined, [63ced25a384320161f14e044f809758b],
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsn41E4.exe, Quarantined, [062bb874bdbe9d99052ef23226db669a],
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsn5568.exe, Quarantined, [ad84e943cead3bfb151e8b99996814ec],
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsy5336.exe, Quarantined, [dd54ea42ed8e55e1f24153d1bf42d22e],
PUP.Optional.InstallMonetizer.A, C:\Users\Alexander\AppData\Local\Temp\is-NI1I5.tmp\sam__2268_il459.exe, Quarantined, [e74aea42f586bb7bbf47b0721de425db],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\BExternal.dll, Quarantined, [77ba68c4b4c7c57110cd130fec147987],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\ccp.exe, Quarantined, [ef42d25ade9daa8cc956d14dc33db54b],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\CrxInstaller.dll, Quarantined, [f14064c80b703bfb9455c94a5fa2a15f],
PUP.Optional.Delta, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\MyDeltaTB.exe, Quarantined, [ea4775b7c3b86ec87e5853b0e21f8977],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\Setup.exe, Quarantined, [9e93e7454d2e94a224061d01d828c23e],
PUP.Optional.Conduit.A, C:\Users\Alexander\AppData\Local\Temp\nsy315F\SpSetup.exe, Quarantined, [76bb43e945361422f032011813eef60a],

Physical Sectors: 0
(No malicious items detected)


(end)
Wie mache ich so scrollbare Fenster ? So produziere ich ja ewig lange Einträge.

Ich dachte mir, bevor ich den Rechner neu aufsetzte, frag ich mal hier

Es dankt
der Spender

 

Themen zu Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden
.dll, adobe flash player, browser, explorer, flash player, installation, neu, newtab, pup.optional.babylon.a, pup.optional.conduit.a, pup.optional.delta, pup.optional.searchprotect.a, pup.optional.vbates, pup.optional.vbateshelper.a, registry, services.exe, super, svchost.exe, vcredist, warum, win32/adware.agent.nmz, win32/speedingupmypc.i, win32/trojannotifier.small.a, windows, winlogon.exe




Ähnliche Themen: Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden


  1. Verdächtige Datei gestartet --> Installation mehrer Programme
    Plagegeister aller Art und deren Bekämpfung - 20.02.2015 (19)
  2. Nach Installation von DVDstyler kein Internet mehr und Programme lassen sich nicht starten
    Plagegeister aller Art und deren Bekämpfung - 27.01.2015 (13)
  3. nach Installation von adobe reader Probleme mit öffnen andere Programme
    Log-Analyse und Auswertung - 22.10.2014 (3)
  4. Win 7: sämtliche Verknüpfungen/Programme aus Verwaltung und Startmenüordner verschwunden
    Log-Analyse und Auswertung - 12.08.2014 (17)
  5. Programme Starten zeitlich verzöger, Probleme bei Installation von Spybot S&D
    Log-Analyse und Auswertung - 29.01.2014 (5)
  6. Probleme mit searchgol nach deltatoolbar nach installation von imgburn (Win8-x64-chrome)
    Log-Analyse und Auswertung - 31.10.2013 (29)
  7. Virus nach installation von "hdplugin_firefox.exe" - Office und andere Programme gelöscht?
    Plagegeister aller Art und deren Bekämpfung - 23.08.2013 (29)
  8. 2x | Programme verschwunden - Logfile Malwarebytes
    Mülltonne - 14.02.2013 (1)
  9. schwarzer desktop und alle datein + programme verschwunden
    Log-Analyse und Auswertung - 07.10.2012 (26)
  10. Desktop schwarz und alle Programme im Startmenü verschwunden
    Plagegeister aller Art und deren Bekämpfung - 07.10.2012 (3)
  11. Programmdateien im Explorer verschwunden, Programme lassen sich nicht mehr starten
    Log-Analyse und Auswertung - 05.06.2012 (10)
  12. Programme sind verschwunden!
    Plagegeister aller Art und deren Bekämpfung - 13.05.2012 (9)
  13. Dateien & Symbole verschwunden / Programme nicht mehr ausführbar
    Plagegeister aller Art und deren Bekämpfung - 23.09.2011 (30)
  14. Nach Trojaner Desktop schwarz Programme und Dateien verschwunden
    Log-Analyse und Auswertung - 23.05.2011 (39)
  15. "Windows Fix Disk"-Problem und alle Daten und Programme scheinbar verschwunden
    Plagegeister aller Art und deren Bekämpfung - 15.04.2011 (4)
  16. Programme reagieren Sekunden lang nicht seit ServicePack 3 Installation
    Log-Analyse und Auswertung - 15.01.2009 (13)
  17. CD-Rom Laufwerk verschwunden+sämtliche Programme nur eingeschränkt nutzbar
    Alles rund um Windows - 24.10.2006 (1)

Zum Thema Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden - Hallo zusammen, wie oben beschrieben habe ich SUPER2014 installiert, die Installation dann abgebrochen, da ich gesehen habe, was alles an Müll installiert wird. Leider hatte ich dann Programme wie V-bates - Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden...
Archiv
Du betrachtest: Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.