|
Log-Analyse und Auswertung: Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwundenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.04.2014, 11:47 | #1 | ||
| Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden Hallo zusammen, wie oben beschrieben habe ich SUPER2014 installiert, die Installation dann abgebrochen, da ich gesehen habe, was alles an Müll installiert wird. Leider hatte ich dann Programme wie V-bates 2.0.0.438 und Search Protect installiert. Ebenfalls erscheinen nur noch 7 Programme in der Übersicht, die installiert sind, was definitiv zu wenif sind. Systemwiederherstellung ist leider deaktiviert (warum auch immer). Firefox hatte auch "conduit" als Standardsuche. Seit dem stürzt FF auch immer mal wieder ab. Was tun sprach Zeus? Zitat:
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by Alexander (administrator) on SAUVIEH on 19-04-2014 12:29:33 Running from C:\Users\Alexander\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-19] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD) HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6FFAA25E6C4DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default FF NewTab: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF Homepage: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\ich@maltegoetz.de [2014-04-18] FF Extension: NoScript - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30] FF Extension: Adblock Plus - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-30] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-04-19] (Avira Operations GmbH & Co. KG) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-19] (Avira Operations GmbH & Co. KG) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-03-13] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-19] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R0 Pnp680r; C:\Windows\System32\DRIVERS\pnp680r.sys [125992 2007-07-24] (Silicon Image, Inc) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-19 12:14 - 2014-04-19 12:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 12:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 12:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 12:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe 2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 12:12 - 2014-04-19 12:29 - 00011061 _____ () C:\Users\Alexander\Downloads\FRST.txt 2014-04-19 12:12 - 2014-04-19 12:29 - 00000000 ____D () C:\FRST 2014-04-19 12:12 - 2014-04-19 12:13 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt 2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe 2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi 2014-04-19 10:14 - 2014-04-19 12:08 - 00000000 ____D () C:\AdwCleaner 2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe 2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results 2014-04-19 09:57 - 2014-04-19 12:27 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job 2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp 2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E} 2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe 2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment 2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-18 21:39 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-04-18 21:39 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-04-18 21:39 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-04-18 21:39 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo 2014-04-18 21:33 - 2014-04-18 21:34 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-04-18 21:33 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-18 21:33 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe 2014-04-18 21:25 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-18 21:25 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-18 21:25 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-18 21:25 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-18 21:25 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-18 21:25 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-18 21:25 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-18 21:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-18 21:25 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-18 21:25 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-18 21:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-18 21:25 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-18 21:25 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-18 21:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-18 21:25 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-18 21:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-18 21:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-18 21:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-18 21:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-18 21:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-18 21:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-18 21:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-18 21:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-18 21:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-18 21:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-18 21:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-18 21:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-18 21:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-18 21:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-18 21:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-18 21:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-18 21:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-18 21:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-18 21:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-18 21:25 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-18 21:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-18 21:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-18 21:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-18 21:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-18 21:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-18 21:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-18 21:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-18 21:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-18 21:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-18 21:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-18 21:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-18 21:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-18 21:25 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-18 21:25 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-04-18 21:25 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-04-18 21:25 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-18 21:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-04-18 21:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-04-18 21:25 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-18 21:25 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-04-18 21:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-04-18 21:25 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-04-18 21:25 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-18 21:25 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-04-18 21:25 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-04-18 21:25 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-04-18 21:25 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-04-18 21:25 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-04-18 21:25 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-04-18 21:25 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-04-18 21:25 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-04-18 21:25 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-04-18 21:25 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-04-18 21:25 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-04-18 21:25 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-04-18 21:25 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-04-18 21:25 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-04-18 21:25 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-04-18 21:25 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-04-18 21:25 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-04-18 21:25 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-04-18 21:25 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-04-18 21:25 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-04-18 21:25 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-04-18 21:25 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-04-18 21:25 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-04-18 21:25 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-04-18 21:25 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-04-18 21:25 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-04-18 21:25 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-04-18 21:25 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-04-18 21:25 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-04-18 21:25 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-04-18 21:25 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-04-18 21:25 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-04-18 21:25 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-04-18 21:25 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-04-18 21:25 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys ==================== One Month Modified Files and Folders ======= 2014-04-19 12:29 - 2014-04-19 12:12 - 00011061 _____ () C:\Users\Alexander\Downloads\FRST.txt 2014-04-19 12:29 - 2014-04-19 12:12 - 00000000 ____D () C:\FRST 2014-04-19 12:29 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-19 12:29 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-19 12:27 - 2014-04-19 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job 2014-04-19 12:26 - 2009-07-14 19:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-19 12:26 - 2009-07-14 19:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-19 12:26 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-19 12:22 - 2014-04-19 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 12:22 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-04-19 12:21 - 2012-12-31 21:16 - 00212804 _____ () C:\Windows\PFRO.log 2014-04-19 12:21 - 2012-12-09 20:35 - 01392025 _____ () C:\Windows\WindowsUpdate.log 2014-04-19 12:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-19 12:21 - 2009-07-14 06:51 - 00046315 _____ () C:\Windows\setupact.log 2014-04-19 12:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe 2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 12:13 - 2014-04-19 12:12 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt 2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe 2014-04-19 12:08 - 2014-04-19 10:14 - 00000000 ____D () C:\AdwCleaner 2014-04-19 12:07 - 2013-01-07 23:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-19 11:49 - 2013-07-08 15:59 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\vlc 2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi 2014-04-19 11:38 - 2013-04-04 12:21 - 00000000 ____D () C:\Windows\rescache 2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe 2014-04-19 10:07 - 2013-01-07 23:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-19 10:07 - 2013-01-07 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-19 10:07 - 2013-01-07 23:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results 2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp 2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E} 2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe 2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-04-19 09:47 - 2013-07-12 13:51 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-04-19 09:47 - 2013-06-30 12:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-04-19 09:46 - 2013-06-30 12:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-04-19 09:46 - 2013-06-30 12:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-04-19 09:45 - 2013-12-27 11:39 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\dvdcss 2014-04-19 09:43 - 2013-06-30 12:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-19 00:22 - 2013-03-04 23:08 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment 2014-04-18 23:00 - 2013-04-04 18:26 - 00000000 ____D () C:\Users\Alexander\Documents\StarCraft II 2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-18 21:43 - 2009-07-14 06:45 - 00342952 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-18 21:39 - 2013-07-08 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:33 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-04-18 21:34 - 2013-11-30 20:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe 2014-04-18 21:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-03 09:51 - 2014-04-19 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-19 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-19 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:51 - 2013-04-04 08:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Alexander\AppData\Local\Temp\avgnt.exe C:\Users\Alexander\AppData\Local\Temp\BackupSetup.exe C:\Users\Alexander\AppData\Local\Temp\MP3_German_Launcher_1_27_0_0.exe C:\Users\Alexander\AppData\Local\Temp\MP3_German_Patch_Update_1_0_0_78.exe C:\Users\Alexander\AppData\Local\Temp\ose00000.exe C:\Users\Alexander\AppData\Local\Temp\Quarantine.exe C:\Users\Alexander\AppData\Local\Temp\uninst1.exe C:\Users\Alexander\AppData\Local\Temp\vcredist_x64.exe C:\Users\Alexander\AppData\Local\Temp\_isABF7.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 11:31 ==================== End Of Log ============================ Sodele dann noch mal eine Log! GMER Logfile: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-19 12:45:22 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.CXM0 59,63GB Running: Gmer-19357.exe; Driver: C:\Users\ALEXAN~1\AppData\Local\Temp\pwtdypob.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075831465 2 bytes [83, 75] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000758314bb 2 bytes [83, 75] .text ... * 2 .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075831465 2 bytes [83, 75] .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000758314bb 2 bytes [83, 75] .text ... * 2 .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075831465 2 bytes [83, 75] .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000758314bb 2 bytes [83, 75] .text ... * 2 .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075831465 2 bytes [83, 75] .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000758314bb 2 bytes [83, 75] .text ... * 2 ---- EOF - GMER 2.1 ---- Zitat:
Ich dachte mir, bevor ich den Rechner neu aufsetzte, frag ich mal hier Es dankt der Spender |
19.04.2014, 12:15 | #2 |
/// the machine /// TB-Ausbilder | Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden hi,
__________________Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
19.04.2014, 12:35 | #3 | |
| Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwundenZitat:
Code:
ATTFilter # AdwCleaner v3.024 - Bericht erstellt am 19/04/2014 um 13:27:45 # Aktualisiert 18/04/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Alexander - SAUVIEH # Gestartet von : C:\Users\Alexander\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\gfklq0mm.default\user.js Datei Gelöscht : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Optimizer Pro Schlüssel Gelöscht : HKLM\Software\InstallCore ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\gfklq0mm.default\prefs.js ] [ Datei : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\prefs.js ] ************************* AdwCleaner[R0].txt - [5367 octets] - [19/04/2014 10:14:37] AdwCleaner[R1].txt - [1039 octets] - [19/04/2014 12:08:09] AdwCleaner[R2].txt - [2344 octets] - [19/04/2014 13:24:25] AdwCleaner[S0].txt - [4854 octets] - [19/04/2014 10:14:55] AdwCleaner[S1].txt - [1101 octets] - [19/04/2014 12:08:42] AdwCleaner[S2].txt - [2201 octets] - [19/04/2014 13:27:45] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2261 octets] ########## FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by Alexander (administrator) on SAUVIEH on 19-04-2014 13:36:59 Running from C:\Users\Alexander\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Users\Alexander\Downloads\adwcleaner.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-19] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD) HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6FFAA25E6C4DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default FF NewTab: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF Homepage: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\ich@maltegoetz.de [2014-04-18] FF Extension: NoScript - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30] FF Extension: Adblock Plus - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-30] FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-04-19] (Avira Operations GmbH & Co. KG) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-19] (Avira Operations GmbH & Co. KG) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-03-13] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-19] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R0 Pnp680r; C:\Windows\System32\DRIVERS\pnp680r.sys [125992 2007-07-24] (Silicon Image, Inc) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt 2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe 2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe 2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log 2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe 2014-04-19 12:14 - 2014-04-19 13:29 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 12:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 12:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 12:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe 2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 12:12 - 2014-04-19 13:36 - 00011365 _____ () C:\Users\Alexander\Downloads\FRST.txt 2014-04-19 12:12 - 2014-04-19 13:36 - 00000000 ____D () C:\FRST 2014-04-19 12:12 - 2014-04-19 12:13 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt 2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe 2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi 2014-04-19 10:14 - 2014-04-19 13:27 - 00000000 ____D () C:\AdwCleaner 2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe 2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results 2014-04-19 09:57 - 2014-04-19 13:28 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job 2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp 2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E} 2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe 2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment 2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-18 21:39 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-04-18 21:39 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-04-18 21:39 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-04-18 21:39 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo 2014-04-18 21:33 - 2014-04-18 21:34 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-04-18 21:33 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-18 21:33 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe 2014-04-18 21:25 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-18 21:25 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-18 21:25 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-18 21:25 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-18 21:25 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-18 21:25 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-18 21:25 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-18 21:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-18 21:25 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-18 21:25 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-18 21:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-18 21:25 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-18 21:25 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-18 21:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-18 21:25 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-18 21:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-18 21:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-18 21:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-18 21:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-18 21:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-18 21:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-18 21:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-18 21:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-18 21:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-18 21:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-18 21:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-18 21:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-18 21:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-18 21:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-18 21:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-18 21:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-18 21:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-18 21:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-18 21:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-18 21:25 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-18 21:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-18 21:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-18 21:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-18 21:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-18 21:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-18 21:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-18 21:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-18 21:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-18 21:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-18 21:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-18 21:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-18 21:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-18 21:25 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-18 21:25 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-04-18 21:25 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-04-18 21:25 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-18 21:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-04-18 21:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-04-18 21:25 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-18 21:25 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-04-18 21:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-04-18 21:25 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-04-18 21:25 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-18 21:25 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-04-18 21:25 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-04-18 21:25 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-04-18 21:25 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-04-18 21:25 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-04-18 21:25 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-04-18 21:25 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-04-18 21:25 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-04-18 21:25 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-04-18 21:25 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-04-18 21:25 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-04-18 21:25 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-04-18 21:25 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-04-18 21:25 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-04-18 21:25 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-04-18 21:25 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-04-18 21:25 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-04-18 21:25 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-04-18 21:25 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-04-18 21:25 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-04-18 21:25 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-04-18 21:25 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-04-18 21:25 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-04-18 21:25 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-04-18 21:25 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-04-18 21:25 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-04-18 21:25 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-04-18 21:25 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-04-18 21:25 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-04-18 21:25 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-04-18 21:25 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-04-18 21:25 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-04-18 21:25 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-04-18 21:25 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-04-18 21:25 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys ==================== One Month Modified Files and Folders ======= 2014-04-19 13:37 - 2014-04-19 12:12 - 00011365 _____ () C:\Users\Alexander\Downloads\FRST.txt 2014-04-19 13:36 - 2014-04-19 12:12 - 00000000 ____D () C:\FRST 2014-04-19 13:36 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-19 13:36 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-19 13:34 - 2009-07-14 19:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-19 13:34 - 2009-07-14 19:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-19 13:34 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt 2014-04-19 13:29 - 2014-04-19 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 13:28 - 2014-04-19 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job 2014-04-19 13:28 - 2012-12-09 20:35 - 01410901 _____ () C:\Windows\WindowsUpdate.log 2014-04-19 13:28 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-19 13:28 - 2009-07-14 06:51 - 00046427 _____ () C:\Windows\setupact.log 2014-04-19 13:27 - 2014-04-19 10:14 - 00000000 ____D () C:\AdwCleaner 2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe 2014-04-19 13:21 - 2012-12-31 21:16 - 00238656 _____ () C:\Windows\PFRO.log 2014-04-19 13:07 - 2013-01-07 23:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-19 12:55 - 2013-06-30 11:49 - 00001243 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\DVDVideoSoft 2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe 2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log 2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe 2014-04-19 12:22 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-04-19 12:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe 2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 12:13 - 2014-04-19 12:12 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt 2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe 2014-04-19 11:49 - 2013-07-08 15:59 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\vlc 2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi 2014-04-19 11:38 - 2013-04-04 12:21 - 00000000 ____D () C:\Windows\rescache 2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe 2014-04-19 10:07 - 2013-01-07 23:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-19 10:07 - 2013-01-07 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-19 10:07 - 2013-01-07 23:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results 2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp 2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E} 2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe 2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-04-19 09:47 - 2013-07-12 13:51 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-04-19 09:47 - 2013-06-30 12:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-04-19 09:46 - 2013-06-30 12:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-04-19 09:46 - 2013-06-30 12:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-04-19 09:45 - 2013-12-27 11:39 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\dvdcss 2014-04-19 09:43 - 2013-06-30 12:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-19 00:22 - 2013-03-04 23:08 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment 2014-04-18 23:00 - 2013-04-04 18:26 - 00000000 ____D () C:\Users\Alexander\Documents\StarCraft II 2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-18 21:43 - 2009-07-14 06:45 - 00342952 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-18 21:39 - 2013-07-08 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:33 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-04-18 21:34 - 2013-11-30 20:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe 2014-04-18 21:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-03 09:51 - 2014-04-19 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-19 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-19 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:51 - 2013-04-04 08:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Alexander\AppData\Local\Temp\avgnt.exe C:\Users\Alexander\AppData\Local\Temp\BackupSetup.exe C:\Users\Alexander\AppData\Local\Temp\ICReinstall_COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe C:\Users\Alexander\AppData\Local\Temp\ICReinstall_FreeStudio.exe C:\Users\Alexander\AppData\Local\Temp\MP3_German_Launcher_1_27_0_0.exe C:\Users\Alexander\AppData\Local\Temp\MP3_German_Patch_Update_1_0_0_78.exe C:\Users\Alexander\AppData\Local\Temp\ose00000.exe C:\Users\Alexander\AppData\Local\Temp\Quarantine.exe C:\Users\Alexander\AppData\Local\Temp\uninst1.exe C:\Users\Alexander\AppData\Local\Temp\vcredist_x64.exe C:\Users\Alexander\AppData\Local\Temp\_isABF7.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 11:31 ==================== End Of Log ============================ --- --- --- und nu? Es dankt der SPender |
19.04.2014, 19:45 | #4 |
/// the machine /// TB-Ausbilder | Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwundenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.04.2014, 09:14 | #5 |
| Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=43121529290bb949b5cce2cfc8ccbda1 # engine=17964 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-21 08:04:21 # local_time=2014-04-21 10:04:21 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 24353885 149697311 0 0 # scanned=287386 # found=4 # cleaned=0 # scan_time=3404 sh=DD3B3E78A941CBAEF1F2A8E1ECC09843C1E2AF06 ft=1 fh=43333f9ad1e6939f vn="Win32/SpeedingUpMyPC.I application" ac=I fn="C:\Users\Alexander\AppData\Local\Temp\is1158881826\1895309_stp\OptimizerPro.exe" sh=3C772095F8E5B8E8DC957090E4B5D7C5D3DC6922 ft=1 fh=185b18bd4d33e5b3 vn="a variant of Win32/Adware.Agent.NMZ application" ac=I fn="G:\System Volume Information\_restore{DBEF6E60-C5C5-47E2-8E78-49320D8CFCDD}\RP63\A0009078.exe" sh=7A064A6070258754A2E7D1872478201CB1136257 ft=1 fh=fc3cceb629d45fe4 vn="a variant of Generik.GOVROCE trojan" ac=I fn="G:\System Volume Information\_restore{DBEF6E60-C5C5-47E2-8E78-49320D8CFCDD}\RP63\A0013931.EXE" sh=291DFDBFDA6F9261B6A07DFCA15973AEA4585B3E ft=1 fh=f0f94d3d453410fe vn="Win32/TrojanNotifier.Small.A trojan" ac=I fn="G:\System Volume Information\_restore{DBEF6E60-C5C5-47E2-8E78-49320D8CFCDD}\RP85\A0018861.dll" Results of screen317's Security Check version 0.99.81 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 12.0.0.77 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2014 02 Ran by Alexander (administrator) on SAUVIEH on 21-04-2014 10:12:26 Running from C:\Users\Alexander\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe (VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-19] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe HKU\S-1-5-21-2409692257-2134198246-3569125786-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD) HKU\S-1-5-21-2409692257-2134198246-3569125786-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6FFAA25E6C4DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default FF NewTab: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF Homepage: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\ich@maltegoetz.de [2014-04-18] FF Extension: NoScript - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30] FF Extension: Adblock Plus - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-30] FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-04-19] (Avira Operations GmbH & Co. KG) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-19] (Avira Operations GmbH & Co. KG) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-03-13] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-21] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R0 Pnp680r; C:\Windows\System32\DRIVERS\pnp680r.sys [125992 2007-07-24] (Silicon Image, Inc) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-21 10:12 - 2014-04-21 10:12 - 00000000 ____D () C:\Users\Alexander\Downloads\FRST-OlderVersion 2014-04-21 10:10 - 2014-04-21 10:10 - 00987448 _____ () C:\Users\Alexander\Downloads\SecurityCheck.exe 2014-04-21 09:06 - 2014-04-21 09:06 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-21 09:05 - 2014-04-21 09:05 - 02347384 _____ (ESET) C:\Users\Alexander\Downloads\esetsmartinstaller_enu.exe 2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt 2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe 2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe 2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log 2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe 2014-04-19 12:14 - 2014-04-21 09:04 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 12:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 12:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 12:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe 2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 12:12 - 2014-04-21 10:12 - 02056704 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe 2014-04-19 12:12 - 2014-04-21 10:12 - 00011377 _____ () C:\Users\Alexander\Downloads\FRST.txt 2014-04-19 12:12 - 2014-04-21 10:12 - 00000000 ____D () C:\FRST 2014-04-19 12:12 - 2014-04-19 12:13 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt 2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi 2014-04-19 10:14 - 2014-04-19 13:27 - 00000000 ____D () C:\AdwCleaner 2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe 2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results 2014-04-19 09:57 - 2014-04-21 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job 2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp 2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E} 2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe 2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment 2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-18 21:39 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-04-18 21:39 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-04-18 21:39 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-04-18 21:39 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo 2014-04-18 21:33 - 2014-04-18 21:34 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-04-18 21:33 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-18 21:33 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe 2014-04-18 21:25 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-18 21:25 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-18 21:25 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-18 21:25 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-18 21:25 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-18 21:25 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-18 21:25 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-18 21:25 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-18 21:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-18 21:25 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-18 21:25 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-18 21:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-18 21:25 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-18 21:25 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-18 21:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-18 21:25 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-18 21:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-18 21:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-18 21:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-18 21:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-18 21:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-18 21:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-18 21:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-18 21:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-18 21:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-18 21:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-18 21:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-18 21:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-18 21:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-18 21:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-18 21:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-18 21:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-18 21:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-18 21:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-18 21:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-18 21:25 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-18 21:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-18 21:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-18 21:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-18 21:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-18 21:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-18 21:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-18 21:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-18 21:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-18 21:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-18 21:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-18 21:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-18 21:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-18 21:25 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-18 21:25 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-18 21:25 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-04-18 21:25 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-04-18 21:25 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-18 21:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-04-18 21:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-04-18 21:25 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-18 21:25 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-04-18 21:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-04-18 21:25 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-04-18 21:25 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-18 21:25 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-04-18 21:25 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-04-18 21:25 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-04-18 21:25 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-04-18 21:25 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-04-18 21:25 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-04-18 21:25 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-04-18 21:25 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-04-18 21:25 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-04-18 21:25 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-04-18 21:25 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-04-18 21:25 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-04-18 21:25 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-04-18 21:25 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-04-18 21:25 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-04-18 21:25 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-04-18 21:25 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-04-18 21:25 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-04-18 21:25 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-04-18 21:25 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-04-18 21:25 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-04-18 21:25 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-04-18 21:25 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-04-18 21:25 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-04-18 21:25 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-04-18 21:25 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-04-18 21:25 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-04-18 21:25 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-04-18 21:25 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-04-18 21:25 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-04-18 21:25 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-04-18 21:25 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-04-18 21:25 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-04-18 21:25 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-04-18 21:25 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-04-18 21:25 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-04-18 21:25 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-04-18 21:25 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys ==================== One Month Modified Files and Folders ======= 2014-04-21 10:12 - 2014-04-21 10:12 - 00000000 ____D () C:\Users\Alexander\Downloads\FRST-OlderVersion 2014-04-21 10:12 - 2014-04-19 12:12 - 02056704 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe 2014-04-21 10:12 - 2014-04-19 12:12 - 00011377 _____ () C:\Users\Alexander\Downloads\FRST.txt 2014-04-21 10:12 - 2014-04-19 12:12 - 00000000 ____D () C:\FRST 2014-04-21 10:10 - 2014-04-21 10:10 - 00987448 _____ () C:\Users\Alexander\Downloads\SecurityCheck.exe 2014-04-21 10:07 - 2013-01-07 23:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-21 09:57 - 2014-04-19 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job 2014-04-21 09:11 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-21 09:11 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-21 09:10 - 2012-12-09 20:35 - 01469273 _____ () C:\Windows\WindowsUpdate.log 2014-04-21 09:10 - 2009-07-14 19:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-21 09:10 - 2009-07-14 19:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-21 09:10 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-21 09:06 - 2014-04-21 09:06 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-21 09:05 - 2014-04-21 09:05 - 02347384 _____ (ESET) C:\Users\Alexander\Downloads\esetsmartinstaller_enu.exe 2014-04-21 09:04 - 2014-04-19 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-21 09:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-21 09:04 - 2009-07-14 06:51 - 00046819 _____ () C:\Windows\setupact.log 2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt 2014-04-19 13:27 - 2014-04-19 10:14 - 00000000 ____D () C:\AdwCleaner 2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe 2014-04-19 13:21 - 2012-12-31 21:16 - 00238656 _____ () C:\Windows\PFRO.log 2014-04-19 12:55 - 2013-06-30 11:49 - 00001243 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\DVDVideoSoft 2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe 2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log 2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe 2014-04-19 12:22 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-04-19 12:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe 2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 12:13 - 2014-04-19 12:12 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt 2014-04-19 11:49 - 2013-07-08 15:59 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\vlc 2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi 2014-04-19 11:38 - 2013-04-04 12:21 - 00000000 ____D () C:\Windows\rescache 2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe 2014-04-19 10:07 - 2013-01-07 23:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-19 10:07 - 2013-01-07 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-19 10:07 - 2013-01-07 23:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results 2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results 2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp 2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E} 2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe 2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-04-19 09:47 - 2013-07-12 13:51 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-04-19 09:47 - 2013-06-30 12:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-04-19 09:46 - 2013-06-30 12:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-04-19 09:46 - 2013-06-30 12:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-04-19 09:45 - 2013-12-27 11:39 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\dvdcss 2014-04-19 09:43 - 2013-06-30 12:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-19 00:22 - 2013-03-04 23:08 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment 2014-04-18 23:00 - 2013-04-04 18:26 - 00000000 ____D () C:\Users\Alexander\Documents\StarCraft II 2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-18 21:43 - 2009-07-14 06:45 - 00342952 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-18 21:39 - 2013-07-08 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo 2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo 2014-04-18 21:34 - 2014-04-18 21:33 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-04-18 21:34 - 2013-11-30 20:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe 2014-04-18 21:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-03 09:51 - 2014-04-19 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-19 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-19 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:51 - 2013-04-04 08:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Alexander\AppData\Local\Temp\avgnt.exe C:\Users\Alexander\AppData\Local\Temp\BackupSetup.exe C:\Users\Alexander\AppData\Local\Temp\ICReinstall_COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe C:\Users\Alexander\AppData\Local\Temp\ICReinstall_FreeStudio.exe C:\Users\Alexander\AppData\Local\Temp\MP3_German_Launcher_1_27_0_0.exe C:\Users\Alexander\AppData\Local\Temp\MP3_German_Patch_Update_1_0_0_78.exe C:\Users\Alexander\AppData\Local\Temp\ose00000.exe C:\Users\Alexander\AppData\Local\Temp\uninst1.exe C:\Users\Alexander\AppData\Local\Temp\vcredist_x64.exe C:\Users\Alexander\AppData\Local\Temp\_isABF7.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 11:31 ==================== End Of Log ============================ Nach diesen Schritten, habe ich doch lediglich gescannt und nichts gelöscht. Warum sollte ich beim ersten Tool nicht die gefundenen Threads löschen? Probleme bestehen weiterhin! Meine Liste der installierten Programme ist immer noch unvollständig. Es dankt der Spender |
21.04.2014, 20:54 | #6 |
/// the machine /// TB-Ausbilder | Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden Zeigt der CCleaner alle Programme an? Das Probem mit der Uninstall Liste lässt sich auch nicht mehr beheben. Das wurde von Adware zerstört. Funde von ESET sind nur Temps und SWH, bereinigen wir jetzt. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden |
22.04.2014, 12:41 | #7 |
| Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden Im CCleaner werden mir mehr Programme angezeigt als in der Systemsteuerung von Win7, aber auch nicht alle installierten Programme angezeigt. Alle Aktionen, die ich noch durchführen kann, führen ja nicht mehr zu einer intakten Ansicht oder? Also Neuinstallation! Es dankt der SPender |
22.04.2014, 19:07 | #8 |
/// the machine /// TB-Ausbilder | Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden Wenn Dich das stört dann ja. Es wird zwar aktuell daran gearbeitet, ob man da irgend nen Tool bauen kann welches das wiederherstellt, aber im Moment ist es leider so.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.04.2014, 20:52 | #9 |
| Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden WAs heißt "stören" ich würde ja vielleicht auch gerne mal wieder Programme deinstallieren, weil meine SSDHDD nicht unendlich groß ist. Ja aber nach den Tools die drüber gerannt sind, ist so weit wieder alles Roger... mal schauen. Trotzdem Danke |
24.04.2014, 12:34 | #10 |
/// the machine /// TB-Ausbilder | Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden |
.dll, adobe flash player, browser, explorer, flash player, installation, neu, newtab, pup.optional.babylon.a, pup.optional.conduit.a, pup.optional.delta, pup.optional.searchprotect.a, pup.optional.vbates, pup.optional.vbateshelper.a, registry, services.exe, super, svchost.exe, vcredist, warum, win32/adware.agent.nmz, win32/speedingupmypc.i, win32/trojannotifier.small.a, windows, winlogon.exe |