Alt 19.04.2014, 11:47   #1
Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden - Standard

Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

Hallo zusammen,

wie oben beschrieben habe ich SUPER2014 installiert, die Installation dann abgebrochen, da ich gesehen habe, was alles an Müll installiert wird. Leider hatte ich dann Programme wie V-bates und Search Protect installiert. Ebenfalls erscheinen nur noch 7 Programme in der Übersicht, die installiert sind, was definitiv zu wenif sind.
Systemwiederherstellung ist leider deaktiviert (warum auch immer).
Firefox hatte auch "conduit" als Standardsuche. Seit dem stürzt FF auch immer mal wieder ab.
Was tun sprach Zeus?
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Alexander on 19.04.2014 at 12:31:19,61

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ FireFox

Emptied folder: C:\Users\Alexander\AppData\Roaming\mozilla\firefox\profiles\y9w336l0.default\minidumps [3 files]

~~~ Event Viewer Logs were cleared

Scan was completed on 19.04.2014 at 12:35:33,29
End of JRT log

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by Alexander (administrator) on SAUVIEH on 19-04-2014 12:29:33
Running from C:\Users\Alexander\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-19] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6FFAA25E6C4DCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default
FF NewTab: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Homepage: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\ich@maltegoetz.de [2014-04-18]
FF Extension: NoScript - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30]
FF Extension: Adblock Plus - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-30]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-03-13] ()
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R0 Pnp680r; C:\Windows\System32\DRIVERS\pnp680r.sys [125992 2007-07-24] (Silicon Image, Inc)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-04-19 12:14 - 2014-04-19 12:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 12:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 12:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:12 - 2014-04-19 12:29 - 00011061 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-19 12:12 - 2014-04-19 12:29 - 00000000 ____D () C:\FRST
2014-04-19 12:12 - 2014-04-19 12:13 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 10:14 - 2014-04-19 12:08 - 00000000 ____D () C:\AdwCleaner
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-19 12:27 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:39 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-04-18 21:39 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:33 - 2014-04-18 21:34 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:33 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-18 21:33 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:25 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-18 21:25 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-18 21:25 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-18 21:25 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-18 21:25 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-18 21:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-18 21:25 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-18 21:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-18 21:25 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-18 21:25 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-18 21:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-18 21:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-18 21:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-18 21:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-18 21:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-18 21:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-18 21:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-18 21:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-18 21:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-18 21:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-18 21:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-18 21:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-18 21:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-18 21:25 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-18 21:25 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-18 21:25 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-18 21:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-04-18 21:25 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-04-18 21:25 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-18 21:25 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-04-18 21:25 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-04-18 21:25 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-04-18 21:25 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-04-18 21:25 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-04-18 21:25 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-04-18 21:25 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-04-18 21:25 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-04-18 21:25 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-04-18 21:25 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-04-18 21:25 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-04-18 21:25 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-04-18 21:25 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-04-18 21:25 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-04-18 21:25 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-04-18 21:25 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-04-18 21:25 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-04-18 21:25 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-04-18 21:25 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-04-18 21:25 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-04-19 12:29 - 2014-04-19 12:12 - 00011061 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-19 12:29 - 2014-04-19 12:12 - 00000000 ____D () C:\FRST
2014-04-19 12:29 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-19 12:29 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-19 12:27 - 2014-04-19 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-19 12:26 - 2009-07-14 19:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-04-19 12:26 - 2009-07-14 19:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-04-19 12:26 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-19 12:22 - 2014-04-19 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 12:22 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-04-19 12:21 - 2012-12-31 21:16 - 00212804 _____ () C:\Windows\PFRO.log
2014-04-19 12:21 - 2012-12-09 20:35 - 01392025 _____ () C:\Windows\WindowsUpdate.log
2014-04-19 12:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-19 12:21 - 2009-07-14 06:51 - 00046315 _____ () C:\Windows\setupact.log
2014-04-19 12:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:13 - 2014-04-19 12:12 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-19 12:08 - 2014-04-19 10:14 - 00000000 ____D () C:\AdwCleaner
2014-04-19 12:07 - 2013-01-07 23:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-19 11:49 - 2013-07-08 15:59 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\vlc
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 11:38 - 2013-04-04 12:21 - 00000000 ____D () C:\Windows\rescache
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-19 10:07 - 2013-01-07 23:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 09:47 - 2013-07-12 13:51 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-19 09:47 - 2013-06-30 12:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-19 09:45 - 2013-12-27 11:39 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\dvdcss
2014-04-19 09:43 - 2013-06-30 12:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-19 00:22 - 2013-03-04 23:08 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 23:00 - 2013-04-04 18:26 - 00000000 ____D () C:\Users\Alexander\Documents\StarCraft II
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:43 - 2009-07-14 06:45 - 00342952 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-18 21:39 - 2013-07-08 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:33 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:34 - 2013-11-30 20:21 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-03 09:51 - 2014-04-19 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-19 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-19 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:51 - 2013-04-04 08:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-04-19 11:31

==================== End Of Log ============================
--- --- ---

Sodele dann noch mal eine Log!

GMER Logfile:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-19 12:45:22
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.CXM0 59,63GB
Running: Gmer-19357.exe; Driver: C:\Users\ALEXAN~1\AppData\Local\Temp\pwtdypob.sys

---- User code sections - GMER 2.1 ----

.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                       0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                      00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                         0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                        00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                0000000075831465 2 bytes [83, 75]
.text  C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                               00000000758314bb 2 bytes [83, 75]
.text  ...                                                                                                                                                    * 2

---- EOF - GMER 2.1 ----
--- --- ---

Malwarebytes Anti-Malware

Scan Date: 19.04.2014
Scan Time: 12:19:36
Logfile: Malwarebytes_log.txt
Administrator: Yes

Malware Database: v2014.04.19.05
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Alexander

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 246406
Time Elapsed: 4 min, 25 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 7
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Quarantined, [68c9fb31621994a2e6609c7c7b8708f8],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\V-bates, Quarantined, [c071101c3a41c0761b50b0d047bb4db3],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\WOW6432NODE\V-bates, Quarantined, [ea47ae7e473480b6412acbb55aa8d32d],
PUP.Optional.VbatesHelper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\V-bates Updater, Quarantined, [3100f735d2a9d46294d4512f5ca6d927],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 11
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsn3FC1.exe, Quarantined, [63ced25a384320161f14e044f809758b],
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsn41E4.exe, Quarantined, [062bb874bdbe9d99052ef23226db669a],
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsn5568.exe, Quarantined, [ad84e943cead3bfb151e8b99996814ec],
PUP.Optional.SearchProtect.A, C:\Users\Alexander\AppData\Local\Temp\nsy5336.exe, Quarantined, [dd54ea42ed8e55e1f24153d1bf42d22e],
PUP.Optional.InstallMonetizer.A, C:\Users\Alexander\AppData\Local\Temp\is-NI1I5.tmp\sam__2268_il459.exe, Quarantined, [e74aea42f586bb7bbf47b0721de425db],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\BExternal.dll, Quarantined, [77ba68c4b4c7c57110cd130fec147987],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\ccp.exe, Quarantined, [ef42d25ade9daa8cc956d14dc33db54b],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\CrxInstaller.dll, Quarantined, [f14064c80b703bfb9455c94a5fa2a15f],
PUP.Optional.Delta, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\MyDeltaTB.exe, Quarantined, [ea4775b7c3b86ec87e5853b0e21f8977],
PUP.Optional.Babylon.A, C:\Users\Alexander\AppData\Local\Temp\E4020124-BAB0-7891-8633-EF2A5549B124\Latest\Setup.exe, Quarantined, [9e93e7454d2e94a224061d01d828c23e],
PUP.Optional.Conduit.A, C:\Users\Alexander\AppData\Local\Temp\nsy315F\SpSetup.exe, Quarantined, [76bb43e945361422f032011813eef60a],

Physical Sectors: 0
(No malicious items detected)

Wie mache ich so scrollbare Fenster ? So produziere ich ja ewig lange Einträge.

Ich dachte mir, bevor ich den Rechner neu aufsetzte, frag ich mal hier

Es dankt
der Spender

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

und ein frisches FRST log bitte.


Alt 19.04.2014, 12:15   #2
Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden - Standard

Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Alexander on 19.04.2014 at 13:29:35,70

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ Event Viewer Logs were cleared

Scan was completed on 19.04.2014 at 13:33:45,33
End of JRT log
AdwCleaner Logfile:
# AdwCleaner v3.024 - Bericht erstellt am 19/04/2014 um 13:27:45
# Aktualisiert 18/04/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Alexander - SAUVIEH
# Gestartet von : C:\Users\Alexander\Downloads\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****

***** [ Dateien / Ordner ] *****

Datei Gelöscht : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\gfklq0mm.default\user.js
Datei Gelöscht : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\user.js

***** [ Verknüpfungen ] *****

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKLM\Software\InstallCore

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16521

-\\ Mozilla Firefox v28.0 (de)

[ Datei : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\gfklq0mm.default\prefs.js ]

[ Datei : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\prefs.js ]


AdwCleaner[R0].txt - [5367 octets] - [19/04/2014 10:14:37]
AdwCleaner[R1].txt - [1039 octets] - [19/04/2014 12:08:09]
AdwCleaner[R2].txt - [2344 octets] - [19/04/2014 13:24:25]
AdwCleaner[S0].txt - [4854 octets] - [19/04/2014 10:14:55]
AdwCleaner[S1].txt - [1101 octets] - [19/04/2014 12:08:42]
AdwCleaner[S2].txt - [2201 octets] - [19/04/2014 13:27:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2261 octets] ##########

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by Alexander (administrator) on SAUVIEH on 19-04-2014 13:36:59
Running from C:\Users\Alexander\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Users\Alexander\Downloads\adwcleaner.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-19] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6FFAA25E6C4DCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default
FF NewTab: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Homepage: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\ich@maltegoetz.de [2014-04-18]
FF Extension: NoScript - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30]
FF Extension: Adblock Plus - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-30]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-03-13] ()
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R0 Pnp680r; C:\Windows\System32\DRIVERS\pnp680r.sys [125992 2007-07-24] (Silicon Image, Inc)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt
2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe
2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe
2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe
2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log
2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe
2014-04-19 12:14 - 2014-04-19 13:29 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 12:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 12:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:12 - 2014-04-19 13:36 - 00011365 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-19 12:12 - 2014-04-19 13:36 - 00000000 ____D () C:\FRST
2014-04-19 12:12 - 2014-04-19 12:13 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 10:14 - 2014-04-19 13:27 - 00000000 ____D () C:\AdwCleaner
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-19 13:28 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:39 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-04-18 21:39 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:33 - 2014-04-18 21:34 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:33 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-18 21:33 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:25 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-18 21:25 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-18 21:25 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-18 21:25 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-18 21:25 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-18 21:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-18 21:25 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-18 21:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-18 21:25 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-18 21:25 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-18 21:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-18 21:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-18 21:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-18 21:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-18 21:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-18 21:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-18 21:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-18 21:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-18 21:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-18 21:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-18 21:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-18 21:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-18 21:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-18 21:25 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-18 21:25 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-18 21:25 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-18 21:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-04-18 21:25 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-04-18 21:25 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-18 21:25 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-04-18 21:25 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-04-18 21:25 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-04-18 21:25 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-04-18 21:25 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-04-18 21:25 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-04-18 21:25 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-04-18 21:25 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-04-18 21:25 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-04-18 21:25 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-04-18 21:25 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-04-18 21:25 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-04-18 21:25 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-04-18 21:25 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-04-18 21:25 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-04-18 21:25 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-04-18 21:25 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-04-18 21:25 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-04-18 21:25 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-04-18 21:25 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-04-19 13:37 - 2014-04-19 12:12 - 00011365 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-19 13:36 - 2014-04-19 12:12 - 00000000 ____D () C:\FRST
2014-04-19 13:36 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-19 13:36 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-19 13:34 - 2009-07-14 19:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-04-19 13:34 - 2009-07-14 19:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-04-19 13:34 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt
2014-04-19 13:29 - 2014-04-19 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 13:28 - 2014-04-19 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-19 13:28 - 2012-12-09 20:35 - 01410901 _____ () C:\Windows\WindowsUpdate.log
2014-04-19 13:28 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-19 13:28 - 2009-07-14 06:51 - 00046427 _____ () C:\Windows\setupact.log
2014-04-19 13:27 - 2014-04-19 10:14 - 00000000 ____D () C:\AdwCleaner
2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe
2014-04-19 13:21 - 2012-12-31 21:16 - 00238656 _____ () C:\Windows\PFRO.log
2014-04-19 13:07 - 2013-01-07 23:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-19 12:55 - 2013-06-30 11:49 - 00001243 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\DVDVideoSoft
2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe
2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe
2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log
2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe
2014-04-19 12:22 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-04-19 12:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:13 - 2014-04-19 12:12 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 12:12 - 2014-04-19 12:12 - 02158592 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-19 11:49 - 2013-07-08 15:59 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\vlc
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 11:38 - 2013-04-04 12:21 - 00000000 ____D () C:\Windows\rescache
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-19 10:07 - 2013-01-07 23:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 09:47 - 2013-07-12 13:51 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-19 09:47 - 2013-06-30 12:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-19 09:45 - 2013-12-27 11:39 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\dvdcss
2014-04-19 09:43 - 2013-06-30 12:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-19 00:22 - 2013-03-04 23:08 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 23:00 - 2013-04-04 18:26 - 00000000 ____D () C:\Users\Alexander\Documents\StarCraft II
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:43 - 2009-07-14 06:45 - 00342952 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-18 21:39 - 2013-07-08 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:33 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:34 - 2013-11-30 20:21 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-03 09:51 - 2014-04-19 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-19 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-19 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:51 - 2013-04-04 08:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-04-19 11:31

==================== End Of Log ============================
--- --- ---

--- --- ---

und nu?
Es dankt
der SPender

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?

Alt 21.04.2014, 09:14   #5
Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden - Standard

Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=43121529290bb949b5cce2cfc8ccbda1
# engine=17964
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-21 08:04:21
# local_time=2014-04-21 10:04:21 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 24353885 149697311 0 0
# scanned=287386
# found=4
# cleaned=0
# scan_time=3404
sh=DD3B3E78A941CBAEF1F2A8E1ECC09843C1E2AF06 ft=1 fh=43333f9ad1e6939f vn="Win32/SpeedingUpMyPC.I application" ac=I fn="C:\Users\Alexander\AppData\Local\Temp\is1158881826\1895309_stp\OptimizerPro.exe"
sh=3C772095F8E5B8E8DC957090E4B5D7C5D3DC6922 ft=1 fh=185b18bd4d33e5b3 vn="a variant of Win32/Adware.Agent.NMZ application" ac=I fn="G:\System Volume Information\_restore{DBEF6E60-C5C5-47E2-8E78-49320D8CFCDD}\RP63\A0009078.exe"
sh=7A064A6070258754A2E7D1872478201CB1136257 ft=1 fh=fc3cceb629d45fe4 vn="a variant of Generik.GOVROCE trojan" ac=I fn="G:\System Volume Information\_restore{DBEF6E60-C5C5-47E2-8E78-49320D8CFCDD}\RP63\A0013931.EXE"
sh=291DFDBFDA6F9261B6A07DFCA15973AEA4585B3E ft=1 fh=f0f94d3d453410fe vn="Win32/TrojanNotifier.Small.A trojan" ac=I fn="G:\System Volume Information\_restore{DBEF6E60-C5C5-47E2-8E78-49320D8CFCDD}\RP85\A0018861.dll"

Results of screen317's Security Check version 0.99.81
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Adobe Flash Player
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2014 02
Ran by Alexander (administrator) on SAUVIEH on 21-04-2014 10:12:26
Running from C:\Users\Alexander\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-04-19] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD)
HKU\S-1-5-21-2409692257-2134198246-3569125786-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {398a9aeb-419d-11e2-8fd5-806e6f6e6963} - D:\Run.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6FFAA25E6C4DCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default
FF NewTab: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Homepage: hxxp://www.google.com/search?sourceid=navclient&hl=de&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\ich@maltegoetz.de [2014-04-18]
FF Extension: NoScript - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30]
FF Extension: Adblock Plus - C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\y9w336l0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-30]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-04-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-04-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-04-19] (Avira Operations GmbH & Co. KG)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-03-13] ()
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R0 Pnp680r; C:\Windows\System32\DRIVERS\pnp680r.sys [125992 2007-07-24] (Silicon Image, Inc)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-04-21 10:12 - 2014-04-21 10:12 - 00000000 ____D () C:\Users\Alexander\Downloads\FRST-OlderVersion
2014-04-21 10:10 - 2014-04-21 10:10 - 00987448 _____ () C:\Users\Alexander\Downloads\SecurityCheck.exe
2014-04-21 09:06 - 2014-04-21 09:06 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-21 09:05 - 2014-04-21 09:05 - 02347384 _____ (ESET) C:\Users\Alexander\Downloads\esetsmartinstaller_enu.exe
2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt
2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe
2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe
2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe
2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log
2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe
2014-04-19 12:14 - 2014-04-21 09:04 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 12:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 12:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:12 - 2014-04-21 10:12 - 02056704 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-19 12:12 - 2014-04-21 10:12 - 00011377 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-19 12:12 - 2014-04-21 10:12 - 00000000 ____D () C:\FRST
2014-04-19 12:12 - 2014-04-19 12:13 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 10:14 - 2014-04-19 13:27 - 00000000 ____D () C:\AdwCleaner
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-21 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:39 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-04-18 21:39 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-04-18 21:39 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:33 - 2014-04-18 21:34 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:33 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-18 21:33 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:25 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-18 21:25 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-18 21:25 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-18 21:25 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-18 21:25 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-18 21:25 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-18 21:25 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-18 21:25 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-18 21:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-18 21:25 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-18 21:25 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-18 21:25 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-18 21:25 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-18 21:25 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-18 21:25 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-18 21:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-18 21:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-18 21:25 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-18 21:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-18 21:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-18 21:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-18 21:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-18 21:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-18 21:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-18 21:25 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-18 21:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-18 21:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-18 21:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-18 21:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-18 21:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-18 21:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-18 21:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-18 21:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-18 21:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-18 21:25 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-18 21:25 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-18 21:25 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-04-18 21:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-04-18 21:25 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-18 21:25 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-18 21:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-04-18 21:25 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-04-18 21:25 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-18 21:25 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-04-18 21:25 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-04-18 21:25 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-04-18 21:25 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-04-18 21:25 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-04-18 21:25 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-04-18 21:25 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-04-18 21:25 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-04-18 21:25 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-04-18 21:25 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-04-18 21:25 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-04-18 21:25 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-04-18 21:25 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-04-18 21:25 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-04-18 21:25 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-04-18 21:25 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-04-18 21:25 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-04-18 21:25 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-04-18 21:25 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-04-18 21:25 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-04-18 21:25 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-04-18 21:25 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-04-18 21:25 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-04-18 21:25 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-04-18 21:25 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-04-18 21:25 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-04-18 21:25 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-04-18 21:25 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-04-18 21:25 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-04-21 10:12 - 2014-04-21 10:12 - 00000000 ____D () C:\Users\Alexander\Downloads\FRST-OlderVersion
2014-04-21 10:12 - 2014-04-19 12:12 - 02056704 _____ (Farbar) C:\Users\Alexander\Downloads\FRST64.exe
2014-04-21 10:12 - 2014-04-19 12:12 - 00011377 _____ () C:\Users\Alexander\Downloads\FRST.txt
2014-04-21 10:12 - 2014-04-19 12:12 - 00000000 ____D () C:\FRST
2014-04-21 10:10 - 2014-04-21 10:10 - 00987448 _____ () C:\Users\Alexander\Downloads\SecurityCheck.exe
2014-04-21 10:07 - 2013-01-07 23:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-21 09:57 - 2014-04-19 09:57 - 00000290 _____ () C:\Windows\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}.job
2014-04-21 09:11 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-21 09:11 - 2009-07-14 06:45 - 00015504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-21 09:10 - 2012-12-09 20:35 - 01469273 _____ () C:\Windows\WindowsUpdate.log
2014-04-21 09:10 - 2009-07-14 19:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-04-21 09:10 - 2009-07-14 19:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-04-21 09:10 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-21 09:06 - 2014-04-21 09:06 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-21 09:05 - 2014-04-21 09:05 - 02347384 _____ (ESET) C:\Users\Alexander\Downloads\esetsmartinstaller_enu.exe
2014-04-21 09:04 - 2014-04-19 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-21 09:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-21 09:04 - 2009-07-14 06:51 - 00046819 _____ () C:\Windows\setupact.log
2014-04-19 13:33 - 2014-04-19 13:33 - 00000629 _____ () C:\Users\Alexander\Desktop\JRT.txt
2014-04-19 13:27 - 2014-04-19 10:14 - 00000000 ____D () C:\AdwCleaner
2014-04-19 13:26 - 2014-04-19 13:26 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT(1).exe
2014-04-19 13:21 - 2012-12-31 21:16 - 00238656 _____ () C:\Windows\PFRO.log
2014-04-19 12:55 - 2013-06-30 11:49 - 00001243 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\DVDVideoSoft
2014-04-19 12:55 - 2013-06-30 11:49 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-04-19 12:53 - 2014-04-19 12:53 - 00636744 _____ () C:\Users\Alexander\Downloads\FreeStudio.exe
2014-04-19 12:49 - 2014-04-19 12:49 - 00710848 _____ ( ) C:\Users\Alexander\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe
2014-04-19 12:45 - 2014-04-19 12:45 - 00002546 _____ () C:\Users\Alexander\Desktop\Gmerlog.log
2014-04-19 12:41 - 2014-04-19 12:41 - 00380416 _____ () C:\Users\Alexander\Downloads\Gmer-19357.exe
2014-04-19 12:22 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-04-19 12:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-04-19 12:14 - 2014-04-19 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\mbam-setup-
2014-04-19 12:14 - 2014-04-19 12:14 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 12:14 - 2014-04-19 12:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-19 12:13 - 2014-04-19 12:13 - 01016261 _____ (Thisisu) C:\Users\Alexander\Downloads\JRT.exe
2014-04-19 12:13 - 2014-04-19 12:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 12:13 - 2014-04-19 12:12 - 00017202 _____ () C:\Users\Alexander\Downloads\Addition.txt
2014-04-19 11:49 - 2013-07-08 15:59 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\vlc
2014-04-19 11:42 - 2014-04-19 11:42 - 00683008 _____ () C:\Users\Alexander\Downloads\MicrosoftFixit50542.msi
2014-04-19 11:38 - 2013-04-04 12:21 - 00000000 ____D () C:\Windows\rescache
2014-04-19 10:14 - 2014-04-19 10:14 - 01258805 _____ () C:\Users\Alexander\Downloads\adwcleaner.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-19 10:07 - 2013-01-07 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-19 10:07 - 2013-01-07 23:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-19 09:58 - 2014-04-19 09:58 - 00001210 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.quick.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000324 _____ () C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 09:58 - 2014-04-19 09:58 - 00000000 _____ () C:\Users\Alexander\AppData\Roaming\aps.scan.results
2014-04-19 09:57 - 2014-04-19 09:57 - 01097384 _____ (AnyProtect.com) C:\Users\Alexander\AppData\Local\nsy8E07.tmp
2014-04-19 09:57 - 2014-04-19 09:57 - 00003258 _____ () C:\Windows\System32\Tasks\FF Watcher {F884485B-E130-4387-8E45-8DFB9BD9A24E}
2014-04-19 09:55 - 2014-04-19 09:55 - 67155686 _____ (eRightSoft ) C:\Users\Alexander\Downloads\SUPERsetup.exe
2014-04-19 09:48 - 2014-04-19 09:48 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-19 09:47 - 2013-07-12 13:51 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-19 09:47 - 2013-06-30 12:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-19 09:46 - 2013-06-30 12:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-19 09:45 - 2013-12-27 11:39 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\dvdcss
2014-04-19 09:43 - 2013-06-30 12:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-19 00:22 - 2013-03-04 23:08 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-04-19 00:21 - 2014-04-19 00:21 - 00000000 ____D () C:\Users\Alexander\AppData\Local\Blizzard Entertainment
2014-04-18 23:00 - 2013-04-04 18:26 - 00000000 ____D () C:\Users\Alexander\Documents\StarCraft II
2014-04-18 22:28 - 2014-04-18 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-18 21:43 - 2009-07-14 06:45 - 00342952 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-18 21:39 - 2013-07-08 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-18 21:35 - 2014-04-18 21:35 - 00000000 ____D () C:\Users\Alexander\AppData\Roaming\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00001307 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Users\Alexander\AppData\Local\ashampoo
2014-04-18 21:34 - 2014-04-18 21:34 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-04-18 21:34 - 2014-04-18 21:33 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-18 21:34 - 2013-11-30 20:21 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-18 21:31 - 2014-04-18 21:31 - 92789928 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Alexander\Downloads\ashampoo_burning_studio_2014_12.0.5_15376.exe
2014-04-18 21:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-03 09:51 - 2014-04-19 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-19 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-19 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:51 - 2013-04-04 08:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-04-19 11:31

==================== End Of Log ============================
--- --- ---

Nach diesen Schritten, habe ich doch lediglich gescannt und nichts gelöscht. Warum sollte ich beim ersten Tool nicht die gefundenen Threads löschen?
Probleme bestehen weiterhin! Meine Liste der installierten Programme ist immer noch unvollständig.

Es dankt
der Spender

Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

Zeigt der CCleaner alle Programme an?

Das Probem mit der Uninstall Liste lässt sich auch nicht mehr beheben. Das wurde von Adware zerstört.

Funde von ESET sind nur Temps und SWH, bereinigen wir jetzt.

Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop.
Schließe nun alle offenen Programme und trenne Dich von dem Internet.
Doppelklick auf die TFC.exe und drücke auf Start.
Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen.


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.

Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.

Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.

Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.

Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.

Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.

Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )

  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
--> Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

Alt 22.04.2014, 12:41   #7
Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden - Standard

Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

Im CCleaner werden mir mehr Programme angezeigt als in der Systemsteuerung von Win7, aber auch nicht alle installierten Programme angezeigt.
Alle Aktionen, die ich noch durchführen kann, führen ja nicht mehr zu einer intakten Ansicht oder? Also Neuinstallation!

Es dankt
der SPender

Alt 23.04.2014, 20:52   #9
Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden - Standard

Nach Installation von SUPER2014 Programme aus Installationsübersicht verschwunden

WAs heißt "stören" ich würde ja vielleicht auch gerne mal wieder Programme deinstallieren, weil meine SSDHDD nicht unendlich groß ist.
Ja aber nach den Tools die drüber gerannt sind, ist so weit wieder alles Roger...
mal schauen.

