Plagegeister aller Art und deren Bekämpfung: Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert'
![]() | ![]() Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert' Hallihallo liebe Community, verzeiht mir bitte, wenn ich keine Fachbegriffe verwende und meine Erklärung etwas unbeholfen(und lang) rüberkommt. Also, mein Problem besteht darin, dass mein Desktop, nachdem ich mit Malwarebytes-Antimalware ein paar Trojaner/Viren gelöscht habe, irgendwie vergrößert ist, es sind jetzt zum Beispiel nur noch 8 Textdokumente in einer Zeile und es ist alles gequetscht(obwohl dort vorher ja immer 10-11 hingepasst haben...), auch im Internet. Der Laptop hat sich, nachdem er die Trojaner/Viren 'eliminiert' hat, automatisch heruntergefahren. Als ich ihn neu gestartet habe, ist es dann passiert... Ich habe schon verschiedene Auflösungen probiert -> kein Erfolg, mehrmals einen Neustart versucht(über 2 tage hinweg)-> auch kein Erfolg. Ich vermute, dass Malwarebytes irgendetwas versehentlich gelöscht hat, was nötig war, damit alles seine richtige Größe hat. Ich hoffe, ihr könnt mir helfen, da ich wirklich etwas am Verzweifeln bin. Wenn es euch weiterhilft, gebe ich euch noch ein paar Infos zu meinem Laptop. Also, ich besitze den alten Mac von meiner Mum(er ist jetzt bestimmt 6 Jahre alt, deswegen kann ich euch das Model nicht sagen) mit dem Betriebssystem von Windows 7. Ich habe eigentlich nur ein Programm, Paint.net, runtergeladen, aber ich denke nicht, dass es daran liegt. Ich bedanke mich jetzt schon mal, falls mir irgendwer helfen kann. Liebe Grüße, ChubbyBunny |
Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert'
hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() | ![]() Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert' Der FRST Log:
__________________FRST Logfile: Code:
Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert'
hi,

Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | ![]() Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert'Code:
Vor Suchlauf: 12 Verzeichnis(se), 107.985.862.656 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 108.349.394.944 Bytes frei . - - End Of File - - C1EF281B3C4F0EEB3E6C14B9AC845E88 A36C5E4F47E84449FF07ED3517B43A31 ![]() |
![]() | #6 |
Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert'

Downloade Dir bitte
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert' |
![]() | #7 |
![]() | ![]() Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert' hallihallo, hier sind die Logs ![]() Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Protection, 29.06.2014 18:24:49, SYSTEM, JOI-PC, Protection, Malware Protection, Starting, Protection, 29.06.2014 18:24:49, SYSTEM, JOI-PC, Protection, Malware Protection, Started, Protection, 29.06.2014 18:24:49, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Starting, Protection, 29.06.2014 18:24:49, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Started, Update, 29.06.2014 18:24:53, SYSTEM, JOI-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.6.23.2, Update, 29.06.2014 18:24:57, SYSTEM, JOI-PC, Manual, Malware Database, 2014.3.4.9, 2014.6.29.7, Protection, 29.06.2014 18:25:13, SYSTEM, JOI-PC, Protection, Refresh, Starting, Protection, 29.06.2014 18:25:13, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Stopping, Protection, 29.06.2014 18:25:14, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Stopped, Protection, 29.06.2014 18:25:19, SYSTEM, JOI-PC, Protection, Refresh, Success, Protection, 29.06.2014 18:25:19, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Starting, Protection, 29.06.2014 18:25:20, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Started, Protection, 29.06.2014 18:32:51, SYSTEM, JOI-PC, Protection, Malware Protection, Starting, Protection, 29.06.2014 18:32:51, SYSTEM, JOI-PC, Protection, Malware Protection, Started, Protection, 29.06.2014 18:32:51, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Starting, Protection, 29.06.2014 18:35:04, SYSTEM, JOI-PC, Protection, Malicious Website Protection, Started, (end) Code:
ATTFilter # AdwCleaner v3.213 - Bericht erstellt am 29/06/2014 um 18:42:57 # Aktualisiert 23/06/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : joi - JOI-PC # Gestartet von : C:\Users\joi\Downloads\adwcleaner_3.213 (1).exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : bupService ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\joi\AppData\Roaming\BupSystem Datei Gelöscht : C:\Users\joi\AppData\Roaming\Mozilla\Firefox\Profiles\aj3e2uwl.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Mozilla Firefox v29.0.1 (de) [ Datei : C:\Users\joi\AppData\Roaming\Mozilla\Firefox\Profiles\aj3e2uwl.default\prefs.js ] -\\ Google Chrome v35.0.1916.153 [ Datei : C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms} ************************* AdwCleaner[R0].txt - [1378 octets] - [29/06/2014 18:39:17] AdwCleaner[R1].txt - [1497 octets] - [29/06/2014 18:42:16] AdwCleaner[S0].txt - [319 octets] - [29/06/2014 18:41:18] AdwCleaner[S1].txt - [1372 octets] - [29/06/2014 18:42:57] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1432 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by joi on 29.06.2014 at 18:49:49,66 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ FireFox Successfully deleted: [Folder] C:\Users\joi\AppData\Roaming\mozilla\firefox\profiles\aj3e2uwl.default\extensions\staged ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.06.2014 at 18:58:23,35 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02 Ran by joi (administrator) on JOI-PC on 29-06-2014 19:01:24 Running from C:\Users\joi\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Windows\System32\AppleOSSMgr.exe (Apple Inc.) C:\Windows\System32\AppleTimeSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Apple Inc.) C:\Program Files\Boot Camp\Bootcamp.exe (Akamai Technologies, Inc.) C:\Users\joi\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\joi\AppData\Local\Akamai\netsession_win.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\joi\Downloads\FRST64 (2).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apple_KbdMgr] => C:\Program Files\Boot Camp\Bootcamp.exe [741760 2011-06-29] (Apple Inc.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-122941782-1223332903-279443231-1000\...\Run: [Akamai NetSession Interface] => C:\Users\joi\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD06CB812FD74CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=securitascout BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\joi\AppData\Roaming\Mozilla\Firefox\Profiles\aj3e2uwl.default FF Homepage: about:home|hxxp://www.giga.de/foto/ FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-21] CHR Extension: (Google Drive) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-21] CHR Extension: (YouTube) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-21] CHR Extension: (Google-Suche) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-21] CHR Extension: (Securita Scout) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfkilfadjoneaheacgmkahfgcjchkpad [2014-05-23] CHR Extension: (Google Wallet) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-21] CHR Extension: (Google Mail) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-21] ==================== Services (Whitelisted) ================= R2 AppleOSSMgr; C:\Windows\system32\AppleOSSMgr.exe [224640 2011-06-29] () S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-24] (BitRaider, LLC) R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] () R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] () ==================== Drivers (Whitelisted) ==================== R3 applemtm; C:\Windows\System32\DRIVERS\applemtm.sys [12288 2011-03-25] (Apple Inc.) R3 applemtp; C:\Windows\System32\DRIVERS\applemtp.sys [38912 2011-03-25] (Apple Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-29] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] U2 TMAgent; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-29 19:00 - 2014-06-29 19:01 - 02083328 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (2).exe 2014-06-29 18:59 - 2014-06-29 18:59 - 01073664 _____ (Farbar) C:\Users\joi\Downloads\FRST.exe 2014-06-29 18:58 - 2014-06-29 18:58 - 00000835 _____ () C:\Users\joi\Desktop\JRT.txt 2014-06-29 18:49 - 2014-06-29 18:49 - 00000000 ____D () C:\Windows\ERUNT 2014-06-29 18:48 - 2014-06-29 18:48 - 01016261 _____ (Thisisu) C:\Users\joi\Downloads\JRT.exe 2014-06-29 18:47 - 2014-06-29 18:47 - 00001516 _____ () C:\Users\joi\Desktop\AdwCleaner[S1].txt 2014-06-29 18:39 - 2014-06-29 18:43 - 00000000 ____D () C:\AdwCleaner 2014-06-29 18:39 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213.exe 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213 (1).exe 2014-06-29 18:37 - 2014-06-29 18:37 - 00001610 _____ () C:\Users\joi\Desktop\mbam.txt 2014-06-29 18:30 - 2014-06-29 18:30 - 00001148 _____ () C:\mbam.txt 2014-06-29 18:28 - 2014-06-29 18:28 - 00001175 _____ () C:\Malwarebytes Bedrohungssuchlauf.txt 2014-06-29 18:24 - 2014-06-29 18:46 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-29 18:24 - 2014-06-29 18:24 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-29 18:24 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-29 18:24 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-29 18:24 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-29 18:23 - 2014-06-29 18:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (2).exe 2014-06-28 19:34 - 2014-06-28 19:34 - 00019040 _____ () C:\ComboFix.txt 2014-06-28 19:24 - 2014-06-28 19:34 - 00000000 ____D () C:\Qoobox 2014-06-28 19:24 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-28 19:24 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-28 19:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-28 19:23 - 2014-06-28 19:33 - 00000000 ____D () C:\Windows\erdnt 2014-06-28 19:22 - 2014-06-28 19:22 - 05212118 ____R (Swearware) C:\Users\joi\Downloads\ComboFix.exe 2014-06-28 12:26 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-28 12:26 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-06-28 12:26 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-06-28 12:26 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-06-27 16:54 - 2014-06-27 16:55 - 00030016 _____ () C:\Users\joi\Downloads\Addition.txt 2014-06-27 16:52 - 2014-06-29 19:01 - 00008733 _____ () C:\Users\joi\Downloads\FRST.txt 2014-06-27 16:52 - 2014-06-29 19:01 - 00000000 ____D () C:\FRST 2014-06-27 16:51 - 2014-06-27 16:52 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (1).exe 2014-06-27 16:51 - 2014-06-27 16:51 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64.exe 2014-06-27 16:50 - 2014-06-27 16:50 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (5).exe 2014-06-27 16:47 - 2014-06-27 16:47 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (4).exe 2014-06-27 16:44 - 2014-06-27 16:44 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (3).exe 2014-06-27 16:43 - 2014-06-27 16:43 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (2).exe 2014-06-27 16:42 - 2014-06-27 16:42 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (1).exe 2014-06-27 16:22 - 2014-06-27 16:22 - 00001375 _____ () C:\Users\Public\Desktop\Installationsprogramm für Trend Micro Titanium Maximum Security.lnk 2014-06-27 16:18 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-06-27 16:18 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-06-27 16:18 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-06-27 16:18 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-06-27 16:18 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-06-27 16:18 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-06-27 16:18 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-06-27 16:18 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-06-27 16:18 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-06-27 16:18 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-06-27 16:18 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-06-27 16:18 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-06-27 16:18 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-06-27 16:18 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-06-27 16:18 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-06-27 16:18 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-06-27 16:17 - 2014-06-29 18:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-27 16:16 - 2014-06-29 18:32 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-27 16:16 - 2014-06-29 18:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-27 16:14 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-27 16:14 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-06-27 16:14 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-06-27 16:14 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-06-27 16:05 - 2014-06-27 16:05 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Vorlagen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Startmenü 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Netzwerkumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Lokale Einstellungen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Eigene Dateien 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Druckumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Musik 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Anwendungsdaten 2014-06-27 16:05 - 2014-05-20 17:14 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Microsoft Help 2014-06-27 16:05 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-27 16:05 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-06-27 15:51 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-06-27 15:51 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-06-27 15:51 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-06-27 15:51 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-06-26 21:45 - 2014-06-26 21:45 - 00234800 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup.exe 2014-06-26 20:41 - 2014-06-26 20:42 - 00010485 _____ () C:\Users\joi\Documents\Uninstall STAR WARS The Old Republic.log 2014-06-26 19:15 - 2014-06-26 19:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 19:12 - 2014-06-26 19:14 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- 2014-06-26 19:12 - 2014-06-26 19:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (1).exe 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-24 18:53 - 2014-06-26 20:41 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\joi\AppData\Local\SWTORPerf 2014-06-24 18:51 - 2014-06-24 18:51 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-24 18:51 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-06-24 18:51 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-06-24 18:50 - 2014-06-24 18:52 - 00014481 _____ () C:\Users\joi\Documents\Install STAR WARS The Old Republic.log 2014-06-24 18:50 - 2014-06-24 18:50 - 29720272 _____ () C:\Users\joi\Downloads\SWTOR_setup.exe 2014-06-24 17:38 - 2014-06-24 17:38 - 00003176 _____ () C:\Windows\System32\Tasks\{558CA202-CDCE-430A-B4F0-65F91E15263D} 2014-06-24 17:33 - 2014-06-24 17:33 - 43627880 _____ (NVIDIA Corporation ) C:\Users\joi\Downloads\15.35_nforce_win7_64bit_international_whql.exe 2014-06-24 17:33 - 2014-06-24 17:33 - 00000000 ____D () C:\NVIDIA 2014-06-24 17:33 - 2011-06-14 03:40 - 00660072 _____ (NVIDIA Corporation) C:\Windows\system32\NVUNINST.EXE 2014-06-17 13:20 - 2014-06-17 13:20 - 00052754 _____ () C:\Users\joi\Downloads\WhatsApp Chat mit Markus.txt 2014-06-14 14:32 - 2014-06-14 14:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2014-06-14 14:18 - 2014-06-14 14:18 - 00001308 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk 2014-06-14 14:18 - 2014-06-14 14:18 - 00001296 _____ () C:\Users\Public\Desktop\Paint.NET.lnk 2014-06-14 14:17 - 2014-06-14 14:18 - 00000000 ____D () C:\Program Files\Paint.NET 2014-06-14 14:16 - 2014-06-21 21:39 - 00000000 ____D () C:\Users\joi\AppData\Local\Paint.NET 2014-06-14 14:16 - 2014-06-14 14:16 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-06-14 14:14 - 2014-06-14 14:14 - 03739157 _____ () C:\Users\joi\Downloads\Paint.NET.3.5.11.Install.zip 2014-06-11 21:33 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 21:33 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-11 21:33 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 21:33 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-11 21:33 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-11 21:33 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-11 21:33 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-11 21:33 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 21:33 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-11 21:33 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-11 21:33 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-11 21:33 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-11 21:33 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-11 21:33 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-11 21:33 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-11 21:33 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-11 21:33 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-11 21:33 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 21:33 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-11 21:33 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 21:33 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-11 21:33 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-11 21:33 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-11 21:33 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-11 21:33 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-11 21:33 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-11 21:33 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-11 21:33 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-11 21:33 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 21:33 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-11 21:33 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 21:33 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-11 21:33 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 21:33 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-11 21:33 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 21:33 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-11 21:33 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-11 21:33 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-11 21:33 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-11 21:33 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-11 21:33 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-11 21:33 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-11 21:32 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 21:32 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 21:32 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 21:32 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-11 21:32 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 21:32 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 21:32 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-11 21:32 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-11 21:32 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 21:32 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-11 21:32 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 21:32 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-11 21:32 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 21:32 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-11 21:32 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-11 21:32 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-11 21:32 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-11 21:32 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 21:32 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 21:32 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-11 21:32 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-11 21:32 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-11 21:31 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-11 21:31 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 13:28 - 2014-06-04 13:28 - 05760976 _____ () C:\Users\joi\Downloads\Rappelz_de_Downloader.exe ==================== One Month Modified Files and Folders ======= 2014-06-29 19:01 - 2014-06-29 19:00 - 02083328 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (2).exe 2014-06-29 19:01 - 2014-06-27 16:52 - 00008733 _____ () C:\Users\joi\Downloads\FRST.txt 2014-06-29 19:01 - 2014-06-27 16:52 - 00000000 ____D () C:\FRST 2014-06-29 18:59 - 2014-06-29 18:59 - 01073664 _____ (Farbar) C:\Users\joi\Downloads\FRST.exe 2014-06-29 18:58 - 2014-06-29 18:58 - 00000835 _____ () C:\Users\joi\Desktop\JRT.txt 2014-06-29 18:52 - 2009-07-14 06:45 - 00015120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-29 18:52 - 2009-07-14 06:45 - 00015120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-29 18:49 - 2014-06-29 18:49 - 00000000 ____D () C:\Windows\ERUNT 2014-06-29 18:48 - 2014-06-29 18:48 - 01016261 _____ (Thisisu) C:\Users\joi\Downloads\JRT.exe 2014-06-29 18:47 - 2014-06-29 18:47 - 00001516 _____ () C:\Users\joi\Desktop\AdwCleaner[S1].txt 2014-06-29 18:46 - 2014-06-29 18:24 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-29 18:45 - 2014-05-21 16:05 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-29 18:44 - 2014-05-19 22:31 - 01377062 _____ () C:\Windows\PFRO.log 2014-06-29 18:44 - 2014-05-19 22:23 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-06-29 18:44 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-29 18:44 - 2009-07-14 06:51 - 00024347 _____ () C:\Windows\setupact.log 2014-06-29 18:43 - 2014-06-29 18:39 - 00000000 ____D () C:\AdwCleaner 2014-06-29 18:43 - 2014-05-19 19:57 - 01911354 _____ () C:\Windows\WindowsUpdate.log 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213.exe 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213 (1).exe 2014-06-29 18:37 - 2014-06-29 18:37 - 00001610 _____ () C:\Users\joi\Desktop\mbam.txt 2014-06-29 18:32 - 2014-06-27 16:16 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-29 18:32 - 2014-06-27 16:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-29 18:30 - 2014-06-29 18:30 - 00001148 _____ () C:\mbam.txt 2014-06-29 18:28 - 2014-06-29 18:28 - 00001175 _____ () C:\Malwarebytes Bedrohungssuchlauf.txt 2014-06-29 18:24 - 2014-06-29 18:24 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-29 18:23 - 2014-06-29 18:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (2).exe 2014-06-29 18:16 - 2014-05-21 16:05 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-29 18:14 - 2014-06-27 16:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-28 19:34 - 2014-06-28 19:34 - 00019040 _____ () C:\ComboFix.txt 2014-06-28 19:34 - 2014-06-28 19:24 - 00000000 ____D () C:\Qoobox 2014-06-28 19:34 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-06-28 19:33 - 2014-06-28 19:23 - 00000000 ____D () C:\Windows\erdnt 2014-06-28 19:32 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-28 19:22 - 2014-06-28 19:22 - 05212118 ____R (Swearware) C:\Users\joi\Downloads\ComboFix.exe 2014-06-28 19:19 - 2014-05-20 16:27 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-06-28 19:17 - 2014-05-20 16:27 - 00000000 ____D () C:\ProgramData\Trend Micro 2014-06-28 19:16 - 2014-05-20 16:29 - 00000000 ____D () C:\Users\joi\AppData\Local\Trend Micro 2014-06-27 16:55 - 2014-06-27 16:54 - 00030016 _____ () C:\Users\joi\Downloads\Addition.txt 2014-06-27 16:52 - 2014-06-27 16:51 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (1).exe 2014-06-27 16:51 - 2014-06-27 16:51 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64.exe 2014-06-27 16:50 - 2014-06-27 16:50 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (5).exe 2014-06-27 16:47 - 2014-06-27 16:47 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (4).exe 2014-06-27 16:44 - 2014-06-27 16:44 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (3).exe 2014-06-27 16:43 - 2014-06-27 16:43 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (2).exe 2014-06-27 16:42 - 2014-06-27 16:42 - 00226096 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup (1).exe 2014-06-27 16:32 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-27 16:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-06-27 16:22 - 2014-06-27 16:22 - 00001375 _____ () C:\Users\Public\Desktop\Installationsprogramm für Trend Micro Titanium Maximum Security.lnk 2014-06-27 16:14 - 2014-05-23 15:08 - 01592784 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-06-27 16:14 - 2009-07-14 19:58 - 00698926 _____ () C:\Windows\system32\perfh007.dat 2014-06-27 16:14 - 2009-07-14 19:58 - 00149034 _____ () C:\Windows\system32\perfc007.dat 2014-06-27 16:14 - 2009-07-14 07:13 - 01592784 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-27 16:05 - 2014-06-27 16:05 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Vorlagen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Startmenü 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Netzwerkumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Lokale Einstellungen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Eigene Dateien 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Druckumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Musik 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Anwendungsdaten 2014-06-27 16:05 - 2014-05-19 22:23 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-06-27 16:05 - 2014-05-19 22:22 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-06-27 16:04 - 2014-05-20 16:40 - 00000000 ____D () C:\temp 2014-06-26 21:45 - 2014-06-26 21:45 - 00234800 _____ (Fusion Install ) C:\Users\joi\Downloads\Setup.exe 2014-06-26 20:42 - 2014-06-26 20:41 - 00010485 _____ () C:\Users\joi\Documents\Uninstall STAR WARS The Old Republic.log 2014-06-26 20:41 - 2014-06-24 18:53 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-26 20:41 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-26 20:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Web 2014-06-26 19:15 - 2014-06-26 19:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 19:14 - 2014-06-26 19:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- 2014-06-26 19:13 - 2014-06-26 19:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (1).exe 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-25 18:58 - 2014-05-19 22:22 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\joi\AppData\Local\SWTORPerf 2014-06-24 18:52 - 2014-06-24 18:50 - 00014481 _____ () C:\Users\joi\Documents\Install STAR WARS The Old Republic.log 2014-06-24 18:51 - 2014-06-24 18:51 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-24 18:50 - 2014-06-24 18:50 - 29720272 _____ () C:\Users\joi\Downloads\SWTOR_setup.exe 2014-06-24 17:38 - 2014-06-24 17:38 - 00003176 _____ () C:\Windows\System32\Tasks\{558CA202-CDCE-430A-B4F0-65F91E15263D} 2014-06-24 17:33 - 2014-06-24 17:33 - 43627880 _____ (NVIDIA Corporation ) C:\Users\joi\Downloads\15.35_nforce_win7_64bit_international_whql.exe 2014-06-24 17:33 - 2014-06-24 17:33 - 00000000 ____D () C:\NVIDIA 2014-06-21 21:39 - 2014-06-14 14:16 - 00000000 ____D () C:\Users\joi\AppData\Local\Paint.NET 2014-06-17 13:20 - 2014-06-17 13:20 - 00052754 _____ () C:\Users\joi\Downloads\WhatsApp Chat mit Markus.txt 2014-06-14 14:32 - 2014-06-14 14:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2014-06-14 14:18 - 2014-06-14 14:18 - 00001308 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk 2014-06-14 14:18 - 2014-06-14 14:18 - 00001296 _____ () C:\Users\Public\Desktop\Paint.NET.lnk 2014-06-14 14:18 - 2014-06-14 14:17 - 00000000 ____D () C:\Program Files\Paint.NET 2014-06-14 14:16 - 2014-06-14 14:16 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-06-14 14:14 - 2014-06-14 14:14 - 03739157 _____ () C:\Users\joi\Downloads\Paint.NET.3.5.11.Install.zip 2014-06-13 22:21 - 2014-05-21 16:07 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-06-13 17:11 - 2014-05-21 16:05 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-13 17:11 - 2014-05-21 16:05 - 00003848 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-12 18:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-06-12 14:25 - 2014-05-22 13:00 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-12 14:23 - 2014-05-22 13:00 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-12 14:22 - 2014-05-20 10:19 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-12 14:20 - 2014-05-23 15:28 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-08 11:13 - 2014-06-11 21:31 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-11 21:31 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 13:28 - 2014-06-04 13:28 - 05760976 _____ () C:\Users\joi\Downloads\Rappelz_de_Downloader.exe 2014-05-30 12:21 - 2014-06-11 21:32 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-30 12:02 - 2014-06-11 21:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-30 12:02 - 2014-06-11 21:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-05-30 11:45 - 2014-06-11 21:33 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-30 11:39 - 2014-06-11 21:33 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-05-30 11:39 - 2014-06-11 21:32 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-30 11:38 - 2014-06-11 21:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-05-30 11:28 - 2014-06-11 21:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-30 11:27 - 2014-06-11 21:32 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-05-30 11:24 - 2014-06-11 21:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-30 11:21 - 2014-06-11 21:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-05-30 11:21 - 2014-06-11 21:32 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-30 11:20 - 2014-06-11 21:32 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-11 21:33 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-30 11:11 - 2014-06-11 21:32 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-05-30 11:08 - 2014-06-11 21:32 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-11 21:33 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-30 11:02 - 2014-06-11 21:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-30 10:55 - 2014-06-11 21:33 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-05-30 10:49 - 2014-06-11 21:32 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-05-30 10:46 - 2014-06-11 21:32 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-11 21:32 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-05-30 10:44 - 2014-06-11 21:32 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-11 21:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-05-30 10:42 - 2014-06-11 21:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-05-30 10:38 - 2014-06-11 21:33 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-11 21:33 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-05-30 10:34 - 2014-06-11 21:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-05-30 10:33 - 2014-06-11 21:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-05-30 10:30 - 2014-06-11 21:33 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-05-30 10:29 - 2014-06-11 21:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-30 10:28 - 2014-06-11 21:32 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-05-30 10:27 - 2014-06-11 21:33 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-05-30 10:24 - 2014-06-11 21:32 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-05-30 10:23 - 2014-06-11 21:33 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-11 21:33 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-05-30 10:10 - 2014-06-11 21:33 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-30 10:06 - 2014-06-11 21:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-05-30 10:04 - 2014-06-11 21:33 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-11 21:33 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-11 21:32 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-11 21:32 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-30 09:54 - 2014-06-11 21:33 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-05-30 09:50 - 2014-06-11 21:33 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-05-30 09:49 - 2014-06-11 21:33 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-11 21:32 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-11 21:33 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-11 21:33 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-11 21:32 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-11 21:33 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-11 21:32 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-11 21:32 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\joi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-04 13:21 ==================== End Of Log =========================== |
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
Hallo Schrauber! :3

Ich habe leider gerade totale Probleme mit Eset, deshalb werde ich es morgen noch einmal probieren und dir dann separat noch einmal schicken, aber hier sind erstmal die anderen
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Mozilla Firefox (29.0.1) Google Chrome 35.0.1916.114 Google Chrome 35.0.1916.153 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02 Ran by joi (administrator) on JOI-PC on 30-06-2014 18:54:24 Running from C:\Users\joi\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Windows\System32\AppleOSSMgr.exe (Apple Inc.) C:\Windows\System32\AppleTimeSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files\Boot Camp\Bootcamp.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Akamai Technologies, Inc.) C:\Users\joi\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\joi\AppData\Local\Akamai\netsession_win.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\joi\Downloads\FRST64 (3).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apple_KbdMgr] => C:\Program Files\Boot Camp\Bootcamp.exe [741760 2011-06-29] (Apple Inc.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-122941782-1223332903-279443231-1000\...\Run: [Akamai NetSession Interface] => C:\Users\joi\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD06CB812FD74CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=securitascout SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=securitascout BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\joi\AppData\Roaming\Mozilla\Firefox\Profiles\aj3e2uwl.default FF Homepage: about:home|hxxp://www.giga.de/foto/ FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-21] CHR Extension: (Google Drive) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-21] CHR Extension: (YouTube) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-21] CHR Extension: (Google-Suche) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-21] CHR Extension: (Securita Scout) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfkilfadjoneaheacgmkahfgcjchkpad [2014-05-23] CHR Extension: (Google Wallet) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-21] CHR Extension: (Google Mail) - C:\Users\joi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-21] ==================== Services (Whitelisted) ================= R2 AppleOSSMgr; C:\Windows\system32\AppleOSSMgr.exe [224640 2011-06-29] () S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-24] (BitRaider, LLC) R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] () R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] () ==================== Drivers (Whitelisted) ==================== R3 applemtm; C:\Windows\System32\DRIVERS\applemtm.sys [12288 2011-03-25] (Apple Inc.) R3 applemtp; C:\Windows\System32\DRIVERS\applemtp.sys [38912 2011-03-25] (Apple Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-30] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] U2 TMAgent; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-30 18:53 - 2014-06-30 18:53 - 02083328 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (3).exe 2014-06-30 18:52 - 2014-06-30 18:52 - 01073664 _____ (Farbar) C:\Users\joi\Downloads\FRST (1).exe 2014-06-30 18:47 - 2014-06-30 18:47 - 00000831 _____ () C:\Users\joi\Desktop\checkup.txt 2014-06-30 18:44 - 2014-06-30 18:44 - 00854367 _____ () C:\Users\joi\Downloads\SecurityCheck.exe 2014-06-30 14:58 - 2014-06-30 14:58 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-06-30 14:57 - 2014-06-30 14:57 - 02347384 _____ (ESET) C:\Users\joi\Downloads\esetsmartinstaller_deu.exe 2014-06-29 19:00 - 2014-06-29 19:01 - 02083328 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (2).exe 2014-06-29 18:59 - 2014-06-29 18:59 - 01073664 _____ (Farbar) C:\Users\joi\Downloads\FRST.exe 2014-06-29 18:58 - 2014-06-29 18:58 - 00000835 _____ () C:\Users\joi\Desktop\JRT.txt 2014-06-29 18:49 - 2014-06-29 18:49 - 00000000 ____D () C:\Windows\ERUNT 2014-06-29 18:48 - 2014-06-29 18:48 - 01016261 _____ (Thisisu) C:\Users\joi\Downloads\JRT.exe 2014-06-29 18:47 - 2014-06-29 18:47 - 00001516 _____ () C:\Users\joi\Desktop\AdwCleaner[S1].txt 2014-06-29 18:39 - 2014-06-29 18:43 - 00000000 ____D () C:\AdwCleaner 2014-06-29 18:39 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213.exe 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213 (1).exe 2014-06-29 18:37 - 2014-06-29 18:37 - 00001610 _____ () C:\Users\joi\Desktop\mbam.txt 2014-06-29 18:30 - 2014-06-29 18:30 - 00001148 _____ () C:\mbam.txt 2014-06-29 18:28 - 2014-06-29 18:28 - 00001175 _____ () C:\Malwarebytes Bedrohungssuchlauf.txt 2014-06-29 18:24 - 2014-06-30 18:10 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-29 18:24 - 2014-06-29 18:24 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-29 18:24 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-29 18:24 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-29 18:24 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-29 18:23 - 2014-06-29 18:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (2).exe 2014-06-28 19:34 - 2014-06-28 19:34 - 00019040 _____ () C:\ComboFix.txt 2014-06-28 19:24 - 2014-06-28 19:34 - 00000000 ____D () C:\Qoobox 2014-06-28 19:24 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-28 19:24 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-28 19:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-28 19:24 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-28 19:23 - 2014-06-28 19:33 - 00000000 ____D () C:\Windows\erdnt 2014-06-28 19:22 - 2014-06-28 19:22 - 05212118 ____R (Swearware) C:\Users\joi\Downloads\ComboFix.exe 2014-06-28 12:26 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-28 12:26 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-06-28 12:26 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-06-28 12:26 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-06-27 16:54 - 2014-06-27 16:55 - 00030016 _____ () C:\Users\joi\Downloads\Addition.txt 2014-06-27 16:52 - 2014-06-30 18:54 - 00009241 _____ () C:\Users\joi\Downloads\FRST.txt 2014-06-27 16:52 - 2014-06-30 18:54 - 00000000 ____D () C:\FRST 2014-06-27 16:51 - 2014-06-27 16:52 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (1).exe 2014-06-27 16:51 - 2014-06-27 16:51 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64.exe 2014-06-27 16:22 - 2014-06-27 16:22 - 00001375 _____ () C:\Users\Public\Desktop\Installationsprogramm für Trend Micro Titanium Maximum Security.lnk 2014-06-27 16:18 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-06-27 16:18 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-06-27 16:18 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-06-27 16:18 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-06-27 16:18 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-06-27 16:18 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-06-27 16:18 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-06-27 16:18 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-06-27 16:18 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-06-27 16:18 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-06-27 16:18 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-06-27 16:18 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-06-27 16:18 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-06-27 16:18 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-06-27 16:18 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-06-27 16:18 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-06-27 16:17 - 2014-06-29 18:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-27 16:16 - 2014-06-29 18:32 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-27 16:16 - 2014-06-29 18:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-27 16:14 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-27 16:14 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-06-27 16:14 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-06-27 16:14 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-06-27 16:05 - 2014-06-27 16:05 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Vorlagen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Startmenü 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Netzwerkumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Lokale Einstellungen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Eigene Dateien 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Druckumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Musik 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Anwendungsdaten 2014-06-27 16:05 - 2014-05-20 17:14 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Microsoft Help 2014-06-27 16:05 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-27 16:05 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-06-27 15:51 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-06-27 15:51 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-06-27 15:51 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-06-27 15:51 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-06-26 20:41 - 2014-06-26 20:42 - 00010485 _____ () C:\Users\joi\Documents\Uninstall STAR WARS The Old Republic.log 2014-06-26 19:15 - 2014-06-26 19:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 19:12 - 2014-06-26 19:14 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- 2014-06-26 19:12 - 2014-06-26 19:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (1).exe 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-24 18:53 - 2014-06-26 20:41 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\joi\AppData\Local\SWTORPerf 2014-06-24 18:51 - 2014-06-24 18:51 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-24 18:51 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-06-24 18:51 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-06-24 18:50 - 2014-06-24 18:52 - 00014481 _____ () C:\Users\joi\Documents\Install STAR WARS The Old Republic.log 2014-06-24 18:50 - 2014-06-24 18:50 - 29720272 _____ () C:\Users\joi\Downloads\SWTOR_setup.exe 2014-06-24 17:38 - 2014-06-24 17:38 - 00003176 _____ () C:\Windows\System32\Tasks\{558CA202-CDCE-430A-B4F0-65F91E15263D} 2014-06-24 17:33 - 2014-06-24 17:33 - 43627880 _____ (NVIDIA Corporation ) C:\Users\joi\Downloads\15.35_nforce_win7_64bit_international_whql.exe 2014-06-24 17:33 - 2014-06-24 17:33 - 00000000 ____D () C:\NVIDIA 2014-06-24 17:33 - 2011-06-14 03:40 - 00660072 _____ (NVIDIA Corporation) C:\Windows\system32\NVUNINST.EXE 2014-06-17 13:20 - 2014-06-17 13:20 - 00052754 _____ () C:\Users\joi\Downloads\WhatsApp Chat mit Markus.txt 2014-06-14 14:32 - 2014-06-14 14:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2014-06-14 14:18 - 2014-06-14 14:18 - 00001308 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk 2014-06-14 14:18 - 2014-06-14 14:18 - 00001296 _____ () C:\Users\Public\Desktop\Paint.NET.lnk 2014-06-14 14:17 - 2014-06-14 14:18 - 00000000 ____D () C:\Program Files\Paint.NET 2014-06-14 14:16 - 2014-06-21 21:39 - 00000000 ____D () C:\Users\joi\AppData\Local\Paint.NET 2014-06-14 14:16 - 2014-06-14 14:16 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-06-14 14:14 - 2014-06-14 14:14 - 03739157 _____ () C:\Users\joi\Downloads\Paint.NET.3.5.11.Install.zip 2014-06-11 21:33 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 21:33 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-11 21:33 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 21:33 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-11 21:33 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-11 21:33 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-11 21:33 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-11 21:33 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 21:33 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-11 21:33 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-11 21:33 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-11 21:33 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-11 21:33 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-11 21:33 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-11 21:33 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-11 21:33 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-11 21:33 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-11 21:33 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 21:33 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-11 21:33 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 21:33 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-11 21:33 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-11 21:33 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-11 21:33 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-11 21:33 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-11 21:33 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-11 21:33 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-11 21:33 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-11 21:33 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 21:33 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-11 21:33 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 21:33 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-11 21:33 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 21:33 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-11 21:33 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 21:33 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-11 21:33 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-11 21:33 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-11 21:33 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-11 21:33 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-11 21:33 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-11 21:33 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-11 21:32 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 21:32 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 21:32 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 21:32 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-11 21:32 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 21:32 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 21:32 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-11 21:32 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-11 21:32 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 21:32 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-11 21:32 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 21:32 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-11 21:32 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 21:32 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-11 21:32 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-11 21:32 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-11 21:32 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-11 21:32 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 21:32 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 21:32 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-11 21:32 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-11 21:32 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-11 21:31 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-11 21:31 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 13:28 - 2014-06-04 13:28 - 05760976 _____ () C:\Users\joi\Downloads\Rappelz_de_Downloader.exe ==================== One Month Modified Files and Folders ======= 2014-06-30 18:54 - 2014-06-27 16:52 - 00009241 _____ () C:\Users\joi\Downloads\FRST.txt 2014-06-30 18:54 - 2014-06-27 16:52 - 00000000 ____D () C:\FRST 2014-06-30 18:53 - 2014-06-30 18:53 - 02083328 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (3).exe 2014-06-30 18:52 - 2014-06-30 18:52 - 01073664 _____ (Farbar) C:\Users\joi\Downloads\FRST (1).exe 2014-06-30 18:47 - 2014-06-30 18:47 - 00000831 _____ () C:\Users\joi\Desktop\checkup.txt 2014-06-30 18:44 - 2014-06-30 18:44 - 00854367 _____ () C:\Users\joi\Downloads\SecurityCheck.exe 2014-06-30 18:16 - 2014-05-21 16:05 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-30 18:10 - 2014-06-29 18:24 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-30 17:55 - 2014-05-19 19:57 - 01929049 _____ () C:\Windows\WindowsUpdate.log 2014-06-30 17:16 - 2014-05-21 16:05 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-30 14:58 - 2014-06-30 14:58 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-06-30 14:57 - 2014-06-30 14:57 - 02347384 _____ (ESET) C:\Users\joi\Downloads\esetsmartinstaller_deu.exe 2014-06-30 14:42 - 2009-07-14 06:45 - 00015120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-30 14:42 - 2009-07-14 06:45 - 00015120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-30 14:33 - 2014-05-19 22:23 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-06-30 14:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-30 14:33 - 2009-07-14 06:51 - 00024403 _____ () C:\Windows\setupact.log 2014-06-29 19:01 - 2014-06-29 19:00 - 02083328 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (2).exe 2014-06-29 18:59 - 2014-06-29 18:59 - 01073664 _____ (Farbar) C:\Users\joi\Downloads\FRST.exe 2014-06-29 18:58 - 2014-06-29 18:58 - 00000835 _____ () C:\Users\joi\Desktop\JRT.txt 2014-06-29 18:49 - 2014-06-29 18:49 - 00000000 ____D () C:\Windows\ERUNT 2014-06-29 18:48 - 2014-06-29 18:48 - 01016261 _____ (Thisisu) C:\Users\joi\Downloads\JRT.exe 2014-06-29 18:47 - 2014-06-29 18:47 - 00001516 _____ () C:\Users\joi\Desktop\AdwCleaner[S1].txt 2014-06-29 18:44 - 2014-05-19 22:31 - 01377062 _____ () C:\Windows\PFRO.log 2014-06-29 18:43 - 2014-06-29 18:39 - 00000000 ____D () C:\AdwCleaner 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213.exe 2014-06-29 18:38 - 2014-06-29 18:38 - 01342659 _____ () C:\Users\joi\Downloads\adwcleaner_3.213 (1).exe 2014-06-29 18:37 - 2014-06-29 18:37 - 00001610 _____ () C:\Users\joi\Desktop\mbam.txt 2014-06-29 18:32 - 2014-06-27 16:16 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-29 18:32 - 2014-06-27 16:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-29 18:30 - 2014-06-29 18:30 - 00001148 _____ () C:\mbam.txt 2014-06-29 18:28 - 2014-06-29 18:28 - 00001175 _____ () C:\Malwarebytes Bedrohungssuchlauf.txt 2014-06-29 18:24 - 2014-06-29 18:24 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-29 18:24 - 2014-06-29 18:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-29 18:23 - 2014-06-29 18:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (2).exe 2014-06-29 18:14 - 2014-06-27 16:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-28 19:34 - 2014-06-28 19:34 - 00019040 _____ () C:\ComboFix.txt 2014-06-28 19:34 - 2014-06-28 19:24 - 00000000 ____D () C:\Qoobox 2014-06-28 19:34 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-06-28 19:33 - 2014-06-28 19:23 - 00000000 ____D () C:\Windows\erdnt 2014-06-28 19:32 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-28 19:22 - 2014-06-28 19:22 - 05212118 ____R (Swearware) C:\Users\joi\Downloads\ComboFix.exe 2014-06-28 19:19 - 2014-05-20 16:27 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-06-28 19:17 - 2014-05-20 16:27 - 00000000 ____D () C:\ProgramData\Trend Micro 2014-06-28 19:16 - 2014-05-20 16:29 - 00000000 ____D () C:\Users\joi\AppData\Local\Trend Micro 2014-06-27 16:55 - 2014-06-27 16:54 - 00030016 _____ () C:\Users\joi\Downloads\Addition.txt 2014-06-27 16:52 - 2014-06-27 16:51 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64 (1).exe 2014-06-27 16:51 - 2014-06-27 16:51 - 02082816 _____ (Farbar) C:\Users\joi\Downloads\FRST64.exe 2014-06-27 16:32 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-27 16:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-06-27 16:22 - 2014-06-27 16:22 - 00001375 _____ () C:\Users\Public\Desktop\Installationsprogramm für Trend Micro Titanium Maximum Security.lnk 2014-06-27 16:14 - 2014-05-23 15:08 - 01592784 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-06-27 16:14 - 2009-07-14 19:58 - 00698926 _____ () C:\Windows\system32\perfh007.dat 2014-06-27 16:14 - 2009-07-14 19:58 - 00149034 _____ () C:\Windows\system32\perfc007.dat 2014-06-27 16:14 - 2009-07-14 07:13 - 01592784 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-27 16:05 - 2014-06-27 16:05 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Vorlagen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Startmenü 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Netzwerkumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Lokale Einstellungen 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Eigene Dateien 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Druckumgebung 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Musik 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-06-27 16:05 - 2014-06-27 16:05 - 00000000 _SHDL () C:\Users\UpdatusUser\Anwendungsdaten 2014-06-27 16:05 - 2014-05-19 22:23 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-06-27 16:05 - 2014-05-19 22:22 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-06-27 16:04 - 2014-05-20 16:40 - 00000000 ____D () C:\temp 2014-06-26 20:42 - 2014-06-26 20:41 - 00010485 _____ () C:\Users\joi\Documents\Uninstall STAR WARS The Old Republic.log 2014-06-26 20:41 - 2014-06-24 18:53 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-26 20:41 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-26 20:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Web 2014-06-26 19:15 - 2014-06-26 19:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 19:14 - 2014-06-26 19:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- 2014-06-26 19:13 - 2014-06-26 19:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\joi\Downloads\mbam-setup- (1).exe 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-25 18:58 - 2014-06-25 18:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-25 18:58 - 2014-05-19 22:22 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-24 18:53 - 2014-06-24 18:53 - 00000000 ____D () C:\Users\joi\AppData\Local\SWTORPerf 2014-06-24 18:52 - 2014-06-24 18:50 - 00014481 _____ () C:\Users\joi\Documents\Install STAR WARS The Old Republic.log 2014-06-24 18:51 - 2014-06-24 18:51 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-24 18:50 - 2014-06-24 18:50 - 29720272 _____ () C:\Users\joi\Downloads\SWTOR_setup.exe 2014-06-24 17:38 - 2014-06-24 17:38 - 00003176 _____ () C:\Windows\System32\Tasks\{558CA202-CDCE-430A-B4F0-65F91E15263D} 2014-06-24 17:33 - 2014-06-24 17:33 - 43627880 _____ (NVIDIA Corporation ) C:\Users\joi\Downloads\15.35_nforce_win7_64bit_international_whql.exe 2014-06-24 17:33 - 2014-06-24 17:33 - 00000000 ____D () C:\NVIDIA 2014-06-21 21:39 - 2014-06-14 14:16 - 00000000 ____D () C:\Users\joi\AppData\Local\Paint.NET 2014-06-17 13:20 - 2014-06-17 13:20 - 00052754 _____ () C:\Users\joi\Downloads\WhatsApp Chat mit Markus.txt 2014-06-14 14:32 - 2014-06-14 14:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2014-06-14 14:18 - 2014-06-14 14:18 - 00001308 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk 2014-06-14 14:18 - 2014-06-14 14:18 - 00001296 _____ () C:\Users\Public\Desktop\Paint.NET.lnk 2014-06-14 14:18 - 2014-06-14 14:17 - 00000000 ____D () C:\Program Files\Paint.NET 2014-06-14 14:16 - 2014-06-14 14:16 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-06-14 14:14 - 2014-06-14 14:14 - 03739157 _____ () C:\Users\joi\Downloads\Paint.NET.3.5.11.Install.zip 2014-06-13 22:21 - 2014-05-21 16:07 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-06-13 17:11 - 2014-05-21 16:05 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-13 17:11 - 2014-05-21 16:05 - 00003848 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-12 18:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-06-12 14:25 - 2014-05-22 13:00 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-12 14:23 - 2014-05-22 13:00 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-12 14:22 - 2014-05-20 10:19 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-12 14:20 - 2014-05-23 15:28 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-08 11:13 - 2014-06-11 21:31 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-11 21:31 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 13:28 - 2014-06-04 13:28 - 05760976 _____ () C:\Users\joi\Downloads\Rappelz_de_Downloader.exe Some content of TEMP: ==================== C:\Users\joi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-04 13:21 ==================== End Of Log ============================ Liebe Grüße, Chubby |
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Sooo, ich habe es jetzt endlich geschafft, hier ist es:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=f8c7ea98661fb54f8c1d8e0bd152ec64 # engine=18950 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=false # utc_time=2014-06-30 04:28:51 # local_time=2014-06-30 06:28:51 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 86257 155775581 0 0 # scanned=668254 # found=9 # cleaned=9 # scan_time=12447 sh=7E1C53DDB00F2FA13F6F385018F8119E746968C8 ft=1 fh=b05143db5f027689 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQVFTST7\Firefox_-_CHIP-Downloader[1].exe" sh=A4C322553488752F871798C3FCE999058888921D ft=1 fh=3ff2da1cbca1e78e vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Harvest-Moon-DS--Die-Sonnenschein-Inseln-lnstall.exe" sh=4548D436F364196CC98207FA400F43DA93A76F1C ft=1 fh=f2357c10bca1e78e vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Harvest-Moon-DS-lnstall.exe" sh=09C20D58C0C53715E7C61944810B13B2DE069356 ft=1 fh=e3bff9a760c014e0 vn="Variante von Win32/AdWare.iBryte.AK Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Setup (1).exe" sh=09C20D58C0C53715E7C61944810B13B2DE069356 ft=1 fh=e3bff9a760c014e0 vn="Variante von Win32/AdWare.iBryte.AK Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Setup (2).exe" sh=09C20D58C0C53715E7C61944810B13B2DE069356 ft=1 fh=e3bff9a760c014e0 vn="Variante von Win32/AdWare.iBryte.AK Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Setup (3).exe" sh=09C20D58C0C53715E7C61944810B13B2DE069356 ft=1 fh=e3bff9a760c014e0 vn="Variante von Win32/AdWare.iBryte.AK Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Setup (4).exe" sh=09C20D58C0C53715E7C61944810B13B2DE069356 ft=1 fh=e3bff9a760c014e0 vn="Variante von Win32/AdWare.iBryte.AK Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Setup (5).exe" sh=ABA729C4DFFCF893FFFADF9C6F1156F9B7DF4576 ft=1 fh=5d8ae07881490e86 vn="Variante von Win32/AdWare.iBryte.AJ Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\joi\Downloads\Setup.exe" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=f8c7ea98661fb54f8c1d8e0bd152ec64 # engine=18953 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=false # utc_time=2014-07-01 09:59:40 # local_time=2014-07-01 11:59:40 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 61746 155838630 0 0 # scanned=669094 # found=0 # cleaned=0 # scan_time=61119 ESETSmartInstaller@High as downloader log: all ok |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert' Fertig ![]() Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun ![]() Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Hallihallo Schrauber,

ich scheine jetzt vor Allem gewarnt zu sein und sicher, was die Programme betrifft, zu sein. Nur ist mein Problem, dass alles vergrößert ist, ja noch immer da und ich leider auch jetzt noch nicht weiß, wie ich das beheben kann..

lg Chubby
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Nach Löschung 5 Trojaner/Viren, mit der Hilfe von Malwarebytes, ist alles 'vergrößert' Screenshot bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Guten Morgen Schrauber,

Ich hab die Screenshots jetzt eingefügt, und hoffe, dass ich's richtig gemacht habe^^
Beim Desktop sieht man, dass weniger Dateien Platz haben und auch im Internet muss ich oft den 'grauen Balken' nach rechts ziehen, um die ganze Seite zu sehen, obwohl ich ja nicht näher rangezoomt habe..

lg Chubby
