|
Plagegeister aller Art und deren Bekämpfung: Pricechopper Chrome erweiterung entfernen!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.07.2014, 15:14 | #16 |
| Pricechopper Chrome erweiterung entfernen! been there, done that keine Probleme mehr. Danke nochmals! Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-07-2014 Ran by HRMN at 2014-07-21 16:05:20 Run:2 Running from C:\Users\HRMN\Downloads\Virus-Exterminationsprogramme Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ZeroAccess: C:\Windows\Installer\{9c0559ee-654a-5c64-df40-86d725681a93} C:\Windows\Installer\{9c0559ee-654a-5c64-df40-86d725681a93}\@ C:\Windows\Installer\{9c0559ee-654a-5c64-df40-86d725681a93}\L\00000004.@ ***************** HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IsMyWinLockerReboot => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. ZeroAccess: => Error: No automatic fix found for this entry. C:\Windows\Installer\{9c0559ee-654a-5c64-df40-86d725681a93} => Moved successfully. "C:\Windows\Installer\{9c0559ee-654a-5c64-df40-86d725681a93}\@" => File/Directory not found. "C:\Windows\Installer\{9c0559ee-654a-5c64-df40-86d725681a93}\L\00000004.@" => File/Directory not found. The system needed a reboot. ==== End of Fixlog ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014 Ran by HRMN (administrator) on HRMN-PC on 21-07-2014 16:14:54 Running from C:\Users\HRMN\Downloads\Virus-Exterminationsprogramme Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Users\HRMN\Downloads\Core Temp.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Microsoft Corporation) C:\Program Files\Microsoft Device Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Device Center\ipoint.exe () C:\Program Files (x86)\RocketDock\RocketDock.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Google Inc.) C:\Users\HRMN\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor) HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated) HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Device Center\itype.exe [1464928 2012-06-26] (Microsoft Corporation) HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Device Center\ipoint.exe [2004584 2012-06-26] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.) HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [179272 2012-04-26] (CyberLink Corp.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2691480 2014-03-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-06-27] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2792858974-2978467211-3077806040-1002\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-2792858974-2978467211-3077806040-1002\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-12-11] (Samsung) HKU\S-1-5-21-2792858974-2978467211-3077806040-1002\...\Run: [icq] => C:\Users\HRMN\AppData\Roaming\ICQM\icq.exe [34848264 2014-07-02] (ICQ) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [166568 2014-06-13] (NVIDIA Corporation) AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-06-13] (NVIDIA Corporation) AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll => c:\Windows\SysWOW64\nvinit.dll [146480 2014-06-13] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [146480 2014-06-13] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\HRMN\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\HRMN\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-08-28] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-07-27] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-14] CHR Extension: (Google Drive) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-26] CHR Extension: (YouTube) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-26] CHR Extension: (Adblock Plus) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-14] CHR Extension: (Google-Suche) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-26] CHR Extension: (avast! Ad Blocker) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplhdcjmbpfkejbhngmlngaecbjmoimd [2013-08-26] CHR Extension: (avast! Online Security) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-07-14] CHR Extension: (Google Wallet) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31] CHR Extension: (Google Mail) - C:\Users\HRMN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-14] CHR HKLM-x32\...\Chrome\Extension: [fplhdcjmbpfkejbhngmlngaecbjmoimd] - C:\Program Files\AVAST Software\Avast\AdBlocker\Chrome\avast-adblocker-chrome.crx [2013-07-27] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-27] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-27] (AVAST Software) R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [239680 2014-02-19] (Foxit Corporation) S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-17] (WildTangent) R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed] S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] () [File not signed] S2 libusbd; C:\Windows\SysWOW64\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5132656 2013-11-25] (INCA Internet Co., Ltd.) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-27] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-27] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-27] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-27] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-06-27] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-05] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2014-01-22] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-06-27] () S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] () S3 hipeer20; C:\Windows\System32\DRIVERS\remobo64.sys [30720 2010-08-01] (Windows (R) Codename Longhorn DDK provider) S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [File not signed] S3 libusb0; C:\Windows\SysWOW64\drivers\libusb0.sys [33792 2005-03-09] () [File not signed] R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 ALSysIO; \??\C:\Users\HRMN\AppData\Local\Temp\ALSysIO64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X] S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-21 13:40 - 2014-07-21 13:40 - 00002890 _____ () C:\Windows\System32\Tasks\{F72EE0A3-BA8C-457B-B3B1-3E5757BAC5DD} 2014-07-21 13:40 - 2014-07-21 13:40 - 00002890 _____ () C:\Windows\System32\Tasks\{13D55962-66D6-4DEC-BB2A-C5FD07188E21} 2014-07-15 22:48 - 2014-07-15 22:48 - 00000624 _____ () C:\Users\HRMN\Desktop\JRT.txt 2014-07-15 22:32 - 2014-07-15 22:58 - 00117746 _____ () C:\Users\HRMN\Desktop\Virenboard.txt 2014-07-15 22:28 - 2014-07-15 22:28 - 00001158 _____ () C:\MBAM.txt 2014-07-14 19:48 - 2014-07-14 19:48 - 00050223 _____ () C:\ComboFix.txt 2014-07-14 19:28 - 2014-07-14 19:49 - 00000000 ____D () C:\Qoobox 2014-07-14 19:28 - 2014-07-14 19:49 - 00000000 ____D () C:\ComboFix 2014-07-14 19:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-14 19:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-14 19:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-14 19:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-14 19:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-14 19:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-14 19:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-14 19:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-14 19:27 - 2014-07-14 19:47 - 00000000 ____D () C:\Windows\erdnt 2014-07-14 00:15 - 2014-07-14 00:15 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\HRMN\Downloads\tdsskiller.exe 2014-07-12 21:20 - 2014-07-12 21:21 - 02084864 _____ (Farbar) C:\Users\HRMN\Downloads\FRST64.exe 2014-07-12 20:27 - 2014-07-12 20:27 - 00369758 _____ () C:\Users\HRMN\Downloads\Mineshafter-launcher.jar 2014-07-12 19:20 - 2014-07-12 19:21 - 01285120 _____ () C:\Users\HRMN\Downloads\zoek.exe 2014-07-12 19:19 - 2014-07-14 19:27 - 05219590 ____R (Swearware) C:\Users\HRMN\Downloads\ComboFix.exe 2014-07-12 19:12 - 2014-07-12 19:12 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\HRMN\Downloads\revosetup95.exe 2014-07-12 19:12 - 2014-07-12 19:12 - 00001272 _____ () C:\Users\HRMN\Desktop\Revo Uninstaller.lnk 2014-07-12 19:12 - 2014-07-12 19:12 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-12 19:06 - 2014-07-12 19:06 - 01348263 _____ () C:\Users\HRMN\Downloads\adwcleaner_3.215 (1).exe 2014-07-12 18:53 - 2014-07-12 18:53 - 00000000 _____ () C:\autoexec.bat 2014-07-12 18:50 - 2014-07-12 18:52 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2014-07-12 17:55 - 2014-07-12 17:55 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\NVIDIA 2014-07-12 17:39 - 2014-07-12 17:39 - 01348263 _____ () C:\Users\HRMN\Downloads\adwcleaner_3.215.exe 2014-07-12 17:35 - 2014-07-12 17:35 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-07-12 17:35 - 2014-07-12 17:35 - 00000000 ____D () C:\Windows\system32\NV 2014-07-12 17:35 - 2014-07-12 17:35 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-12 17:34 - 2014-06-13 04:11 - 06783960 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-07-12 17:34 - 2014-06-13 04:11 - 03523360 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-07-12 17:34 - 2014-06-13 04:11 - 02560968 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-07-12 17:34 - 2014-06-13 04:11 - 01083736 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2014-07-12 17:34 - 2014-06-13 04:11 - 00933208 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-07-12 17:34 - 2014-06-13 04:11 - 00387528 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-07-12 17:34 - 2014-06-13 04:11 - 00067072 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2014-07-12 17:34 - 2014-06-13 04:11 - 00062808 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-07-12 17:34 - 2014-06-06 19:40 - 03802247 _____ () C:\Windows\system32\nvcoproc.bin 2014-07-12 17:33 - 2014-06-13 04:48 - 00075040 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-07-12 17:33 - 2014-06-13 04:48 - 00062920 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-07-12 17:20 - 2014-06-13 04:59 - 01890264 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434043.dll 2014-07-12 17:20 - 2014-06-13 04:59 - 01542088 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434043.dll 2014-07-12 17:20 - 2014-06-13 04:59 - 00026353 _____ () C:\Windows\system32\nvinfo.pb 2014-07-12 17:20 - 2014-06-13 04:48 - 13911928 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 13824408 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 11272544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 11211224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 04248520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 03989464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 00946120 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 00909256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 00902616 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-07-12 17:20 - 2014-06-13 04:48 - 00869336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-07-12 17:20 - 2014-06-13 04:47 - 31512352 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-07-12 17:20 - 2014-06-13 04:47 - 24198616 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-07-12 17:20 - 2014-06-13 04:47 - 18625768 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-07-12 17:20 - 2014-06-13 04:47 - 17553032 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-07-12 17:20 - 2014-06-13 04:47 - 16122344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-07-12 17:20 - 2014-06-13 04:47 - 14497528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-07-12 17:20 - 2014-06-13 04:47 - 12860888 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-07-12 17:20 - 2014-06-13 04:47 - 00033736 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2014-07-12 17:20 - 2014-06-13 04:46 - 22994392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 15294296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 02814120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 00965312 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 00846832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 00354016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 00166568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-07-12 17:20 - 2014-06-13 04:46 - 00146480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-07-12 17:20 - 2014-06-13 04:45 - 03196304 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-07-12 17:04 - 2014-07-12 17:49 - 00000000 ____D () C:\ProgramData\pReIIcEChop 2014-07-12 17:03 - 2014-07-21 16:06 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-07-12 17:03 - 2014-07-12 17:48 - 00000000 ____D () C:\ProgramData\e7e16098dd3a039c 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HRMN\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Gast 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Administrator 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\ProgramData\InstallMate 2014-07-12 15:58 - 2014-07-12 15:58 - 00067727 _____ () C:\Users\HRMN\Downloads\SEUS-v10.1-Ultra-DOF.zip 2014-07-12 15:53 - 2014-07-12 15:53 - 00067725 _____ () C:\Users\HRMN\Downloads\SEUS-v10.1-Ultra-Motion-Blur.zip 2014-07-12 14:59 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-12 14:59 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-12 14:59 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-12 14:59 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-12 14:59 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-12 14:59 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-12 14:59 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-12 14:59 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-12 14:59 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-12 14:59 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-12 14:59 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-12 14:59 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-12 14:59 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-12 14:59 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-12 14:59 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-12 14:59 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-12 14:59 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-12 14:59 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-12 14:59 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-12 14:59 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-12 14:59 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-12 14:59 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-12 14:59 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-12 14:59 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-12 14:59 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-12 14:59 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-12 14:59 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-12 14:59 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-12 14:59 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-12 14:59 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-12 14:59 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-12 14:59 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-12 14:59 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-12 14:59 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-12 14:59 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-12 14:59 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-12 14:59 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-12 14:59 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-12 14:59 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-12 14:59 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-12 14:59 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-12 14:59 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-12 14:59 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-12 14:59 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-12 14:59 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-12 14:59 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-12 14:59 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-12 14:59 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-12 14:59 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-12 14:59 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-12 14:59 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-12 14:59 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-12 14:59 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-12 14:59 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-12 14:59 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-12 14:59 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-12 14:59 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-12 14:59 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-12 14:59 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-12 14:59 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-12 14:59 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-12 14:59 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-12 14:59 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-12 14:59 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-07-12 14:59 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-07-12 14:59 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-07-12 14:59 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-07-12 14:59 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-07-12 14:59 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-07-12 14:59 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-07-12 14:59 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-07-12 14:59 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-07-12 14:59 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-07-12 14:59 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-07-12 14:59 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-07-12 14:59 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-07-12 14:59 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-07-12 14:59 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-12 14:58 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-12 14:58 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-07-12 14:58 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-07-06 18:02 - 2014-07-06 18:02 - 00003462 _____ () C:\Users\HRMN\Desktop\bewerbung fh .txt 2014-07-06 13:31 - 2014-07-06 13:31 - 05641981 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.21_A_A (1).zip 2014-07-06 13:31 - 2014-07-06 13:31 - 04194304 _____ () C:\Users\HRMN\Downloads\P5WE0116 (1) (1).bin 2014-07-06 13:30 - 2014-07-06 13:30 - 04194304 _____ () C:\Users\HRMN\Downloads\P5WE0116.bin 2014-07-06 13:30 - 2014-07-06 13:30 - 04194304 _____ () C:\Users\HRMN\Downloads\P5WE0116 (1).bin 2014-07-06 13:27 - 2014-07-06 13:27 - 05592309 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.16_A_A.zip 2014-07-06 13:27 - 2014-07-06 13:27 - 05591937 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.17_A_A.zip 2014-07-06 13:27 - 2014-07-06 13:27 - 00000000 ____D () C:\Users\HRMN\Downloads\BIOS_Acer_1.17_A_A 2014-07-06 13:27 - 2014-07-06 13:27 - 00000000 ____D () C:\Users\HRMN\Downloads\BIOS_Acer_1.16_A_A 2014-07-06 13:22 - 2014-07-06 13:22 - 00000000 ____D () C:\Users\HRMN\Downloads\BIOS_Acer_1.21_A_A 2014-07-06 13:19 - 2014-07-06 13:19 - 05641981 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.21_A_A.zip 2014-07-06 13:19 - 2014-07-06 13:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics 2014-07-06 13:19 - 2014-07-06 13:19 - 00000000 ____D () C:\Program Files (x86)\Renesas Electronics 2014-07-06 13:17 - 2014-07-06 13:17 - 00000000 ____D () C:\Users\HRMN\Downloads\USB 3.0_NEC_2.0.34.0_W7x64_A 2014-07-06 13:17 - 2014-07-06 13:17 - 00000000 ____D () C:\Users\HRMN\Downloads\MgmtEngine_Intel_7.0.0.1144_W7x64_A 2014-07-06 13:17 - 2014-07-06 13:17 - 00000000 ____D () C:\Intel 2014-07-06 13:16 - 2014-07-06 13:16 - 07077595 _____ () C:\Users\HRMN\Downloads\USB 3.0_NEC_2.0.34.0_W7x64_A.zip 2014-07-06 13:16 - 2014-07-06 13:16 - 04059518 _____ () C:\Users\HRMN\Downloads\MgmtEngine_Intel_7.0.0.1144_W7x64_A.zip 2014-07-03 23:06 - 2014-07-03 23:06 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-07-03 23:06 - 2014-07-03 23:06 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-07-03 23:06 - 2014-07-03 23:06 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-07-03 23:06 - 2014-07-03 23:06 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-07-02 23:58 - 2014-07-02 23:58 - 00854367 _____ () C:\Users\HRMN\Downloads\SecurityCheck.exe 2014-07-02 22:07 - 2014-07-02 23:14 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\TeamViewer 2014-07-02 22:07 - 2014-07-02 22:07 - 06253160 _____ (TeamViewer GmbH) C:\Users\HRMN\Downloads\TeamViewer_Setup_de-ckc.exe 2014-07-02 22:02 - 2014-07-02 22:02 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-02 21:37 - 2014-07-02 21:45 - 00009442 _____ () C:\Users\HRMN\Downloads\SystemLook.txt 2014-07-02 21:36 - 2014-07-02 21:36 - 00165376 _____ () C:\Users\HRMN\Downloads\SystemLook_x64.exe 2014-07-02 21:34 - 2014-07-02 21:36 - 00045912 _____ () C:\Users\HRMN\Downloads\Addition.txt 2014-07-02 21:33 - 2014-07-21 16:14 - 00000000 ____D () C:\FRST 2014-07-02 21:33 - 2014-07-02 21:36 - 00048799 _____ () C:\Users\HRMN\Downloads\FRST.txt 2014-07-02 21:11 - 2014-07-15 21:34 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-02 21:11 - 2014-07-02 21:11 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-02 21:11 - 2014-07-02 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-02 21:11 - 2014-07-02 21:11 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-02 21:11 - 2014-07-02 21:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-02 21:11 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-02 21:11 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-02 21:11 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-02 21:01 - 2014-07-02 21:01 - 00000000 ____D () C:\Windows\ERUNT 2014-07-02 20:59 - 2014-07-21 16:06 - 00004424 _____ () C:\Windows\setupact.log 2014-07-02 20:59 - 2014-07-02 20:59 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-02 20:58 - 2014-07-15 22:33 - 00005426 _____ () C:\Windows\PFRO.log 2014-07-02 20:58 - 2014-07-14 00:31 - 00459168 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-02 20:57 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-07-02 20:54 - 2014-07-21 16:14 - 00000000 ____D () C:\Users\HRMN\Downloads\Virus-Exterminationsprogramme 2014-07-02 20:44 - 2014-07-02 20:44 - 00102738 _____ () C:\Users\HRMN\Documents\2014_07_02.reg 2014-07-02 20:44 - 2014-07-02 20:44 - 00003924 _____ () C:\Users\HRMN\Documents\2014_07_03.reg 2014-07-02 18:21 - 2014-07-02 18:23 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\ICQ-Profile 2014-07-02 18:21 - 2014-07-02 18:21 - 00001802 _____ () C:\Users\HRMN\Desktop\ICQ.lnk 2014-07-02 18:21 - 2014-07-02 18:21 - 00001660 _____ () C:\Users\HRMN\AppData\Roaming\Microsoft\Windows\Start Menu\ICQ.lnk 2014-07-02 18:21 - 2014-07-02 18:21 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ 2014-07-02 18:21 - 2014-07-02 18:21 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\ICQM 2014-06-27 19:38 - 2014-06-27 19:38 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr ==================== One Month Modified Files and Folders ======= 2014-07-21 16:14 - 2014-07-02 21:33 - 00000000 ____D () C:\FRST 2014-07-21 16:14 - 2014-07-02 20:54 - 00000000 ____D () C:\Users\HRMN\Downloads\Virus-Exterminationsprogramme 2014-07-21 16:13 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-21 16:13 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-21 16:12 - 2012-06-07 19:39 - 00000000 ____D () C:\ProgramData\clear.fi 2014-07-21 16:06 - 2014-07-12 17:03 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-07-21 16:06 - 2014-07-02 20:59 - 00004424 _____ () C:\Windows\setupact.log 2014-07-21 16:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-21 16:05 - 2012-09-23 10:57 - 01665973 _____ () C:\Windows\WindowsUpdate.log 2014-07-21 16:05 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-07-21 15:06 - 2014-06-12 22:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-21 13:51 - 2012-08-22 20:27 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\foobar2000 2014-07-21 13:40 - 2014-07-21 13:40 - 00002890 _____ () C:\Windows\System32\Tasks\{F72EE0A3-BA8C-457B-B3B1-3E5757BAC5DD} 2014-07-21 13:40 - 2014-07-21 13:40 - 00002890 _____ () C:\Windows\System32\Tasks\{13D55962-66D6-4DEC-BB2A-C5FD07188E21} 2014-07-21 13:01 - 2011-12-03 12:08 - 00703230 _____ () C:\Windows\system32\perfh007.dat 2014-07-21 13:01 - 2011-12-03 12:08 - 00150838 _____ () C:\Windows\system32\perfc007.dat 2014-07-21 13:01 - 2009-07-14 07:13 - 01629508 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-20 23:49 - 2012-06-07 11:40 - 00000000 ____D () C:\Users\HRMN\AppData\Local\Adobe 2014-07-17 03:00 - 2010-11-21 09:17 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-15 22:58 - 2014-07-15 22:32 - 00117746 _____ () C:\Users\HRMN\Desktop\Virenboard.txt 2014-07-15 22:48 - 2014-07-15 22:48 - 00000624 _____ () C:\Users\HRMN\Desktop\JRT.txt 2014-07-15 22:33 - 2014-07-02 20:58 - 00005426 _____ () C:\Windows\PFRO.log 2014-07-15 22:32 - 2013-08-26 21:17 - 00000000 ____D () C:\AdwCleaner 2014-07-15 22:28 - 2014-07-15 22:28 - 00001158 _____ () C:\MBAM.txt 2014-07-15 21:34 - 2014-07-02 21:11 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-15 21:19 - 2013-07-27 15:19 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-07-14 20:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-07-14 19:49 - 2014-07-14 19:28 - 00000000 ____D () C:\Qoobox 2014-07-14 19:49 - 2014-07-14 19:28 - 00000000 ____D () C:\ComboFix 2014-07-14 19:49 - 2013-02-18 22:43 - 00000000 ____D () C:\Users\HRMN\AppData\Local\Apps\2.0 2014-07-14 19:49 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-07-14 19:48 - 2014-07-14 19:48 - 00050223 _____ () C:\ComboFix.txt 2014-07-14 19:47 - 2014-07-14 19:27 - 00000000 ____D () C:\Windows\erdnt 2014-07-14 19:42 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-07-14 19:27 - 2014-07-12 19:19 - 05219590 ____R (Swearware) C:\Users\HRMN\Downloads\ComboFix.exe 2014-07-14 01:30 - 2012-11-07 20:30 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\vlc 2014-07-14 00:31 - 2014-07-02 20:58 - 00459168 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-14 00:29 - 2014-05-10 14:41 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-14 00:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-07-14 00:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-07-14 00:28 - 2012-09-24 17:03 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-14 00:26 - 2013-09-19 06:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-14 00:23 - 2012-06-08 00:20 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-14 00:15 - 2014-07-14 00:15 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\HRMN\Downloads\tdsskiller.exe 2014-07-12 21:21 - 2014-07-12 21:20 - 02084864 _____ (Farbar) C:\Users\HRMN\Downloads\FRST64.exe 2014-07-12 20:41 - 2012-06-07 01:25 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\.minecraft 2014-07-12 20:27 - 2014-07-12 20:27 - 00369758 _____ () C:\Users\HRMN\Downloads\Mineshafter-launcher.jar 2014-07-12 20:23 - 2012-12-07 18:10 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\Skype 2014-07-12 19:21 - 2014-07-12 19:20 - 01285120 _____ () C:\Users\HRMN\Downloads\zoek.exe 2014-07-12 19:12 - 2014-07-12 19:12 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\HRMN\Downloads\revosetup95.exe 2014-07-12 19:12 - 2014-07-12 19:12 - 00001272 _____ () C:\Users\HRMN\Desktop\Revo Uninstaller.lnk 2014-07-12 19:12 - 2014-07-12 19:12 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-12 19:06 - 2014-07-12 19:06 - 01348263 _____ () C:\Users\HRMN\Downloads\adwcleaner_3.215 (1).exe 2014-07-12 18:53 - 2014-07-12 18:53 - 00000000 _____ () C:\autoexec.bat 2014-07-12 18:52 - 2014-07-12 18:50 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2014-07-12 18:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system 2014-07-12 17:55 - 2014-07-12 17:55 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\NVIDIA 2014-07-12 17:49 - 2014-07-12 17:04 - 00000000 ____D () C:\ProgramData\pReIIcEChop 2014-07-12 17:48 - 2014-07-12 17:03 - 00000000 ____D () C:\ProgramData\e7e16098dd3a039c 2014-07-12 17:39 - 2014-07-12 17:39 - 01348263 _____ () C:\Users\HRMN\Downloads\adwcleaner_3.215.exe 2014-07-12 17:35 - 2014-07-12 17:35 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-07-12 17:35 - 2014-07-12 17:35 - 00000000 ____D () C:\Windows\system32\NV 2014-07-12 17:35 - 2014-07-12 17:35 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-12 17:34 - 2011-12-03 03:20 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-07-12 17:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-07-12 17:33 - 2011-12-03 03:20 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-07-12 17:33 - 2011-12-03 03:20 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HRMN\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Gast 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\Users\Administrator 2014-07-12 17:03 - 2014-07-12 17:03 - 00000000 ____D () C:\ProgramData\InstallMate 2014-07-12 17:03 - 2012-06-06 20:13 - 00000000 ____D () C:\Users\HRMN\AppData\Local\Google 2014-07-12 17:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-07-12 16:02 - 2012-12-07 20:10 - 00000000 ____D () C:\Users\HRMN\Desktop\Mincraft sachen 2014-07-12 15:58 - 2014-07-12 15:58 - 00067727 _____ () C:\Users\HRMN\Downloads\SEUS-v10.1-Ultra-DOF.zip 2014-07-12 15:53 - 2014-07-12 15:53 - 00067725 _____ () C:\Users\HRMN\Downloads\SEUS-v10.1-Ultra-Motion-Blur.zip 2014-07-08 18:23 - 2014-05-23 22:01 - 00000000 ____D () C:\Program Files (x86)\CABAL Online (NA - Global) 2014-07-06 18:02 - 2014-07-06 18:02 - 00003462 _____ () C:\Users\HRMN\Desktop\bewerbung fh .txt 2014-07-06 16:42 - 2013-09-08 21:58 - 00118872 _____ () C:\Windows\system32\GDIPFONTCACHEV1.DAT 2014-07-06 13:31 - 2014-07-06 13:31 - 05641981 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.21_A_A (1).zip 2014-07-06 13:31 - 2014-07-06 13:31 - 04194304 _____ () C:\Users\HRMN\Downloads\P5WE0116 (1) (1).bin 2014-07-06 13:30 - 2014-07-06 13:30 - 04194304 _____ () C:\Users\HRMN\Downloads\P5WE0116.bin 2014-07-06 13:30 - 2014-07-06 13:30 - 04194304 _____ () C:\Users\HRMN\Downloads\P5WE0116 (1).bin 2014-07-06 13:27 - 2014-07-06 13:27 - 05592309 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.16_A_A.zip 2014-07-06 13:27 - 2014-07-06 13:27 - 05591937 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.17_A_A.zip 2014-07-06 13:27 - 2014-07-06 13:27 - 00000000 ____D () C:\Users\HRMN\Downloads\BIOS_Acer_1.17_A_A 2014-07-06 13:27 - 2014-07-06 13:27 - 00000000 ____D () C:\Users\HRMN\Downloads\BIOS_Acer_1.16_A_A 2014-07-06 13:22 - 2014-07-06 13:22 - 00000000 ____D () C:\Users\HRMN\Downloads\BIOS_Acer_1.21_A_A 2014-07-06 13:19 - 2014-07-06 13:19 - 05641981 _____ () C:\Users\HRMN\Downloads\BIOS_Acer_1.21_A_A.zip 2014-07-06 13:19 - 2014-07-06 13:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics 2014-07-06 13:19 - 2014-07-06 13:19 - 00000000 ____D () C:\Program Files (x86)\Renesas Electronics 2014-07-06 13:19 - 2011-10-14 05:15 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-06 13:17 - 2014-07-06 13:17 - 00000000 ____D () C:\Users\HRMN\Downloads\USB 3.0_NEC_2.0.34.0_W7x64_A 2014-07-06 13:17 - 2014-07-06 13:17 - 00000000 ____D () C:\Users\HRMN\Downloads\MgmtEngine_Intel_7.0.0.1144_W7x64_A 2014-07-06 13:17 - 2014-07-06 13:17 - 00000000 ____D () C:\Intel 2014-07-06 13:16 - 2014-07-06 13:16 - 07077595 _____ () C:\Users\HRMN\Downloads\USB 3.0_NEC_2.0.34.0_W7x64_A.zip 2014-07-06 13:16 - 2014-07-06 13:16 - 04059518 _____ () C:\Users\HRMN\Downloads\MgmtEngine_Intel_7.0.0.1144_W7x64_A.zip 2014-07-05 21:10 - 2013-07-27 15:20 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-07-03 23:06 - 2014-07-03 23:06 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-07-03 23:06 - 2014-07-03 23:06 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-07-03 23:06 - 2014-07-03 23:06 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-07-03 23:06 - 2014-07-03 23:06 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-07-03 23:06 - 2013-09-02 20:45 - 00000000 ____D () C:\Program Files (x86)\Java 2014-07-03 00:33 - 2013-07-26 21:21 - 00000000 ____D () C:\Users\HRMN\Desktop\X-GamingdotWS 2014-07-02 23:58 - 2014-07-02 23:58 - 00854367 _____ () C:\Users\HRMN\Downloads\SecurityCheck.exe 2014-07-02 23:14 - 2014-07-02 22:07 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\TeamViewer 2014-07-02 22:07 - 2014-07-02 22:07 - 06253160 _____ (TeamViewer GmbH) C:\Users\HRMN\Downloads\TeamViewer_Setup_de-ckc.exe 2014-07-02 22:02 - 2014-07-02 22:02 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-02 21:45 - 2014-07-02 21:37 - 00009442 _____ () C:\Users\HRMN\Downloads\SystemLook.txt 2014-07-02 21:36 - 2014-07-02 21:36 - 00165376 _____ () C:\Users\HRMN\Downloads\SystemLook_x64.exe 2014-07-02 21:36 - 2014-07-02 21:34 - 00045912 _____ () C:\Users\HRMN\Downloads\Addition.txt 2014-07-02 21:36 - 2014-07-02 21:33 - 00048799 _____ () C:\Users\HRMN\Downloads\FRST.txt 2014-07-02 21:11 - 2014-07-02 21:11 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-02 21:11 - 2014-07-02 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-02 21:11 - 2014-07-02 21:11 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-02 21:11 - 2014-07-02 21:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-02 21:01 - 2014-07-02 21:01 - 00000000 ____D () C:\Windows\ERUNT 2014-07-02 20:59 - 2014-07-02 20:59 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-02 20:59 - 2012-09-24 17:34 - 00118872 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2014-07-02 20:49 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-07-02 20:45 - 2012-06-22 11:52 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\Dev-Cpp 2014-07-02 20:45 - 2012-06-22 11:52 - 00000000 ____D () C:\Dev-Cpp 2014-07-02 20:44 - 2014-07-02 20:44 - 00102738 _____ () C:\Users\HRMN\Documents\2014_07_02.reg 2014-07-02 20:44 - 2014-07-02 20:44 - 00003924 _____ () C:\Users\HRMN\Documents\2014_07_03.reg 2014-07-02 20:31 - 2012-06-07 10:23 - 00001164 _____ () C:\Users\HRMN\Downloads\CoreTemp.ini 2014-07-02 18:23 - 2014-07-02 18:21 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\ICQ-Profile 2014-07-02 18:21 - 2014-07-02 18:21 - 00001802 _____ () C:\Users\HRMN\Desktop\ICQ.lnk 2014-07-02 18:21 - 2014-07-02 18:21 - 00001660 _____ () C:\Users\HRMN\AppData\Roaming\Microsoft\Windows\Start Menu\ICQ.lnk 2014-07-02 18:21 - 2014-07-02 18:21 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ 2014-07-02 18:21 - 2014-07-02 18:21 - 00000000 ____D () C:\Users\HRMN\AppData\Roaming\ICQM 2014-06-30 18:49 - 2014-04-29 22:13 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-06-30 18:49 - 2011-10-14 05:30 - 00000000 ____D () C:\ProgramData\Skype 2014-06-30 04:09 - 2014-07-12 14:59 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-30 04:04 - 2014-07-12 14:59 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-27 19:38 - 2014-06-27 19:38 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-06-27 19:38 - 2014-06-19 19:55 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-06-27 19:38 - 2014-03-15 13:27 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-06-27 19:38 - 2013-07-27 15:20 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2014-06-27 19:38 - 2013-07-27 15:20 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-06-27 19:38 - 2013-07-27 15:20 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-06-27 19:38 - 2013-07-27 15:20 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-06-27 19:38 - 2013-07-27 15:20 - 00001970 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-06-27 19:38 - 2013-07-27 15:19 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-06-27 19:38 - 2013-07-27 15:19 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys Files to move or delete: ==================== C:\Users\HRMN\IP_Log_Data.js C:\Users\HRMN\Network_Meter_Data.js Some content of TEMP: ==================== C:\Users\HRMN\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-18 05:40 ==================== End Of Log ============================ |
21.07.2014, 15:18 | #17 |
/// the machine /// TB-Ausbilder | Pricechopper Chrome erweiterung entfernen! Fertig
__________________Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
21.07.2014, 16:47 | #18 |
| Pricechopper Chrome erweiterung entfernen! Danke, hat sich alles erledigt, die Programme und Hilfen, die ich von dir bekommen habe behalte ich aber gerne auch. Man kann ja nie wissen, wann und wie sie einem zunutze sind
__________________Danke auch für die schnelle und ausführliche Hilfe! Ich bin echt begeistert von deiner Ausdauer Hoffe ich muss das nicht nochmal in Anspruch nehmen Du weißt schon, wegen den Viren, nicht wegen dir Ich freue mich echt über meinen Sauberen PC Auf ein andermal! LG HRMN |
22.07.2014, 10:53 | #19 |
/// the machine /// TB-Ausbilder | Pricechopper Chrome erweiterung entfernen! Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |