|
Plagegeister aller Art und deren Bekämpfung: Yourfile Downloader - Troyaner - wie entfernt man den Mist?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.08.2014, 07:06 | #16 |
/// TB-Ausbilder | Yourfile Downloader - Troyaner - wie entfernt man den Mist? Ok, sieht gut aus soweit. Wir machen mit ESET weiter, der braucht in der Regel etwas länger für den Suchlauf: ESET Online Scanner
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
19.08.2014, 21:51 | #17 |
| Yourfile Downloader - Troyaner - wie entfernt man den Mist?Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=bb795e8ec92fd448a26af18fbf307665 # engine=19638 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-13 07:50:25 # local_time=2014-08-13 09:50:25 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777214 100 100 12737691 273379115 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 6668 159589275 0 0 # scanned=405346 # found=20 # cleaned=20 # scan_time=6204 sh=15ED5B6C5946E85E7A5C77F4A7689E4E76CCBAFB ft=1 fh=c71c0011fe889422 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir" sh=8FF07C7F0E7320A1EB53CADD4D30D3154FF33BBA ft=1 fh=f622fe8cae001c0b vn="Win64/Thinknice.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir" sh=532A232C336AB1E5D65E829DFA191A71B96E2CC6 ft=1 fh=c71c001152b88659 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\HpUI.exe.vir" sh=12EBF6FC8AD543662053CA101C2D5DA175137EB2 ft=1 fh=c71c00119e5c1a87 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader32.exe.vir" sh=8F0ABE23DDA3F9DC04497B1A4F455AF8CE9D45B8 ft=1 fh=787e176d56997de7 vn="Win64/Thinknice.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader64.exe.vir" sh=9E99BBE4E9F6026A66DB442D589FF049D44E43E9 ft=1 fh=c71c001149569c6f vn="Win32/ELEX.AV evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir" sh=55B49E6175EC153F5F6D595F7E36CF04D61C70AC ft=1 fh=c71c0011122aac36 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir" sh=B1740CE6528491D6914E0015C836A3A8E31A28E9 ft=1 fh=667e6cf17acea18e vn="Win64/Thinknice.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir" sh=6148DAB05D76E4FCEF4B394B0F60D9ADB2E2AB1E ft=1 fh=c71c0011346812ac vn="Win32/ELEX.AV evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe.vir" sh=03DBFA1572019E6B0A7745CA443E74CCA8FEEFFD ft=1 fh=c71c0011e74d8dee vn="Win32/Thinknice.B evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir" sh=E9BEAFD5EF09360852ECDCC4312188064742E51A ft=1 fh=c71c0011421e8e27 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\uninstall.exe.vir" sh=E3C659B9CAA4B5CFF2906CA02EB3F178906A2416 ft=1 fh=c71c00117f5fd915 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll32.dll.vir" sh=8B488C388E304F78CA88312A651D07494469D292 ft=1 fh=8013085d4e45f122 vn="Win64/Thinknice.D evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll64.dll.vir" sh=915B33C2D279ECCC69F286C3E9088BB7AFFE58C7 ft=1 fh=c71c001175f130b5 vn="Variante von Win32/AdWare.MultiPlug.AY Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\cosstminn\PG2BjJ_.exe.vir" sh=6148DAB05D76E4FCEF4B394B0F60D9ADB2E2AB1E ft=1 fh=c71c0011346812ac vn="Win32/ELEX.AV evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Simon\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=6BBBC7BF49BCA473C83E8C816B63DC04ECE146E9 ft=1 fh=00c07704ae2df0ab vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Simon\Downloads\AdwCleaner - CHIP-Installer.exe" sh=2F54CCA896FD17D917B7D076749C5180BDAEEE88 ft=1 fh=e9c0455c3878dbe3 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Simon\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe" sh=E2C028A886AA7352539DEE32CBB38770C529A76E ft=1 fh=d2aeb2930bcba9f7 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Simon\Downloads\PDFCreator-1_7_3_setup.exe" sh=6A903A6705D9B4BB9D17C219D638FC225F343A9D ft=1 fh=eea1af13a78f60f2 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Simon\Downloads\WavePad - CHIP-Installer.exe" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=bb795e8ec92fd448a26af18fbf307665 # engine=19733 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-08-19 08:38:55 # local_time=2014-08-19 10:38:55 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777214 100 100 13259001 273900425 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 10768 160110585 0 0 # scanned=411002 # found=19 # cleaned=0 # scan_time=8426 sh=8C7BA92F8674F9D37B040D90C3E4182E81C0405D ft=1 fh=4c2da10d68fe0666 vn="Variante von Win32/Bundled.Toolbar.Google.C potenziell unsichere Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\NCH Software\WavePad\wavepad.exe.vir" sh=9A1A181DC9C254E499BA0C2E03E465431CEDFCAA ft=1 fh=ac8bb93429cc4950 vn="Variante von Win32/Bundled.Toolbar.Google.C potenziell unsichere Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\NCH Software\WavePad\wavepadsetup_v5.96.exe.vir" sh=9A1A181DC9C254E499BA0C2E03E465431CEDFCAA ft=1 fh=ac8bb93429cc4950 vn="Variante von Win32/Bundled.Toolbar.Google.C potenziell unsichere Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Simon\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\6253ea0ee7139de5ab015983d904fdcf\wp596setup.exe.vir" sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\apnic.dll" sh=FFA8B6510D624A55F3EB7FFD6D5221A44944681C ft=1 fh=3386eb0d6ed0e5e1 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\apnstub.exe" sh=1A3F14C0A66F9AF050D1F34FBACBAADC31751A07 ft=1 fh=2704a03a0f47b728 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\apntoolbarinstaller.exe" sh=4B553651EF610C0614F8393D6C25ABA0A8F09ECA ft=1 fh=92ef1bb072edf568 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\Offercast_AVIRAV7_.exe" sh=D1D84E78302885295C3EC173CF25B20794123E7F ft=1 fh=62ab64a2f36b7f02 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\ICQ7.5\upgrade\2dcd1d63cb45e6613582211c3d5f4b23" sh=44B1CB2BCCE1BD052FBE05907F4451E1752BC085 ft=1 fh=4ff293b6f57e565a vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\ICQ7.5\upgrade\53e83dd5315bfb1f928441c9b4618b68" sh=1B189BC2EB21622F4A6E0B118B5CE96FB01B201B ft=1 fh=41d362802ecf70c9 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\ICQ7.6\install_dll\OCSetupHlp.dll" sh=4E8A8E380D1A77BA431D61FF87CB4F3ABD9C02B4 ft=1 fh=d813df953ad1d4f7 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="C:\Users\Simon\AppData\Local\Temp\ASK9867.tmp" sh=0C3B662680A08E408A377DF5DF75AF78855D9BB6 ft=1 fh=b7bf4bc877f8f793 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="C:\Users\Simon\AppData\Local\Temp\ASKB03B.tmp" sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Users\Simon\AppData\Local\Temp\AskSLib.dll" sh=44ECD35DFEC564F7F4382E7E6688AC46EE8AD362 ft=1 fh=b4812403b17104e4 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Simon\AppData\Local\Temp\toolbar20178192.exe" sh=40E49124AD0B55A25F947333CA88E9D0BC30A7E3 ft=1 fh=e26ad988592b2af9 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\ApnIC[1].0" sh=E32AA2E78D2C8F0E9316080E71A714BEFE851E6C ft=1 fh=374915f71a49693e vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\ApnIC[1].0" sh=40E49124AD0B55A25F947333CA88E9D0BC30A7E3 ft=1 fh=e26ad988592b2af9 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\ApnIC[1].0" sh=E32AA2E78D2C8F0E9316080E71A714BEFE851E6C ft=1 fh=374915f71a49693e vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\ApnIC[1].0" sh=40E49124AD0B55A25F947333CA88E9D0BC30A7E3 ft=1 fh=e26ad988592b2af9 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\Temp\AskSLib.dll" |
21.08.2014, 17:07 | #18 |
/// TB-Ausbilder | Yourfile Downloader - Troyaner - wie entfernt man den Mist? Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter "C:\Program Files (x86)\ICQ7.5\upgrade\2dcd1d63cb45e6613582211c3d5f4b23" "C:\Program Files (x86)\ICQ7.5\upgrade\53e83dd5315bfb1f928441c9b4618b68" "C:\Program Files (x86)\ICQ7.6\install_dll\OCSetupHlp.dll" emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Der Rest der AdWare "gehört" zu Avira. Der folgende Abschnitt ist meine persönliche Meinung Du hast Avira Free als Virenschutz installiert und das ist "leider" ein zweischneidiges Schwert. Zum einen ist es ein Virenschutz, zum anderen Adware, denn die Free Version von Avira bringt die AskToolbar mit, ohne die der Surfschutz nicht funktioniert. Deswegen würde ich dir "persönlich" ein anderes Produkt empfehlen. Als kostenlose Alternative nenne ich: Soweit sieht aber alles ok aus, aber Starte noch einmal FRST.
__________________ |
21.08.2014, 19:23 | #19 |
| Yourfile Downloader - Troyaner - wie entfernt man den Mist? Fixlog - Rest kommt später... Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-08-2014 01 Ran by Simon at 2014-08-21 20:10:48 Run:4 Running from C:\Users\Simon\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** "C:\Program Files (x86)\ICQ7.5\upgrade\2dcd1d63cb45e6613582211c3d5f4b23" "C:\Program Files (x86)\ICQ7.5\upgrade\53e83dd5315bfb1f928441c9b4618b68" "C:\Program Files (x86)\ICQ7.6\install_dll\OCSetupHlp.dll" emptytemp: ***************** C:\Program Files (x86)\ICQ7.5\upgrade\2dcd1d63cb45e6613582211c3d5f4b23 => Moved successfully. C:\Program Files (x86)\ICQ7.5\upgrade\53e83dd5315bfb1f928441c9b4618b68 => Moved successfully. C:\Program Files (x86)\ICQ7.6\install_dll\OCSetupHlp.dll => Moved successfully. EmptyTemp: => Removed 2.8 GB temporary data. The system needed a reboot. ==== End of Fixlog ==== FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2014 01 Ran by Simon (administrator) on SIMON-PC on 21-08-2014 20:20:39 Running from C:\Users\Simon\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe (CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (Acer Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\ipmgui.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-28] (Realtek Semiconductor) HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [36864 2007-03-20] () HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-08-13] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-18] () HKLM-x32\...\Run: [EgisTecLiveUpdate] => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-04] (Egis Technology Inc.) HKLM-x32\...\Run: [ArcadeDeluxeAgent] => C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [128296 2009-11-16] (CyberLink Corp.) HKLM-x32\...\Run: [PlayMovie] => C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe [181480 2009-11-12] (Acer Corp.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2006-09-01] (Apple Computer, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [BlockAndSurf] => C:\Program Files (x86)\ver1BlockAndSurf\BlockAndSurf.exe HKU\S-1-5-21-2701147688-1485282812-3783366192-1000\...\Run: [] => [X] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll (Egis Technology Inc.) ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll (Egis Technology Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: No Name -> {120A8821-2BEE-4C29-BCDA-62C577781992} -> No File BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\sv53x1ay.default-1350505399289 FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: Wikipedia (de) FF SelectedSearchEngine: Wikipedia (de) FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.10.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Computer, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Computer, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Computer, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Computer, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Computer, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Computer, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Computer, Inc.) FF SearchPlugin: C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\sv53x1ay.default-1350505399289\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\sv53x1ay.default-1350505399289\searchplugins\google-maps.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\sv53x1ay.default-1350505399289\Extensions\donottrackplus@abine.com [2014-07-12] FF Extension: CouponsHelper - C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\sv53x1ay.default-1350505399289\Extensions\{239cc760-75a9-4276-b1fc-c0ceb963f373}.xpi [2013-12-14] FF Extension: Adblock Plus - C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\sv53x1ay.default-1350505399289\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-14] FF Extension: Recorder Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\{10743931-94DF-476f-A987-4391233C17A2} [2014-08-03] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-07-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-07-29] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.com/" CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Extension: (YouTube) - C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-09] CHR Extension: (Google-Suche) - C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-09] CHR Extension: (Google Mail) - C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-09] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.) S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-17] (pdfforge GmbH) S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-17] (pdfforge GmbH) R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [247152 2009-02-16] () S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-21] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 OlyUsbCam; C:\Windows\System32\DRIVERS\OlyUsbCam.sys [24512 2007-01-12] (OLYMPUS IMAGING CORP.) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-08-06] () R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [146928 2009-11-12] (CyberLink Corp.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-19 20:14 - 2014-08-19 20:15 - 02347384 _____ (ESET) C:\Users\Simon\Downloads\esetsmartinstaller_deu(1).exe 2014-08-15 00:35 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-15 00:35 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-15 00:35 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-15 00:35 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-15 00:35 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-15 00:35 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-15 00:35 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-15 00:35 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-14 23:57 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-14 23:57 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-14 23:57 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-14 23:57 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-14 23:57 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-14 23:57 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-14 23:57 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-14 23:57 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-14 23:57 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-14 23:57 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-14 23:57 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-14 23:57 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-14 23:57 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-14 23:57 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-14 23:57 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-14 23:57 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-14 23:57 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-14 23:57 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-14 23:57 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-14 23:57 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-14 23:57 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-14 23:57 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-14 23:57 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-14 23:57 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-14 23:57 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-14 23:57 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-14 23:57 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-14 23:57 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-14 23:57 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-14 23:57 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-14 23:57 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-14 23:57 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-14 23:57 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-14 23:57 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-14 23:57 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-14 23:57 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-14 23:57 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-14 23:57 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-14 23:57 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-14 23:57 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-14 23:57 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-14 23:57 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-14 23:57 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-14 23:57 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-14 23:57 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-14 23:57 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-14 23:57 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-14 23:57 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-14 23:57 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-14 23:57 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-14 23:57 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-14 23:57 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-14 23:57 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-14 23:57 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-14 23:57 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-14 23:57 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-14 23:30 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-14 23:30 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-14 23:30 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-14 23:30 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-14 23:30 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-14 23:30 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-14 23:30 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-14 23:30 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-14 23:30 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-14 23:30 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-14 23:30 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-14 23:30 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-14 23:25 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-14 23:25 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-14 23:25 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-14 23:25 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-14 23:25 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-14 23:25 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-14 23:25 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-14 23:25 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-14 23:25 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-14 23:25 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-14 23:25 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-14 23:25 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-14 23:25 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-14 23:24 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-14 23:24 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-14 23:18 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-14 23:18 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-14 23:18 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-14 23:18 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-13 22:19 - 2014-08-18 20:10 - 00000000 ____D () C:\Users\Simon\Downloads\FRST-OlderVersion 2014-08-13 20:03 - 2014-08-13 20:03 - 02347384 _____ (ESET) C:\Users\Simon\Downloads\esetsmartinstaller_deu.exe 2014-08-12 22:38 - 2014-08-12 22:38 - 00003051 _____ () C:\Users\Simon\Downloads\mbam.txt 2014-08-11 23:52 - 2014-08-21 20:19 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-11 23:52 - 2014-08-11 23:52 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-11 23:52 - 2014-08-11 23:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-11 23:52 - 2014-08-11 23:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-11 23:52 - 2014-08-11 23:52 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-11 23:52 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-11 23:52 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-11 23:52 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-11 23:50 - 2014-08-11 23:50 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Simon\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-11 23:43 - 2014-08-11 23:43 - 01016261 _____ (Thisisu) C:\Users\Simon\Downloads\JRT(1).exe 2014-08-11 23:36 - 2014-08-11 23:36 - 01366203 _____ () C:\Users\Simon\Downloads\adwcleaner_3.304.exe 2014-08-11 22:34 - 2014-08-11 22:34 - 01016261 _____ (Thisisu) C:\Users\Simon\Downloads\JRT.exe 2014-08-11 22:34 - 2014-08-11 22:34 - 00000000 ____D () C:\Windows\ERUNT 2014-08-11 22:27 - 2014-08-11 22:27 - 00016383 _____ () C:\Users\Simon\Desktop\Vdez5405.htm 2014-08-11 22:00 - 2014-08-15 20:26 - 00040656 _____ () C:\Users\Simon\Downloads\Addition.txt 2014-08-11 21:58 - 2014-08-21 20:21 - 00018064 _____ () C:\Users\Simon\Downloads\FRST.txt 2014-08-11 21:58 - 2014-08-21 20:20 - 00000000 ____D () C:\FRST 2014-08-11 21:57 - 2014-08-18 20:10 - 02101760 _____ (Farbar) C:\Users\Simon\Downloads\FRST64.exe 2014-08-11 21:45 - 2014-08-11 21:45 - 01101648 _____ () C:\Users\Simon\Downloads\AdwCleaner - CHIP-Installer(1).exe 2014-08-11 21:36 - 2014-08-11 21:36 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-08-11 21:36 - 2014-08-11 21:36 - 00001409 _____ () C:\Windows\QTFont.for 2014-08-11 20:22 - 2014-08-11 20:22 - 00027909 _____ () C:\Users\Simon\.recently-used.xbel 2014-08-06 21:34 - 2014-08-06 21:34 - 00001276 _____ () C:\Users\Public\Desktop\NCH Suite.lnk 2014-08-06 21:34 - 2014-08-06 21:34 - 00001138 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk 2014-08-06 21:34 - 2014-08-06 21:34 - 00001126 _____ () C:\Users\Public\Desktop\WavePad Sound Editor.lnk 2014-08-06 21:34 - 2014-08-06 21:34 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2014-08-06 21:34 - 2014-08-06 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite 2014-08-06 21:30 - 2014-08-06 21:30 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\mp3DirectCut 2014-08-06 21:28 - 2014-08-06 21:28 - 00001063 _____ () C:\Users\Simon\Desktop\mp3DirectCut.lnk 2014-08-06 21:27 - 2014-08-06 21:28 - 00308709 _____ () C:\Users\Simon\Downloads\mpdc_16957.exe 2014-08-03 11:51 - 2014-08-03 11:51 - 00000000 ____D () C:\Users\Simon\Tracing 2014-08-03 11:50 - 2014-08-03 11:50 - 00001309 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk 2014-08-03 11:50 - 2014-08-03 11:50 - 00000000 ____D () C:\Windows\de 2014-08-03 00:18 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-08-03 00:17 - 2014-08-11 23:39 - 00000000 ____D () C:\AdwCleaner 2014-08-03 00:17 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll 2014-08-03 00:17 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll 2014-08-03 00:13 - 2014-08-03 00:13 - 00000000 ____D () C:\Users\Simon\AppData\Local\MedienTeam66 2014-08-03 00:11 - 2014-08-03 00:11 - 00000000 ____D () C:\Users\Simon\Documents\YouTube Recordings 2014-08-03 00:10 - 2014-08-21 00:10 - 00000314 _____ () C:\Windows\Tasks\MT66 Software Update.job 2014-08-03 00:10 - 2014-08-03 00:10 - 10061576 _____ (MedienTeam66 Verlags GmbH ) C:\Users\Simon\Downloads\MP3_Recorder_for_YouTube.exe 2014-08-03 00:10 - 2014-08-03 00:10 - 00002908 _____ () C:\Windows\System32\Tasks\MT66 Software Update 2014-08-03 00:10 - 2014-08-03 00:10 - 00000000 ____D () C:\Program Files (x86)\MedienTeam66 2014-08-03 00:03 - 2014-08-03 00:03 - 00003150 _____ () C:\Windows\System32\Tasks\{F14520F0-57E8-473B-B7CA-55041ED72F79} 2014-08-03 00:01 - 2014-08-03 00:01 - 00000114 _____ () C:\Windows\wininit.ini 2014-08-02 23:57 - 2014-08-03 00:02 - 00000000 ____D () C:\ProgramData\8aa681781fbef9a8 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Simon\AppData\Local\Packages 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Simon\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Gast 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Administrator 2014-08-02 23:56 - 2014-08-11 23:30 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-08-02 23:56 - 2014-08-02 23:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf 2014-08-01 20:26 - 2014-08-01 20:26 - 00000000 ___HD () C:\Users\Simon\Documents\ShadowEditFiles 2014-08-01 20:26 - 2014-08-01 20:26 - 00000000 ____D () C:\Users\Simon\Documents\CyberLink 2014-08-01 20:25 - 2014-08-01 20:25 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\CyberLink 2014-08-01 19:48 - 2014-08-06 21:55 - 00000000 ____D () C:\Users\Simon\Desktop\Videomaterial C u A 2014-07-29 21:51 - 2014-07-29 21:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-26 21:57 - 2014-08-05 20:11 - 00000000 ____D () C:\Users\Simon\Desktop\LaLala Bob 2014-07-26 02:38 - 2014-07-27 01:00 - 00000000 ____D () C:\Users\Simon\Desktop\FCKW ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-21 20:21 - 2014-08-11 21:58 - 00018064 _____ () C:\Users\Simon\Downloads\FRST.txt 2014-08-21 20:21 - 2010-08-27 08:28 - 01343477 _____ () C:\Windows\WindowsUpdate.log 2014-08-21 20:20 - 2014-08-11 21:58 - 00000000 ____D () C:\FRST 2014-08-21 20:19 - 2014-08-11 23:52 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-21 20:19 - 2009-07-14 06:45 - 00438200 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-21 20:17 - 2010-09-19 19:27 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-21 20:17 - 2010-08-27 08:40 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-21 20:17 - 2009-11-19 00:09 - 01029778 _____ () C:\Windows\PFRO.log 2014-08-21 20:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-21 20:17 - 2009-07-14 06:51 - 00215269 _____ () C:\Windows\setupact.log 2014-08-21 20:05 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-21 20:05 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-21 20:00 - 2012-05-18 18:48 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-21 00:10 - 2014-08-03 00:10 - 00000314 _____ () C:\Windows\Tasks\MT66 Software Update.job 2014-08-20 23:48 - 2010-09-19 19:27 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-20 22:11 - 2014-07-09 17:08 - 00000000 ____D () C:\Users\Simon\Desktop\Bilder vom Bob 2014-08-20 22:08 - 2010-08-27 18:19 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-08-20 22:08 - 2010-08-27 18:19 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-08-20 22:08 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-20 21:24 - 2010-09-12 14:19 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6D5A817C-B063-4DF2-95A2-90BC099FE999} 2014-08-19 20:15 - 2014-08-19 20:14 - 02347384 _____ (ESET) C:\Users\Simon\Downloads\esetsmartinstaller_deu(1).exe 2014-08-18 20:10 - 2014-08-13 22:19 - 00000000 ____D () C:\Users\Simon\Downloads\FRST-OlderVersion 2014-08-18 20:10 - 2014-08-11 21:57 - 02101760 _____ (Farbar) C:\Users\Simon\Downloads\FRST64.exe 2014-08-16 23:57 - 2010-11-24 21:08 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-08-16 23:57 - 2010-11-24 21:08 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\Skype 2014-08-16 23:57 - 2010-11-24 21:07 - 00000000 ____D () C:\ProgramData\Skype 2014-08-16 23:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-15 20:26 - 2014-08-11 22:00 - 00040656 _____ () C:\Users\Simon\Downloads\Addition.txt 2014-08-15 20:08 - 2010-09-09 20:59 - 00000000 ___RD () C:\Users\Simon\Eigene Bilder 2014-08-15 20:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-15 00:44 - 2013-07-30 00:40 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-15 00:39 - 2010-09-18 21:01 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-15 00:34 - 2014-05-07 00:15 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-14 21:43 - 2010-09-12 14:30 - 00000000 ____D () C:\Users\Simon\.gimp-2.6 2014-08-13 20:03 - 2014-08-13 20:03 - 02347384 _____ (ESET) C:\Users\Simon\Downloads\esetsmartinstaller_deu.exe 2014-08-12 23:36 - 2010-09-11 19:20 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\ICQ 2014-08-12 22:38 - 2014-08-12 22:38 - 00003051 _____ () C:\Users\Simon\Downloads\mbam.txt 2014-08-11 23:52 - 2014-08-11 23:52 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-11 23:52 - 2014-08-11 23:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-11 23:52 - 2014-08-11 23:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-11 23:52 - 2014-08-11 23:52 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-11 23:50 - 2014-08-11 23:50 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Simon\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-11 23:43 - 2014-08-11 23:43 - 01016261 _____ (Thisisu) C:\Users\Simon\Downloads\JRT(1).exe 2014-08-11 23:39 - 2014-08-03 00:17 - 00000000 ____D () C:\AdwCleaner 2014-08-11 23:36 - 2014-08-11 23:36 - 01366203 _____ () C:\Users\Simon\Downloads\adwcleaner_3.304.exe 2014-08-11 23:30 - 2014-08-02 23:56 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-08-11 23:27 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-08-11 22:34 - 2014-08-11 22:34 - 01016261 _____ (Thisisu) C:\Users\Simon\Downloads\JRT.exe 2014-08-11 22:34 - 2014-08-11 22:34 - 00000000 ____D () C:\Windows\ERUNT 2014-08-11 22:27 - 2014-08-11 22:27 - 00016383 _____ () C:\Users\Simon\Desktop\Vdez5405.htm 2014-08-11 21:45 - 2014-08-11 21:45 - 01101648 _____ () C:\Users\Simon\Downloads\AdwCleaner - CHIP-Installer(1).exe 2014-08-11 21:36 - 2014-08-11 21:36 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-08-11 21:36 - 2014-08-11 21:36 - 00001409 _____ () C:\Windows\QTFont.for 2014-08-11 20:22 - 2014-08-11 20:22 - 00027909 _____ () C:\Users\Simon\.recently-used.xbel 2014-08-11 20:22 - 2010-09-12 19:10 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\gtk-2.0 2014-08-11 20:22 - 2010-09-09 20:59 - 00000000 ____D () C:\Users\Simon 2014-08-07 04:06 - 2014-08-14 23:18 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-14 23:18 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-06 21:55 - 2014-08-01 19:48 - 00000000 ____D () C:\Users\Simon\Desktop\Videomaterial C u A 2014-08-06 21:34 - 2014-08-06 21:34 - 00001276 _____ () C:\Users\Public\Desktop\NCH Suite.lnk 2014-08-06 21:34 - 2014-08-06 21:34 - 00001138 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk 2014-08-06 21:34 - 2014-08-06 21:34 - 00001126 _____ () C:\Users\Public\Desktop\WavePad Sound Editor.lnk 2014-08-06 21:34 - 2014-08-06 21:34 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2014-08-06 21:34 - 2014-08-06 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite 2014-08-06 21:30 - 2014-08-06 21:30 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\mp3DirectCut 2014-08-06 21:28 - 2014-08-06 21:28 - 00001063 _____ () C:\Users\Simon\Desktop\mp3DirectCut.lnk 2014-08-06 21:28 - 2014-08-06 21:27 - 00308709 _____ () C:\Users\Simon\Downloads\mpdc_16957.exe 2014-08-05 20:11 - 2014-07-26 21:57 - 00000000 ____D () C:\Users\Simon\Desktop\LaLala Bob 2014-08-05 09:20 - 2010-09-10 21:09 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-03 11:55 - 2013-07-04 23:25 - 00000000 ____D () C:\Users\Simon\AppData\Local\Windows Live 2014-08-03 11:51 - 2014-08-03 11:51 - 00000000 ____D () C:\Users\Simon\Tracing 2014-08-03 11:50 - 2014-08-03 11:50 - 00001309 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk 2014-08-03 11:50 - 2014-08-03 11:50 - 00000000 ____D () C:\Windows\de 2014-08-03 11:50 - 2013-07-04 23:32 - 00001494 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2014-08-03 11:50 - 2013-07-04 23:32 - 00001378 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk 2014-08-03 11:50 - 2010-08-27 08:51 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live 2014-08-03 11:49 - 2013-07-04 23:32 - 00002538 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk 2014-08-03 11:49 - 2013-07-04 23:31 - 00000000 ____D () C:\Program Files\Windows Live 2014-08-03 11:49 - 2010-08-27 08:51 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-08-03 11:47 - 2010-08-27 08:52 - 00133212 _____ () C:\Windows\DirectX.log 2014-08-03 00:18 - 2011-04-30 13:49 - 00001069 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-08-03 00:18 - 2011-04-30 13:49 - 00001057 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-08-03 00:18 - 2010-09-11 19:20 - 00000000 ____D () C:\ProgramData\ICQ 2014-08-03 00:18 - 2010-09-09 21:00 - 00001041 _____ () C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-08-03 00:13 - 2014-08-03 00:13 - 00000000 ____D () C:\Users\Simon\AppData\Local\MedienTeam66 2014-08-03 00:11 - 2014-08-03 00:11 - 00000000 ____D () C:\Users\Simon\Documents\YouTube Recordings 2014-08-03 00:10 - 2014-08-03 00:10 - 10061576 _____ (MedienTeam66 Verlags GmbH ) C:\Users\Simon\Downloads\MP3_Recorder_for_YouTube.exe 2014-08-03 00:10 - 2014-08-03 00:10 - 00002908 _____ () C:\Windows\System32\Tasks\MT66 Software Update 2014-08-03 00:10 - 2014-08-03 00:10 - 00000000 ____D () C:\Program Files (x86)\MedienTeam66 2014-08-03 00:03 - 2014-08-03 00:03 - 00003150 _____ () C:\Windows\System32\Tasks\{F14520F0-57E8-473B-B7CA-55041ED72F79} 2014-08-03 00:02 - 2014-08-02 23:57 - 00000000 ____D () C:\ProgramData\8aa681781fbef9a8 2014-08-03 00:01 - 2014-08-03 00:01 - 00000114 _____ () C:\Windows\wininit.ini 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Simon\AppData\Local\Packages 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Simon\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Gast 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Administrator 2014-08-02 23:57 - 2010-09-19 19:26 - 00000000 ____D () C:\Users\Simon\AppData\Local\Google 2014-08-02 23:57 - 2009-11-18 23:56 - 00000000 ____D () C:\Program Files (x86)\Google 2014-08-02 23:56 - 2014-08-02 23:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf 2014-08-02 23:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-08-02 21:20 - 2010-11-27 00:10 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\XnView 2014-08-01 20:26 - 2014-08-01 20:26 - 00000000 ___HD () C:\Users\Simon\Documents\ShadowEditFiles 2014-08-01 20:26 - 2014-08-01 20:26 - 00000000 ____D () C:\Users\Simon\Documents\CyberLink 2014-08-01 20:26 - 2010-08-27 08:45 - 00000000 ____D () C:\ProgramData\CyberLink 2014-08-01 20:25 - 2014-08-01 20:25 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\CyberLink 2014-08-01 01:41 - 2014-08-14 23:57 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-01 01:16 - 2014-08-14 23:57 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-31 17:31 - 2012-04-27 19:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-07-29 21:51 - 2014-07-29 21:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-27 01:00 - 2014-07-26 02:38 - 00000000 ____D () C:\Users\Simon\Desktop\FCKW 2014-07-26 11:54 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-25 16:52 - 2014-08-14 23:57 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-25 16:02 - 2014-08-14 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-25 16:01 - 2014-08-14 23:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-25 15:51 - 2014-08-14 23:57 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-25 15:30 - 2014-08-14 23:57 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-25 15:28 - 2014-08-14 23:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-25 15:28 - 2014-08-14 23:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-25 15:25 - 2014-08-14 23:57 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-25 15:25 - 2014-08-14 23:57 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-25 15:11 - 2014-08-14 23:57 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-25 15:10 - 2014-08-14 23:57 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-25 15:04 - 2014-08-14 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-25 15:03 - 2014-08-14 23:57 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-25 15:00 - 2014-08-14 23:57 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-25 15:00 - 2014-08-14 23:57 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-25 14:59 - 2014-08-14 23:57 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-25 14:47 - 2014-08-14 23:57 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-25 14:40 - 2014-08-14 23:57 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-25 14:34 - 2014-08-14 23:57 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-25 14:34 - 2014-08-14 23:57 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-25 14:33 - 2014-08-14 23:57 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-25 14:30 - 2014-08-14 23:57 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-25 14:28 - 2014-08-14 23:57 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-25 14:28 - 2014-08-14 23:57 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-25 14:21 - 2014-08-14 23:57 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-25 14:19 - 2014-08-14 23:57 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-25 14:18 - 2014-08-14 23:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-25 14:17 - 2014-08-14 23:57 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-25 14:17 - 2014-08-14 23:57 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-25 14:12 - 2014-08-14 23:57 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-25 14:10 - 2014-08-14 23:57 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-25 14:10 - 2014-08-14 23:57 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-25 14:08 - 2014-08-14 23:57 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-25 14:06 - 2014-08-14 23:57 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-25 13:52 - 2014-08-14 23:57 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-25 13:47 - 2014-08-14 23:57 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-25 13:43 - 2014-08-14 23:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-25 13:42 - 2014-08-14 23:57 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-25 13:39 - 2014-08-14 23:57 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-25 13:39 - 2014-08-14 23:57 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-25 13:36 - 2014-08-14 23:57 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-25 13:34 - 2014-08-14 23:57 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-25 13:29 - 2014-08-14 23:57 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-25 13:23 - 2014-08-14 23:57 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-25 13:13 - 2014-08-14 23:57 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-25 13:07 - 2014-08-14 23:57 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-25 13:07 - 2014-08-14 23:57 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-25 13:03 - 2014-08-14 23:57 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-25 12:52 - 2014-08-14 23:57 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-25 12:26 - 2014-08-14 23:57 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-25 12:17 - 2014-08-14 23:57 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-25 12:09 - 2014-08-14 23:57 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-25 12:05 - 2014-08-14 23:57 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-25 12:00 - 2014-08-14 23:57 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-24 23:22 - 2013-03-14 00:32 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-24 23:22 - 2013-03-14 00:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-24 20:20 - 2013-03-14 00:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-22 17:52 - 2014-05-06 23:20 - 00000000 ____D () C:\Users\Simon\Documents\Bewerbungen Some content of TEMP: ==================== C:\Users\Simon\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-18 19:49 ==================== End Of Log ============================ --- --- --- |
23.08.2014, 11:17 | #20 |
/// TB-Ausbilder | Yourfile Downloader - Troyaner - wie entfernt man den Mist? Ok, die Logs sehen soweit sauber aus ! Zeigt der Rechner noch irgendwelche Anzeichen vom Yourfile Downloader oder sonstigem ? Falls nicht, so weitermachen: Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Die Reihenfolge ist hier entscheidend.
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
25.08.2014, 19:57 | #21 |
| Yourfile Downloader - Troyaner - wie entfernt man den Mist? In der Adresszeile des Firefox steht noch immer "chrome://quick_start/content/index.html" Ansonsten aber schonmal vielen vielen Dank für Deine Hilfe! Ich hätte ohne Dich niemals geschafft, diesen hässlichen DL-Manager herunterzuladen! Ich werde mich auch dem Forum gegenüber erkenntlich zeigen (selbstverständlich!) |