|
Alles rund um Windows: Windows-Explorer Funktioniert nicht mehr?Windows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
17.08.2014, 23:21 | #31 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst] Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Matthias\AppData\Local\{80aa28bd-953b-0d79-ac52-59b01480de54} Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
18.08.2014, 02:02 | #32 |
| Windows-Explorer Funktioniert nicht mehr? [gelöst] Funktioniert nicht es kommt folgende Meldung:
__________________''No fixlist.txt found.'' ''The fixlist.txt should be in the same folder/directory the tool is located.'' Der folder zu FRST ist doch ''FRST Older Version'' oder? Habe zumindest keinen weiteren gefunden in meinem Download Bereich. Hab versucht während beide auf dem desktop sind, und habe die beiden (exe von FRST und die Fixliste) in dem FRST Older Version Ordner hineingetan, kommt aber selbe Meldung. Ich habe 2 mal die FRST exe. Kann ich sie einmal löschen? |
18.08.2014, 08:13 | #33 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst] Funktioniert deswegen nicht:
__________________Zitat:
__________________ |
18.08.2014, 09:02 | #34 |
| Windows-Explorer Funktioniert nicht mehr? [gelöst] Habe jetzt Farbar's Recovery Scan Tool aus dem download gelöscht, und im Papierkorb eleminiert. Scheint nicht bei Systemsteuerung -> System und SIcherheit zu sein. Habe jetzt den Speicherort geändert, nochmals gedownloadet,sodass es direkt zum Desktop geht. Und es kommt die selbe Naricht. |
18.08.2014, 09:44 | #35 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst] Dann hast du den Dateinamen der fixlist falsch geschrieben.
__________________ Logfiles bitte immer in CODE-Tags posten |
18.08.2014, 10:02 | #36 |
| Windows-Explorer Funktioniert nicht mehr? [gelöst] Ja das habe ich. Habe fixliste geschrieben.... Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-08-2014 01 Ran by Matthias at 2014-08-18 11:00:11 Run:1 Running from C:\Users\Matthias\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Matthias\AppData\Local\{80aa28bd-953b-0d79-ac52-59b01480de54} ***************** C:\Users\Matthias\AppData\Local\{80aa28bd-953b-0d79-ac52-59b01480de54} => Moved successfully. ==== End of Fixlog ==== |
18.08.2014, 11:01 | #37 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst] Ok. Rechner rebooten und neue FRST Logs bitte.
__________________ Logfiles bitte immer in CODE-Tags posten |
18.08.2014, 12:23 | #38 |
| Windows-Explorer Funktioniert nicht mehr? [gelöst] FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2014 01 Ran by Matthias (administrator) on MATTHIAS-PC on 18-08-2014 13:20:28 Running from C:\Users\Matthias\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE () C:\Program Files (x86)\Infigo\InfigoOperator.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Overwolf LTD) C:\Program Files (x86)\Overwolf\Overwolf.exe (NewSoft Technology Corporation) C:\Program Files (x86)\NewSoft\Presto! PageManager 9 for EP\Pmsb.exe (NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (MAVIN LOG, S.L.) C:\Program Files (x86)\Infigo\Infigo.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (NewSoft Technology Corporation) C:\Program Files (x86)\NewSoft\Presto! PageManager 9 for EP\PMSpeed.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.78.41.0\OverwolfHelper.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe () C:\Program Files (x86)\Overwolf\0.78.41.0\OverwolfBrowser.exe (Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.78.41.0\OverwolfHelper64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-01] (Realtek Semiconductor) HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-11] (Alcor Micro Corp.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [WrtMon.exe] => C:\Windows\system32\spool\drivers\x64\3\WrtMon.exe [26448 2008-05-24] (NewSoft Technology Corporation) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [PMSpeed] => C:\Program Files (x86)\NewSoft\Presto! PageManager 9 for EP\PMSpeed.EXE [112464 2009-12-04] (NewSoft Technology Corporation) HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [847872 2009-12-03] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect" HKU\S-1-5-21-4002615419-2591733308-3372411449-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe [39712 2014-08-06] (Overwolf LTD) HKU\S-1-5-21-4002615419-2591733308-3372411449-1001\...\Run: [Scan Buttons] => C:\Program Files (x86)\NewSoft\Presto! PageManager 9 for EP\PMSB.EXE [202576 2009-12-09] (NewSoft Technology Corporation) HKU\S-1-5-21-4002615419-2591733308-3372411449-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1753280 2014-07-16] (Valve Corporation) HKU\S-1-5-21-4002615419-2591733308-3372411449-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.) HKU\S-1-5-21-4002615419-2591733308-3372411449-1001\...\Run: [Infigo] => C:\Program Files (x86)\Infigo\Infigo.exe [607032 2014-06-26] (MAVIN LOG, S.L.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe () Startup: C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Matthias\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Meine Dienste.lnk ShortcutTarget: Meine Dienste.lnk -> C:\Program Files\Telekom\Meine Dienste\StartMeineDienste.exe (Deutsche Telekom AG) Startup: C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG) Startup: C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.) ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll No File FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Plugin HKCU: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) Chrome: ======= CHR HomePage: CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter} CHR Extension: (Google Docs) - C:\Users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-10] CHR Extension: (Google Drive) - C:\Users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-16] CHR Extension: (YouTube) - C:\Users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-16] CHR Extension: (Google-Suche) - C:\Users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-16] CHR Extension: (Avira Browser Safety) - C:\Users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-16] CHR Extension: (Google Wallet) - C:\Users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21] CHR Extension: (Google Mail) - C:\Users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-08] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-08] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG) R2 InfigoOperator; C:\Program Files (x86)\Infigo\InfigoOperator.exe [19768 2014-06-26] () R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed] S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4229912 2011-11-28] (INCA Internet Co., Ltd.) [File not signed] S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [977184 2014-08-06] (Overwolf LTD) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-02-19] () R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2144056 2013-10-22] (TuneUp Software) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [627992 2013-12-17] (Wacom Technology, Corp.) S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-12] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-26] (DT Soft Ltd) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-18] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-03] (INCA Internet Co., Ltd.) [File not signed] S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-08] (TuneUp Software) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 EraserUtilDrv11220; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [X] S3 X6va006; \??\C:\Users\Matthias\AppData\Local\Temp\006912B.tmp [X] S3 X6va008; \??\C:\Users\Matthias\AppData\Local\Temp\0085798.tmp [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-18 13:20 - 2014-08-18 13:20 - 00023169 _____ () C:\Users\Matthias\Desktop\FRST.txt 2014-08-18 09:59 - 2014-08-18 09:59 - 02101760 _____ (Farbar) C:\Users\Matthias\Desktop\FRST64.exe 2014-08-17 23:40 - 2014-08-17 23:40 - 00000739 _____ () C:\Users\Matthias\Desktop\JRT.txt 2014-08-16 23:43 - 2014-08-16 23:43 - 04161313 _____ () C:\Users\Matthias\Downloads\tdsskiller.zip 2014-08-16 23:38 - 2014-08-16 23:39 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Matthias\Downloads\tdsskiller.exe 2014-08-16 21:21 - 2014-08-16 21:21 - 00054036 _____ () C:\ComboFix.txt 2014-08-16 20:55 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-08-16 20:55 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-08-16 20:55 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-08-16 20:55 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-08-16 20:55 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-08-16 20:55 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-08-16 20:55 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-08-16 20:55 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-08-16 20:49 - 2014-08-16 21:21 - 00000000 ____D () C:\Qoobox 2014-08-16 20:48 - 2014-08-16 21:20 - 00000000 ____D () C:\Windows\erdnt 2014-08-16 20:47 - 2014-08-16 20:48 - 05571320 ____R (Swearware) C:\Users\Matthias\Downloads\ComboFix.exe 2014-08-16 01:58 - 2014-08-16 01:58 - 00000000 ____D () C:\Users\Matthias\Desktop\Protokolle 2014-08-16 01:10 - 2014-08-16 01:15 - 00041952 _____ () C:\Users\Matthias\Downloads\Addition.txt 2014-08-16 01:09 - 2014-08-18 13:20 - 00000000 ____D () C:\FRST 2014-08-16 01:09 - 2014-08-17 23:44 - 00057730 _____ () C:\Users\Matthias\Downloads\FRST.txt 2014-08-16 00:56 - 2014-08-16 00:56 - 00000000 ____D () C:\Windows\ERUNT 2014-08-16 00:54 - 2014-08-16 00:54 - 01016261 _____ (Thisisu) C:\Users\Matthias\Downloads\JRT.exe 2014-08-16 00:32 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-08-16 00:31 - 2014-08-17 23:19 - 00000000 ____D () C:\AdwCleaner 2014-08-16 00:31 - 2014-08-16 00:31 - 01361203 _____ () C:\Users\Matthias\Downloads\adwcleaner_3.306.exe 2014-08-15 17:16 - 2014-08-15 17:16 - 00000000 ____D () C:\Users\Matthias\Desktop\Sherlock Holmes -Teile 2014-08-15 17:15 - 2014-08-16 13:30 - 00000000 ____D () C:\Users\Matthias\Desktop\Stronghold-Teile 2014-08-14 21:16 - 2014-08-14 21:17 - 00000000 ____D () C:\Users\Matthias\Desktop\Diverse Dateien 2014-08-14 21:14 - 2014-08-14 21:16 - 00000000 ____D () C:\Users\Matthias\Desktop\Diverse Ordner 2014-08-14 18:06 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-14 18:06 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-14 18:06 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-14 18:06 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-14 18:05 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-14 18:05 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-14 18:05 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-14 18:05 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-14 18:04 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-14 18:04 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-14 18:04 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-14 18:04 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-14 18:04 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-14 18:04 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-14 18:04 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-14 18:04 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-14 18:04 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-14 18:04 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-14 18:04 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-14 18:04 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-14 18:04 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-14 18:04 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-14 18:04 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-14 18:04 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-14 18:04 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-14 18:04 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-14 18:04 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-14 18:04 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-14 18:04 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-14 18:04 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-14 18:04 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-14 18:04 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-14 18:04 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-14 18:04 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-14 18:04 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-14 18:04 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-14 18:04 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-14 18:04 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-14 18:04 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-14 18:04 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-14 18:04 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-14 18:04 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-14 18:04 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-14 18:04 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-14 18:04 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-14 18:04 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-14 18:04 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-14 18:04 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-14 18:04 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-14 18:04 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-14 18:04 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-14 18:04 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-14 18:04 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-14 18:04 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-14 18:04 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-14 18:04 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-14 18:04 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-14 18:04 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-14 18:04 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-14 18:04 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-14 18:04 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-14 18:04 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-14 18:04 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-14 18:04 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-14 18:01 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-14 18:01 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-14 18:01 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-14 18:01 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-14 18:01 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-14 18:01 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-14 18:01 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-14 18:01 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-14 18:01 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-14 18:01 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-14 18:01 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-14 18:01 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-14 18:01 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-14 18:01 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-14 18:01 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-14 18:01 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-14 18:01 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-14 18:01 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-14 18:01 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-14 18:01 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-14 18:01 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-14 18:01 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-14 18:01 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-14 18:01 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-14 18:01 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-14 18:01 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-14 18:01 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-14 18:01 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-14 18:01 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-14 18:01 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-14 18:01 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-14 15:57 - 2014-08-18 13:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-14 15:56 - 2014-08-14 15:56 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-14 15:56 - 2014-08-14 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-14 15:56 - 2014-08-14 15:56 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-14 15:56 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-14 15:56 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-14 15:56 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-14 15:54 - 2014-08-14 15:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Matthias\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-14 14:48 - 2014-08-14 14:48 - 00001270 _____ () C:\Users\Matthias\Desktop\Revo Uninstaller.lnk 2014-08-14 14:48 - 2014-08-14 14:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-14 14:47 - 2014-08-14 14:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Matthias\Downloads\revosetup.exe 2014-08-14 14:38 - 2014-08-14 14:40 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Infigo 2014-08-14 14:38 - 2014-08-14 14:38 - 00000993 _____ () C:\Users\Matthias\Desktop\Infigo.lnk 2014-08-14 14:38 - 2014-08-14 14:38 - 00000199 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2014-08-14 14:38 - 2014-08-14 14:38 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Infigo 2014-08-14 14:38 - 2014-08-14 14:38 - 00000000 ____D () C:\Program Files (x86)\Infigo 2014-08-14 14:37 - 2014-08-14 14:37 - 07501568 _____ () C:\Users\Matthias\Downloads\Infigo_setup.exe 2014-08-12 21:04 - 2014-08-12 21:04 - 00000932 _____ () C:\Users\Public\Desktop\CPUID HWMonitor.lnk 2014-08-12 21:04 - 2014-08-12 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID 2014-08-12 21:04 - 2014-08-12 21:04 - 00000000 ____D () C:\Program Files\CPUID 2014-08-08 16:16 - 2014-08-08 16:22 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-07 02:55 - 2014-08-07 02:55 - 00004122 _____ () C:\Users\Matthias\Documents\test.wav.wlmp 2014-08-06 19:48 - 2014-08-07 01:37 - 00000000 ____D () C:\Users\Matthias\Documents\Detektic Conan Projekt 2014-08-06 19:48 - 2014-08-06 19:50 - 00000000 ____D () C:\Users\Matthias\Documents\Cha-Cha-Cha 2014-08-03 17:08 - 2014-08-03 17:08 - 00000222 _____ () C:\Users\Matthias\Desktop\The Forest.url ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-18 13:21 - 2014-08-18 13:20 - 00023169 _____ () C:\Users\Matthias\Desktop\FRST.txt 2014-08-18 13:20 - 2014-08-16 01:09 - 00000000 ____D () C:\FRST 2014-08-18 13:20 - 2014-08-14 15:57 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-18 13:20 - 2012-07-26 12:04 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-08-18 13:17 - 2011-12-17 01:24 - 00000000 ____D () C:\Users\Matthias\AppData\Local\Overwolf 2014-08-18 13:16 - 2013-07-22 22:48 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Dropbox 2014-08-18 13:15 - 2011-12-20 21:31 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\.oit 2014-08-18 13:15 - 2011-10-25 02:22 - 00000000 ___HD () C:\ASUS.DAT 2014-08-18 13:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-18 13:14 - 2009-07-14 06:51 - 00182762 _____ () C:\Windows\setupact.log 2014-08-18 13:13 - 2011-08-31 16:40 - 01633202 _____ () C:\Windows\WindowsUpdate.log 2014-08-18 13:02 - 2012-02-26 21:14 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\TS3Client 2014-08-18 12:56 - 2012-04-01 12:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-18 11:03 - 2012-02-26 21:18 - 00000000 ____D () C:\Users\Matthias\AppData\Local\CrashDumps 2014-08-18 09:59 - 2014-08-18 09:59 - 02101760 _____ (Farbar) C:\Users\Matthias\Desktop\FRST64.exe 2014-08-18 09:42 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-18 09:42 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-18 09:30 - 2009-07-14 06:45 - 00314176 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-17 23:44 - 2014-08-16 01:09 - 00057730 _____ () C:\Users\Matthias\Downloads\FRST.txt 2014-08-17 23:40 - 2014-08-17 23:40 - 00000739 _____ () C:\Users\Matthias\Desktop\JRT.txt 2014-08-17 23:20 - 2011-04-13 03:39 - 02310014 _____ () C:\Windows\PFRO.log 2014-08-17 23:19 - 2014-08-16 00:31 - 00000000 ____D () C:\AdwCleaner 2014-08-16 23:43 - 2014-08-16 23:43 - 04161313 _____ () C:\Users\Matthias\Downloads\tdsskiller.zip 2014-08-16 23:43 - 2014-07-10 12:38 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Matthias\Desktop\TDSSKiller.exe 2014-08-16 23:39 - 2014-08-16 23:38 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Matthias\Downloads\tdsskiller.exe 2014-08-16 21:21 - 2014-08-16 21:21 - 00054036 _____ () C:\ComboFix.txt 2014-08-16 21:21 - 2014-08-16 20:49 - 00000000 ____D () C:\Qoobox 2014-08-16 21:21 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-08-16 21:20 - 2014-08-16 20:48 - 00000000 ____D () C:\Windows\erdnt 2014-08-16 21:15 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-08-16 21:08 - 2011-10-25 02:22 - 00000000 ____D () C:\Users\Matthias 2014-08-16 20:48 - 2014-08-16 20:47 - 05571320 ____R (Swearware) C:\Users\Matthias\Downloads\ComboFix.exe 2014-08-16 13:30 - 2014-08-15 17:15 - 00000000 ____D () C:\Users\Matthias\Desktop\Stronghold-Teile 2014-08-16 01:58 - 2014-08-16 01:58 - 00000000 ____D () C:\Users\Matthias\Desktop\Protokolle 2014-08-16 01:15 - 2014-08-16 01:10 - 00041952 _____ () C:\Users\Matthias\Downloads\Addition.txt 2014-08-16 00:56 - 2014-08-16 00:56 - 00000000 ____D () C:\Windows\ERUNT 2014-08-16 00:54 - 2014-08-16 00:54 - 01016261 _____ (Thisisu) C:\Users\Matthias\Downloads\JRT.exe 2014-08-16 00:31 - 2014-08-16 00:31 - 01361203 _____ () C:\Users\Matthias\Downloads\adwcleaner_3.306.exe 2014-08-15 22:21 - 2011-12-13 17:49 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Skype 2014-08-15 20:10 - 2011-10-25 02:22 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-08-15 17:16 - 2014-08-15 17:16 - 00000000 ____D () C:\Users\Matthias\Desktop\Sherlock Holmes -Teile 2014-08-15 14:59 - 2013-10-25 15:15 - 00000000 ____D () C:\Program Files (x86)\appbarioDE_1 2014-08-14 21:17 - 2014-08-14 21:16 - 00000000 ____D () C:\Users\Matthias\Desktop\Diverse Dateien 2014-08-14 21:16 - 2014-08-14 21:14 - 00000000 ____D () C:\Users\Matthias\Desktop\Diverse Ordner 2014-08-14 19:20 - 2013-07-21 19:17 - 00000000 ____D () C:\Users\Matthias\.gimp-2.8 2014-08-14 18:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-14 18:14 - 2013-08-15 02:23 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-14 18:10 - 2011-12-17 15:15 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-14 18:04 - 2014-05-07 01:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-14 17:08 - 2011-08-31 16:54 - 00002902 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-08-14 17:08 - 2011-08-31 16:54 - 00001973 _____ () C:\Windows\system32\ServiceFilter.ini 2014-08-14 17:03 - 2012-07-30 20:53 - 00000000 ____D () C:\ProgramData\YTD YouTube Downloader & Converter 2014-08-14 16:04 - 2012-07-31 00:15 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\hellomoto 2014-08-14 15:57 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-08-14 15:56 - 2014-08-14 15:56 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-14 15:56 - 2014-08-14 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-14 15:56 - 2014-08-14 15:56 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-14 15:56 - 2013-04-01 20:55 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-14 15:55 - 2014-08-14 15:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Matthias\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-14 15:41 - 2013-07-22 23:48 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\puush 2014-08-14 15:31 - 2012-06-29 22:32 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-08-14 15:06 - 2012-12-04 20:02 - 00000000 ____D () C:\Program Files (x86)\EA Games 2014-08-14 14:48 - 2014-08-14 14:48 - 00001270 _____ () C:\Users\Matthias\Desktop\Revo Uninstaller.lnk 2014-08-14 14:48 - 2014-08-14 14:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-14 14:47 - 2014-08-14 14:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Matthias\Downloads\revosetup.exe 2014-08-14 14:40 - 2014-08-14 14:38 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Infigo 2014-08-14 14:38 - 2014-08-14 14:38 - 00000993 _____ () C:\Users\Matthias\Desktop\Infigo.lnk 2014-08-14 14:38 - 2014-08-14 14:38 - 00000199 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2014-08-14 14:38 - 2014-08-14 14:38 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Infigo 2014-08-14 14:38 - 2014-08-14 14:38 - 00000000 ____D () C:\Program Files (x86)\Infigo 2014-08-14 14:37 - 2014-08-14 14:37 - 07501568 _____ () C:\Users\Matthias\Downloads\Infigo_setup.exe 2014-08-14 09:09 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2014-08-13 10:36 - 2012-02-26 21:13 - 00000000 ____D () C:\Users\Matthias\AppData\Local\TeamSpeak 3 Client 2014-08-13 02:22 - 2012-12-12 22:06 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\SoftGrid Client 2014-08-12 21:04 - 2014-08-12 21:04 - 00000932 _____ () C:\Users\Public\Desktop\CPUID HWMonitor.lnk 2014-08-12 21:04 - 2014-08-12 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID 2014-08-12 21:04 - 2014-08-12 21:04 - 00000000 ____D () C:\Program Files\CPUID 2014-08-12 16:08 - 2011-12-17 01:26 - 00000000 ____D () C:\Program Files (x86)\Overwolf 2014-08-12 00:22 - 2013-10-25 15:13 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-08-08 16:22 - 2014-08-08 16:16 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-08 16:22 - 2014-03-05 16:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-08 16:22 - 2014-03-05 16:55 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-08 16:22 - 2014-02-16 13:46 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-08 16:16 - 2014-03-05 16:55 - 00000000 ____D () C:\ProgramData\Avira 2014-08-07 18:30 - 2011-12-13 17:49 - 00000000 ____D () C:\ProgramData\Skype 2014-08-07 04:06 - 2014-08-14 18:01 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-14 18:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-07 02:57 - 2013-08-25 18:12 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Audacity 2014-08-07 02:55 - 2014-08-07 02:55 - 00004122 _____ () C:\Users\Matthias\Documents\test.wav.wlmp 2014-08-07 01:37 - 2014-08-06 19:48 - 00000000 ____D () C:\Users\Matthias\Documents\Detektic Conan Projekt 2014-08-07 00:08 - 2012-04-19 19:34 - 00997888 ___SH () C:\Users\Matthias\Documents\Thumbs.db 2014-08-06 20:19 - 2012-04-11 17:14 - 00000000 ____D () C:\Users\Matthias\Documents\Sonstiges 2014-08-06 19:51 - 2011-11-06 22:14 - 00000000 ____D () C:\Users\Matthias\Documents\Schule 2014-08-06 19:50 - 2014-08-06 19:48 - 00000000 ____D () C:\Users\Matthias\Documents\Cha-Cha-Cha 2014-08-06 19:49 - 2012-01-26 18:22 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-08-06 19:34 - 2012-01-23 18:26 - 00000000 ____D () C:\Users\Matthias\AppData\Local\Windows Live 2014-08-03 17:08 - 2014-08-03 17:08 - 00000222 _____ () C:\Users\Matthias\Desktop\The Forest.url 2014-08-03 17:08 - 2012-07-26 12:24 - 00000000 ____D () C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-08-03 15:09 - 2011-12-13 17:49 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-08-02 15:18 - 2012-01-01 16:51 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft 2014-08-01 01:41 - 2014-08-14 18:04 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-01 01:16 - 2014-08-14 18:04 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-25 16:52 - 2014-08-14 18:04 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-25 16:02 - 2014-08-14 18:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-25 16:01 - 2014-08-14 18:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-25 15:51 - 2014-08-14 18:04 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-25 15:30 - 2014-08-14 18:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-25 15:28 - 2014-08-14 18:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-25 15:28 - 2014-08-14 18:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-25 15:25 - 2014-08-14 18:04 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-25 15:25 - 2014-08-14 18:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-25 15:11 - 2014-08-14 18:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-25 15:10 - 2014-08-14 18:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-25 15:04 - 2014-08-14 18:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-25 15:03 - 2014-08-14 18:04 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-25 15:00 - 2014-08-14 18:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-25 15:00 - 2014-08-14 18:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-25 14:59 - 2014-08-14 18:04 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-25 14:47 - 2014-08-14 18:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-25 14:40 - 2014-08-14 18:04 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-25 14:34 - 2014-08-14 18:04 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-25 14:34 - 2014-08-14 18:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-25 14:34 - 2013-03-14 01:00 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-25 14:34 - 2011-04-13 04:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-25 14:33 - 2014-08-14 18:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-25 14:30 - 2014-08-14 18:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-25 14:28 - 2014-08-14 18:04 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-25 14:28 - 2014-08-14 18:04 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-25 14:21 - 2014-08-14 18:04 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-25 14:19 - 2014-08-14 18:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-25 14:18 - 2014-08-14 18:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-25 14:17 - 2014-08-14 18:04 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-25 14:17 - 2014-08-14 18:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-25 14:12 - 2014-08-14 18:04 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-25 14:10 - 2014-08-14 18:04 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-25 14:10 - 2014-08-14 18:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-25 14:08 - 2014-08-14 18:04 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-25 14:06 - 2014-08-14 18:04 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-25 13:52 - 2014-08-14 18:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-25 13:47 - 2014-08-14 18:04 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-25 13:43 - 2014-08-14 18:04 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-25 13:42 - 2014-08-14 18:04 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-25 13:39 - 2014-08-14 18:04 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-25 13:39 - 2014-08-14 18:04 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-25 13:36 - 2014-08-14 18:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-25 13:34 - 2014-08-14 18:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-25 13:29 - 2014-08-14 18:04 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-25 13:23 - 2014-08-14 18:04 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-25 13:13 - 2014-08-14 18:04 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-25 13:07 - 2014-08-14 18:04 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-25 13:07 - 2014-08-14 18:04 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-25 13:03 - 2014-08-14 18:04 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-25 12:52 - 2014-08-14 18:04 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-25 12:26 - 2014-08-14 18:04 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-25 12:17 - 2014-08-14 18:04 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-25 12:09 - 2014-08-14 18:04 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-25 12:05 - 2014-08-14 18:04 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-25 12:00 - 2014-08-14 18:04 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-25 02:17 - 2013-04-06 03:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight Some content of TEMP: ==================== C:\Users\Matthias\AppData\Local\Temp\avgnt.exe C:\Users\Matthias\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-09 17:36 ==================== End Of Log ============================ --- --- --- Habe zuerst den Laptop Neu getsartet und dann gescannt. |
18.08.2014, 12:54 | #39 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst] Hat sich der Windows-Explorer wieder eingerenkt?
__________________ Logfiles bitte immer in CODE-Tags posten |
18.08.2014, 13:12 | #40 |
| Windows-Explorer Funktioniert nicht mehr? [gelöst] Wenn du direkt nach dem Vorgang meinst, nein. Bin aber ein paar mal zu ''Bilder'' , dann wieder Download, dann wieder Bilder, dann wieder Doawnload, und dann kam wieder Internet Explorer funktioniert nicht mehr etc. |
18.08.2014, 13:41 | #41 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst]Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten Geändert von cosinus (18.08.2014 um 13:43 Uhr) Grund: typo |
18.08.2014, 14:58 | #42 |
| Windows-Explorer Funktioniert nicht mehr? [gelöst] Ich meine Windows Explorer, verwrchsel die beiden gerne |
18.08.2014, 15:16 | #43 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst] Okay, erstmal Kontrollscans mit MBAM und ESET bitte: Downloade Dir bitte Malwarebytes Anti-Malware
ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
18.08.2014, 16:31 | #44 |
| Windows-Explorer Funktioniert nicht mehr? [gelöst] 1. Schritt: Es wurde nach dem Scan nichts gefunden, weshlab ich den Rechner auch nicht neu gestartete habe. Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Protection, 14.08.2014 15:57:03, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, Starting, Protection, 14.08.2014 15:57:03, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, Started, Protection, 14.08.2014 15:57:03, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Update, 14.08.2014 15:57:12, SYSTEM, MATTHIAS-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.8.4.1, Update, 14.08.2014 15:57:37, SYSTEM, MATTHIAS-PC, Manual, Malware Database, 2014.3.4.9, 2014.8.14.6, Protection, 14.08.2014 15:57:38, SYSTEM, MATTHIAS-PC, Protection, Refresh, Starting, Protection, 14.08.2014 15:58:14, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, Protection, 14.08.2014 15:58:14, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopping, Protection, 14.08.2014 15:58:14, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopped, Protection, 14.08.2014 15:58:18, SYSTEM, MATTHIAS-PC, Protection, Refresh, Success, Protection, 14.08.2014 15:58:18, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Protection, 14.08.2014 15:58:18, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, Detection, 14.08.2014 15:58:25, Matthias, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Detection, 14.08.2014 15:58:32, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 15:58:32, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 15:58:32, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Detection, 14.08.2014 16:00:09, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 16:00:09, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 16:00:09, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Detection, 14.08.2014 16:02:10, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 16:02:10, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 16:02:10, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Detection, 14.08.2014 16:04:22, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, Trojan.Ransom.FGen, C:\Users\Matthias\AppData\Roaming\hellomoto\TujP.dat, Quarantine, [b8c6972fe695c3735b4b5995887baf51] Detection, 14.08.2014 16:04:23, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 16:04:23, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 16:04:23, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Detection, 14.08.2014 16:06:25, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 16:06:25, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 16:06:25, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Detection, 14.08.2014 16:08:26, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 16:08:26, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 16:08:26, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Detection, 14.08.2014 16:10:27, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 16:10:27, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 16:10:27, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Detection, 14.08.2014 16:27:46, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.Skytech.A, c:\program files (x86)\suptab\searchprotect64.dll, Quarantine, [ceb0e6e0126993a3aa23f898e41d49b7] Protection, 14.08.2014 16:27:47, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Error, 14.08.2014 16:27:47, SYSTEM, MATTHIAS-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\suptab\searchprotect64.dll, Update, 14.08.2014 16:52:33, SYSTEM, MATTHIAS-PC, Scheduler, Malware Database, 2014.8.14.6, 2014.8.14.7, Protection, 14.08.2014 16:53:31, SYSTEM, MATTHIAS-PC, Protection, Refresh, Starting, Protection, 14.08.2014 16:53:31, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopping, Protection, 14.08.2014 16:53:31, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopped, Protection, 14.08.2014 16:53:37, SYSTEM, MATTHIAS-PC, Protection, Refresh, Success, Protection, 14.08.2014 16:53:37, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Protection, 14.08.2014 16:53:38, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, Detection, 14.08.2014 16:56:58, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurfdc171.exe, Quarantine, [a6d9cff7dba01f17b728b40959a9f20e] Detection, 14.08.2014 17:06:06, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, File, PUP.Optional.SweetIM, C:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll, Quarantine, [037cfec8a8d346f0aec800f405ff0cf4] Protection, 14.08.2014 17:06:06, SYSTEM, MATTHIAS-PC, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll, Error, 14.08.2014 17:06:06, SYSTEM, MATTHIAS-PC, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll, Protection, 14.08.2014 17:08:29, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, Starting, Protection, 14.08.2014 17:08:29, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, Started, Protection, 14.08.2014 17:08:29, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Protection, 14.08.2014 17:11:16, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, Update, 14.08.2014 17:42:58, SYSTEM, MATTHIAS-PC, Scheduler, Malware Database, 2014.8.14.7, 2014.8.14.8, Protection, 14.08.2014 17:43:01, SYSTEM, MATTHIAS-PC, Protection, Refresh, Starting, Protection, 14.08.2014 17:43:01, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopping, Protection, 14.08.2014 17:43:01, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopped, Protection, 14.08.2014 17:43:37, SYSTEM, MATTHIAS-PC, Protection, Refresh, Success, Protection, 14.08.2014 17:43:37, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Protection, 14.08.2014 17:43:37, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, Protection, 14.08.2014 18:27:06, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, Starting, Protection, 14.08.2014 18:27:06, SYSTEM, MATTHIAS-PC, Protection, Malware Protection, Started, Protection, 14.08.2014 18:27:06, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Protection, 14.08.2014 18:28:30, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, Update, 14.08.2014 18:50:42, SYSTEM, MATTHIAS-PC, Scheduler, Malware Database, 2014.8.14.8, 2014.8.14.9, Protection, 14.08.2014 18:50:45, SYSTEM, MATTHIAS-PC, Protection, Refresh, Starting, Protection, 14.08.2014 18:50:45, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopping, Protection, 14.08.2014 18:50:45, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopped, Protection, 14.08.2014 18:50:49, SYSTEM, MATTHIAS-PC, Protection, Refresh, Success, Protection, 14.08.2014 18:50:49, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Protection, 14.08.2014 18:50:49, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, Update, 14.08.2014 21:03:17, SYSTEM, MATTHIAS-PC, Scheduler, Malware Database, 2014.8.14.9, 2014.8.14.10, Protection, 14.08.2014 21:03:18, SYSTEM, MATTHIAS-PC, Protection, Refresh, Starting, Protection, 14.08.2014 21:03:18, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopping, Protection, 14.08.2014 21:03:19, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Stopped, Protection, 14.08.2014 21:03:23, SYSTEM, MATTHIAS-PC, Protection, Refresh, Success, Protection, 14.08.2014 21:03:23, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Starting, Protection, 14.08.2014 21:03:23, SYSTEM, MATTHIAS-PC, Protection, Malicious Website Protection, Started, (end) |
18.08.2014, 17:21 | #45 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows-Explorer Funktioniert nicht mehr? [gelöst] Ist aber trotzdem das falsche Log von MBAM
__________________ Logfiles bitte immer in CODE-Tags posten |