|
Log-Analyse und Auswertung: Gdata läßt sich nicht öffnen !Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
06.09.2014, 19:02 | #16 |
/// the machine /// TB-Ausbilder | Gdata läßt sich nicht öffnen ! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter KU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Ordner D:\Downloads leeren. Frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.09.2014, 20:24 | #17 |
| Gdata läßt sich nicht öffnen ! Hallo Schrauber,
__________________hier die neue Fixlog. Gdata läßt sich wieder starten. Gruß Otscho Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-08-2014 02 Ran by Acer at 2014-09-06 21:22:17 Run:2 Running from C:\Users\Downloads\First Boot Mode: Normal ============================================== Content of fixlist: ***************** KU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION ***************** KU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} => Error: No automatic fix found for this entry. HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully. HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully. HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully. ==== End of Fixlog ==== |
07.09.2014, 13:06 | #18 |
/// the machine /// TB-Ausbilder | Gdata läßt sich nicht öffnen ! Frisches FRST Scanlog bitte
__________________
__________________ |
07.09.2014, 14:56 | #19 |
| Gdata läßt sich nicht öffnen ! Hallo, hier ein neues log. Gruß Otscho FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02 Ran by Acer (administrator) on ACER-PC on 07-09-2014 15:52:22 Running from C:\Users\Downloads\First Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GdBgInx64.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Box, Inc.) C:\Program Files\Box\Box Sync\BoxSync.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\lync.exe () C:\Program Files (x86)\RocketDock\RocketDock.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe (Box, Inc.) C:\Program Files\Box\Box Sync\BoxSync.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe () C:\Program Files\Box\Box Sync\BoxSyncMonitor.exe (CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (GP Software) C:\Program Files\GPSoftware\Directory Opus\dopus.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11785832 2011-03-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-09] (Realtek Semiconductor) HKLM\...\Run: [BoxSync] => C:\Program Files\Box\Box Sync\BoxSync.exe [13540752 2014-08-22] (Box, Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.) HKLM-x32\...\Run: [G Data ASM] => C:\Program Files (x86)\G Data\InternetSecurity\DelayLoader\AutorunDelayLoader.exe [431224 2013-12-19] (G Data Software AG) HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1756792 2014-05-20] (G Data Software AG) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-3406220267-2230971110-2032019791-1000\...\Run: [Lync] => C:\Program Files\Microsoft Office 15\root\office15\lync.exe [18999456 2014-08-26] (Microsoft Corporation) HKU\S-1-5-21-3406220267-2230971110-2032019791-1000\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () Startup: C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneDrive for Business.lnk ShortcutTarget: OneDrive for Business.lnk -> C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: 0000BoxSyncFileLocked -> {472d7e0f-709e-3d42-adf8-3ccc2f0ed21c} => C:\Windows\system32\mscoree.dll (Microsoft Corporation) ShellIconOverlayIdentifiers: 0000BoxSyncNotSynced -> {697ea78e-7d56-3e3d-9463-70807d4e6c6c} => C:\Windows\system32\mscoree.dll (Microsoft Corporation) ShellIconOverlayIdentifiers: 0000BoxSyncProblem -> {d9161200-fd91-3d5f-91bf-3b63c48f2ee4} => C:\Windows\system32\mscoree.dll (Microsoft Corporation) ShellIconOverlayIdentifiers: 0000BoxSyncSynced -> {3e98134b-38c1-3752-87b3-7dc5a5c95620} => C:\Windows\system32\mscoree.dll (Microsoft Corporation) ShellIconOverlayIdentifiers: 01UnsuppModule -> {AEB16659-2125-4ADA-A4AB-45EE21E86469} => C:\Users\Acer\AppData\Local\CloudStation\iconoverlay_v2\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 02SyncingModule -> {48AB5ADA-36B1-4137-99C9-2BD97F8788AB} => C:\Users\Acer\AppData\Local\CloudStation\iconoverlay_v2\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 03SyncedModule -> {472CE1AD-5D53-4BCF-A1FB-3982A5F55138} => C:\Users\Acer\AppData\Local\CloudStation\iconoverlay_v2\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: AcronisSyncError -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncInProgress -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncOk -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: No Name -> {5114DD3B-516D-EF4E-E0F7-1DA15B707DB5} -> No File BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name -> {7C11799F-052C-9921-E37C-6015BD7BAD44} -> No File BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - C:\Program Files (x86)\FireShot for Internet Explorer\fsaddin64-0.983.dll (getfireshot.com) Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No File Toolbar: HKLM-x32 - No Name - !{9E131A93-EED7-4BEB-B015-A0ADB30B5646} - No File Toolbar: HKLM-x32 - No Name - !{F9639E4A-801B-4843-AEE3-03D9DA199E77} - No File Toolbar: HKLM-x32 - FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - C:\Program Files (x86)\FireShot for Internet Explorer\fsaddin-0.983.dll (getfireshot.com) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks: Directory Opus Shell Execute Hook - {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll [1571456 2014-07-04] (GP Software) ShellExecuteHooks-x32: Directory Opus Shell Execute Hook - {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - C:\Program Files\GPSoftware\Directory Opus\dopuslib32.dll [343128 2014-07-04] (GP Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\hes6phug.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll No File FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll No File FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: Soda PDF 6 -> C:\Program Files (x86)\Soda PDF 6\np-previewer.dll (LULU SOFTWARE LIMITED) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\hes6phug.default\Extensions\2020Player_IKEA@2020Technologies.com [2014-02-22] FF Extension: FireShot - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\hes6phug.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2014-07-26] FF Extension: Firebug - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\hes6phug.default\Extensions\firebug@software.joehewitt.com.xpi [2014-02-08] FF Extension: FireFTP - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\hes6phug.default\Extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}.xpi [2014-02-08] FF Extension: Web Developer - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\hes6phug.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2014-02-08] FF Extension: Adblock Plus - C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\hes6phug.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-19] FF Extension: Anti-Banner - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 [2014-09-02] FF Extension: Modul zur Link-Untersuchung - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 [2014-09-02] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-09-02] FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-05-12] FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff Chrome: ======= CHR HomePage: Default -> CHR DefaultSearchKeyword: Default -> omiga-plus CHR DefaultSearchProvider: Default -> omiga-plus CHR DefaultSearchURL: Default -> hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1406193805&from=kmp&uid=INTELXSSDSA2BW120G3A_CVPR119603T8120LGN&q={searchTerms} CHR DefaultSuggestURL: Default -> CHR Profile: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-02] CHR Extension: (Google Wallet) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-18] CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-07-02] CHR HKLM-x32\...\Chrome\Extension: [fmlpgkiekchdonifafhpbchlkhacllpf] - C:\ProgramData\Download and Sa\fmlpgkiekchdonifafhpbchlkhacllpf.crx [] CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-05-06] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S4 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-03] (Adobe Systems Incorporated) S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations) [File not signed] R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-07-30] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2683760 2014-05-20] (G Data Software AG) S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [27672 2014-08-22] (Box, Inc.) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2369720 2014-08-01] (Microsoft Corporation) S4 CLKMSVC10_34E30CCC; C:\Program Files (x86)\Acer\clear.fi\Movie\NavFilter\kmsvc.exe [242664 2012-04-17] (CyberLink) R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed] S4 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [3227624 2014-08-06] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG) S4 GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [29696 2011-05-26] (Acer Incorporated) [File not signed] S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2013-11-12] () [File not signed] S4 LaCieDesktopManagerService; C:\Program Files\LaCie\Desktop Manager\lacie_dm_service.exe [1227776 2012-03-16] () [File not signed] S3 LULU Software CrashHandler; C:\Program Files (x86)\Soda PDF 6\crash-handler-ws.exe [744800 2014-06-20] (LULU SOFTWARE LIMITED) S4 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S4 NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [5352960 2011-04-07] (Native Instruments GmbH) [File not signed] S4 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation) S4 O&O CleverCache; C:\Program Files\OO Software\CleverCache\ooccag.exe [844616 2009-12-09] (O&O Software GmbH) S4 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2572072 2013-10-23] (O&O Software GmbH) S4 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV) S4 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] () S4 Soda PDF 6; C:\Program Files (x86)\Soda PDF 6\ws.exe [1655136 2014-06-20] (LULU SOFTWARE LIMITED) S4 Soda PDF 6 Creator; C:\Program Files (x86)\Soda PDF 6\creator-ws.exe [621408 2014-06-20] (LULU SOFTWARE LIMITED) S4 Virtual CDAudio Service; C:\Program Files (x86)\Audials\Audials 10\VCDWriter\64\VCDAudioService.exe [179464 2013-06-27] (RapidSolution Software AG) S4 WDDMService; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [288768 2011-03-09] (WDC) [File not signed] S4 WDFME; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [1066896 2011-03-09] () S4 WDSC; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [491920 2011-03-09] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [138400 2012-08-26] (SlySoft, Inc.) R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [138400 2012-08-26] (SlySoft, Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 AsapiW2K; C:\Windows\SysWOW64\drivers\Asapiw2k.sys [11264 2002-04-17] (VOB Computersysteme GmbH) [File not signed] R3 azvusb; C:\Windows\System32\DRIVERS\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.) R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [37704 2013-04-25] (Grass Valley K.K.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-02-23] (DT Soft Ltd) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) S3 ffusb2audio; C:\Windows\System32\DRIVERS\ffusb2audio.sys [125304 2012-09-10] (Focusrite Audio Engineering Limited.) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-09-03] (G Data Software AG) R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-09-03] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-09-03] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-09-03] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-09-03] (G Data Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-09-03] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-09-03] (G Data Software AG) S3 L6GX; C:\Windows\System32\Drivers\L6GX64.sys [772864 2013-06-26] (Line 6) S3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus64.sys [261120 2005-09-23] (Pinnacle Systems GmbH) [File not signed] S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 OXSDIDRV_x64; C:\Windows\System32\DRIVERS\OXSDIDRV_x64.sys [51760 2009-09-28] () R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-07-19] (Corel Corporation) S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-06-27] (RapidSolution Software AG) R3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-06-27] (RapidSolution Software AG) R3 rsvcdwdr; C:\Windows\System32\DRIVERS\rsvcdwdr.sys [45192 2013-06-27] (RapidSolution Software AG) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [1093256 2012-10-02] (Acronis) S0 TPkd; C:\Windows\SysWow64\Drivers\TPkd.sys [68928 2012-01-16] (PACE Anti-Piracy, Inc.) [File not signed] R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [166024 2012-10-02] (Acronis) R3 WsAudioDevice_383S(1); C:\Windows\System32\drivers\WsAudioDevice_383S(1).sys [29288 2011-11-17] (Wondershare) S3 ZMGHPAudioSrv; C:\Windows\System32\drivers\zmghpau.sys [45568 2013-05-22] (ZOOM) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-07 10:32 - 2014-09-07 10:32 - 00001545 _____ () C:\Users\Acer\Desktop\Box Sync.lnk 2014-09-07 10:32 - 2014-09-07 10:32 - 00000000 ___SD () C:\Users\Acer\Box Sync 2014-09-07 10:31 - 2014-09-07 10:32 - 00000000 ____D () C:\Users\Acer\AppData\Local\Box Sync 2014-09-07 10:31 - 2014-09-07 10:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync 2014-09-07 10:31 - 2014-09-07 10:31 - 00000000 ____D () C:\Program Files\Box 2014-09-07 10:29 - 2014-09-07 10:30 - 32833992 _____ (Box Inc.) C:\Users\Downloads\BoxSyncSetup.exe 2014-09-06 08:34 - 2014-09-06 08:34 - 00003662 _____ () C:\Users\Downloads\Eset.txt 2014-09-05 22:18 - 2014-09-05 22:18 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-05 22:15 - 2014-09-05 22:15 - 00854417 _____ () C:\Users\Downloads\SecurityCheck.exe 2014-09-05 22:14 - 2014-09-05 22:14 - 02347384 _____ (ESET) C:\Users\Downloads\esetsmartinstaller_deu.exe 2014-09-04 12:31 - 2014-09-04 12:31 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys 2014-09-03 23:52 - 2014-09-03 23:52 - 00000000 ____D () C:\Windows\ERUNT 2014-09-03 23:39 - 2014-09-03 23:39 - 00001152 _____ () C:\Users\Downloads\mbam.txt 2014-09-03 23:12 - 2014-09-03 23:12 - 01016261 _____ (Thisisu) C:\Users\Downloads\JRT.exe 2014-09-03 23:11 - 2014-09-03 23:11 - 01370483 _____ () C:\Users\Downloads\adwcleaner_3.309.exe 2014-09-03 23:08 - 2014-09-03 23:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-03 22:01 - 2014-09-03 22:01 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2014-09-03 21:58 - 2014-09-03 21:58 - 00001942 _____ () C:\Users\Public\Desktop\G DATA INTERNET SECURITY.lnk 2014-09-03 21:58 - 2014-09-03 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA INTERNET SECURITY 2014-09-03 21:45 - 2014-09-03 21:58 - 00142336 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2014-09-03 21:45 - 2014-09-03 21:58 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2014-09-03 21:45 - 2014-09-03 21:58 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2014-09-03 21:45 - 2014-09-03 21:58 - 00061440 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2014-09-03 21:45 - 2014-09-03 21:58 - 00055808 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2014-09-03 21:45 - 2014-09-03 21:58 - 00020992 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys 2014-09-03 13:50 - 2014-09-03 13:50 - 00135010 _____ () C:\ComboFix.txt 2014-09-03 13:41 - 2014-09-03 13:50 - 00000000 ____D () C:\Qoobox 2014-09-03 13:41 - 2014-09-03 13:48 - 00000000 ____D () C:\Windows\erdnt 2014-09-03 13:41 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-03 13:41 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-03 13:41 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-03 13:41 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-03 13:41 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-03 13:41 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-03 13:41 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-03 13:41 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-03 13:39 - 2014-09-03 13:38 - 05576326 ____R (Swearware) C:\Users\Acer\Desktop\ComboFix.exe 2014-09-02 22:50 - 2014-09-02 22:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-02 13:46 - 2014-09-02 13:46 - 00030613 _____ () C:\Users\Downloads\First.rar 2014-09-02 13:41 - 2014-09-02 13:41 - 00004273 _____ () C:\Users\Downloads\Logfiles.rar 2014-09-02 13:11 - 2014-09-02 13:11 - 00073299 _____ () C:\Users\Downloads\gmer.txt 2014-09-02 12:08 - 2014-09-02 12:08 - 00000470 _____ () C:\Users\Downloads\defogger_disable.log 2014-09-02 11:47 - 2014-09-02 11:47 - 00000000 _____ () C:\Users\Acer\defogger_reenable 2014-09-02 11:22 - 2014-09-02 11:23 - 00000000 ____D () C:\Users\Downloads\Service scan 2014-09-02 11:11 - 2014-09-07 15:52 - 00000000 ____D () C:\Users\Downloads\First 2014-09-02 11:11 - 2014-09-02 11:12 - 00000000 ____D () C:\Users\Downloads\Gdata 2014-09-02 10:50 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-09-02 10:19 - 2014-09-07 15:52 - 00000000 ____D () C:\FRST 2014-08-31 00:29 - 2014-09-03 21:42 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-08-31 00:29 - 2014-08-31 00:36 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-08-31 00:29 - 2014-08-31 00:29 - 00707354 _____ () C:\Windows\unins000.exe 2014-08-31 00:29 - 2014-08-31 00:29 - 00001529 _____ () C:\Windows\unins000.dat 2014-08-31 00:29 - 2014-08-31 00:29 - 00000000 ____D () C:\Windows\SysWOW64\GPBAK 2014-08-31 00:29 - 2008-04-14 02:11 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgr.dll 2014-08-31 00:29 - 2001-08-23 13:00 - 00034871 _____ () C:\Windows\SysWOW64\gpedit.msc 2014-08-31 00:29 - 2001-08-23 13:00 - 00034871 _____ () C:\Windows\system32\gpedit.msc 2014-08-31 00:27 - 2014-08-31 00:27 - 00875012 _____ () C:\Users\Downloads\group_policy.zip 2014-08-30 23:53 - 2014-08-30 23:53 - 00000000 ____D () C:\Users\Downloads\406874_intl_x64_zip 2014-08-30 22:01 - 2014-08-30 22:01 - 00000000 ____D () C:\bootmedium 2014-08-30 20:48 - 2014-09-06 19:52 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-30 20:47 - 2014-09-03 23:14 - 00001070 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-30 20:47 - 2014-09-03 23:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-30 20:47 - 2014-09-03 23:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-30 20:47 - 2014-08-30 20:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-30 20:47 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-30 20:47 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-30 20:47 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-30 20:21 - 2014-08-30 22:50 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Nico Mak Computing 2014-08-30 12:31 - 2014-08-30 12:37 - 226580480 _____ () C:\Users\Downloads\GDBootMedium_2014.iso 2014-08-30 09:41 - 2014-08-30 09:45 - 00000000 ____D () C:\Users\Acer\AppData\OICE_15_974FA576_32C1D314_F3B 2014-08-29 17:01 - 2014-08-30 10:03 - 00000000 ____D () C:\Users\Downloads\piwik 2014-08-29 16:48 - 2014-08-29 16:48 - 00022789 _____ () C:\Users\Downloads\Contao_PiwikTrackingTag_20030029_6.zip 2014-08-28 12:41 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-28 12:41 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 12:41 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-24 18:35 - 2013-08-10 16:39 - 01839104 _____ () C:\Users\Downloads\memtest86+-5.01.iso 2014-08-24 13:29 - 2014-08-24 13:29 - 00007817 _____ () C:\Windows\BROMJ245.INI 2014-08-23 13:47 - 2014-08-23 13:47 - 00002103 _____ () C:\Users\Acer\Desktop\Skype.lnk 2014-08-23 10:46 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-23 10:46 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-23 10:46 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-23 10:46 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-23 10:46 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-23 10:46 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-23 10:46 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-23 10:46 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-23 10:46 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-23 10:46 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-23 10:46 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-23 10:46 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-23 10:46 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-23 10:46 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-08-15 10:01 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-15 10:01 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-15 10:01 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-15 10:01 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-15 10:01 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-15 10:01 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-15 10:01 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-15 10:01 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-15 09:54 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-15 09:54 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-15 09:54 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-15 09:54 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-15 09:54 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-15 09:54 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-15 09:54 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-15 09:54 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-15 09:54 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-15 09:54 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-15 09:54 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-15 09:54 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-15 09:54 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-15 09:54 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-15 09:54 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-15 09:54 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-15 09:54 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-15 09:54 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-15 09:54 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-15 09:54 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-15 09:54 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-15 09:54 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-15 09:54 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-15 09:54 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-15 09:54 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-15 09:54 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-15 09:54 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-15 09:54 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-15 09:54 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-15 09:54 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-15 09:54 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-15 09:54 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-15 09:54 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-15 09:54 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-15 09:54 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-15 09:54 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-15 09:54 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-15 09:54 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-15 09:54 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-15 09:54 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-15 09:54 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-15 09:54 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-15 09:54 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-15 09:54 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-15 09:54 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-15 09:54 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-15 09:54 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-15 09:54 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-15 09:54 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-15 09:54 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-15 09:54 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-15 09:54 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-15 09:54 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-15 09:54 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-15 09:54 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-15 09:54 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-15 09:54 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-15 09:54 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-15 09:54 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-15 09:54 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-15 09:54 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-15 09:54 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-15 09:54 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-15 09:54 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-15 09:54 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-15 09:54 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-15 09:54 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-15 09:54 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-15 09:54 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-15 09:54 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-15 09:54 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-15 09:54 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-15 09:54 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-15 09:54 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-15 09:54 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-15 09:54 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-15 09:54 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-15 09:54 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-15 09:54 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-15 09:54 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-15 09:53 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-15 09:53 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-15 09:53 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-15 09:53 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-07 15:52 - 2014-09-02 11:11 - 00000000 ____D () C:\Users\Downloads\First 2014-09-07 15:52 - 2014-09-02 10:19 - 00000000 ____D () C:\FRST 2014-09-07 15:48 - 2014-02-19 22:30 - 00005128 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Acer-PC-Acer Acer-PC 2014-09-07 15:48 - 2013-12-08 23:04 - 00034549 _____ () C:\Windows\setupact.log 2014-09-07 15:48 - 2012-09-09 15:12 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-07 15:48 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-07 10:35 - 2011-07-05 21:38 - 01933494 _____ () C:\Windows\WindowsUpdate.log 2014-09-07 10:34 - 2011-07-21 16:21 - 00000000 ____D () C:\Users\Acer\AppData\Local\CrashDumps 2014-09-07 10:33 - 2012-09-09 15:12 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-07 10:32 - 2014-09-07 10:32 - 00001545 _____ () C:\Users\Acer\Desktop\Box Sync.lnk 2014-09-07 10:32 - 2014-09-07 10:32 - 00000000 ___SD () C:\Users\Acer\Box Sync 2014-09-07 10:32 - 2014-09-07 10:31 - 00000000 ____D () C:\Users\Acer\AppData\Local\Box Sync 2014-09-07 10:32 - 2011-07-21 11:27 - 00000000 ____D () C:\Users\Acer 2014-09-07 10:31 - 2014-09-07 10:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync 2014-09-07 10:31 - 2014-09-07 10:31 - 00000000 ____D () C:\Program Files\Box 2014-09-07 10:31 - 2013-05-25 12:45 - 00000000 ____D () C:\ProgramData\Package Cache 2014-09-07 10:30 - 2014-09-07 10:29 - 32833992 _____ (Box Inc.) C:\Users\Downloads\BoxSyncSetup.exe 2014-09-07 10:26 - 2012-04-03 18:06 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-07 10:20 - 2014-01-24 14:33 - 00000000 ____D () C:\Users\Acer\iPIN 2014-09-07 10:05 - 2011-07-21 15:41 - 00000000 ____D () C:\Users\Acer\AppData\Local\Adobe 2014-09-07 10:02 - 2009-07-14 06:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-07 10:02 - 2009-07-14 06:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-07 09:59 - 2011-07-06 07:32 - 00703230 _____ () C:\Windows\system32\perfh007.dat 2014-09-07 09:59 - 2011-07-06 07:32 - 00150838 _____ () C:\Windows\system32\perfc007.dat 2014-09-07 09:59 - 2009-07-14 07:13 - 01629444 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-06 19:52 - 2014-08-30 20:48 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-06 08:34 - 2014-09-06 08:34 - 00003662 _____ () C:\Users\Downloads\Eset.txt 2014-09-05 22:18 - 2014-09-05 22:18 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-05 22:15 - 2014-09-05 22:15 - 00854417 _____ () C:\Users\Downloads\SecurityCheck.exe 2014-09-05 22:14 - 2014-09-05 22:14 - 02347384 _____ (ESET) C:\Users\Downloads\esetsmartinstaller_deu.exe 2014-09-04 12:31 - 2014-09-04 12:31 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys 2014-09-03 23:52 - 2014-09-03 23:52 - 00000000 ____D () C:\Windows\ERUNT 2014-09-03 23:46 - 2013-12-08 23:04 - 01106400 _____ () C:\Windows\PFRO.log 2014-09-03 23:46 - 2013-12-06 11:40 - 00000000 ____D () C:\AdwCleaner 2014-09-03 23:39 - 2014-09-03 23:39 - 00001152 _____ () C:\Users\Downloads\mbam.txt 2014-09-03 23:14 - 2014-08-30 20:47 - 00001070 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-03 23:14 - 2014-08-30 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-03 23:14 - 2014-08-30 20:47 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-03 23:12 - 2014-09-03 23:12 - 01016261 _____ (Thisisu) C:\Users\Downloads\JRT.exe 2014-09-03 23:11 - 2014-09-03 23:11 - 01370483 _____ () C:\Users\Downloads\adwcleaner_3.309.exe 2014-09-03 23:09 - 2014-09-03 23:08 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-03 22:01 - 2014-09-03 22:01 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2014-09-03 21:58 - 2014-09-03 21:58 - 00001942 _____ () C:\Users\Public\Desktop\G DATA INTERNET SECURITY.lnk 2014-09-03 21:58 - 2014-09-03 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA INTERNET SECURITY 2014-09-03 21:58 - 2014-09-03 21:45 - 00142336 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2014-09-03 21:58 - 2014-09-03 21:45 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2014-09-03 21:58 - 2014-09-03 21:45 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2014-09-03 21:58 - 2014-09-03 21:45 - 00061440 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2014-09-03 21:58 - 2014-09-03 21:45 - 00055808 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2014-09-03 21:58 - 2014-09-03 21:45 - 00020992 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys 2014-09-03 21:58 - 2014-01-18 23:05 - 00036798 _____ () C:\Windows\DPINST.LOG 2014-09-03 21:47 - 2012-08-18 12:00 - 00000000 ____D () C:\ProgramData\G DATA 2014-09-03 21:45 - 2014-07-07 13:19 - 00001558 _____ () C:\Users\Acer\AppData\Roaming\gdscan.log 2014-09-03 21:44 - 2012-08-18 12:00 - 00000000 ____D () C:\Program Files (x86)\G Data 2014-09-03 21:42 - 2014-08-31 00:29 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-09-03 13:50 - 2014-09-03 13:50 - 00135010 _____ () C:\ComboFix.txt 2014-09-03 13:50 - 2014-09-03 13:41 - 00000000 ____D () C:\Qoobox 2014-09-03 13:50 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-09-03 13:48 - 2014-09-03 13:41 - 00000000 ____D () C:\Windows\erdnt 2014-09-03 13:48 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-03 13:38 - 2014-09-03 13:39 - 05576326 ____R (Swearware) C:\Users\Acer\Desktop\ComboFix.exe 2014-09-02 23:04 - 2012-08-22 13:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-02 22:50 - 2014-09-02 22:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-02 22:26 - 2014-04-29 18:01 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\gnupg 2014-09-02 13:46 - 2014-09-02 13:46 - 00030613 _____ () C:\Users\Downloads\First.rar 2014-09-02 13:41 - 2014-09-02 13:41 - 00004273 _____ () C:\Users\Downloads\Logfiles.rar 2014-09-02 13:11 - 2014-09-02 13:11 - 00073299 _____ () C:\Users\Downloads\gmer.txt 2014-09-02 12:08 - 2014-09-02 12:08 - 00000470 _____ () C:\Users\Downloads\defogger_disable.log 2014-09-02 11:47 - 2014-09-02 11:47 - 00000000 _____ () C:\Users\Acer\defogger_reenable 2014-09-02 11:31 - 2012-01-20 23:23 - 00000000 ____D () C:\Program Files (x86)\MusicLab 2014-09-02 11:30 - 2012-11-12 13:29 - 00000000 ____D () C:\Users\Public\Documents\MAGIX 2014-09-02 11:30 - 2011-08-07 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX 2014-09-02 11:23 - 2014-09-02 11:22 - 00000000 ____D () C:\Users\Downloads\Service scan 2014-09-02 11:12 - 2014-09-02 11:11 - 00000000 ____D () C:\Users\Downloads\Gdata 2014-09-02 11:01 - 2013-11-20 21:55 - 00000000 ___RD () C:\Users\Acer\Dropbox 2014-09-02 11:01 - 2011-08-03 12:35 - 00000000 ____D () C:\Windows\pss 2014-09-02 10:57 - 2013-11-20 21:43 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Dropbox 2014-09-02 10:57 - 2013-07-01 20:29 - 00000000 ___RD () C:\Users\Acer\CloudStation 2014-09-02 10:57 - 2013-07-01 20:20 - 00000000 ___RD () C:\Users\Acer\Cloud-2 2014-09-02 10:57 - 2012-04-03 18:04 - 00000015 _____ () C:\Windows\system32\deviceAppeared.txt 2014-09-02 10:16 - 2013-12-10 14:35 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-08-31 00:36 - 2014-08-31 00:29 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-08-31 00:29 - 2014-08-31 00:29 - 00707354 _____ () C:\Windows\unins000.exe 2014-08-31 00:29 - 2014-08-31 00:29 - 00001529 _____ () C:\Windows\unins000.dat 2014-08-31 00:29 - 2014-08-31 00:29 - 00000000 ____D () C:\Windows\SysWOW64\GPBAK 2014-08-31 00:27 - 2014-08-31 00:27 - 00875012 _____ () C:\Users\Downloads\group_policy.zip 2014-08-30 23:53 - 2014-08-30 23:53 - 00000000 ____D () C:\Users\Downloads\406874_intl_x64_zip 2014-08-30 22:52 - 2014-01-23 17:38 - 00000000 ____D () C:\ProgramData\Vexel 2014-08-30 22:52 - 2011-06-01 06:14 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-08-30 22:50 - 2014-08-30 20:21 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Nico Mak Computing 2014-08-30 22:01 - 2014-08-30 22:01 - 00000000 ____D () C:\bootmedium 2014-08-30 21:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Globalization 2014-08-30 20:47 - 2014-08-30 20:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-30 20:12 - 2013-12-08 23:04 - 00110795 _____ () C:\Windows\AutoKMS.log 2014-08-30 16:49 - 2012-02-22 19:38 - 00000166 ___SH () C:\ProgramData\.zreglib 2014-08-30 12:37 - 2014-08-30 12:31 - 226580480 _____ () C:\Users\Downloads\GDBootMedium_2014.iso 2014-08-30 12:26 - 2012-04-03 18:06 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-08-30 12:26 - 2012-04-03 18:06 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-08-30 12:26 - 2011-07-21 19:41 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-08-30 12:15 - 2013-11-20 21:44 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-30 10:03 - 2014-08-29 17:01 - 00000000 ____D () C:\Users\Downloads\piwik 2014-08-30 09:45 - 2014-08-30 09:41 - 00000000 ____D () C:\Users\Acer\AppData\OICE_15_974FA576_32C1D314_F3B 2014-08-30 09:34 - 2014-08-03 17:32 - 00073356 _____ () C:\nospam.log 2014-08-30 09:34 - 2014-08-03 17:32 - 00033612 _____ () C:\spam.log 2014-08-29 17:31 - 2013-10-06 22:10 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer 2014-08-29 16:48 - 2014-08-29 16:48 - 00022789 _____ () C:\Users\Downloads\Contao_PiwikTrackingTag_20030029_6.zip 2014-08-29 10:09 - 2013-12-08 23:04 - 05254200 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-28 20:53 - 2012-10-15 12:08 - 00000000 ____D () C:\Users\Acer\Documents\Video Editoren 2014-08-26 12:26 - 2014-03-02 22:59 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-08-25 17:21 - 2009-07-14 04:34 - 00000718 _____ () C:\Windows\win.ini 2014-08-24 19:22 - 2013-12-21 23:56 - 00008101 _____ () C:\Windows\BRRBCOM.INI 2014-08-24 13:29 - 2014-08-24 13:29 - 00007817 _____ () C:\Windows\BROMJ245.INI 2014-08-23 14:50 - 2011-07-21 11:51 - 00000000 ____D () C:\Users\Acer\AppData\Roaming\Skype 2014-08-23 13:49 - 2013-06-15 10:13 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-08-23 13:49 - 2011-06-01 06:43 - 00000000 ____D () C:\ProgramData\Skype 2014-08-23 13:47 - 2014-08-23 13:47 - 00002103 _____ () C:\Users\Acer\Desktop\Skype.lnk 2014-08-23 13:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-23 10:43 - 2012-10-14 18:46 - 00000000 ____D () C:\Windows\system32\inf32 2014-08-23 04:07 - 2014-08-28 12:41 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-23 03:45 - 2014-08-28 12:41 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 02:59 - 2014-08-28 12:41 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-15 10:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-15 10:06 - 2013-08-15 10:53 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-15 10:03 - 2011-07-21 12:00 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-15 10:01 - 2014-05-06 17:12 - 00000000 ___SD () C:\Windows\system32\CompatTel Files to move or delete: ==================== C:\Users\Downloads\adwcleaner_3.309.exe C:\Users\Downloads\BoxSyncSetup.exe C:\Users\Downloads\esetsmartinstaller_deu.exe C:\Users\Downloads\JRT.exe C:\Users\Downloads\mbam-setup-2.0.2.1012.exe C:\Users\Downloads\SecurityCheck.exe Some content of TEMP: ==================== C:\Users\Acer\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-06 00:55 ==================== End Of Log ============================ |
08.09.2014, 10:48 | #20 |
/// the machine /// TB-Ausbilder | Gdata läßt sich nicht öffnen ! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.09.2014, 11:18 | #21 |
| Gdata läßt sich nicht öffnen ! Hallo, hier die fixlog. Gruß Otscho Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-09-2014 01 Ran by Acer at 2014-09-08 12:15:36 Run:3 Running from C:\Users\Downloads\First Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} ***************** HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} => Value not found. ==== End of Fixlog ==== |
08.09.2014, 19:14 | #22 |
/// the machine /// TB-Ausbilder | Gdata läßt sich nicht öffnen ! fertig
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |