Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Plötzliche Werbung in Firefox und Internet Explorer

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 04.09.2014, 17:44   #1
nonever_
 
Plötzliche Werbung in Firefox und Internet Explorer - Standard

Plötzliche Werbung in Firefox und Internet Explorer



Moin Leute,
ich glaube, dass ich gestern durch einen dummen Fehler gestern meinen Rechner infiziert habe... Kleine Vorgeschichte: Ich habe seit Jahren keine Antivirensoftware verwendet und bin damit so weit ich weiß immer gut gefahren. Nur Firefox verwendet, dort mit NoScript, Adblock und Cookies löschen alle Tore zu gemacht und nie Dateien aus unbekannter Quelle geladen.
Gestern fragte ein Freund, ob ich lust hätte eine Runde Minecraft zu spielen, wie wir das Früher oft gemacht hatten. Er Schickte einen Link zu dem Spiel und ich Trottel verließ mich darrauf, dass das Seriös wäre, weil er sagte, dass es bei ihm funktioniert hätte. -.- Schon die Installation wirkte komisch und ich beendete das Ding bevor es ganz durchgelaufen war.
Seitdem tauchte in Firefox immer Werbung auf, das ließ sich aber durch das löschen eines seltsamen Plugins lösen... (Jetzt ist nach jedem Neustart ein Plugin da, dass angeblich Youtube Videos in Hd darstellen soll) Außerdem läuft manchmal im Hintergrund Werbung im Iexplorer die man dann nur im taskmanager beenden kann.
Also Avira installiert und das hat gleich ordentlich Funde geschmissen:

Code:
ATTFilter
Exportierte Ereignisse:

04.09.2014 17:45 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files 
      (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:45 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files 
      (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:45 [System-Scanner] Suche
      Suchlauf beendet [Der Suchlauf wurde vollständig durchgeführt.].
      Anzahl Dateien:	737947
      Anzahl Verzeichnisse:	28965
      Anzahl Malware:	17
      Anzahl Warnungen:	3

04.09.2014 17:45 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files 
      (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:45 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files 
      (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Users\Nils\AppData\Roaming\OYVXKZPY.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Users\Nils\AppData\Local\Temp\setup.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 
      'C:\Users\Nils\AppData\Local\Temp\MinecraftInstaller__2490_il11711.exe'
      enthielt einen Virus oder unerwünschtes Programm 'Adware/Amonetize.tzv' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Windows\SysWOW64\installd.exe'
      enthielt einen Virus oder unerwünschtes Programm 'Adware/Amonetize.ges' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Users\Nils\Downloads\MinecraftInstaller__2490_il11711.exe'
      enthielt einen Virus oder unerwünschtes Programm 'Adware/Amonetize.tzv' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Users\Nils\AppData\Roaming\SESSEC.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files (x86)\HD-V9.4\HD-V9.4-codedownloader.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files (x86)\HD-V9.4\HD-V9.4-bg.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files 
      (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.exe'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Users\Nils\AppData\Local\Temp\awhE124.tmp'
      enthielt einen Virus oder unerwünschtes Programm 'TR/Rogue.11455022' [trojan].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Users\Nils\AppData\Local\Genesis_09031222\Genesis_09031222.exe'
      enthielt einen Virus oder unerwünschtes Programm 'Adware/Symmi.11385.158' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '527f262b.qua' 
      verschoben!

04.09.2014 17:44 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files (x86)\HD-V9.4\Uninstall.exe'
      enthielt einen Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan].
      Durchgeführte Aktion(en):
      Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4aef0985.qua' 
      verschoben!

04.09.2014 16:41 [System-Scanner] Suche
      Suchlauf beendet [Der Suchlauf wurde vollständig durchgeführt.].
      Anzahl Dateien:	6734
      Anzahl Verzeichnisse:	0
      Anzahl Malware:	5
      Anzahl Warnungen:	0

04.09.2014 16:41 [System-Scanner] Malware gefunden
      Die Datei 'C:\Windows\SysWOW64\netupdsrv.exe'
      enthielt einen Virus oder unerwünschtes Programm 'TR/Rogue.gere.3' [trojan].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 16:41 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files (x86)\HD-V9.4\HD-V9.4-bho64.dll'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.

04.09.2014 16:41 [System-Scanner] Malware gefunden
      Die Datei 'C:\Program Files (x86)\HD-V9.4\HD-V9.4-bho.dll'
      enthielt einen Virus oder unerwünschtes Programm 'ADWARE/CrossRider.Gen2' 
      [adware].
      Durchgeführte Aktion(en):
      Die Datei wurde gelöscht.
         
Dazu die defogger log:

Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 17:46 on 04/09/2014 (Nils)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         
Die Frst:

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02
Ran by Nils (administrator) on NILS-PC on 04-09-2014 17:47:18
Running from C:\Users\Nils\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(
ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Spotify Ltd) C:\Users\Nils\AppData\Roaming\Spotify\spotify.exe
() C:\Program Files (x86)\Boost\BoostUpdater.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Users\Nils\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Nils\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Nils\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Nils\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Nils\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(CM&V Hackbart) C:\Program Files (x86)\DVBViewer TE2\DVBViewerTE.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11057768 2010-07-06] (Realtek Semiconductor)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [281312 2014-05-19] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1722010485-1478986846-2879839138-1000\...\Run: [Spotify] => C:\Users\Nils\AppData\Roaming\Spotify\Spotify.exe [6621752 2014-08-26] (Spotify Ltd)
Startup: C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk3QXKJIpUiKJVWs0CnkAF86UfDdTXFyGwOF52nYjAD_zI0z6KMNAKGu87Y-NnRpu9t6c7XBtgwXvstSbYIzDoJlBF7AaCqOwcdIQ,,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk7Rx6aJKOGzMJ-TszzFyYyJwT3_JjBcmD3HDBoyw7rxBHQe9W9i6MEA7J4XOVzmJwrhCnJskNG5UkTKV1cPpwASSlsCWoq8JKQkQ,,
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7D561050E1A8CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk3QXKJIpUiKJVWs0CnkAF86UfDdTXFyGwOF52nYjAD_zI0z6KMNAKGu87Y-NnRpu9t6c7XBtgwXvstSbYIzDoJlBF7AaCqOwcdIQ,,&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk3QXKJIpUiKJVWs0CnkAF86UfDdTXFyGwOF52nYjAD_zI0z6KMNAKGu87Y-NnRpu9t6c7XBtgwXvstSbYPzHq6gqdKhvy_PvXp0Q,,&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk3QXKJIpUiKJVWs0CnkAF86UfDdTXFyGwOF52nYjAD_zI0z6KMNAKGu87Y-NnRpu9t6c7XBtgwXvstSbYPzHq6gqdKhvy_PvXp0Q,,&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk3QXKJIpUiKJVWs0CnkAF86UfDdTXFyGwOF52nYjAD_zI0z6KMNAKGu87Y-NnRpu9t6c7XBtgwXvstSbYIzDoJlBF7AaCqOwcdIQ,,&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk3QXKJIpUiKJVWs0CnkAF86UfDdTXFyGwOF52nYjAD_zI0z6KMNAKGu87Y-NnRpu9t6c7XBtgwXvstSbYIzDoJlBF7AaCqOwcdIQ,,&q={searchTerms}
BHO: Boost -> {8DE6FC60-E023-4AD7-A3B7-591E1460E7F7} -> C:\Program Files (x86)\Boost\64Boost.dll (Jigsaw)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Boost -> {8DE6FC60-E023-4AD7-A3B7-591E1460E7F7} -> C:\Program Files (x86)\Boost\Boost.dll (Jigsaw)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default
FF Homepage: google.de
FF Keyword.URL: hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjBVwSW3oS9azFioQNIYYOtzIs1EAWHZA8YdfIpZWoAYDk7j2u0rBQHr1ySV7lntlk3QXKJIpUiKJVWs0CnkAF86UfDdTXFyGwOF52nYjAD_zI0z6KMNAKGu87Y-NnRpu9t6c7XBtgwXvstSbYIzDoJlBF7AaCqOwcdIQ,,&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF user.js: detected! => C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\user.js
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\Extensions\abs@avira.com [2014-09-04]
FF Extension: Hide My Ass Proxy Extension - C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\Extensions\extension@hidemyass.com.xpi [2014-08-31]
FF Extension: Ghostery - C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\Extensions\firefox@ghostery.com.xpi [2014-08-19]
FF Extension: Self-Destructing Cookies - C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\Extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi [2014-08-19]
FF Extension: NoScript - C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-19]
FF Extension: Adblock Plus - C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-19]
FF Extension: BetterPrivacy - C:\Users\Nils\AppData\Roaming\Mozilla\Firefox\Profiles\fsit9ray.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2014-08-19]

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-09-03] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-09-03] (globalUpdate) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-08-08] (LogMeIn, Inc.)
S2 NetHttpService; C:\Windows\SysWOW64\nethtsrv.exe [179712 2014-09-03] () [File not signed]
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [27872 2014-05-19] (Samsung Electronics Co., Ltd.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 AODDriver; C:\Program Files (x86)\ASUS\GPU Boost Driver\amd64\AODDriver.sys [52280 2010-03-12] (Advanced Micro Devices)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-09] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-08-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-08-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
R1 nethfdrv; C:\Windows\system32\drivers\nethfdrv.sys [46160 2014-09-03] (nethfdrv)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [265952 2014-05-19] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111328 2014-05-19] (Samsung Electronics Co., Ltd.)
R3 UDST7000BDA; C:\Windows\System32\Drivers\UDST7000BDA.sys [538768 2014-07-15] (TechniSat Digital S.A.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-04 17:47 - 2014-09-04 17:47 - 00014335 _____ () C:\Users\Nils\Desktop\FRST.txt
2014-09-04 17:47 - 2014-09-04 17:47 - 00000000 ____D () C:\FRST
2014-09-04 17:46 - 2014-09-04 17:46 - 02104832 _____ (Farbar) C:\Users\Nils\Desktop\FRST64.exe
2014-09-04 17:46 - 2014-09-04 17:46 - 00000470 _____ () C:\Users\Nils\Downloads\defogger_disable.log
2014-09-04 17:46 - 2014-09-04 17:46 - 00000000 _____ () C:\Users\Nils\defogger_reenable
2014-09-04 17:45 - 2014-09-04 17:45 - 00050477 _____ () C:\Users\Nils\Downloads\Defogger.exe
2014-09-04 16:40 - 2014-09-04 16:46 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-04 16:40 - 2014-09-04 16:45 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-04 16:40 - 2014-09-04 16:39 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-09-04 16:39 - 2014-09-04 16:39 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Avira
2014-09-04 16:38 - 2014-09-04 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-04 16:38 - 2014-09-04 16:45 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-04 16:38 - 2014-09-04 16:40 - 00000000 ____D () C:\ProgramData\Avira
2014-09-04 16:38 - 2014-09-04 16:38 - 00002070 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-09-04 16:38 - 2014-08-15 10:30 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-09-04 16:38 - 2014-08-15 10:30 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-09-04 16:38 - 2014-08-15 10:30 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-09-04 16:37 - 2014-09-04 16:37 - 00000000 ____D () C:\Windows\pss
2014-09-04 16:33 - 2014-09-04 16:35 - 149527616 _____ () C:\Users\Nils\Downloads\avira_free_antivirus_de_14.0.6.570.exe
2014-09-04 16:32 - 2014-09-04 16:32 - 00000687 _____ () C:\awhC62B.tmp
2014-09-04 16:28 - 2014-09-04 16:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-04 16:28 - 2014-09-04 16:28 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-03 21:50 - 2012-11-22 12:45 - 00000000 ____D () C:\Users\Nils\Desktop\FreeIMU-20121122_1126
2014-09-03 21:49 - 2014-09-03 21:49 - 03224287 _____ () C:\Users\Nils\Downloads\FreeIMU-20121122_1126.zip
2014-09-03 21:33 - 2014-09-03 21:42 - 00000000 ____D () C:\Users\Nils\Desktop\arduimu_vD
2014-09-03 21:33 - 2014-09-03 21:33 - 00000000 ____D () C:\Users\Nils\Documents\Arduino
2014-09-03 21:33 - 2014-09-03 21:33 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Arduino
2014-09-03 21:32 - 2014-09-03 21:32 - 00001007 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arduino.lnk
2014-09-03 21:32 - 2014-09-03 21:32 - 00000995 _____ () C:\Users\Public\Desktop\Arduino.lnk
2014-09-03 21:32 - 2014-09-03 21:32 - 00000000 ____D () C:\Program Files (x86)\Arduino
2014-09-03 21:30 - 2014-09-03 21:31 - 55119888 _____ () C:\Users\Nils\Downloads\arduino-1.0.5-r2-windows.exe
2014-09-03 21:26 - 2014-09-03 21:26 - 00016221 _____ () C:\Users\Nils\Downloads\arduimu_vD.rar
2014-09-03 16:11 - 2014-09-03 16:11 - 01659099 _____ () C:\Users\Nils\Downloads\aokpatch2a-crk(1).zip
2014-09-03 16:00 - 2014-09-03 16:00 - 00000000 __RHD () C:\Users\Nils\AppData\Roaming\SecuROM
2014-09-03 15:59 - 2014-09-03 15:59 - 00675988 _____ () C:\Users\Nils\Downloads\Minecraft(2).exe
2014-09-03 14:27 - 2014-09-03 14:27 - 00000687 _____ () C:\awh7A1F.tmp
2014-09-03 14:25 - 2014-09-03 14:25 - 00675988 _____ () C:\Users\Nils\Downloads\Minecraft(1).exe
2014-09-03 14:23 - 2014-09-04 17:45 - 00000000 ____D () C:\Program Files (x86)\HD-V9.4
2014-09-03 14:23 - 2014-09-04 16:28 - 00004466 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00003784 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00002678 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00001788 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-1.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00001736 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5_user.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00001716 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00001682 _____ () C:\Windows\Tasks\OYVXKZPY.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00001432 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00001334 _____ () C:\Windows\Tasks\SESSEC.job
2014-09-03 14:23 - 2014-09-04 16:28 - 00000908 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-09-03 14:23 - 2014-09-03 20:28 - 00000912 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-09-03 14:23 - 2014-09-03 14:23 - 00007496 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11
2014-09-03 14:23 - 2014-09-03 14:23 - 00006814 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3
2014-09-03 14:23 - 2014-09-03 14:23 - 00005708 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4
2014-09-03 14:23 - 2014-09-03 14:23 - 00004818 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-1
2014-09-03 14:23 - 2014-09-03 14:23 - 00004746 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5
2014-09-03 14:23 - 2014-09-03 14:23 - 00004704 _____ () C:\Windows\System32\Tasks\OYVXKZPY
2014-09-03 14:23 - 2014-09-03 14:23 - 00004462 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2
2014-09-03 14:23 - 2014-09-03 14:23 - 00004356 _____ () C:\Windows\System32\Tasks\SESSEC
2014-09-03 14:23 - 2014-09-03 14:23 - 00003910 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-09-03 14:23 - 2014-09-03 14:23 - 00003656 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\InetStat
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Users\Nils\AppData\Local\globalUpdate
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Program Files (x86)\Boost
2014-09-03 14:22 - 2014-09-04 17:44 - 00000000 ____D () C:\Users\Nils\AppData\Local\Genesis_09031222
2014-09-03 14:21 - 2014-09-03 14:21 - 00675988 _____ () C:\Users\Nils\Downloads\Minecraft.exe
2014-09-03 14:10 - 2014-09-03 15:59 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\.minecraft
2014-09-03 14:10 - 2014-09-03 14:10 - 00000000 ____D () C:\ProgramData\Sun
2014-09-03 14:10 - 2014-09-03 14:10 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-03 14:10 - 2014-09-03 14:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-03 14:10 - 2014-09-03 14:09 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-03 14:10 - 2014-09-03 14:09 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-03 14:10 - 2014-09-03 14:09 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-03 14:10 - 2014-09-03 14:09 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-09-03 14:09 - 2014-09-03 14:09 - 00918952 _____ (Oracle Corporation) C:\Users\Nils\Downloads\jxpiinstall.exe
2014-09-03 14:09 - 2014-09-03 14:09 - 00000000 ____D () C:\Program Files (x86)\Java
2014-09-03 14:07 - 2011-08-09 12:14 - 00695296 _____ (AnjoCaido) C:\Users\Nils\Desktop\MinecraftSP.exe
2014-09-03 14:07 - 2004-01-01 23:19 - 302548481 _____ (InstallShield Software Corporation) C:\Users\Nils\Desktop\cs16full standalone.exe
2014-09-03 14:06 - 2014-09-03 14:06 - 00270142 _____ () C:\Users\Nils\Documents\Minecraft.exe
2014-09-03 14:03 - 2014-09-03 14:04 - 285203507 _____ () C:\Users\Nils\Desktop\AoE 2 - The Age of Kings.rar
2014-09-03 13:58 - 2014-09-03 13:58 - 00652192 _____ (Steamless) C:\Users\Nils\Documents\Steamless Counter Strike Source Pack.exe
2014-09-03 13:40 - 2014-09-03 13:40 - 00002027 _____ () C:\Users\Nils\Desktop\Counter-Strike Source.lnk
2014-09-03 13:40 - 2014-09-03 13:40 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
2014-09-03 13:40 - 2014-09-03 13:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
2014-09-03 13:37 - 2014-09-03 13:40 - 00000000 ____D () C:\Program Files (x86)\Counter-Strike Source
2014-09-03 13:34 - 2009-03-18 18:35 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2014-09-03 10:39 - 2014-09-03 10:39 - 00249856 _____ () C:\Windows\SysWOW64\hfpapi.dll
2014-09-03 10:39 - 2014-09-03 10:39 - 00179712 _____ () C:\Windows\SysWOW64\nethtsrv.exe
2014-09-03 10:39 - 2014-09-03 10:39 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Nils\AppData\Roaming\SESSEC
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Nils\AppData\Roaming\OYVXKZPY
2014-08-31 14:28 - 2014-08-31 14:29 - 23207244 _____ () C:\Users\Nils\Downloads\youscope-wave.flac
2014-08-29 16:18 - 2014-08-29 16:18 - 00002684 _____ () C:\Users\Nils\AppData\Local\recently-used.xbel
2014-08-28 18:58 - 2014-08-28 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wings 3D 1.5.3
2014-08-28 18:57 - 2014-08-28 18:58 - 00000000 ____D () C:\Program Files\wings3d_1.5.3
2014-08-28 18:56 - 2014-08-28 18:56 - 16062920 _____ () C:\Users\Nils\Downloads\wings-x64-1.5.3.exe
2014-08-28 18:51 - 2014-08-28 18:51 - 00001049 _____ () C:\Users\Public\Desktop\KiCad.lnk
2014-08-28 18:51 - 2014-08-28 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KiCad
2014-08-28 18:51 - 2014-08-28 18:51 - 00000000 ____D () C:\Program Files (x86)\KiCad
2014-08-28 15:22 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 15:22 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 15:22 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-28 13:26 - 2014-08-28 13:29 - 207245212 _____ () C:\Users\Nils\Downloads\KiCad_stable-2013.07.07-BZR4022_Win_full_version.exe
2014-08-21 19:43 - 2014-08-21 19:43 - 00000000 ____D () C:\Program Files\Recuva
2014-08-21 19:42 - 2014-08-21 19:42 - 04210920 _____ (Piriform Ltd) C:\Users\Nils\Downloads\rcsetup151.exe
2014-08-21 13:53 - 2014-08-21 13:55 - 00000000 ____D () C:\Users\Nils\Desktop\Neuer Ordner
2014-08-21 13:53 - 2014-08-21 13:53 - 00121069 _____ () C:\Users\Nils\Downloads\memtest86+-5.01.usb.installer.zip
2014-08-20 23:39 - 2014-08-21 00:12 - 00077688 _____ () C:\Users\Nils\Desktop\Unbenannt 1.ods
2014-08-20 16:39 - 2014-08-20 16:39 - 04526080 _____ () C:\Users\Nils\Downloads\FRITZ.Box_Fon_WLAN_7113.60.04.68.image
2014-08-20 12:48 - 2014-08-20 12:48 - 00195072 _____ () C:\Users\Nils\Downloads\BERECHNUNG_PT1000.XLS
2014-08-19 19:49 - 2014-08-19 19:49 - 00015127 _____ () C:\Users\Nils\Documents\Unbenannt 1.ods
2014-08-19 17:27 - 2014-08-19 17:27 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk
2014-08-19 17:27 - 2014-08-19 17:27 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-08-19 17:27 - 2014-08-19 17:27 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\OpenOffice
2014-08-19 17:27 - 2014-08-19 17:27 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-08-19 17:26 - 2014-08-19 17:26 - 00000000 ____D () C:\Users\Nils\Desktop\OpenOffice 4.1.0 (de) Installation Files
2014-08-19 17:24 - 2014-08-19 17:25 - 164962843 _____ () C:\Users\Nils\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe
2014-08-18 17:34 - 2014-08-18 17:35 - 00000000 ____D () C:\Users\Nils\AppData\Local\gtk-2.0
2014-08-15 22:41 - 2014-08-15 22:41 - 00000000 __SHD () C:\Users\Nils\AppData\Local\EmieUserList
2014-08-15 22:41 - 2014-08-15 22:41 - 00000000 __SHD () C:\Users\Nils\AppData\Local\EmieSiteList
2014-08-15 00:20 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-15 00:20 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-15 00:20 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 00:20 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 00:20 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-15 00:20 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-15 00:20 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-15 00:20 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 19:36 - 2014-08-14 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voobly
2014-08-14 19:36 - 2014-08-14 19:39 - 00000000 ____D () C:\Program Files (x86)\Voobly
2014-08-14 19:36 - 2014-08-14 19:36 - 09961548 _____ (Voobly ) C:\Users\Nils\Downloads\voobly-v2.1.67.1.exe
2014-08-14 19:36 - 2014-08-14 19:36 - 00000983 _____ () C:\Users\Nils\Desktop\Voobly.lnk
2014-08-14 17:31 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-14 17:31 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-14 17:31 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-14 17:31 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 17:31 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-14 17:31 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-14 17:31 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-14 17:31 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-14 17:31 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-14 17:31 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-14 17:31 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-14 17:31 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-14 17:31 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-14 17:31 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-14 17:31 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-14 17:31 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-14 17:31 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-14 17:31 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-14 17:31 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-14 17:31 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-14 17:31 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-14 17:31 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-14 17:31 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-14 17:31 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-14 17:31 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-14 17:31 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-14 17:31 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-14 17:31 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 17:31 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 17:31 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 17:31 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 17:31 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 17:31 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 17:31 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 17:31 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-14 17:30 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-14 17:30 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-14 17:30 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-14 17:30 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-14 17:30 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-14 17:30 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-14 17:30 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 17:30 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-14 17:30 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-14 17:30 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-14 17:30 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-14 17:30 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-14 17:30 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-14 17:30 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-14 17:30 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-14 17:30 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-14 17:30 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-14 17:30 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-14 17:30 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 17:30 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-14 17:30 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-14 17:30 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-14 17:30 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-14 17:30 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-14 17:30 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-14 17:30 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-14 17:30 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-14 17:30 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-14 17:30 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-14 17:30 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-14 17:30 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-14 17:30 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-14 17:30 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-14 17:30 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-14 17:30 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-14 17:30 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-14 17:30 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-14 17:30 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-14 17:30 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-14 17:30 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-14 17:30 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-14 17:30 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-14 17:30 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-14 17:30 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-14 17:30 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-14 17:30 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-14 17:30 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-14 17:30 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 17:30 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-14 17:24 - 2014-09-04 16:28 - 00000000 ____D () C:\Users\Nils\AppData\Local\LogMeIn Hamachi
2014-08-14 17:24 - 2014-08-14 17:24 - 00000000 ____D () C:\Users\Nils\AppData\Local\LogMeIn
2014-08-14 17:24 - 2014-08-14 17:24 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-08-14 17:23 - 2014-08-14 17:23 - 08499200 _____ () C:\Users\Nils\Downloads\hamachi.msi
2014-08-12 21:19 - 2014-08-12 21:19 - 00000219 _____ () C:\Windows\Directx.log
2014-08-12 21:19 - 2014-08-12 21:19 - 00000000 ____D () C:\Program Files (x86)\directx
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2014-08-11 18:38 - 2014-08-11 18:38 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Riot Games
2014-08-11 18:37 - 2014-08-11 18:38 - 34888568 _____ (Riot Games) C:\Users\Nils\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe
2014-08-11 15:52 - 2008-01-19 01:10 - 00154168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WimFltr.sys
2014-08-11 15:50 - 2014-08-11 16:26 - 00000000 ____D () C:\Program Files (x86)\vLite
2014-08-11 15:50 - 2014-08-11 15:50 - 01620715 _____ (Dino Nuhagic (nuhi) ) C:\Users\Nils\Downloads\vLite-1.2.installer.exe
2014-08-11 15:50 - 2014-08-11 15:50 - 00518940 _____ () C:\Users\Nils\Downloads\wimfltr.exe
2014-08-11 15:50 - 2014-08-11 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vLite
2014-08-11 15:49 - 2014-08-11 16:15 - 2463242240 _____ () C:\Users\Nils\Downloads\X15-65740.iso
2014-08-11 15:32 - 2014-08-11 15:32 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\WinRAR
2014-08-11 15:30 - 2014-08-11 15:31 - 00000000 ____D () C:\Users\Nils\Desktop\stick
2014-08-11 15:30 - 2014-08-11 15:30 - 02060744 _____ () C:\Users\Nils\Downloads\winrar-x64-510d.exe
2014-08-11 15:30 - 2014-08-11 15:30 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-11 15:30 - 2014-08-11 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-11 15:30 - 2014-08-11 15:30 - 00000000 ____D () C:\Program Files\WinRAR
2014-08-11 15:20 - 2014-08-11 15:24 - 348127232 _____ () C:\Users\Nils\Downloads\android-x86-4.4-RC2.iso
2014-08-10 11:30 - 2014-08-10 11:30 - 00400569 _____ () C:\Users\Nils\Downloads\agmp3plugin.exe
2014-08-10 11:28 - 2014-08-10 11:28 - 00001164 _____ () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-10 11:27 - 2014-08-10 11:27 - 00000435 _____ () C:\Windows\cdplayer.ini
2014-08-10 11:23 - 2014-08-10 11:30 - 00000000 ____D () C:\Program Files (x86)\Audiograbber
2014-08-10 11:23 - 2014-08-10 11:28 - 00000000 ____D () C:\Program Files (x86)\Security Guard
2014-08-10 11:23 - 2014-08-10 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audiograbber
2014-08-10 11:21 - 2014-08-10 11:21 - 00471536 _____ () C:\Users\Nils\Downloads\download_audiograbber.exe
2014-08-09 17:54 - 2014-08-09 17:54 - 00587776 _____ (Igor Pavlov) C:\Users\Nils\Downloads\7za.exe
2014-08-09 17:54 - 2014-08-09 17:54 - 00078848 _____ () C:\Users\Nils\Downloads\Archive.dll
2014-08-09 17:54 - 2014-08-09 17:54 - 00043008 _____ () C:\Users\Nils\Downloads\39dll.dll
2014-08-09 17:54 - 2014-08-09 17:54 - 00005845 _____ () C:\Users\Nils\Downloads\txt.sec
2014-08-09 17:54 - 2014-08-09 17:54 - 00000000 ____D () C:\Users\Nils\Downloads\Resources
2014-08-09 17:42 - 2014-08-09 17:42 - 00000034 _____ () C:\Windows\AvastEmUpdate.ini
2014-08-09 17:42 - 2014-08-09 17:42 - 00000000 _____ () C:\Windows\SysWOW64\config.nt
2014-08-09 17:41 - 2014-08-09 17:41 - 00519488 _____ (AVAST Software) C:\Users\Nils\Downloads\avastclear.exe
2014-08-09 17:37 - 2014-08-09 17:43 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\AVAST Software
2014-08-09 17:37 - 2014-08-09 17:37 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-09 17:36 - 2014-08-09 17:43 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-08-09 17:36 - 2014-08-09 17:43 - 00000000 ____D () C:\Program Files\AVAST Software
2014-08-09 17:36 - 2014-08-09 17:36 - 00426848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1407598624688
2014-08-09 17:36 - 2014-08-09 17:36 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-09 17:29 - 2014-08-09 17:29 - 08499200 _____ () C:\Users\Nils\Downloads\hamachi_CB-DL-Manager [1].exe
2014-08-09 17:19 - 2014-09-04 00:06 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Skype
2014-08-09 17:19 - 2014-08-09 17:19 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ____D () C:\Users\Nils\AppData\Local\Skype
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ____D () C:\ProgramData\Skype
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-09 17:17 - 2014-08-09 17:17 - 00787392 _____ ( ) C:\Users\Nils\Downloads\hamachi_CB-DL-Manager.exe
2014-08-09 17:16 - 2014-08-09 17:16 - 01677928 _____ (Skype Technologies S.A.) C:\Users\Nils\Downloads\SkypeSetup.exe
2014-08-09 16:17 - 2014-08-09 16:42 - 361544078 _____ () C:\Users\Nils\Downloads\gta2installer.zip
2014-08-09 16:16 - 2014-08-09 16:17 - 01101648 _____ () C:\Users\Nils\Downloads\Grand Theft Auto GTA 2 - CHIP-Installer.exe
2014-08-09 15:08 - 2014-08-09 15:08 - 01659099 _____ () C:\Users\Nils\Downloads\aokpatch2a-crk.zip
2014-08-09 15:08 - 2014-08-09 15:08 - 00000948 _____ () C:\Users\Nils\Downloads\aoe2-vista-win7-fix.zip
2014-08-09 15:05 - 2014-08-09 16:09 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-08-09 15:04 - 2014-08-09 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-08-09 14:58 - 2014-08-14 19:44 - 00000000 ____D () C:\Users\Nils\Desktop\Age of Empires II & The Conquerors
2014-08-09 14:54 - 2014-09-03 13:37 - 00000000 ____D () C:\Users\Nils\Desktop\Counter Strike Source
2014-08-09 14:53 - 2014-08-09 14:54 - 00000000 ____D () C:\Users\Nils\Desktop\AoE 2 - The Age of Kings
2014-08-09 14:53 - 2006-10-10 07:56 - 733777632 _____ () C:\Users\Nils\Desktop\Counter Strike Source.install.exe
2014-08-08 19:07 - 2014-08-08 19:07 - 00008628 _____ () C:\Users\Nils\Downloads\p.txt
2014-08-08 18:19 - 2014-08-08 19:07 - 397550563 _____ () C:\Users\Nils\Downloads\CarTFT_EX70-2_Windows_Drivers.zip
2014-08-08 18:19 - 2014-08-08 19:02 - 375104654 _____ () C:\Users\Nils\Downloads\CarTFT_X70EX-2_BASIC_Android.zip

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-04 17:47 - 2014-09-04 17:47 - 00014335 _____ () C:\Users\Nils\Desktop\FRST.txt
2014-09-04 17:47 - 2014-09-04 17:47 - 00000000 ____D () C:\FRST
2014-09-04 17:46 - 2014-09-04 17:46 - 02104832 _____ (Farbar) C:\Users\Nils\Desktop\FRST64.exe
2014-09-04 17:46 - 2014-09-04 17:46 - 00000470 _____ () C:\Users\Nils\Downloads\defogger_disable.log
2014-09-04 17:46 - 2014-09-04 17:46 - 00000000 _____ () C:\Users\Nils\defogger_reenable
2014-09-04 17:46 - 2014-07-14 11:29 - 00000000 ____D () C:\Users\Nils
2014-09-04 17:45 - 2014-09-04 17:45 - 00050477 _____ () C:\Users\Nils\Downloads\Defogger.exe
2014-09-04 17:45 - 2014-09-03 14:23 - 00000000 ____D () C:\Program Files (x86)\HD-V9.4
2014-09-04 17:44 - 2014-09-03 14:22 - 00000000 ____D () C:\Users\Nils\AppData\Local\Genesis_09031222
2014-09-04 16:47 - 2014-07-14 11:29 - 01121612 _____ () C:\Windows\WindowsUpdate.log
2014-09-04 16:46 - 2014-09-04 16:40 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-04 16:45 - 2014-09-04 16:40 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-04 16:45 - 2014-09-04 16:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-04 16:45 - 2014-09-04 16:38 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-04 16:40 - 2014-09-04 16:38 - 00000000 ____D () C:\ProgramData\Avira
2014-09-04 16:39 - 2014-09-04 16:40 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-09-04 16:39 - 2014-09-04 16:39 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Avira
2014-09-04 16:38 - 2014-09-04 16:38 - 00002070 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-09-04 16:37 - 2014-09-04 16:37 - 00000000 ____D () C:\Windows\pss
2014-09-04 16:35 - 2014-09-04 16:33 - 149527616 _____ () C:\Users\Nils\Downloads\avira_free_antivirus_de_14.0.6.570.exe
2014-09-04 16:34 - 2009-07-14 06:45 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-04 16:34 - 2009-07-14 06:45 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-04 16:33 - 2014-07-14 17:07 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Spotify
2014-09-04 16:33 - 2010-11-21 08:50 - 00698688 _____ () C:\Windows\system32\perfh007.dat
2014-09-04 16:33 - 2010-11-21 08:50 - 00148828 _____ () C:\Windows\system32\perfc007.dat
2014-09-04 16:33 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-04 16:32 - 2014-09-04 16:32 - 00000687 _____ () C:\awhC62B.tmp
2014-09-04 16:28 - 2014-09-04 16:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-04 16:28 - 2014-09-04 16:28 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-04 16:28 - 2014-09-03 14:23 - 00004466 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00003784 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00002678 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00001788 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-1.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00001736 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5_user.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00001716 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00001682 _____ () C:\Windows\Tasks\OYVXKZPY.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00001432 _____ () C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00001334 _____ () C:\Windows\Tasks\SESSEC.job
2014-09-04 16:28 - 2014-09-03 14:23 - 00000908 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-09-04 16:28 - 2014-08-14 17:24 - 00000000 ____D () C:\Users\Nils\AppData\Local\LogMeIn Hamachi
2014-09-04 16:28 - 2014-07-14 11:51 - 00000000 _____ () C:\ProgramData\Gpu.log
2014-09-04 16:27 - 2010-11-21 05:47 - 00007438 _____ () C:\Windows\PFRO.log
2014-09-04 16:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-04 16:27 - 2009-07-14 06:51 - 00035213 _____ () C:\Windows\setupact.log
2014-09-04 00:06 - 2014-08-09 17:19 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Skype
2014-09-03 21:49 - 2014-09-03 21:49 - 03224287 _____ () C:\Users\Nils\Downloads\FreeIMU-20121122_1126.zip
2014-09-03 21:42 - 2014-09-03 21:33 - 00000000 ____D () C:\Users\Nils\Desktop\arduimu_vD
2014-09-03 21:33 - 2014-09-03 21:33 - 00000000 ____D () C:\Users\Nils\Documents\Arduino
2014-09-03 21:33 - 2014-09-03 21:33 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Arduino
2014-09-03 21:32 - 2014-09-03 21:32 - 00001007 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arduino.lnk
2014-09-03 21:32 - 2014-09-03 21:32 - 00000995 _____ () C:\Users\Public\Desktop\Arduino.lnk
2014-09-03 21:32 - 2014-09-03 21:32 - 00000000 ____D () C:\Program Files (x86)\Arduino
2014-09-03 21:32 - 2014-07-31 14:01 - 00012926 _____ () C:\Windows\DPINST.LOG
2014-09-03 21:31 - 2014-09-03 21:30 - 55119888 _____ () C:\Users\Nils\Downloads\arduino-1.0.5-r2-windows.exe
2014-09-03 21:26 - 2014-09-03 21:26 - 00016221 _____ () C:\Users\Nils\Downloads\arduimu_vD.rar
2014-09-03 20:28 - 2014-09-03 14:23 - 00000912 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-09-03 16:11 - 2014-09-03 16:11 - 01659099 _____ () C:\Users\Nils\Downloads\aokpatch2a-crk(1).zip
2014-09-03 16:00 - 2014-09-03 16:00 - 00000000 __RHD () C:\Users\Nils\AppData\Roaming\SecuROM
2014-09-03 15:59 - 2014-09-03 15:59 - 00675988 _____ () C:\Users\Nils\Downloads\Minecraft(2).exe
2014-09-03 15:59 - 2014-09-03 14:10 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\.minecraft
2014-09-03 14:27 - 2014-09-03 14:27 - 00000687 _____ () C:\awh7A1F.tmp
2014-09-03 14:25 - 2014-09-03 14:25 - 00675988 _____ () C:\Users\Nils\Downloads\Minecraft(1).exe
2014-09-03 14:23 - 2014-09-03 14:23 - 00007496 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11
2014-09-03 14:23 - 2014-09-03 14:23 - 00006814 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3
2014-09-03 14:23 - 2014-09-03 14:23 - 00005708 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4
2014-09-03 14:23 - 2014-09-03 14:23 - 00004818 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-1
2014-09-03 14:23 - 2014-09-03 14:23 - 00004746 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5
2014-09-03 14:23 - 2014-09-03 14:23 - 00004704 _____ () C:\Windows\System32\Tasks\OYVXKZPY
2014-09-03 14:23 - 2014-09-03 14:23 - 00004462 _____ () C:\Windows\System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2
2014-09-03 14:23 - 2014-09-03 14:23 - 00004356 _____ () C:\Windows\System32\Tasks\SESSEC
2014-09-03 14:23 - 2014-09-03 14:23 - 00003910 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-09-03 14:23 - 2014-09-03 14:23 - 00003656 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\InetStat
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Users\Nils\AppData\Local\globalUpdate
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-03 14:23 - 2014-09-03 14:23 - 00000000 ____D () C:\Program Files (x86)\Boost
2014-09-03 14:21 - 2014-09-03 14:21 - 00675988 _____ () C:\Users\Nils\Downloads\Minecraft.exe
2014-09-03 14:10 - 2014-09-03 14:10 - 00000000 ____D () C:\ProgramData\Sun
2014-09-03 14:10 - 2014-09-03 14:10 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-03 14:10 - 2014-09-03 14:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-03 14:09 - 2014-09-03 14:10 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-03 14:09 - 2014-09-03 14:10 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-03 14:09 - 2014-09-03 14:10 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-03 14:09 - 2014-09-03 14:10 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-09-03 14:09 - 2014-09-03 14:09 - 00918952 _____ (Oracle Corporation) C:\Users\Nils\Downloads\jxpiinstall.exe
2014-09-03 14:09 - 2014-09-03 14:09 - 00000000 ____D () C:\Program Files (x86)\Java
2014-09-03 14:06 - 2014-09-03 14:06 - 00270142 _____ () C:\Users\Nils\Documents\Minecraft.exe
2014-09-03 14:04 - 2014-09-03 14:03 - 285203507 _____ () C:\Users\Nils\Desktop\AoE 2 - The Age of Kings.rar
2014-09-03 13:58 - 2014-09-03 13:58 - 00652192 _____ (Steamless) C:\Users\Nils\Documents\Steamless Counter Strike Source Pack.exe
2014-09-03 13:40 - 2014-09-03 13:40 - 00002027 _____ () C:\Users\Nils\Desktop\Counter-Strike Source.lnk
2014-09-03 13:40 - 2014-09-03 13:40 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
2014-09-03 13:40 - 2014-09-03 13:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
2014-09-03 13:40 - 2014-09-03 13:37 - 00000000 ____D () C:\Program Files (x86)\Counter-Strike Source
2014-09-03 13:37 - 2014-08-09 14:54 - 00000000 ____D () C:\Users\Nils\Desktop\Counter Strike Source
2014-09-03 10:39 - 2014-09-03 10:39 - 00249856 _____ () C:\Windows\SysWOW64\hfpapi.dll
2014-09-03 10:39 - 2014-09-03 10:39 - 00179712 _____ () C:\Windows\SysWOW64\nethtsrv.exe
2014-09-03 10:39 - 2014-09-03 10:39 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Nils\AppData\Roaming\SESSEC
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Nils\AppData\Roaming\OYVXKZPY
2014-08-31 20:19 - 2014-07-16 22:09 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\vlc
2014-08-31 14:29 - 2014-08-31 14:28 - 23207244 _____ () C:\Users\Nils\Downloads\youscope-wave.flac
2014-08-29 16:18 - 2014-08-29 16:18 - 00002684 _____ () C:\Users\Nils\AppData\Local\recently-used.xbel
2014-08-29 16:18 - 2014-07-14 22:18 - 00000000 ____D () C:\Users\Nils\.gimp-2.8
2014-08-28 18:58 - 2014-08-28 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wings 3D 1.5.3
2014-08-28 18:58 - 2014-08-28 18:57 - 00000000 ____D () C:\Program Files\wings3d_1.5.3
2014-08-28 18:56 - 2014-08-28 18:56 - 16062920 _____ () C:\Users\Nils\Downloads\wings-x64-1.5.3.exe
2014-08-28 18:51 - 2014-08-28 18:51 - 00001049 _____ () C:\Users\Public\Desktop\KiCad.lnk
2014-08-28 18:51 - 2014-08-28 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KiCad
2014-08-28 18:51 - 2014-08-28 18:51 - 00000000 ____D () C:\Program Files (x86)\KiCad
2014-08-28 17:49 - 2014-07-14 17:13 - 00000000 ____D () C:\Users\Nils\AppData\Local\Spotify
2014-08-28 17:49 - 2009-07-14 06:45 - 00304712 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:29 - 2014-08-28 13:26 - 207245212 _____ () C:\Users\Nils\Downloads\KiCad_stable-2013.07.07-BZR4022_Win_full_version.exe
2014-08-23 04:07 - 2014-08-28 15:22 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-28 15:22 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-28 15:22 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 19:43 - 2014-08-21 19:43 - 00000000 ____D () C:\Program Files\Recuva
2014-08-21 19:42 - 2014-08-21 19:42 - 04210920 _____ (Piriform Ltd) C:\Users\Nils\Downloads\rcsetup151.exe
2014-08-21 13:55 - 2014-08-21 13:53 - 00000000 ____D () C:\Users\Nils\Desktop\Neuer Ordner
2014-08-21 13:53 - 2014-08-21 13:53 - 00121069 _____ () C:\Users\Nils\Downloads\memtest86+-5.01.usb.installer.zip
2014-08-21 00:12 - 2014-08-20 23:39 - 00077688 _____ () C:\Users\Nils\Desktop\Unbenannt 1.ods
2014-08-20 16:39 - 2014-08-20 16:39 - 04526080 _____ () C:\Users\Nils\Downloads\FRITZ.Box_Fon_WLAN_7113.60.04.68.image
2014-08-20 14:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-20 12:48 - 2014-08-20 12:48 - 00195072 _____ () C:\Users\Nils\Downloads\BERECHNUNG_PT1000.XLS
2014-08-19 19:49 - 2014-08-19 19:49 - 00015127 _____ () C:\Users\Nils\Documents\Unbenannt 1.ods
2014-08-19 19:08 - 2014-07-14 11:32 - 00067128 _____ () C:\Users\Nils\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-19 17:27 - 2014-08-19 17:27 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk
2014-08-19 17:27 - 2014-08-19 17:27 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-08-19 17:27 - 2014-08-19 17:27 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\OpenOffice
2014-08-19 17:27 - 2014-08-19 17:27 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-08-19 17:26 - 2014-08-19 17:26 - 00000000 ____D () C:\Users\Nils\Desktop\OpenOffice 4.1.0 (de) Installation Files
2014-08-19 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-08-19 17:25 - 2014-08-19 17:24 - 164962843 _____ () C:\Users\Nils\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe
2014-08-18 17:35 - 2014-08-18 17:34 - 00000000 ____D () C:\Users\Nils\AppData\Local\gtk-2.0
2014-08-15 22:41 - 2014-08-15 22:41 - 00000000 __SHD () C:\Users\Nils\AppData\Local\EmieUserList
2014-08-15 22:41 - 2014-08-15 22:41 - 00000000 __SHD () C:\Users\Nils\AppData\Local\EmieSiteList
2014-08-15 13:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-15 10:30 - 2014-09-04 16:38 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-08-15 10:30 - 2014-09-04 16:38 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-08-15 10:30 - 2014-09-04 16:38 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-08-15 00:20 - 2014-07-30 11:40 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 19:44 - 2014-08-09 14:58 - 00000000 ____D () C:\Users\Nils\Desktop\Age of Empires II & The Conquerors
2014-08-14 19:39 - 2014-08-14 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voobly
2014-08-14 19:39 - 2014-08-14 19:36 - 00000000 ____D () C:\Program Files (x86)\Voobly
2014-08-14 19:36 - 2014-08-14 19:36 - 09961548 _____ (Voobly ) C:\Users\Nils\Downloads\voobly-v2.1.67.1.exe
2014-08-14 19:36 - 2014-08-14 19:36 - 00000983 _____ () C:\Users\Nils\Desktop\Voobly.lnk
2014-08-14 17:24 - 2014-08-14 17:24 - 00000000 ____D () C:\Users\Nils\AppData\Local\LogMeIn
2014-08-14 17:24 - 2014-08-14 17:24 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-08-14 17:23 - 2014-08-14 17:23 - 08499200 _____ () C:\Users\Nils\Downloads\hamachi.msi
2014-08-12 21:19 - 2014-08-12 21:19 - 00000219 _____ () C:\Windows\Directx.log
2014-08-12 21:19 - 2014-08-12 21:19 - 00000000 ____D () C:\Program Files (x86)\directx
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2014-08-12 21:18 - 2014-07-14 11:41 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-11 18:38 - 2014-08-11 18:38 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Riot Games
2014-08-11 18:38 - 2014-08-11 18:37 - 34888568 _____ (Riot Games) C:\Users\Nils\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe
2014-08-11 16:26 - 2014-08-11 15:50 - 00000000 ____D () C:\Program Files (x86)\vLite
2014-08-11 16:15 - 2014-08-11 15:49 - 2463242240 _____ () C:\Users\Nils\Downloads\X15-65740.iso
2014-08-11 15:50 - 2014-08-11 15:50 - 01620715 _____ (Dino Nuhagic (nuhi) ) C:\Users\Nils\Downloads\vLite-1.2.installer.exe
2014-08-11 15:50 - 2014-08-11 15:50 - 00518940 _____ () C:\Users\Nils\Downloads\wimfltr.exe
2014-08-11 15:50 - 2014-08-11 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vLite
2014-08-11 15:32 - 2014-08-11 15:32 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\WinRAR
2014-08-11 15:31 - 2014-08-11 15:30 - 00000000 ____D () C:\Users\Nils\Desktop\stick
2014-08-11 15:30 - 2014-08-11 15:30 - 02060744 _____ () C:\Users\Nils\Downloads\winrar-x64-510d.exe
2014-08-11 15:30 - 2014-08-11 15:30 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-11 15:30 - 2014-08-11 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-11 15:30 - 2014-08-11 15:30 - 00000000 ____D () C:\Program Files\WinRAR
2014-08-11 15:24 - 2014-08-11 15:20 - 348127232 _____ () C:\Users\Nils\Downloads\android-x86-4.4-RC2.iso
2014-08-10 11:35 - 2014-07-14 11:29 - 00000000 ____D () C:\Users\Nils\AppData\Local\VirtualStore
2014-08-10 11:30 - 2014-08-10 11:30 - 00400569 _____ () C:\Users\Nils\Downloads\agmp3plugin.exe
2014-08-10 11:30 - 2014-08-10 11:23 - 00000000 ____D () C:\Program Files (x86)\Audiograbber
2014-08-10 11:28 - 2014-08-10 11:28 - 00001164 _____ () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-10 11:28 - 2014-08-10 11:23 - 00000000 ____D () C:\Program Files (x86)\Security Guard
2014-08-10 11:27 - 2014-08-10 11:27 - 00000435 _____ () C:\Windows\cdplayer.ini
2014-08-10 11:23 - 2014-08-10 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audiograbber
2014-08-10 11:21 - 2014-08-10 11:21 - 00471536 _____ () C:\Users\Nils\Downloads\download_audiograbber.exe
2014-08-09 17:54 - 2014-08-09 17:54 - 00587776 _____ (Igor Pavlov) C:\Users\Nils\Downloads\7za.exe
2014-08-09 17:54 - 2014-08-09 17:54 - 00078848 _____ () C:\Users\Nils\Downloads\Archive.dll
2014-08-09 17:54 - 2014-08-09 17:54 - 00043008 _____ () C:\Users\Nils\Downloads\39dll.dll
2014-08-09 17:54 - 2014-08-09 17:54 - 00005845 _____ () C:\Users\Nils\Downloads\txt.sec
2014-08-09 17:54 - 2014-08-09 17:54 - 00000000 ____D () C:\Users\Nils\Downloads\Resources
2014-08-09 17:43 - 2014-08-09 17:37 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\AVAST Software
2014-08-09 17:43 - 2014-08-09 17:36 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-08-09 17:43 - 2014-08-09 17:36 - 00000000 ____D () C:\Program Files\AVAST Software
2014-08-09 17:42 - 2014-08-09 17:42 - 00000034 _____ () C:\Windows\AvastEmUpdate.ini
2014-08-09 17:42 - 2014-08-09 17:42 - 00000000 _____ () C:\Windows\SysWOW64\config.nt
2014-08-09 17:41 - 2014-08-09 17:41 - 00519488 _____ (AVAST Software) C:\Users\Nils\Downloads\avastclear.exe
2014-08-09 17:37 - 2014-08-09 17:37 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-09 17:36 - 2014-08-09 17:36 - 00426848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1407598624688
2014-08-09 17:36 - 2014-08-09 17:36 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-09 17:29 - 2014-08-09 17:29 - 08499200 _____ () C:\Users\Nils\Downloads\hamachi_CB-DL-Manager [1].exe
2014-08-09 17:19 - 2014-08-09 17:19 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ____D () C:\Users\Nils\AppData\Local\Skype
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ____D () C:\ProgramData\Skype
2014-08-09 17:19 - 2014-08-09 17:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-09 17:17 - 2014-08-09 17:17 - 00787392 _____ ( ) C:\Users\Nils\Downloads\hamachi_CB-DL-Manager.exe
2014-08-09 17:16 - 2014-08-09 17:16 - 01677928 _____ (Skype Technologies S.A.) C:\Users\Nils\Downloads\SkypeSetup.exe
2014-08-09 16:42 - 2014-08-09 16:17 - 361544078 _____ () C:\Users\Nils\Downloads\gta2installer.zip
2014-08-09 16:31 - 2014-07-15 12:17 - 00001001 _____ () C:\Users\Nils\Desktop\DVBViewer TE2.lnk
2014-08-09 16:17 - 2014-08-09 16:16 - 01101648 _____ () C:\Users\Nils\Downloads\Grand Theft Auto GTA 2 - CHIP-Installer.exe
2014-08-09 16:09 - 2014-08-09 15:05 - 00000000 ____D () C:\Users\Nils\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-08-09 15:08 - 2014-08-09 15:08 - 01659099 _____ () C:\Users\Nils\Downloads\aokpatch2a-crk.zip
2014-08-09 15:08 - 2014-08-09 15:08 - 00000948 _____ () C:\Users\Nils\Downloads\aoe2-vista-win7-fix.zip
2014-08-09 15:04 - 2014-08-09 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-08-09 14:54 - 2014-08-09 14:53 - 00000000 ____D () C:\Users\Nils\Desktop\AoE 2 - The Age of Kings
2014-08-08 21:48 - 2014-07-29 23:51 - 00000000 ____D () C:\Users\Nils\dl-fldigi.files
2014-08-08 19:07 - 2014-08-08 19:07 - 00008628 _____ () C:\Users\Nils\Downloads\p.txt
2014-08-08 19:07 - 2014-08-08 18:19 - 397550563 _____ () C:\Users\Nils\Downloads\CarTFT_EX70-2_Windows_Drivers.zip
2014-08-08 19:02 - 2014-08-08 18:19 - 375104654 _____ () C:\Users\Nils\Downloads\CarTFT_X70EX-2_BASIC_Android.zip
2014-08-07 04:06 - 2014-08-14 17:30 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-14 17:30 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

Some content of TEMP:
====================
C:\Users\Nils\AppData\Local\Temp\avgnt.exe
C:\Users\Nils\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Nils\AppData\Local\Temp\drm_dyndata_7270014.dll
C:\Users\Nils\AppData\Local\Temp\erplcnms.dll
C:\Users\Nils\AppData\Local\Temp\i4jdel0.exe
C:\Users\Nils\AppData\Local\Temp\install_reader11_de_mssd_aaa_aih.exe
C:\Users\Nils\AppData\Local\Temp\project1.exe
C:\Users\Nils\AppData\Local\Temp\Samsung_Magician_Setup_v44.exe
C:\Users\Nils\AppData\Local\Temp\Shockwave_Installer_FF.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-20 14:41

==================== End Of Log ============================
         

und die Addition:

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-09-2014 02
Ran by Nils at 2014-09-04 17:47:48
Running from C:\Users\Nils\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Arduino (HKLM-x32\...\Arduino) (Version: 1.0.5-r2 - Arduino LLC)
ATI Catalyst Install Manager (HKLM\...\{2A13EF26-4D68-B2D7-A486-DBBD2FDE366B}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Audiograbber 1.83 SE  (HKLM-x32\...\Audiograbber) (Version: 1.83 SE  - Audiograbber)
Audiograbber MP3-Plugin (HKLM-x32\...\Audiograbber-Lame) (Version: 1.0 - AG)
AutoIt v3.3.12.0 (HKLM-x32\...\AutoItv3) (Version: 3.3.12.0 - AutoIt Team)
Avira (HKLM-x32\...\{e67154a7-9cc5-4167-b782-f3982bc6c70d}) (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira)
Boost for Internet Explorer (HKLM-x32\...\Boost) (Version: 3.0.0.10 - Boost Shopping)
Catalyst Control Center Core Implementation (x32 Version: 2010.0210.2206.39615 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0210.2206.39615 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0210.2206.39615 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0210.2206.39615 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0210.2206.39615 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0210.2206.39615 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0210.2206.39615 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help English (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help French (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help German (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0210.2205.39615 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0210.2206.39615 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2010.0210.2206.39615 - ATI) Hidden
Counter-Strike: Source (HKLM-x32\...\Counter-Strike: Source) (Version:  - Valve)
Dl-Fldigi 3.21.50 (HKLM-x32\...\Dl-Fldigi-3.21.50) (Version: 3.21.50 - Fldigi developers)
DVBViewer TE2 (HKLM-x32\...\DVBViewer TE2_is1) (Version:  - CM&V)
EAGLE 7.0.0 (HKLM-x32\...\EAGLE 7.0.0) (Version: 7.0.0 - CadSoft Computer GmbH)
Genesis (HKCU\...\genesis_09031222) (Version:  - ) <==== ATTENTION
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
GPU Boost Driver (HKLM-x32\...\{B8887E02-C910-4498-A7C0-186ABFDCD110}) (Version: 1.01.15 - ASUS)
GTA2 (HKLM-x32\...\{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}) (Version: 1.00.001 - )
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version:  - EFD Software)
HD-V9.4 (HKLM-x32\...\HD-V9.4) (Version: 1.34.8.12 - HD-V9.4)
InetStat (HKCU\...\InetStat) (Version: 0.5b - InetStat)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
KiCad 2013.07.07 (HKLM-x32\...\KiCad) (Version: 2013.07.07 - )
Lazarus 1.2.4 (HKLM\...\lazarus_is1) (Version: 1.2.4 - Lazarus Team)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.236 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.236 - LogMeIn, Inc.) Hidden
MainConcept DTV Decoder Pro (HKLM-x32\...\{793FCE60-DE5E-4977-A942-A7B69A45B17D}) (Version: 1.5.0.2 - MainConcept GmbH)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Age of Empires II (HKLM-x32\...\Age of Empires 2.0) (Version:  - )
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
OffersWizard Network System Driver (HKLM-x32\...\inethnfd) (Version: 1.0.0.3001 - ) <==== ATTENTION
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
RAPID Mode (Version: 1.0.1.68 - Samsung Electronics Co., Ltd.) Hidden
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.23.623.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6151 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.4.0 - Samsung Electronics)
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
Spotify (HKCU\...\Spotify) (Version: 0.9.12.10.g89b2a4fc - Spotify AB)
TechniSat DVB-PC TV Star (HKLM-x32\...\{CE9F9FBC-5253-46D2-9883-09E55003D794}) (Version: 1.0.0 - TechniSat)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
vLite (HKLM-x32\...\vLite_is1) (Version: 1.2 - Dino Nuhagic (nuhi))
Voobly Game Data (HKLM-x32\...\Voobly_is1) (Version: Voobly Game Datas - Voobly)
Windows 7 Codec Pack 4.0.9 (HKLM-x32\...\Windows 7 - Codec Pack) (Version: 4.0.9 - Windows 7 Codec Pack)
Wings 3D 1.5.3 (HKLM-x32\...\Wings 3D 1.5.3) (Version:  - )
WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

22-08-2014 10:50:58 Windows Update
26-08-2014 14:45:02 Windows Update
28-08-2014 13:25:07 Windows Update
02-09-2014 09:16:38 Windows Update
03-09-2014 12:09:52 Installed Java 7 Update 67
03-09-2014 19:32:35 Gerätetreiber-Paketinstallation: Arduino LLC (www.arduino.cc) Anschlüsse (COM & LPT)

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1A7E86B7-1B7A-427A-A43D-CF86881C04D2} - System32\Tasks\ASUS\Gpu Boost Driver => C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe [2010-03-27] (
ASUSTeK Computer Inc.)
Task: {21E161E9-F0A2-4753-9154-BEE74EBD977D} - System32\Tasks\OYVXKZPY => C:\Users\Nils\AppData\Roaming\OYVXKZPY.exe
Task: {334D1D1E-84D8-4491-9B00-4FB937487589} - System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3 => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3.exe <==== ATTENTION
Task: {37E04530-C25C-4D4B-81A3-071B059D26B5} - System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11 => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11.exe <==== ATTENTION
Task: {86EBF3A1-CE11-4504-9514-76FD514A65C3} - System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5 => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.exe <==== ATTENTION
Task: {9968A1D7-DAF4-4B6C-B559-18363113DDB0} - System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4 => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4.exe <==== ATTENTION
Task: {9B227FDB-4B0B-4622-9AA7-2F9C2C31FAEB} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-03] (globalUpdate) <==== ATTENTION
Task: {A16C1411-E8F9-4999-93EA-8383EF555869} - System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2 => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2.exe <==== ATTENTION
Task: {A5FE5D67-2448-49D8-9FD7-16A07383B622} - System32\Tasks\SESSEC => C:\Users\Nils\AppData\Roaming\SESSEC.exe
Task: {BE19A5CA-B5A3-43A9-AB23-A5348881770A} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-03] (globalUpdate) <==== ATTENTION
Task: {BE6D4175-D219-4B4F-ADBD-A0E9BD2D3FE6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: {D9D7CAD7-4878-4BAC-BA72-167CB32390C8} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-05-19] (Samsung Electronics.)
Task: {DE6E9868-23D3-414D-A81B-1F0945CE5F56} - System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5_user => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.exe <==== ATTENTION
Task: {F4AADD0E-4C9F-45DD-97E7-503C9C3B2F85} - System32\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-1 => C:\Program Files (x86)\HD-V9.4\HD-V9.4-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-1.job => C:\Program Files (x86)\HD-V9.4\HD-V9.4-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11.job => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2.job => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3.job => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4.job => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.job => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5_user.job => C:\Program Files (x86)\HD-V9.4\197bc0c9-2fbe-45b5-b37c-2d65549b8c82-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\OYVXKZPY.job => C:\Users\Nils\AppData\Roaming\OYVXKZPY.exe
Task: C:\Windows\Tasks\SESSEC.job => C:\Users\Nils\AppData\Roaming\SESSEC.exe

==================== Loaded Modules (whitelisted) =============

2014-04-21 21:24 - 2014-04-21 21:24 - 00392704 _____ () C:\Program Files (x86)\Boost\BoostUpdater.exe
2014-07-14 11:47 - 2014-07-14 11:47 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-07-14 17:13 - 2014-08-26 12:28 - 00610872 _____ () C:\Users\Nils\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
2014-07-14 11:49 - 2010-03-12 05:40 - 04449632 _____ () C:\Program Files (x86)\ASUS\GPU Boost Driver\Platform.dll
2014-07-14 11:49 - 2010-03-12 05:40 - 00423256 _____ () C:\Program Files (x86)\ASUS\GPU Boost Driver\Device.dll
2014-07-14 17:13 - 2014-08-26 12:28 - 36966968 _____ () C:\Users\Nils\AppData\Roaming\Spotify\Data\libcef.dll
2014-07-14 12:02 - 2014-05-06 11:24 - 00013824 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll
2014-07-14 12:02 - 2014-05-19 20:20 - 00103424 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\PAL.dll
2014-07-14 12:02 - 2014-05-19 20:20 - 00039424 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SATA.dll
2014-07-14 12:02 - 2014-05-19 20:19 - 00038400 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAT.dll
2014-07-14 12:02 - 2014-05-19 20:20 - 00031232 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SMINI.dll
2014-07-14 12:02 - 2014-05-19 20:19 - 00029696 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAS.dll
2014-07-14 21:16 - 2014-08-26 12:28 - 00867896 _____ () C:\Users\Nils\AppData\Roaming\Spotify\Data\ffmpegsumo.dll
2014-07-14 17:13 - 2014-08-26 12:28 - 00886840 _____ () C:\Users\Nils\AppData\Roaming\Spotify\Data\libglesv2.dll
2014-07-14 17:13 - 2014-08-26 12:28 - 00108600 _____ () C:\Users\Nils\AppData\Roaming\Spotify\Data\libegl.dll
2014-07-15 12:17 - 2009-01-24 14:44 - 00107520 _____ () C:\Program Files (x86)\DVBViewer TE2\Plugins\Skystar.dll
2014-07-15 12:17 - 2009-04-01 10:06 - 00043520 _____ () C:\Program Files (x86)\DVBViewer TE2\Plugins\WinLirc.dll
2014-05-13 17:01 - 2014-05-13 17:01 - 03502592 _____ () C:\Windows\SysWow64\ffdshow.ax
2014-05-13 17:05 - 2014-05-13 17:05 - 04009984 _____ () C:\Windows\system32\ffmpeg.dll
2014-07-23 20:45 - 2014-07-23 20:46 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-09-04 16:40 - 2014-07-14 16:49 - 00049744 _____ () C:\Users\Nils\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-08-04 14:20 - 2014-08-04 14:20 - 00139056 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-08-04 14:20 - 2014-08-04 14:20 - 00067832 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Users^Nils^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BoostUpdater.lnk => C:\Windows\pss\BoostUpdater.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Nils^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^genesis_09031222.lnk => C:\Windows\pss\genesis_09031222.lnk.Startup
MSCONFIG\startupreg: genesis_09031222 => "c:\users\nils\appdata\local\genesis_09031222\genesis_09031222.exe" /r
MSCONFIG\startupreg: InetStat => C:\Users\Nils\AppData\Roaming\InetStat\inetstat.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Voobly => "C:\Program Files (x86)\Voobly\voobly.exe" --startup

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/04/2014 04:29:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/03/2014 02:23:35 PM) (Source: MsiInstaller) (EventID: 11309) (User: Nils-PC)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.

Error: (09/03/2014 01:41:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4145efeb
Name des fehlerhaften Moduls: Steam.dll, Version: 0.0.0.0, Zeitstempel: 0x41e7fcca
Ausnahmecode: 0x4000001f
Fehleroffset: 0x00006260
ID des fehlerhaften Prozesses: 0x13c0
Startzeit der fehlerhaften Anwendung: 0xhl2.exe0
Pfad der fehlerhaften Anwendung: hl2.exe1
Pfad des fehlerhaften Moduls: hl2.exe2
Berichtskennung: hl2.exe3

Error: (09/03/2014 01:37:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4145efeb
Name des fehlerhaften Moduls: Steam.dll, Version: 0.0.0.0, Zeitstempel: 0x41e7fcca
Ausnahmecode: 0x4000001f
Fehleroffset: 0x00006260
ID des fehlerhaften Prozesses: 0x47c
Startzeit der fehlerhaften Anwendung: 0xhl2.exe0
Pfad der fehlerhaften Anwendung: hl2.exe1
Pfad des fehlerhaften Moduls: hl2.exe2
Berichtskennung: hl2.exe3

Error: (09/03/2014 01:35:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/02/2014 11:14:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/01/2014 04:05:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/01/2014 00:22:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/31/2014 02:03:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/30/2014 05:11:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (09/04/2014 04:41:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Network Support Service Updater" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (09/04/2014 04:41:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Network HTTP Support Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (09/04/2014 04:29:02 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (09/04/2014 04:28:22 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (09/03/2014 01:35:12 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (09/03/2014 01:34:40 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (09/01/2014 04:04:28 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (09/01/2014 00:21:48 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (08/31/2014 02:02:47 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (08/31/2014 00:42:25 AM) (Source: Server) (EventID: 2505) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{CD0CC67C-8D16-4508-94C7-ACDB3FD49A5B} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.


Microsoft Office Sessions:
=========================
Error: (09/04/2014 04:29:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/03/2014 02:23:35 PM) (Source: MsiInstaller) (EventID: 11309) (User: Nils-PC)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (09/03/2014 01:41:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: hl2.exe0.0.0.04145efebSteam.dll0.0.0.041e7fcca4000001f0000626013c001cfc76bf25658d2C:\Program Files (x86)\Counter-Strike Source\hl2.exeC:\Program Files (x86)\Counter-Strike Source\Steam.dll34d1082e-335f-11e4-b637-00158350f7b1

Error: (09/03/2014 01:37:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: hl2.exe0.0.0.04145efebSteam.dll0.0.0.041e7fcca4000001f0000626047c01cfc76b63343c8bC:\Users\Nils\Desktop\Counter Strike Source\hl2.exeC:\Users\Nils\Desktop\Counter Strike Source\bin\Steam.dlla5cf6cb1-335e-11e4-b637-00158350f7b1

Error: (09/03/2014 01:35:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/02/2014 11:14:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/01/2014 04:05:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/01/2014 00:22:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/31/2014 02:03:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/30/2014 05:11:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info =========================== 

Processor: AMD Phenom(tm) II X4 965 Processor
Percentage of memory in use: 47%
Total physical RAM: 7935.16 MB
Available physical RAM: 4164.42 MB
Total Pagefile: 15868.5 MB
Available Pagefile: 11601.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.69 GB) (Free:54.1 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 50B522E3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
und die gmer:

Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-09-04 18:17:24
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Samsung_SSD_840_EVO_120GB rev.EXT0BB6Q 111,79GB
Running: yn11zb4n.exe; Driver: C:\Users\Nils\AppData\Local\Temp\kxldqpoc.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                             fffff80002df9000 45 bytes [05, 00, 00, 00, 06, 00, 00, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575                                                             fffff80002df902f 5 bytes [00, 10, B5, F0, 6E]

---- User code sections - GMER 2.1 ----

.text     C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe[5636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69        0000000077ad1465 2 bytes [AD, 77]
.text     C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe[5636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155       0000000077ad14bb 2 bytes [AD, 77]
.text     ...                                                                                                                            * 2
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[1768] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000077ad1465 2 bytes [AD, 77]
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[1768] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  0000000077ad14bb 2 bytes [AD, 77]
.text     ...                                                                                                                            * 2
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[5788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69       0000000077ad1465 2 bytes [AD, 77]
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[5788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155      0000000077ad14bb 2 bytes [AD, 77]
.text     ...                                                                                                                            * 2

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations                                              ????????????????????????? ?????????????????????0????????????&???????????????????????? ?????????????????????0????????????????????? ???????????????????x?0????????*???????????? ?????????????????????0??????????????????????????????????????*?????????????? ???????????????????x?0????????*?????????????*?????????????hxxp://www.zyxel.com????{36fc9e60-c465-11cf-8056-444553540000}?m94?????????????????n?????????????n??am??? ?????????????????????0????????????????????ZyXEL???????????????????? ???????????????????x?0?????????????????????????????v???u????*??????????x??hxxp://www.zyxel.com????????????????????? ?????????????????????0????????????????????? ???????????????????x?0?????????????????????????????????????z??????????????????????NSA325 v2????????????????????????????????????????????4???????????????????????????????????????i???????????????????????? ????(??????P????????????(??????P????????????(??????P????????????(??????P????????????(??????P????????????(??????P????????????(??????P?????????????@usbport.inf,%usb\root_hub.devicede
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158350f7b1                                                    
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158350f7b1@88124e878892                                       0xE0 0xC8 0xB3 0x02 ...
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158350f7b1 (not active ControlSet)                                
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158350f7b1@88124e878892                                           0xE0 0xC8 0xB3 0x02 ...

---- EOF - GMER 2.1 ----
         
Besteht da Hoffnung das ganze relativ einfach sauber zu bekommen? Wenn nein würde ich dazu tendieren gleich alles Platt zumachen und Windows neu aufzusetzen, da sowieso noch nicht viele Datein auf dem Rechner sind und alle Dokumente und Bilder extern auf meinem Nas liegen.... Aber das ist natürlich Aufwand, den ich gerne vermeiden würde ;-)
Ich danke schonmal im Vorraus für die Hilfe und hoffem, dass ihr mir helfen könnt...

Nils

 

Themen zu Plötzliche Werbung in Firefox und Internet Explorer
4d36e972-e325-11ce-bfc1-08002be10318, adware/amonetize.ges, adware/amonetize.tzv, adware/crossrider.gen, adware/crossrider.gen2, adware/symmi.11385.158, fehler 0x4000001f, fehlercode 0x4000001f, grand theft auto, hacktool.agent, install.exe, msil/toolbar.linkury.c, msil/toolbar.linkury.f, msil/toolbar.linkury.g, pup.optional.ciuvo.a, pup.optional.crossrider.a, pup.optional.plushd.a, pup.optional.smartbar, pup.optional.spigot, teredo, tr/crypt.zpack.gen2, tr/rogue.gere.3, win32/amonetize.az, win32/bundled.toolbar.google.d, win32/downloadguide.a, win32/downloadsponsor.a, win32/installcore.oz, win32/riskware.netfilter.b, win32/verti.g, win64/riskware.netfilter.c




Ähnliche Themen: Plötzliche Werbung in Firefox und Internet Explorer


  1. Firefox durch Werbung unbrauchbar, viele Internet Explorer Prozesse
    Plagegeister aller Art und deren Bekämpfung - 23.04.2015 (19)
  2. Windows 7: Internet Explorer startet automatisch Werbung/ Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 27.07.2014 (7)
  3. Windows 7: Firefox fehlermeldung : Proxy-Server verweigert die Verbindung, Internet Explorer falsche Startseite, viel werbung
    Log-Analyse und Auswertung - 22.04.2014 (23)
  4. Win 7: unzählige pop-up Fenster und Werbung in Internet Explorer und Firefox
    Log-Analyse und Auswertung - 22.03.2014 (11)
  5. Firefox / Internet Explorer öffnet Werbung in neuen Tabs
    Log-Analyse und Auswertung - 11.02.2012 (7)
  6. Firefox bzw. Internet Explorer öffnet Tabs/Fenster mit Werbung
    Plagegeister aller Art und deren Bekämpfung - 04.08.2011 (13)
  7. Firefox öffnet plötzlich, immer wieder unerwünschte Webseiten ...Internet Explorer öffnet Werbung
    Log-Analyse und Auswertung - 12.06.2011 (17)
  8. Avast Web Schutz verhindert Internet-Zugang über Firefox/Internet Explorer
    Antiviren-, Firewall- und andere Schutzprogramme - 27.05.2011 (7)
  9. Internet Explorer und Firefox kommen nicht ins Internet
    Plagegeister aller Art und deren Bekämpfung - 16.06.2010 (71)
  10. Internet Explorer/Firefox öffnet automatisch und ständig Werbung
    Log-Analyse und Auswertung - 11.06.2010 (6)
  11. Internet Explorer/Firefox öffnet automatisch Werbung
    Log-Analyse und Auswertung - 09.06.2010 (31)
  12. Werbung im Internet Explorer
    Log-Analyse und Auswertung - 11.11.2009 (1)
  13. Werbung Internet Explorer 1 und 1
    Log-Analyse und Auswertung - 20.08.2009 (12)
  14. Internet Explorer Werbung
    Log-Analyse und Auswertung - 15.07.2009 (1)
  15. Internet Explorer Werbung
    Log-Analyse und Auswertung - 28.11.2008 (5)
  16. Werbung Internet Explorer
    Mülltonne - 18.03.2008 (0)
  17. Internet Explorer Werbung
    Log-Analyse und Auswertung - 11.06.2005 (1)

Zum Thema Plötzliche Werbung in Firefox und Internet Explorer - Moin Leute, ich glaube, dass ich gestern durch einen dummen Fehler gestern meinen Rechner infiziert habe... Kleine Vorgeschichte: Ich habe seit Jahren keine Antivirensoftware verwendet und bin damit so weit - Plötzliche Werbung in Firefox und Internet Explorer...
Archiv
Du betrachtest: Plötzliche Werbung in Firefox und Internet Explorer auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.