Jemand hat unbemerkt ein Programm auf meinem PC geöffnet

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Jemand hat unbemerkt ein Programm auf meinem PC geöffnet


vor kurzem habe ich einen "Freund" per Teamviewer einige überschaubare Sachen bei mir machen lassen - die Sitzung dauerte ca. 30 Sekunden und daran war auch erstmal nichts auffällig. Den Teamviewer log besitze ich noch und mir kommt es so vor, als hätte die Sitzung doch etwas länger angedauert. Ich war in einem Spiel und konnte kurz nachdem wir Teamviewer (vermeidlich?!) geschlossen hatten, nicht auf Windows tabben. Der Bildschirm war dann einfach nur schwarz - und erst mit dem Taskmanager bekam ich wieder ein normales Bild.

Diese Nacht habe ich den PC angelassen und als ich vorhin aufgewacht bin, hatte ich zwei mal die Programme "Rechner" geöffnet. In einem stand eine 850 und in einem ne 0. Ich bin mir 100% sicher, dass ich diese zuvor nicht geöffnet hatte - und auch sonst hatte über Nacht niemand Zuhause Zugang auf meinen PC.

Also ich habe einfach mal im Ereignisprotokoll rumgesurft und das hier gefunden
Die automatische Aktualisierung des Drittanbieterstammzertifikats wurde erfolgreich ausgeführt: Antragsteller: <CN=UTN-USERFirst-Hardware, OU=hxxp://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US> Sha1-Fingerabdruck: <0483ED3399AC3608058722EDBC5E4600E3BEF9D7>.
Ich weiß nicht, was das bedeuten soll. Aber da der Kerl, mit dem ich das über Teamviewer gemacht habe, aus den USA stammt, habe ich gerade etwas Angst.
Vor allem, weil ich Onlinebanking etc. habe.

Könntet ihr mir freundlicherweise helfen und sagen was dies bedeutet, sowie eine bestimmte vorgehensweise anbieten um dieses Phänomen ein für alle Male zu lösen?

Der Defogger hat bei mir nicht gescannt, es hieß nur nach nichtmal einer Sekunde "Finished", aber es wurde kein Logfile o.Ä. erstellt.

Vielen Dank, bin echt verzweifelt und gerade etwas confus :/

Jemand hat unbemerkt ein Programm auf meinem PC geöffnet


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Jemand hat unbemerkt ein Programm auf meinem PC geöffnet


FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-09-2014
Ran by Admin (administrator) on ADMIN-PC on 07-09-2014 09:01:42
Running from C:\Users\Admin\Downloads
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(PCTV Systems S.à r.l.) C:\Program Files (x86)\Common Files\PCTV Systems\RemoTerm\remoterm.exe
(Spotify Ltd) C:\Users\Admin\AppData\Roaming\Spotify\spotify.exe
(Spotify Ltd) C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Valve Corporation) D:\Games\Steam\Steam.exe
(Valve Corporation) D:\Games\Steam\bin\steamwebhelper.exe
() D:\Games\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
(Valve Corporation) D:\Games\Steam\GameOverlayUI.exe
() C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Valve Corporation) D:\Games\Steam\bin\steamwebhelper.exe
(Valve Corporation) D:\Games\Steam\bin\steamwebhelper.exe
(Valve Corporation) D:\Games\Steam\bin\steamwebhelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-27826031-60937729-2427931102-1000\...\Run: [RemoTerm.exe] => C:\Program Files (x86)\Common Files\PCTV Systems\RemoTerm\RemoTerm.exe [227640 2013-02-20] (PCTV Systems S.à r.l.)
HKU\S-1-5-21-27826031-60937729-2427931102-1000\...\Run: [Spotify] => C:\Users\Admin\AppData\Roaming\Spotify\Spotify.exe [6621752 2014-08-26] (Spotify Ltd)
HKU\S-1-5-21-27826031-60937729-2427931102-1000\...\Run: [Spotify Web Helper] => C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-08-26] (Spotify Ltd)
HKU\S-1-5-21-27826031-60937729-2427931102-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_70_Plugin.exe [841096 2014-02-22] (Adobe Systems Incorporated)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Nach Updates suchen.lnk
ShortcutTarget: Nach Updates suchen.lnk -> C:\Program Files (x86)\Common Files\PCTV Systems\WebUpdater\WebUpdater.exe (PCTV Systems)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x98015095A9D7CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
BHO-x32: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5jxybyh7.default
FF Homepage: www.t-online.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*'))%20%7B%20return%20'PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxMate - Proxy on steroids! - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5jxybyh7.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2014-03-19]
FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5jxybyh7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-22]


==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 azvusb; C:\Windows\System32\DRIVERS\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [335464 2011-01-14] (Realtek Semiconductor Corporation                           )

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-07 09:01 - 2014-09-07 09:01 - 00012363 _____ () C:\Users\Admin\Downloads\FRST.txt
2014-09-07 09:01 - 2014-09-07 09:01 - 00000000 ____D () C:\FRST
2014-09-07 08:59 - 2014-09-07 09:00 - 00000472 _____ () C:\Users\Admin\Downloads\defogger_disable.log
2014-09-07 08:59 - 2014-09-07 08:59 - 00000000 _____ () C:\Users\Admin\defogger_reenable
2014-09-07 08:56 - 2014-09-07 08:56 - 02104832 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2014-09-07 08:56 - 2014-09-07 08:56 - 00050477 _____ () C:\Users\Admin\Downloads\Defogger.exe
2014-09-07 01:00 - 2014-09-07 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-07 01:00 - 2014-09-07 01:00 - 00000000 _____ () C:\Windows\setupact.log
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Admin\Documents\SelfMV
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Admin\Documents\samsung
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Samsung
2014-09-05 10:35 - 2014-09-05 10:39 - 00000000 ____D () C:\Program Files (x86)\Samsung
2014-09-05 10:35 - 2014-09-05 10:35 - 00000000 ____D () C:\Users\Admin\AppData\Local\Downloaded Installations
2014-09-05 10:34 - 2014-09-05 10:35 - 75211320 _____ (Samsung Electronics Co., Ltd.) C:\Users\Admin\Downloads\KiesSetup.exe
2014-09-05 10:34 - 2014-09-05 10:35 - 39279648 _____ (Samsung Electronics Co., Ltd.) C:\Users\Admin\Downloads\Kies3Setup.exe
2014-09-04 00:34 - 2014-09-04 00:34 - 00010800 _____ () C:\Users\Admin\Downloads\config.cfg
2014-09-04 00:34 - 2014-09-04 00:34 - 00002109 _____ () C:\Users\Admin\Downloads\autoexec.cfg
2014-09-03 16:04 - 2014-09-04 18:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-31 03:15 - 2014-08-31 03:15 - 00000000 ____D () C:\Windows\Sun
2014-08-28 20:58 - 2014-09-06 17:26 - 00539548 ____N () C:\Windows\WindowsUpdate.log
2014-08-28 10:53 - 2014-08-28 10:53 - 04901352 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup417.exe
2014-08-28 01:01 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 01:01 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 01:01 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 16:54 - 2014-08-27 16:54 - 00000000 ____D () C:\4im
2014-08-27 13:19 - 2014-08-27 13:19 - 00000585 _____ () C:\Users\Admin\Downloads\run(1).bat
2014-08-27 12:33 - 2014-08-27 12:33 - 01101648 _____ () C:\Users\Admin\Downloads\TeamViewer - CHIP-Installer.exe
2014-08-27 12:09 - 2014-08-27 12:09 - 00108446 _____ () C:\Users\Admin\Desktop\TeamViewer9_Logfile.log
2014-08-27 05:11 - 2014-08-27 05:11 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-27 05:10 - 2014-08-27 05:11 - 07500112 _____ (TeamViewer GmbH) C:\Users\Admin\Downloads\TeamViewer_Setup_9.0.31064.exe
2014-08-27 01:56 - 2014-08-27 01:56 - 00816064 _____ ( ) C:\Users\Admin\Downloads\FreeVK_CB-DL-Manager.exe
2014-08-27 00:23 - 2014-08-27 00:23 - 00000585 _____ () C:\Users\Admin\Downloads\run.bat
2014-08-23 20:57 - 2014-08-23 20:57 - 00000193 _____ () C:\Windows\WORDPAD.INI
2014-08-23 20:38 - 2014-08-23 20:39 - 07190152 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe
2014-08-23 20:38 - 2014-08-23 20:39 - 06499816 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x86.exe
2014-08-23 20:38 - 2014-08-23 20:38 - 01417568 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_arm.exe
2014-08-23 17:13 - 2014-08-28 11:03 - 00000866 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-23 17:13 - 2014-08-28 10:54 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-23 17:13 - 2014-08-23 17:13 - 03738080 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup416_slim.exe
2014-08-23 17:13 - 2014-08-23 17:13 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-23 17:13 - 2014-08-23 17:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-23 16:31 - 2014-08-23 16:31 - 00000000 ____D () C:\Users\Admin\Neuer Ordner
2014-08-22 01:27 - 2014-08-22 01:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-22 01:26 - 2014-08-22 01:27 - 00004623 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_67-b01.log
2014-08-21 17:26 - 2014-08-21 17:26 - 00010592 _____ () C:\Users\Admin\Documents\config.cfg
2014-08-21 17:23 - 2014-08-21 17:23 - 00000000 ____D () C:\Users\Admin\Downloads\cfg
2014-08-21 17:22 - 2014-08-21 17:22 - 00005058 _____ () C:\Users\Admin\Downloads\CFG(1).rar
2014-08-21 17:20 - 2014-08-21 17:20 - 00004890 _____ () C:\Users\Admin\Downloads\autoexec.zip
2014-08-21 16:47 - 2014-08-21 16:47 - 00061268 _____ () C:\Users\Admin\Downloads\cfg.rar
2014-08-17 16:51 - 2014-08-17 16:51 - 00000755 _____ () C:\Users\Public\Desktop\AION Free-to-Play.lnk
2014-08-17 16:48 - 2014-08-17 16:49 - 20136920 _____ (Gameforge ) C:\Users\Admin\Downloads\AION_GameforgeLiveSetup.exe
2014-08-16 22:42 - 2014-08-17 16:51 - 00000000 ____D () C:\Program Files (x86)\GameforgeLive
2014-08-16 22:42 - 2014-08-16 22:42 - 00001063 _____ () C:\Users\Public\Desktop\Gameforge Live.lnk
2014-08-16 22:42 - 2014-08-16 22:42 - 00000000 ____D () C:\Users\Admin\AppData\Local\Gameforge4d
2014-08-16 22:39 - 2014-08-16 22:39 - 15575488 _____ (Gameforge Productions GmbH ) C:\Users\Admin\Downloads\TERASetup.exe
2014-08-16 22:39 - 2014-08-16 22:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-08-15 22:40 - 2014-08-15 22:40 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\TERA
2014-08-15 22:31 - 2014-08-15 22:31 - 20115464 _____ (Gameforge ) C:\Users\Admin\Downloads\TERA_GameforgeLiveSetup.exe
2014-08-14 03:01 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 03:01 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 03:01 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 03:01 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 03:01 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 03:01 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 03:00 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 03:00 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-14 01:47 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-14 01:47 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-14 01:47 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-14 01:47 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-14 01:47 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-14 01:47 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-14 01:47 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-14 01:47 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-14 01:47 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-14 01:47 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-14 01:47 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-14 01:47 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-14 01:47 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-14 01:47 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-14 01:47 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 01:47 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 01:47 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 01:47 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 01:47 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 01:47 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 01:47 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 01:47 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-14 01:46 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-14 01:46 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-14 01:46 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-14 01:46 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-14 01:46 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 01:46 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-14 01:46 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-14 01:46 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-14 01:46 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-14 01:46 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-14 01:46 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-14 01:46 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-14 01:46 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-14 01:46 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-14 01:46 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-14 01:46 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-14 01:46 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-14 01:46 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-14 01:46 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 01:46 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-14 01:46 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-14 01:46 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-14 01:46 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-14 01:46 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-14 01:46 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-14 01:46 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 01:46 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-14 01:46 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-14 01:46 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-14 01:46 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-14 01:46 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-14 01:46 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-14 01:46 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-14 01:46 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-14 01:46 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-14 01:46 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-14 01:46 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-14 01:46 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-14 01:46 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-14 01:46 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-14 01:46 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-14 01:46 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-14 01:46 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-14 01:46 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-14 01:46 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-14 01:46 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-14 01:46 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-14 01:46 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-14 01:46 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-14 01:46 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-14 01:46 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-14 01:46 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-14 01:46 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-14 01:46 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-14 01:46 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-14 01:46 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-14 01:46 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-14 01:46 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-14 01:44 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-14 01:44 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-14 01:44 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 01:44 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-07 09:01 - 2014-09-07 09:01 - 00012363 _____ () C:\Users\Admin\Downloads\FRST.txt
2014-09-07 09:01 - 2014-09-07 09:01 - 00000000 ____D () C:\FRST
2014-09-07 09:00 - 2014-09-07 08:59 - 00000472 _____ () C:\Users\Admin\Downloads\defogger_disable.log
2014-09-07 08:59 - 2014-09-07 08:59 - 00000000 _____ () C:\Users\Admin\defogger_reenable
2014-09-07 08:59 - 2013-11-02 10:12 - 00000000 ____D () C:\Users\Admin
2014-09-07 08:56 - 2014-09-07 08:56 - 02104832 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2014-09-07 08:56 - 2014-09-07 08:56 - 00050477 _____ () C:\Users\Admin\Downloads\Defogger.exe
2014-09-07 08:45 - 2014-05-29 16:44 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype
2014-09-07 06:37 - 2014-02-22 00:27 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Spotify
2014-09-07 04:03 - 2014-05-29 16:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\TS3Client
2014-09-07 01:00 - 2014-09-07 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-07 01:00 - 2014-09-07 01:00 - 00000000 _____ () C:\Windows\setupact.log
2014-09-06 17:26 - 2014-08-28 20:58 - 00539548 ____N () C:\Windows\WindowsUpdate.log
2014-09-06 15:54 - 2009-07-14 06:45 - 00041744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-06 15:54 - 2009-07-14 06:45 - 00041744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-06 15:53 - 2011-04-12 09:43 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-09-06 15:53 - 2011-04-12 09:43 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-09-06 15:53 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-06 15:47 - 2014-06-09 12:47 - 00000000 ___RD () C:\Users\Admin\Dropbox
2014-09-06 15:47 - 2014-06-09 12:46 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Dropbox
2014-09-06 15:47 - 2013-11-06 09:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-06 15:47 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-05 10:39 - 2014-09-05 10:35 - 00000000 ____D () C:\Program Files (x86)\Samsung
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Admin\Documents\SelfMV
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Admin\Documents\samsung
2014-09-05 10:36 - 2014-09-05 10:36 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Samsung
2014-09-05 10:36 - 2013-11-02 11:25 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-09-05 10:35 - 2014-09-05 10:35 - 00000000 ____D () C:\Users\Admin\AppData\Local\Downloaded Installations
2014-09-05 10:35 - 2014-09-05 10:34 - 75211320 _____ (Samsung Electronics Co., Ltd.) C:\Users\Admin\Downloads\KiesSetup.exe
2014-09-05 10:35 - 2014-09-05 10:34 - 39279648 _____ (Samsung Electronics Co., Ltd.) C:\Users\Admin\Downloads\Kies3Setup.exe
2014-09-05 04:10 - 2014-02-22 00:28 - 00000000 ____D () C:\Users\Admin\AppData\Local\Spotify
2014-09-04 18:02 - 2014-09-03 16:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-04 00:34 - 2014-09-04 00:34 - 00010800 _____ () C:\Users\Admin\Downloads\config.cfg
2014-09-04 00:34 - 2014-09-04 00:34 - 00002109 _____ () C:\Users\Admin\Downloads\autoexec.cfg
2014-08-31 03:15 - 2014-08-31 03:15 - 00000000 ____D () C:\Windows\Sun
2014-08-28 11:03 - 2014-08-23 17:13 - 00000866 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-28 10:54 - 2014-08-23 17:13 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-28 10:53 - 2014-08-28 10:53 - 04901352 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup417.exe
2014-08-28 03:16 - 2009-07-14 06:45 - 00294640 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 16:54 - 2014-08-27 16:54 - 00000000 ____D () C:\4im
2014-08-27 13:42 - 2014-05-29 16:47 - 00001011 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-08-27 13:26 - 2013-11-02 10:43 - 00064024 _____ () C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-27 13:19 - 2014-08-27 13:19 - 00000585 _____ () C:\Users\Admin\Downloads\run(1).bat
2014-08-27 12:33 - 2014-08-27 12:33 - 01101648 _____ () C:\Users\Admin\Downloads\TeamViewer - CHIP-Installer.exe
2014-08-27 12:09 - 2014-08-27 12:09 - 00108446 _____ () C:\Users\Admin\Desktop\TeamViewer9_Logfile.log
2014-08-27 05:11 - 2014-08-27 05:11 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-27 05:11 - 2014-08-27 05:10 - 07500112 _____ (TeamViewer GmbH) C:\Users\Admin\Downloads\TeamViewer_Setup_9.0.31064.exe
2014-08-27 01:56 - 2014-08-27 01:56 - 00816064 _____ ( ) C:\Users\Admin\Downloads\FreeVK_CB-DL-Manager.exe
2014-08-27 00:23 - 2014-08-27 00:23 - 00000585 _____ () C:\Users\Admin\Downloads\run.bat
2014-08-26 04:49 - 2013-11-02 10:01 - 00000000 ____D () C:\Windows\Panther
2014-08-23 20:57 - 2014-08-23 20:57 - 00000193 _____ () C:\Windows\WORDPAD.INI
2014-08-23 20:40 - 2014-02-21 17:09 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-23 20:39 - 2014-08-23 20:38 - 07190152 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe
2014-08-23 20:39 - 2014-08-23 20:38 - 06499816 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x86.exe
2014-08-23 20:38 - 2014-08-23 20:38 - 01417568 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_arm.exe
2014-08-23 17:13 - 2014-08-23 17:13 - 03738080 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup416_slim.exe
2014-08-23 17:13 - 2014-08-23 17:13 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-23 17:13 - 2014-08-23 17:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-23 16:31 - 2014-08-23 16:31 - 00000000 ____D () C:\Users\Admin\Neuer Ordner
2014-08-23 04:07 - 2014-08-28 01:01 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-28 01:01 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-28 01:01 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 01:27 - 2014-08-22 01:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-22 01:27 - 2014-08-22 01:26 - 00004623 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_67-b01.log
2014-08-22 01:27 - 2014-03-04 06:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-22 01:27 - 2014-03-04 06:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-21 17:26 - 2014-08-21 17:26 - 00010592 _____ () C:\Users\Admin\Documents\config.cfg
2014-08-21 17:23 - 2014-08-21 17:23 - 00000000 ____D () C:\Users\Admin\Downloads\cfg
2014-08-21 17:22 - 2014-08-21 17:22 - 00005058 _____ () C:\Users\Admin\Downloads\CFG(1).rar
2014-08-21 17:20 - 2014-08-21 17:20 - 00004890 _____ () C:\Users\Admin\Downloads\autoexec.zip
2014-08-21 16:47 - 2014-08-21 16:47 - 00061268 _____ () C:\Users\Admin\Downloads\cfg.rar
2014-08-18 22:23 - 2014-05-29 18:39 - 00000000 ____D () C:\Users\Admin\AppData\Local\Battle.net
2014-08-17 16:51 - 2014-08-17 16:51 - 00000755 _____ () C:\Users\Public\Desktop\AION Free-to-Play.lnk
2014-08-17 16:51 - 2014-08-16 22:42 - 00000000 ____D () C:\Program Files (x86)\GameforgeLive
2014-08-17 16:51 - 2014-07-02 22:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
2014-08-17 16:50 - 2014-07-02 22:46 - 00000000 ____D () C:\Users\Admin\Downloads\Gameforge Live
2014-08-17 16:49 - 2014-08-17 16:48 - 20136920 _____ (Gameforge ) C:\Users\Admin\Downloads\AION_GameforgeLiveSetup.exe
2014-08-16 22:42 - 2014-08-16 22:42 - 00001063 _____ () C:\Users\Public\Desktop\Gameforge Live.lnk
2014-08-16 22:42 - 2014-08-16 22:42 - 00000000 ____D () C:\Users\Admin\AppData\Local\Gameforge4d
2014-08-16 22:39 - 2014-08-16 22:39 - 15575488 _____ (Gameforge Productions GmbH ) C:\Users\Admin\Downloads\TERASetup.exe
2014-08-16 22:39 - 2014-08-16 22:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-08-15 22:40 - 2014-08-15 22:40 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\TERA
2014-08-15 22:31 - 2014-08-15 22:31 - 20115464 _____ (Gameforge ) C:\Users\Admin\Downloads\TERA_GameforgeLiveSetup.exe
2014-08-14 04:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-14 03:26 - 2014-06-09 12:46 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-14 03:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-14 03:05 - 2013-11-02 11:39 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 03:04 - 2013-11-02 11:39 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 03:00 - 2014-05-28 15:03 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-13 22:41 - 2014-02-21 18:10 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI
2014-08-13 10:53 - 2014-05-29 18:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net

Some content of TEMP:

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-09-06 00:55

==================== End Of Log ============================
--- --- ---

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-09-2014
Ran by Admin at 2014-09-07 09:02:07
Running from C:\Users\Admin\Downloads
Boot Mode: Normal

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Adobe Reader 6.0 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-000000000001}) (Version: 6.0 - Adobe Systems Incorporated)
AION Free-to-Play (HKLM-x32\...\{82E73E8D-E1E7-45A4-A311-6D31492AA913}_is1) (Version: - Gameforge)
AMD Accelerated Video Transcoding (Version: - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden
AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: - Advanced Micro Devices, Inc.) Hidden
AutoUpdate (HKLM-x32\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - )
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
DivX Codec (HKLM-x32\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.6.1 - DivX, Inc.)
Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.27 - Dropbox, Inc.)
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology)
Etron USB3.0 Host Controller (x32 Version: 0.115 - Etron Technology) Hidden
Gameforge Live 2.0.4 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.4 - Gameforge)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Heroes of Newerth (HKLM-x32\...\hon) (Version: 2.3.0 - S2 Games)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: - Oracle, Inc.) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Mozilla Firefox 32.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0 (x86 de)) (Version: 32.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: - Tracker Software Products Ltd)
Pinnacle TVCenter Pro (HKLM-x32\...\{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}) (Version: - )
S.K.I.L.L. - Special Force 2 (HKLM-x32\...\Special Force 2 Beta_is1) (Version: - )
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Spotify (HKCU\...\Spotify) (Version: - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
TERA (HKLM-x32\...\{A2F166A0-F031-4E27-A057-C69733219434}_is1) (Version: 28 - Gameforge Productions GmbH)
The Elder Scrolls Online Beta (HKLM-x32\...\The Elder Scrolls Online Beta_is1) (Version: 0.3.4 - )
TVCenter (HKLM\...\{DD0A0C72-A7C3-4722-86C9-2399F9FC0DE7}) (Version: - PCTV Systems)
WinRAR 5.10 beta 4 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-27826031-60937729-2427931102-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points =========================

23-08-2014 18:39:19 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
23-08-2014 18:40:14 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
24-08-2014 18:48:51 Windows Update
26-08-2014 01:00:10 Windows Update
28-08-2014 01:00:10 Windows Update
31-08-2014 19:08:31 Windows Update
03-09-2014 21:51:10 Windows Update
05-09-2014 08:35:28 Installed Samsung Kies3
05-09-2014 08:39:26 Removed Samsung Kies3

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {31A17543-1B97-4F7E-A83B-2945363B7DFC} - System32\Tasks\{0293C197-EA5E-4E73-919A-4E96F715695B} => C:\Program Files (x86)\Pinnacle\TVCenter Pro\PMC.exe
Task: {3F78AD55-3E54-496B-A045-EC8359107AAD} - System32\Tasks\{AB002DD0-2F91-44E2-9710-89E22ED3E934} => C:\Program Files (x86)\Pinnacle\TVCenter Pro\PMC.exe
Task: {70FB4BBE-040C-445E-9967-429FD437F350} - System32\Tasks\{01AE570C-3B2D-43BC-8D30-5DA14CD482B3} => C:\Program Files (x86)\Pinnacle\TVCenter Pro\PMC.exe
Task: {A7AA8795-9AB8-4953-A19C-0DBD7A9D9439} - System32\Tasks\{C9EEB7DB-D34E-4F6D-BABB-67BF03A45999} => C:\Program Files (x86)\Pinnacle\TVCenter Pro\PMC.exe
Task: {B91F040D-9CB2-4BB6-878E-5F5AC93194C6} - System32\Tasks\{60151372-F89D-4A5B-B34D-BD76B59BAED7} => C:\Program Files (x86)\Pinnacle\TVCenter Pro\PMC.exe
Task: {C341BEF7-7A35-4C80-AB25-C2DCB1F2955D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {E883F16D-8756-4AB1-9F57-19BEFF2988E2} - System32\Tasks\{3764CACF-87F7-4AFB-ADEC-84271E6CE9B4} => C:\Program Files (x86)\Pinnacle\TVCenter Pro\PMC.exe

==================== Loaded Modules (whitelisted) =============

2013-12-06 17:06 - 2013-12-06 17:06 - 00214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2013-07-26 06:59 - 2013-07-26 06:59 - 00814592 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2013-07-26 06:59 - 2013-07-26 06:59 - 03650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2013-12-06 17:06 - 2013-12-06 17:06 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-02-22 00:27 - 2014-08-26 19:11 - 00610872 _____ () C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
2014-07-02 02:54 - 2014-07-02 02:54 - 00103424 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
2014-02-22 00:27 - 2014-08-26 19:11 - 36966968 _____ () C:\Users\Admin\AppData\Roaming\Spotify\Data\libcef.dll
2014-07-20 15:57 - 2014-08-26 19:11 - 00867896 _____ () C:\Users\Admin\AppData\Roaming\Spotify\Data\ffmpegsumo.dll
2014-02-22 00:27 - 2014-08-26 19:11 - 00886840 _____ () C:\Users\Admin\AppData\Roaming\Spotify\Data\libglesv2.dll
2014-02-22 00:27 - 2014-08-26 19:11 - 00108600 _____ () C:\Users\Admin\AppData\Roaming\Spotify\Data\libegl.dll
2014-09-04 00:30 - 2014-08-21 20:15 - 01171456 _____ () D:\Games\Steam\libavcodec-56.dll
2014-09-04 00:30 - 2014-08-21 20:15 - 00442368 _____ () D:\Games\Steam\libavutil-54.dll
2014-09-04 00:30 - 2014-08-21 20:15 - 00332800 _____ () D:\Games\Steam\libavresample-2.dll
2014-02-22 00:21 - 2014-08-21 00:38 - 00774656 _____ () D:\Games\Steam\SDL2.dll
2014-05-30 17:50 - 2014-08-28 13:48 - 02224320 _____ () D:\Games\Steam\video.dll
2014-09-04 00:30 - 2014-08-21 20:15 - 00403968 _____ () D:\Games\Steam\libavformat-56.dll
2014-09-04 00:30 - 2014-08-21 20:15 - 00485888 _____ () D:\Games\Steam\libswscale-3.dll
2014-02-22 00:21 - 2014-08-28 13:48 - 00678080 _____ () D:\Games\Steam\bin\chromehtml.DLL
2014-09-06 20:02 - 2014-09-06 20:02 - 00155232 ___HT () C:\Users\Admin\AppData\Local\Temp\~CD80.tmp
2014-02-22 00:21 - 2014-08-21 00:38 - 34589376 _____ () D:\Games\Steam\bin\libcef.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00198144 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\launcher.dll
2014-07-02 02:53 - 2014-08-17 15:25 - 00308224 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\tier0.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00203776 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\vstdlib.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00387072 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\filesystem_stdio.dll
2014-07-02 08:36 - 2014-09-03 19:36 - 05838848 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\engine.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00155648 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\inputsystem.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 01174528 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\vphysics.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 01240064 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\materialsystem.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00352256 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\datacache.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00608256 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\studiorender.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00164864 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\soundemittersystem.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00708096 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\vscript.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00134656 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\valve_avi.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 01338880 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\vguimatsurface.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00397312 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\vgui2.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 03186176 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\scaleformui.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 01763328 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\shaderapidx9.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00143872 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\localize.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00231424 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\stdshader_dbg.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00987648 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\stdshader_dx9.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 01059840 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\chromehtml.dll
2014-06-28 11:08 - 2014-06-28 11:14 - 20625832 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\libcef.dll
2014-06-28 11:08 - 2014-06-28 11:14 - 01099616 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\avcodec-53.dll
2014-06-28 11:14 - 2014-06-28 11:14 - 00123232 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\avutil-51.dll
2014-06-28 11:14 - 2014-06-28 11:14 - 00190816 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\avformat-53.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00583680 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\csgo\bin\matchmaking.dll
2014-07-03 04:13 - 2014-09-03 19:36 - 11924992 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\csgo\bin\client.dll
2014-07-03 04:13 - 2014-09-03 19:36 - 09738240 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\csgo\bin\server.dll
2014-07-02 02:54 - 2014-09-03 19:36 - 00094720 _____ () D:\Games\Steam\steamapps\common\Counter-Strike Global Offensive\bin\scenefilecache.dll
2014-07-02 02:53 - 2014-09-03 19:36 - 00969216 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\serverbrowser.dll
2014-06-28 11:14 - 2014-06-28 11:14 - 00068096 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\vaudio_miles.dll
2014-06-28 11:14 - 2014-06-28 11:14 - 00095744 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\mssmp3.asi
2014-06-28 11:14 - 2014-06-28 11:14 - 00153600 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\mssvoice.asi
2014-06-28 11:14 - 2014-06-28 11:14 - 00013312 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\mssds3d.flt
2014-06-28 11:14 - 2014-06-28 11:14 - 00060416 _____ () d:\games\steam\steamapps\common\counter-strike global offensive\bin\msseax.flt
2014-08-15 03:01 - 2014-08-21 00:38 - 00837824 _____ () D:\Games\Steam\bin\ffmpegsumo.dll
2014-09-03 16:04 - 2014-09-03 16:04 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-02-22 00:32 - 2014-02-22 00:32 - 16265096 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (09/06/2014 08:01:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version:, Zeitstempel: 0x53fc3d9f
Name des fehlerhaften Moduls: mozalloc.dll, Version:, Zeitstempel: 0x53fc0a56
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x1034
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3

Error: (09/06/2014 03:49:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Der Index kann nicht initialisiert werden.

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog

Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet.

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben.

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

System errors:
Error: (09/06/2014 03:48:18 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:

Error: (09/06/2014 03:47:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (09/06/2014 03:47:48 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535.

Error: (09/06/2014 03:47:42 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:

Error: (09/05/2014 06:24:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:

Error: (09/05/2014 06:24:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (09/03/2014 07:13:01 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:

Error: (08/28/2014 08:58:01 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:

Error: (08/28/2014 05:51:04 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:

Error: (08/28/2014 05:22:03 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:

Microsoft Office Sessions:
Error: (09/06/2014 08:01:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe32.0.0.535053fc3d9fmozalloc.dll32.0.0.535053fc0a56800000030000141b103401cfc9ee9c099566C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dlld4216161-35ef-11e4-8dfa-50e54947e093

Error: (09/06/2014 03:49:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Kontext: Windows Anwendung

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800)

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
The catalog is corrupt

Error: (09/06/2014 03:47:48 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)

==================== Memory info ===========================

Processor: AMD FX(tm)-6200 Six-Core Processor
Percentage of memory in use: 23%
Total physical RAM: 16365.24 MB
Available physical RAM: 12589.64 MB
Total Pagefile: 32728.66 MB
Available Pagefile: 28503.14 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.69 GB) (Free:20.36 GB) NTFS
Drive d: (Daten) (Fixed) (Total:298.09 GB) (Free:154.42 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows XP) (Size: 298.1 GB) (Disk ID: 428C12D4)
Partition 1: (Not Active) - (Size=298.1 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 68722682)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Jemand hat unbemerkt ein Programm auf meinem PC geöffnet


Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

