![]() |
Log-Analyse und Auswertung: [Windows7] Computer (Arbeitsplatz) öffnet sich ständig!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
![]() | #1 |
| ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Guten Abend!, ![]() Mein Computer bzw. Arbeitsplatz öffnet sich ständig (Das ploppt dann einfach auf), manchmal mit Pause zwischendurch und manchmal einfach un-unterbrochen. Meistens auch während ich spiele (Schmeißt mich dann auf den Desktop und der Arbeitsplatz/Computer ist geöffnet). Wäre nett wenn ihr mir weiterhelfen könntet, denn ich erkenne rein gar nichts >.< .. hoffe mal dass das nicht so schlimm aussieht :P MfG HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 03:11:15, on 22.10.2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.17344) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe C:\Windows\system32\taskhost.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\***\Downloads\HiJackThis204.exe C:\Users\***\AppData\Local\Akamai\netsession_win.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\***\Desktop\HiJackThis204.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office15\URLREDIR.DLL O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\jan\AppData\Local\Akamai\netsession_win.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [Raptr] C:\PROGRA~1\Raptr\raptrstub.exe --startup O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?') O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?') O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?') O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?') O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?') O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?') O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?') O4 - Startup: Curse.lnk = C:\Users\***\AppData\Roaming\Curse Client\Bin\Curse.exe O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~3\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~3\Office15\EXCEL.EXE/3000 O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: hxxp://*.aeriagames.com O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file) O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing) O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Echtzeit-Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files\Hi-Rez Studios\HiPatchService.exe O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - VIA Technologies, Inc. - C:\Windows\system32\viakaraokesrv.exe -- End of file - 9896 bytes |
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
![]() | #3 |
| ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Hey Schrauber,
__________________erst ein mal schönen dank das du mir hilfst ^-^ habe nun den Scan wie gewünscht vom Desktop aus ausgeführt. Hier ein mal FRST. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-10-2014 Ran by *** (administrator) on ***-PC on 22-10-2014 13:15:16 Running from C:\Users\***\Desktop Loaded Profile: *** (Available profiles: ***) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe (Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\System32\PnkBstrA.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe (Google Inc.) C:\Program Files\Google\Update\\GoogleCrashHandler.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Akamai Technologies, Inc.) C:\Users\***\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\***\AppData\Local\Akamai\netsession_win.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Raptr, Inc) C:\Program Files\Raptr\raptr.exe (Raptr, Inc) C:\Program Files\Raptr\raptr_im.exe (Curse, Inc) C:\Users\***\AppData\Roaming\Curse Client\Bin\Curse.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-09-15] (Advanced Micro Devices, Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG) Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X] HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Akamai NetSession Interface] => C:\Users\***\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55568 2014-10-17] (Raptr, Inc) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: G - G:\autorun.exe HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: H - H:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {296507c7-d2d6-11e3-995a-002522f73538} - G:\autorun.exe HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {58054721-f6e6-11e2-a340-002522f73538} - G:\autorun.exe HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {84f78f5f-3f33-11e4-93ac-002522f73538} - H:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {9f3a83cc-5cf2-11e3-b313-002522f73538} - H:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {c6f0e310-0b33-11e3-86c7-806e6f6e6963} - F:\Setup.exe Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk ShortcutTarget: Curse.lnk -> C:\Users\***\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) Handler: AutorunsDisabled\skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll (OGPlanet) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\***\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) Chrome: ======= CHR StartupUrls: Default -> "hxxp://jappy.de/" CHR Profile: C:\Users\***\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-16] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (Turn Off the Lights) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-07-16] CHR Extension: (YouTube) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-16] CHR Extension: (TV) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-05-04] CHR Extension: (Tanki Online) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\chnamgoimgnbgkabfjkikldbfdhhfhdo [2014-08-18] CHR Extension: (Google-Suche) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-16] CHR Extension: (Tampermonkey) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-08-04] CHR Extension: (Realm of the Mad God) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp [2014-07-18] CHR Extension: (RAD Soldiers) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkiahcckehgdocgonfdickeagmoembpe [2014-07-17] CHR Extension: (Rush Team) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2014-05-04] CHR Extension: (Avira SafeSearch) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2014-08-08] CHR Extension: (Freefall Tournament) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2014-05-04] CHR Extension: (Polycraft) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopfmbpfhhfnklgmjpoehcjaajhpbhbl [2014-07-27] CHR Extension: (Avira Browser Safety) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-10] CHR Extension: (Heroes & Generals) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2014-05-20] CHR Extension: (WarChiefs - Tiberium Alliances Combat Simulator) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggiejiffgcdcfogfcgdebmbafcfndpgd [2013-08-04] CHR Extension: (AdBlock) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-16] CHR Extension: (Speed Test) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2014-08-18] CHR Extension: (Red Crucible 2) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\iechpocbkaimjmlpfinoahkolenfdmig [2014-08-17] CHR Extension: (Cut the Rope) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2014-08-03] CHR Extension: (Plug+) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jflocljnfndnnnlmfaamgbkbibnfmlkf [2013-07-16] CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2013-08-05] CHR Extension: (Verdun Game) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\khdppkcpilejlgahecofelpoidcnjbdg [2014-07-18] CHR Extension: (Sand 2) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\klicmgamjpclmbhppmdeamffedflmkcn [2014-10-16] CHR Extension: (Artillery Tower Protector) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgcejmkikbadghamaadggncnbfekdik [2014-08-03] CHR Extension: (Fieldrunners) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2014-05-04] CHR Extension: (Regen-Alarm) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-08-18] CHR Extension: (Spelunky HTML5) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhagnkphcmpkmabhocgimoncfaihkpof [2014-10-01] CHR Extension: (DSL speedtest) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj [2014-08-18] CHR Extension: (Apple Shooter) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbhfnlipcinfjmjplgegncjlmpnihecg [2014-08-18] CHR Extension: (Google Wallet) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Batterfield Map) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\npjmhhanmmlmpcnonlcgplgfnngboodf [2014-09-05] CHR Extension: (Sand) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdknckljjbdpkhgmcokoahffbdinafbo [2014-09-12] CHR Extension: (Reditr - The Best Reddit Client) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmfcbbijgnhoebddbjpmlikabnbnddgb [2014-10-01] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG) R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed] R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-08-04] (Nero AG) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG) S3 npggsvc; C:\Windows\system32\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-07-19] () R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2013-07-16] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [15968 2013-07-16] (Advanced Micro Devices, Inc.) R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [22144 2013-07-16] (Advanced Micro Devices, Inc.) R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-03] (Disc Soft Ltd) S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [114904 2014-10-22] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1846448 2013-07-16] (VIA Technologies, Inc.) S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 vtany; \??\C:\Windows\vtany.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-22 13:15 - 2014-10-22 13:16 - 00018527 _____ () C:\Users\***\Desktop\FRST.txt 2014-10-22 13:14 - 2014-10-22 13:15 - 00000000 ____D () C:\FRST 2014-10-22 13:13 - 2014-10-22 13:13 - 01102336 _____ (Farbar) C:\Users\***\Desktop\FRST.exe 2014-10-22 03:11 - 2014-10-22 03:17 - 00009897 _____ () C:\Users\***\Desktop\hijackthis.log 2014-10-22 03:08 - 2014-10-22 03:08 - 00002238 _____ () C:\Users\***\Downloads\hijackthis.log 2014-10-22 02:51 - 2014-10-22 02:51 - 00388608 _____ (Trend Micro Inc.) C:\Users\***\Desktop\HiJackThis204.exe 2014-10-22 00:11 - 2014-10-22 00:11 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-21 23:04 - 2014-10-21 23:04 - 00117912 _____ () C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT 2014-10-21 22:59 - 2014-10-22 13:07 - 00000112 _____ () C:\Windows\setupact.log 2014-10-21 22:59 - 2014-10-21 22:59 - 00460912 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-21 22:59 - 2014-10-21 22:59 - 00001718 _____ () C:\Windows\PFRO.log 2014-10-21 22:59 - 2014-10-21 22:59 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-21 18:53 - 2014-10-21 18:53 - 00000000 __SHD () C:\Windows\system32\AI_RecycleBin 2014-10-21 18:50 - 2014-10-21 18:50 - 00143690 _____ () C:\Users\***\Desktop\cc_20141021_185023.reg 2014-10-21 18:42 - 2014-10-21 18:42 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-10-21 18:42 - 2014-10-21 18:42 - 00000000 ____D () C:\Program Files\CCleaner 2014-10-21 18:36 - 2014-10-21 18:27 - 03239099 _____ () C:\Users\***\Desktop\CBS.log 2014-10-21 18:33 - 2014-10-21 18:33 - 00030992 _____ () C:\sfcdetails.txt 2014-10-20 23:13 - 2014-10-20 23:13 - 00000689 _____ () C:\Users\***\Desktop\JRT.txt 2014-10-20 23:11 - 2014-10-20 23:11 - 00000000 ____D () C:\Windows\ERUNT 2014-10-20 22:10 - 2014-10-22 13:08 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-10-20 22:10 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-20 22:10 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-20 22:04 - 2014-10-20 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-10-20 22:04 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-17 14:47 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-17 14:47 - 2014-09-29 02:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-17 14:47 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-17 14:47 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-17 14:47 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-17 14:47 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-17 14:47 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-17 14:47 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-17 14:47 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-17 14:47 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-17 14:47 - 2014-09-19 03:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-10-17 14:47 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-17 14:47 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-17 14:47 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-10-17 14:47 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-10-17 14:47 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-17 14:47 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-17 14:47 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-17 14:47 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-17 14:47 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-17 14:47 - 2014-09-19 02:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-10-17 14:47 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-10-17 14:47 - 2014-09-19 02:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-10-17 14:47 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-10-17 14:47 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-17 14:47 - 2014-09-19 02:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-17 14:47 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-17 14:47 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-10-17 14:47 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-17 14:47 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-17 14:47 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-10-17 14:47 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-17 14:47 - 2014-08-29 03:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-10-17 14:47 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-17 14:47 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-17 14:47 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-17 14:47 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-17 14:47 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-17 14:47 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-17 14:47 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-17 14:46 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-17 14:46 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 20:45 - 2014-10-16 20:45 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-10-16 20:43 - 2014-10-16 20:43 - 00638888 _____ (Oracle Corporation) C:\Users\***\Downloads\chromeinstall-8u25.exe 2014-10-13 22:45 - 2014-10-13 22:45 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-10-13 21:11 - 2014-10-13 22:07 - 00001957 _____ () C:\Users\***\Desktop\Engel Englisch.txt 2014-10-01 14:31 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-09-30 15:30 - 2014-09-30 15:30 - 00060300 _____ () C:\Windows\system32\CCCInstall_201409301530165576.log 2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\ProgramData\ATI 2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\Program Files\AMD AVT 2014-09-30 15:29 - 2014-09-30 15:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-09-30 15:15 - 2014-09-30 15:17 - 210974816 _____ (AMD Inc.) C:\Users\***\Downloads\amd-catalyst-14-9-win7-win8.1-32bit-dd-ccc-whql.exe 2014-09-25 16:04 - 2014-09-25 16:06 - 00000104 _____ () C:\Users\***\Desktop\Notizen.txt 2014-09-24 12:29 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-23 19:47 - 2014-09-23 19:47 - 00000000 ____D () C:\Users\***\AppData\Roaming\LolClient 2014-09-23 18:28 - 2014-09-23 18:28 - 00000000 ____D () C:\ProgramData\Riot Games 2014-09-23 18:26 - 2014-09-23 18:26 - 00001613 _____ () C:\Users\Public\Desktop\League of Legends.lnk 2014-09-23 18:26 - 2014-09-23 18:26 - 00000000 ____D () C:\Riot Games 2014-09-23 18:26 - 2014-09-23 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2014-09-23 18:26 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-09-23 18:26 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-09-23 18:26 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-09-23 18:17 - 2014-09-23 18:26 - 00000000 ____D () C:\Users\***\AppData\Roaming\Riot Games 2014-09-23 17:55 - 2014-09-23 17:56 - 30668968 _____ (Riot Games) C:\Users\***\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-22 13:15 - 2013-07-16 16:44 - 01834631 _____ () C:\Windows\WindowsUpdate.log 2014-10-22 13:15 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-22 13:15 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-22 13:09 - 2014-08-17 21:07 - 00000000 ____D () C:\Users\***\AppData\Roaming\Raptr 2014-10-22 13:08 - 2014-09-18 18:05 - 00000000 ____D () C:\Users\***\AppData\Local\HTC MediaHub 2014-10-22 13:08 - 2013-07-16 16:52 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-22 13:07 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-22 03:38 - 2013-07-17 00:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-22 02:58 - 2013-07-16 16:52 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-21 19:38 - 2013-10-03 00:11 - 00000000 ____D () C:\Users\***\Desktop\Musik 2014-10-21 19:12 - 2013-07-18 01:50 - 00000000 ____D () C:\Program Files\Steam 2014-10-21 19:08 - 2013-08-17 01:58 - 00000000 ____D () C:\Users\***\AppData\Roaming\Ubisoft 2014-10-21 19:08 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-10-21 19:06 - 2014-07-30 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon 2014-10-21 19:06 - 2014-07-30 23:25 - 00000000 ____D () C:\Nexon 2014-10-21 18:59 - 2013-07-17 00:17 - 00000000 ____D () C:\Program Files\Java 2014-10-21 18:49 - 2013-08-26 04:56 - 00000000 ____D () C:\Users\***\AppData\Roaming\uTorrent 2014-10-21 18:49 - 2013-07-28 00:36 - 00000000 ____D () C:\Users\***\AppData\Roaming\DAEMON Tools Lite 2014-10-21 18:49 - 2013-07-25 00:40 - 00000000 ____D () C:\Users\***\AppData\Roaming\TS3Client 2014-10-21 18:48 - 2013-10-09 04:16 - 00000000 ____D () C:\Windows\Minidump 2014-10-21 18:48 - 2013-08-17 15:27 - 00000000 ___RD () C:\Users\***\Desktop\Games 2014-10-21 18:48 - 2013-07-25 21:26 - 00000000 ____D () C:\Users\***\Desktop\Programme 2014-10-21 18:48 - 2013-07-16 17:40 - 00000000 ____D () C:\Windows\Panther 2014-10-21 18:22 - 2013-09-14 14:51 - 00000000 ____D () C:\AdwCleaner 2014-10-21 18:17 - 2013-07-16 16:52 - 00000000 ____D () C:\Users\***\Desktop\Anti-Vir 2014-10-20 22:55 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Help 2014-10-20 22:13 - 2013-09-22 17:47 - 00000000 ____D () C:\Users\***\Desktop\Schule 2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\Users\***\AppData\Roaming\Malwarebytes 2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-19 23:21 - 2014-05-03 22:59 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-10-19 23:21 - 2014-05-03 22:55 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-19 03:21 - 2013-08-17 02:27 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-19 03:01 - 2013-07-16 19:20 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-18 14:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-10-18 14:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-10-18 13:30 - 2014-08-17 21:07 - 00000000 ____D () C:\Program Files\Raptr 2014-10-18 13:19 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-10-18 03:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-10-18 03:08 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini 2014-10-18 00:57 - 2013-07-16 16:53 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-10-16 20:45 - 2014-08-11 14:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-16 20:44 - 2014-08-11 14:55 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-10-16 20:44 - 2014-08-11 14:55 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-10-16 20:44 - 2013-10-22 22:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-15 12:17 - 2014-09-10 14:26 - 00000000 ____D () C:\Users\***\AppData\Roaming\Curse Client 2014-10-13 22:45 - 2013-08-17 13:54 - 00000000 ____D () C:\ProgramData\Package Cache 2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\Program Files\Avira 2014-10-02 15:53 - 2014-03-27 10:02 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-01 14:10 - 2013-07-16 23:08 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-10-01 14:10 - 2013-07-16 17:02 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-01 14:10 - 2013-07-16 17:02 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-09-30 15:30 - 2013-07-16 16:56 - 00000000 ____D () C:\ProgramData\AMD 2014-09-30 15:29 - 2013-07-16 16:55 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-09-30 15:19 - 2013-07-16 16:54 - 00000000 ____D () C:\AMD 2014-09-24 16:38 - 2013-07-17 00:45 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-09-24 16:38 - 2013-07-16 19:51 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl Files to move or delete: ==================== C:\Users\***\jagex_cl_runescape_LIVE.dat C:\Users\***\jagex_cl_runescape_LIVE1.dat C:\Users\***\random.dat Some content of TEMP: ==================== C:\Users\***\AppData\Local\Temp\avgnt.exe C:\Users\***\AppData\Local\Temp\BRSVC_10390836_hlp.exe C:\Users\***\AppData\Local\Temp\Quarantine.exe C:\Users\***\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-17 15:28 ==================== End Of Log ============================ --- --- --- und hier ein mal die Additions. FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-10-2014 Ran by *** at 2014-10-22 13:17:00 Running from C:\Users\***\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKCU\...\uTorrent) (Version: - BitTorrent Inc.) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated) Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) Algebrator 4.0 (HKLM\...\Algebrator_is1) (Version: - SoftMath Inc) AMD Accelerated Video Transcoding (Version: - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (Version: 2014.0915.1813.30937 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{319271B3-E2AA-F623-928E-245C9EBF16F7}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Fuel (Version: 2014.0915.1813.30937 - Ihr Firmenname) Hidden AMD Wireless Display v3.0 (Version: - Advanced Micro Devices, Inc.) Hidden Arx Fatalis (HKLM\...\{96443F45-13E2-11D6-AC87-00D0B7A9E540}) (Version: 1.0.0 - JoWood) Arx Fatalis Version 1.21 (HKLM\...\{171251E0-4EED-4EA1-A46D-3213A226F2B3}_is1) (Version: 1.21 - Arkane Studios) Arx Libertatis (HKLM\...\ArxLibertatis) (Version: - ) Avira (HKLM\...\{9bd9b85e-7792-483b-a318-cc51ff0877ed}) (Version: - Avira Operations GmbH & Co. KG) Avira (Version: - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: - Avira) BC Kings (HKLM\...\Steam App 12460) (Version: - Mascot Entertainment) BOSS (HKLM\...\BOSS) (Version: 2.1.1 - BOSS Development Team) Catalyst Control Center - Branding (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help English (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help French (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help German (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden ccc-utility (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform) Command & Conquer Renegade (HKLM\...\Renegade) (Version: - ) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM\...\Steam App 240) (Version: - Valve) Curse (HKLM\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: - Curse) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: - Disc Soft Ltd) Dawngate (HKLM\...\{E20BD715-3CAF-4A6C-A7F5-8F2216710B90}) (Version: - Electronic Arts, Inc.) Dota 2 (HKLM\...\Steam App 570) (Version: - Valve) Drakensang Online (HKLM\...\Drakensang Online) (Version: - ) Dungeon Defenders (HKLM\...\Steam App 65800) (Version: - Trendy Entertainment) F.E.A.R. Online (HKLM\...\F.E.A.R. Online) (Version: - ) Foxit Reader (HKLM\...\Foxit Reader) (Version: - ) Google Chrome (HKLM\...\Google Chrome) (Version: 38.0.2125.104 - Google Inc.) Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: - Google) Google Update Helper (Version: - Google Inc.) Hidden Hi-Rez Studios Authenticate and Update Service (HKLM\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: - Hi-Rez Studios) HTC Driver Installer (HKLM\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: - HTC Corporation) HTC Sync Manager (HKLM\...\{231D0C79-98A6-4693-A366-36DE7D7346EC}) (Version: - HTC) HxD Hex Editor Version (HKLM\...\HxD Hex Editor_is1) (Version: - Maël Hörz) InfiniteCrisis_6EDD581C692E (HKLM\...\InfiniteCrisis_6EDD581C692E) (Version: - Turbine, Inc) IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC) Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Java Auto Updater (Version: - Oracle Corporation) Hidden Killing Floor (HKLM\...\Steam App 1250) (Version: - Tripwire Interactive) League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (Version: 3.0.1 - Riot Games ) Hidden LTspice IV (HKLM\...\LTspice IV) (Version: - ) Malwarebytes Anti-Malware Version (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation) ManyCam 3.1.62 (HKLM\...\ManyCam) (Version: 3.1.62 - ManyCam LLC) Marvel Heroes Game (HKLM\...\{ca6069b5-fc6b-4ce8-a03e-2304143706b7}_is1) (Version: 1.0 - Gazillion Entertainment) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{887868A2-D6DE-3255-AA92-AA0B5A59B874}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) mIRC (HKLM\...\mIRC) (Version: 7.32 - mIRC Co. Ltd.) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Mumble 1.2.4 (HKLM\...\{AF348C2E-7596-481B-92E0-B211836AB949}) (Version: 1.2.4 - Thorvald Natvig) Nero Burning ROM (Version: 12.5.5001 - Nero AG) Hidden Nero Burning ROM Help (CHM) (Version: 12.0.3000 - Nero AG) Hidden Nero BurningROM 12 (HKLM\...\{DCF34348-8673-4E60-97E5-1CBC0D7293AC}) (Version: 12.5.01100 - Nero AG) Nero ControlCenter (Version: 11.0.15600 - Nero AG) Hidden Nero ControlCenter Help (CHM) (Version: 12.0.12000 - Nero AG) Hidden Nero Core Components (Version: 11.0.20200 - Nero AG) Hidden Nero SharedVideoCodecs (Version: 1.0.12100.2.0 - Nero AG) Hidden Nero Update (Version: 11.0.11800.31.0 - Nero AG) Hidden Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.47.3 - Black Tree Gaming) Nosgoth (HKLM\...\Steam App 200110) (Version: 140722.89040 - Square Enix Ltd) Notepad++ (HKLM\...\Notepad++) (Version: 6.4.2 - Notepad++ Team) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - NVIDIA Corporation) NVIDIA PhysX (HKLM\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) OGPlanet Game Launcher (HKLM\...\OGPlanet Game Launcher) (Version: 3.0.0 - OGPlanet, Inc.) OpenAL (HKLM\...\OpenAL) (Version: - ) OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Path of Exile (HKLM\...\Steam App 238960) (Version: - Grinding Gear Games) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PlanetSide 2 (HKLM\...\Steam App 218230) (Version: - Sony Online Entertainment) Prerequisite installer (Version: 12.0.0003 - Nero AG) Hidden PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.) Raptr (HKLM\...\Raptr) (Version: - ) Robocraft (HKLM\...\Steam App 301520) (Version: - Freejam) RuneScape Launcher 1.2.3 (HKLM\...\{FAE99C85-0732-4C58-9C6B-10B5B12FA2E9}) (Version: 1.2.3 - Jagex Ltd) Sanctum 2 (HKLM\...\Steam App 210770) (Version: - Coffee Stain Studios) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (Version: - Microsoft) Hidden Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Smite (HKLM\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 1.0.2348.1 - Hi-Rez Studios) Special Force 2 1.0 (HKLM\...\Special Force 2 Beta_is1) (Version: - ) Spotify (HKCU\...\Spotify) (Version: - Spotify AB) Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.1.21 - Safer-Networking Ltd.) SSIII Solo Ultratus 1.2 (HKLM\...\SSIII Solo Ultratus) (Version: 1.2 - 3RDsense) Star Wars The Old Republic (HKLM\...\swtor_swtor) (Version: - Bioware/EA) Star Wars: The Old Republic (HKLM\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: - Valve Corporation) Strife (HKLM\...\Strife) (Version: - S2 Games) Stronghold Kingdoms (HKLM\...\{D1D632A2-E249-466D-A094-B1B934D37645}_is1) (Version: 1.17 - Firefly Studios) Stronghold Kingdoms (HKLM\...\Steam App 47410) (Version: - FireFly Studios) Tactical Intervention (HKLM\...\Steam App 51100) (Version: - FIX Korea) Team Fortress 2 (HKLM\...\Steam App 440) (Version: - Valve) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Terraria (HKLM\...\Steam App 105600) (Version: - Re-Logic) The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version: - Bethesda Game Studios) The Mighty Quest For Epic Loot Version 1.234953 (HKLM\...\The Mighty Quest For Epic Loot_is1) (Version: 1.234953 - ) Torchlight (HKLM\...\Torchlight_is1) (Version: - GOG.com) Transformers Universe (HKLM\...\{EAB5ACD3-43C0-4B3E-931A-CA61520934AD}) (Version: - Jagex Ltd) UE Explorer (HKLM\...\{235A9BC7-9489-43ED-85A7-695667B91AEA}) (Version: 1.1.0 - Eliot) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Unreal Development Kit: 2013-07 (HKLM\...\UDK-7b92612f-6630-4e3b-a11a-2b4acce44976) (Version: - Epic Games, Inc.) Unturned (HKLM\...\Steam App 304930) (Version: - Nelson Sexton) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) Westwood Shared Internet Components (HKLM\...\WOLAPI) (Version: - ) WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WinZip 17.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DA}) (Version: 17.5.10480 - WinZip Computing, S.L. ) World of Warplanes (HKLM\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C813EU}_is1) (Version: - Wargaming.net) Zanzarah - Das verborgene Portal (HKLM\...\Zanzarah) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-871497826-143411075-1366273650-1001_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\jan\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS) ==================== Restore Points ========================= 17-10-2014 12:31:37 Windows Update 18-10-2014 01:00:25 Windows Update 18-10-2014 01:25:01 Windows Update 19-10-2014 01:00:17 Windows Update 19-10-2014 21:18:28 Windows Update 21-10-2014 16:53:23 Removed Aeria Ignite 21-10-2014 16:58:18 Removed Java 7 Update 67 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {175703BD-2AF2-4C6C-8097-6FD4E49B36F2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated) Task: {1CD6C84E-547F-4F6D-B525-E12DDB9E83C8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe Task: {2AF223C4-AED9-40A0-B799-1696B16D903E} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {41BDC262-7BDD-4A66-AC56-228FB62E8AF0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-16] (Google Inc.) Task: {434DD5EB-F3E5-4849-966E-9807D1B6472A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {44D70773-546C-403A-B6BD-7864E68A8254} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd) Task: {57DB51E6-1190-4A9F-90D1-26D18732B5E3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {6D68D594-1871-4448-9705-53CD7812CD90} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe Task: {9BFEDE87-1525-49C5-8B52-D10A4EB236EF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-16] (Google Inc.) Task: {FF903288-0E8B-4B85-B5CA-E5783D8C11DE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-08-06 13:40 - 2014-08-06 13:40 - 00031080 _____ () C:\Program Files\HTC\HTC Sync Manager\DbAccess.dll 2014-08-06 13:41 - 2014-08-06 13:41 - 00607376 _____ () C:\Program Files\HTC\HTC Sync Manager\sqlite3.dll 2014-08-06 13:41 - 2014-08-06 13:41 - 00059752 _____ () C:\Program Files\HTC\HTC Sync Manager\NAdvLog.dll 2014-08-06 13:41 - 2014-08-06 13:41 - 00036216 _____ () C:\Program Files\HTC\HTC Sync Manager\NFileCacheDBAccess.dll 2014-08-06 13:42 - 2014-08-06 13:42 - 00080248 _____ () C:\Program Files\HTC\HTC Sync Manager\ninstallerhelper.dll 2014-08-06 13:44 - 2014-08-06 13:44 - 00129376 _____ () C:\Program Files\HTC\HTC Sync Manager\zlib1.dll 2014-08-06 13:46 - 2014-08-06 13:46 - 00223592 _____ () C:\Program Files\HTC\HTC Sync Manager\DevConnMon.dll 2013-10-17 15:27 - 2013-10-17 15:27 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe 2013-07-19 18:47 - 2013-07-19 19:15 - 00076888 _____ () C:\Windows\system32\PnkBstrA.exe 2013-09-14 20:34 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-09-14 20:34 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl 2013-09-14 20:34 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-09-14 20:34 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll 2013-09-14 20:34 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2014-08-06 13:42 - 2014-08-06 13:42 - 00821600 _____ () C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe 2014-09-15 18:13 - 2014-09-15 18:13 - 00095744 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2013-10-23 06:31 - 2013-10-23 06:31 - 01241088 _____ () C:\Program Files\ManyCam\Bin\opencv_imgproc220.dll 2013-10-23 06:31 - 2013-10-23 06:31 - 02010624 _____ () C:\Program Files\ManyCam\Bin\opencv_core220.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00087040 _____ () C:\Program Files\Raptr\_ctypes.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00043008 _____ () C:\Program Files\Raptr\_socket.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00805376 _____ () C:\Program Files\Raptr\_ssl.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 05812736 _____ () C:\Program Files\Raptr\PyQt4.QtGui.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00067584 _____ () C:\Program Files\Raptr\sip.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 01662464 _____ () C:\Program Files\Raptr\PyQt4.QtCore.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00494592 _____ () C:\Program Files\Raptr\PyQt4.QtNetwork.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00096256 _____ () C:\Program Files\Raptr\win32api.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00110592 _____ () C:\Program Files\Raptr\pywintypes26.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00010240 _____ () C:\Program Files\Raptr\select.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00356864 _____ () C:\Program Files\Raptr\_hashlib.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00036352 _____ () C:\Program Files\Raptr\win32process.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00111104 _____ () C:\Program Files\Raptr\win32file.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00044544 _____ () C:\Program Files\Raptr\_sqlite3.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 00417501 _____ () C:\Program Files\Raptr\sqlite3.dll 2010-11-23 00:57 - 2010-11-23 00:57 - 00167936 _____ () C:\Program Files\Raptr\win32gui.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00313856 _____ () C:\Program Files\Raptr\PyQt4.QtWebKit.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00127488 _____ () C:\Program Files\Raptr\pyexpat.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00009216 _____ () C:\Program Files\Raptr\winsound.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00354304 _____ () C:\Program Files\Raptr\pythoncom26.dll 2010-11-23 00:57 - 2010-11-23 00:57 - 00016384 _____ () C:\Program Files\Raptr\win32trace.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00583680 _____ () C:\Program Files\Raptr\unicodedata.pyd 2011-11-21 04:20 - 2011-11-21 04:20 - 01949696 _____ () C:\Program Files\Raptr\libtorrent.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00263168 _____ () C:\Program Files\Raptr\win32com.shell.shell.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00324608 _____ () C:\Program Files\Raptr\PIL._imaging.pyd 2013-11-21 02:05 - 2013-11-21 02:05 - 00256000 _____ () C:\Program Files\Raptr\amd_ags.dll 2010-11-23 00:57 - 2010-11-23 00:57 - 00141312 _____ () C:\Program Files\Raptr\gobject._gobject.pyd 2014-06-18 02:56 - 2014-06-18 02:56 - 02717595 _____ () C:\Program Files\Raptr\heliotrope._purple.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 01213633 _____ () C:\Program Files\Raptr\libxml2-2.dll 2010-11-23 01:06 - 2010-11-23 01:06 - 00055808 _____ () C:\Program Files\Raptr\zlib1.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00495680 _____ () C:\Program Files\Raptr\plugins\libaim.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 01183699 _____ () C:\Program Files\Raptr\liboscar.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00483306 _____ () C:\Program Files\Raptr\plugins\libicq.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00655356 _____ () C:\Program Files\Raptr\plugins\libirc.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 01306387 _____ () C:\Program Files\Raptr\plugins\libmsn.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00565461 _____ () C:\Program Files\Raptr\plugins\libxmpp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01640221 _____ () C:\Program Files\Raptr\libjabber.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00506276 _____ () C:\Program Files\Raptr\plugins\libyahoo.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01053730 _____ () C:\Program Files\Raptr\libymsg.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00497782 _____ () C:\Program Files\Raptr\plugins\libyahoojp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00603326 _____ () C:\Program Files\Raptr\plugins\ssl-nss.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00474199 _____ () C:\Program Files\Raptr\plugins\ssl.dll 2014-05-19 17:04 - 2014-05-19 17:04 - 00307712 _____ () C:\Users\jan\AppData\Roaming\Curse Client\Bin\opus.dll 2014-05-19 17:05 - 2014-05-19 17:05 - 00437248 _____ () C:\Users\jan\AppData\Roaming\Curse Client\Bin\WebRTC_CSharpWrapper.dll 2014-10-18 00:57 - 2014-10-10 04:03 - 01042760 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\libglesv2.dll 2014-10-18 00:57 - 2014-10-10 04:03 - 00211272 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\libegl.dll 2014-10-18 00:57 - 2014-10-10 04:04 - 08910664 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\pdf.dll 2014-10-18 00:57 - 2014-10-10 04:03 - 01681224 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Aeria Ignite => "C:\Program Files\Aeria Games\Ignite\aeriaignite.exe" silent MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR MSCONFIG\startupreg: Raptr => C:\PROGRA~1\Raptr\raptrstub.exe --startup MSCONFIG\startupreg: SDTray => "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" MSCONFIG\startupreg: Spotify => "C:\Users\jan\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\jan\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\Steam.exe" -silent ========================= Accounts: ========================== Administrator (S-1-5-21-871497826-143411075-1366273650-500 - Administrator - Disabled) Gast (S-1-5-21-871497826-143411075-1366273650-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-871497826-143411075-1366273650-1002 - Limited - Enabled) *** (S-1-5-21-871497826-143411075-1366273650-1001 - Administrator - Enabled) => C:\Users\*** ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/22/2014 01:17:29 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418231 Error: (10/22/2014 01:07:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/22/2014 03:00:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Procmon.exe, Version:, Zeitstempel: 0x519b927b Name des fehlerhaften Moduls: Procmon.exe, Version:, Zeitstempel: 0x519b927b Ausnahmecode: 0xc0000005 Fehleroffset: 0x0009bd28 ID des fehlerhaften Prozesses: 0x12e0 Startzeit der fehlerhaften Anwendung: 0xProcmon.exe0 Pfad der fehlerhaften Anwendung: Procmon.exe1 Pfad des fehlerhaften Moduls: Procmon.exe2 Berichtskennung: Procmon.exe3 Error: (10/21/2014 11:00:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: raptr.exe, Version:, Zeitstempel: 0x4bbd3163 Name des fehlerhaften Moduls: QtCore4.dll, Version:, Zeitstempel: 0x4fa6d505 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000240e4 ID des fehlerhaften Prozesses: 0x1378 Startzeit der fehlerhaften Anwendung: 0xraptr.exe0 Pfad der fehlerhaften Anwendung: raptr.exe1 Pfad des fehlerhaften Moduls: raptr.exe2 Berichtskennung: raptr.exe3 Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Smite.exe, Version: 1.0.2348.1, Zeitstempel: 0x54405f04 Name des fehlerhaften Moduls: ltc_game32-88237.dll_unloaded, Version:, Zeitstempel: 0x543ee9ba Ausnahmecode: 0xc0000005 Fehleroffset: 0x40e917a0 ID des fehlerhaften Prozesses: 0x13f4 Startzeit der fehlerhaften Anwendung: 0xSmite.exe0 Pfad der fehlerhaften Anwendung: Smite.exe1 Pfad des fehlerhaften Moduls: Smite.exe2 Berichtskennung: Smite.exe3 Error: (10/21/2014 04:58:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Smite.exe, Version: 1.0.2348.1, Zeitstempel: 0x54405f04 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0008a3bc ID des fehlerhaften Prozesses: 0x13f4 Startzeit der fehlerhaften Anwendung: 0xSmite.exe0 Pfad der fehlerhaften Anwendung: Smite.exe1 Pfad des fehlerhaften Moduls: Smite.exe2 Berichtskennung: Smite.exe3 Error: (10/21/2014 04:58:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Smite.exe, Version: 1.0.2348.1, Zeitstempel: 0x54405f04 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c Ausnahmecode: 0xc0000005 Fehleroffset: 0x000532ce ID des fehlerhaften Prozesses: 0x13f4 Startzeit der fehlerhaften Anwendung: 0xSmite.exe0 Pfad der fehlerhaften Anwendung: Smite.exe1 Pfad des fehlerhaften Moduls: Smite.exe2 Berichtskennung: Smite.exe3 Error: (10/21/2014 04:58:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Smite.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: Ausnahmecode c0000005, Ausnahmeadresse 771132CE Error: (10/21/2014 04:02:52 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (10/22/2014 01:10:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht. Error: (10/21/2014 10:59:37 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 21.10.2014 um 19:46:17 unerwartet heruntergefahren. Error: (10/21/2014 07:44:21 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Error: (10/21/2014 07:44:20 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Error: (10/21/2014 07:44:19 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Error: (10/21/2014 07:44:18 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Error: (10/21/2014 07:44:18 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Error: (10/21/2014 07:44:17 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Error: (10/21/2014 07:44:17 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Error: (10/21/2014 07:44:17 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden. Microsoft Office Sessions: ========================= Error: (10/22/2014 01:17:29 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418231 Error: (10/22/2014 01:07:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/22/2014 03:00:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Procmon.exe3.5.0.0519b927bProcmon.exe3.5.0.0519b927bc00000050009bd2812e001cfed92b714bf00C:\Users\jan\Desktop\Anti-Vir\ProcessMonitor\Procmon.exeC:\Users\jan\Desktop\Anti-Vir\ProcessMonitor\Procmon.exed862c980-5986-11e4-a2c2-002522f73538 Error: (10/21/2014 11:00:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: raptr.exe4.1.2.04bbd3163QtCore4.dll4.8.2.04fa6d505c0000005000240e4137801cfed37e4837b80C:\PROGRA~1\Raptr\raptr.exeC:\PROGRA~1\Raptr\QtCore4.dllbdd03fc0-5932-11e4-929d-002522f73538 Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Smite.exe1.0.2348.154405f04ltc_game32-88237.dll_unloaded0.0.0.0543ee9bac000000540e917a013f401cfed3c4f875e70C:\Program Files\Hi-Rez Studios\HiRezGames\smite\binaries\Win32\Smite.exeltc_game32-88237.dllbd83cd70-5932-11e4-929d-002522f73538 Error: (10/21/2014 04:58:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Smite.exe1.0.2348.154405f04ntdll.dll6.1.7601.18247521ea91cc00000050008a3bc13f401cfed3c4f875e70C:\Program Files\Hi-Rez Studios\HiRezGames\smite\binaries\Win32\Smite.exeC:\Windows\SYSTEM32\ntdll.dllbc0543c0-5932-11e4-929d-002522f73538 Error: (10/21/2014 04:58:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Smite.exe1.0.2348.154405f04ntdll.dll6.1.7601.18247521ea91cc0000005000532ce13f401cfed3c4f875e70C:\Program Files\Hi-Rez Studios\HiRezGames\smite\binaries\Win32\Smite.exeC:\Windows\SYSTEM32\ntdll.dllb6f5cb20-5932-11e4-929d-002522f73538 Error: (10/21/2014 04:58:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Smite.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: Ausnahmecode c0000005, Ausnahmeadresse 771132CE Error: (10/21/2014 04:02:52 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: AMD Athlon(tm) II X2 250 Processor Percentage of memory in use: 57% Total physical RAM: 3583.3 MB Available physical RAM: 1531.65 MB Total Pagefile: 7164.9 MB Available Pagefile: 4233.02 MB Total Virtual: 2599.88 MB Available Virtual: 2441.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:147.29 GB) NTFS Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: () (Fixed) (Total:465.66 GB) (Free:443.66 GB) NTFS Drive g: (Renegade Data) (CDROM) (Total:0.37 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 11571157) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 41291E63) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ==================== End Of Log ============================ ps: ich bin heute ab 17 Uhr leider nicht mehr erreichbar, ich bin ab morgen Abend wieder da. Geändert von Ridertsen (22.10.2014 um 13:00 Uhr) |
![]() | #4 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #5 |
| ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Kam mir ein wenig komisch vor, denn Combofix löschte etwas von meinem Avira ? Aber hier ein mal Combofix ![]() Code:
ATTFilter ComboFix 14-10-21.01 - jan 23.10.2014 20:08:59.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.3583.2615 [GMT 2:00] ausgeführt von:: c:\users\jan\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\jan\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\windows\IsUn0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-09-23 bis 2014-10-23 )))))))))))))))))))))))))))))) . . 2014-10-23 18:19 . 2014-10-23 18:19 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D85FBAE-D72B-4041-8993-E96AE5D96F1A}\offreg.dll 2014-10-23 18:18 . 2014-10-23 18:23 -------- d-----w- c:\users\jan\AppData\Local\temp 2014-10-23 18:18 . 2014-10-23 18:18 -------- d-----w- c:\users\hedev\AppData\Local\temp 2014-10-23 18:18 . 2014-10-23 18:18 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-10-22 11:14 . 2014-10-22 11:17 -------- d-----w- C:\FRST 2014-10-22 11:14 . 2014-10-20 01:37 8901368 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D85FBAE-D72B-4041-8993-E96AE5D96F1A}\mpengine.dll 2014-10-21 16:53 . 2014-10-21 16:53 -------- d-sh--w- c:\windows\system32\AI_RecycleBin 2014-10-21 16:42 . 2014-10-21 16:42 -------- d-----w- c:\program files\CCleaner 2014-10-20 21:11 . 2014-10-20 21:11 -------- d-----w- c:\windows\ERUNT 2014-10-20 20:10 . 2014-10-23 18:22 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-10-20 20:10 . 2014-10-21 22:11 -------- d-----w- c:\program files\ Malwarebytes Anti-Malware 2014-10-20 20:10 . 2014-10-01 09:11 51928 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-10-20 20:10 . 2014-10-01 09:11 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-10-20 20:04 . 2014-10-20 20:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2014-10-20 20:04 . 2014-10-01 09:11 23256 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-10-17 12:46 . 2014-09-18 01:32 2363904 ----a-w- c:\windows\system32\msi.dll 2014-10-17 12:46 . 2014-09-13 01:40 67072 ----a-w- c:\windows\system32\packager.dll 2014-10-16 18:45 . 2014-10-16 18:45 -------- d-----w- c:\program files\Common Files\Java 2014-10-01 12:31 . 2014-09-25 01:40 519680 ----a-w- c:\windows\system32\qdvd.dll 2014-09-30 13:30 . 2014-09-30 13:30 -------- d-----w- c:\programdata\ATI 2014-09-30 13:30 . 2014-09-30 13:30 -------- d-----w- c:\program files\AMD AVT 2014-09-28 06:27 . 2014-09-28 06:27 2970808 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\1031\MSOINTL.DLL 2014-09-25 11:30 . 2014-09-25 11:30 81383096 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL 2014-09-25 11:30 . 2014-09-25 11:30 5646032 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe 2014-09-25 11:30 . 2014-09-25 11:30 550064 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE 2014-09-25 11:30 . 2014-09-25 11:30 5353664 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\Csi.dll 2014-09-25 11:30 . 2014-09-25 11:30 26345152 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL 2014-09-24 10:29 . 2014-09-09 21:47 2048 ----a-w- c:\windows\system32\tzres.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-10-16 18:44 . 2014-08-11 12:55 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2014-10-02 13:53 . 2014-03-27 08:02 231568 ------w- c:\windows\system32\MpSigStub.exe 2014-10-01 12:10 . 2013-07-16 21:08 37384 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2014-10-01 12:10 . 2013-07-16 15:02 136216 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-10-01 12:10 . 2013-07-16 15:02 98160 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-09-24 14:38 . 2013-07-16 22:45 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-09-24 14:38 . 2013-07-16 17:51 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-09-15 22:31 . 2014-09-15 22:31 71704 ----a-w- c:\windows\system32\atimpc32.dll 2014-09-15 22:31 . 2014-09-15 22:31 71704 ----a-w- c:\windows\system32\amdpcom32.dll 2014-09-15 22:31 . 2014-04-18 02:42 126848 ----a-w- c:\windows\system32\atiuxpag.dll 2014-09-15 22:31 . 2014-04-18 02:42 100032 ----a-w- c:\windows\system32\atiu9pag.dll 2014-09-15 22:31 . 2014-04-18 02:42 1113576 ----a-w- c:\windows\system32\aticfx32.dll 2014-09-15 22:31 . 2014-04-18 02:42 9254184 ----a-w- c:\windows\system32\atidxx32.dll 2014-09-15 22:31 . 2014-04-18 02:42 7207592 ----a-w- c:\windows\system32\atiumdva.dll 2014-09-15 22:31 . 2014-04-18 02:42 7028336 ----a-w- c:\windows\system32\atiumdag.dll 2014-09-15 22:29 . 2014-09-15 22:29 264928 ----a-w- c:\windows\system32\drivers\amdacpksd.sys 2014-09-15 22:25 . 2014-09-15 22:25 14798336 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2014-09-15 22:18 . 2014-09-15 22:18 203776 ----a-w- c:\windows\system32\clinfo.exe 2014-09-15 22:17 . 2014-09-15 22:17 83456 ----a-w- c:\windows\system32\OpenVideo.dll 2014-09-15 22:17 . 2014-09-15 22:17 73216 ----a-w- c:\windows\system32\OVDecode.dll 2014-09-15 22:17 . 2014-09-15 22:17 28770304 ----a-w- c:\windows\system32\amdocl.dll 2014-09-15 22:16 . 2014-09-15 22:16 58880 ----a-w- c:\windows\system32\OpenCL.dll 2014-09-15 22:09 . 2014-09-15 22:09 37888 ----a-w- c:\windows\system32\amdmmcl.dll 2014-09-15 22:09 . 2014-09-15 22:09 113664 ----a-w- c:\windows\system32\mantle32.dll 2014-09-15 22:08 . 2014-09-15 22:08 23375360 ----a-w- c:\windows\system32\atioglxx.dll 2014-09-15 22:07 . 2014-09-15 22:07 367104 ----a-w- c:\windows\system32\atiapfxx.exe 2014-09-15 22:07 . 2014-09-15 22:07 52224 ----a-w- c:\windows\system32\aticalrt.dll 2014-09-15 22:07 . 2014-09-15 22:07 49152 ----a-w- c:\windows\system32\aticalcl.dll 2014-09-15 22:06 . 2014-09-15 22:06 14302208 ----a-w- c:\windows\system32\aticaldd.dll 2014-09-15 22:05 . 2014-09-15 22:05 4480000 ----a-w- c:\windows\system32\amdmantle32.dll 2014-09-15 22:03 . 2014-09-15 22:03 442368 ----a-w- c:\windows\system32\atidemgy.dll 2014-09-15 22:03 . 2014-09-15 22:03 30720 ----a-w- c:\windows\system32\atimuixx.dll 2014-09-15 22:03 . 2014-09-15 22:03 513536 ----a-w- c:\windows\system32\atieclxx.exe 2014-09-15 22:03 . 2014-09-15 22:03 208896 ----a-w- c:\windows\system32\atiesrxx.exe 2014-09-15 22:03 . 2014-09-15 22:03 85504 ----a-w- c:\windows\system32\mantleaxl32.dll 2014-09-15 22:03 . 2014-09-15 22:03 164352 ----a-w- c:\windows\system32\atitmmxx.dll 2014-09-15 21:59 . 2014-09-15 21:59 637952 ----a-w- c:\windows\system32\coinst_14.30.dll 2014-09-15 21:59 . 2014-09-15 21:59 900608 ----a-w- c:\windows\system32\atiadlxx.dll 2014-09-15 21:59 . 2014-09-15 21:59 69632 ----a-w- c:\windows\system32\atiglpxx.dll 2014-09-15 21:59 . 2014-09-15 21:59 133632 ----a-w- c:\windows\system32\atigktxx.dll 2014-09-15 21:59 . 2014-09-15 21:59 463360 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2014-09-15 21:58 . 2014-09-15 21:58 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2014-09-15 16:19 . 2014-09-15 16:19 38912 ----a-w- c:\windows\system32\kdbsdk32.dll 2014-08-23 01:46 . 2014-08-28 13:35 305152 ----a-w- c:\windows\system32\gdi32.dll 2014-08-01 11:35 . 2014-09-11 13:10 793600 ----a-w- c:\windows\system32\TSWorkspace.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)] @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}" [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}] 2014-09-16 11:50 1729232 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)] @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}" [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}] 2014-09-16 11:50 1729232 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)] @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}" [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}] 2014-09-16 11:50 1729232 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Akamai NetSession Interface"="c:\users\jan\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912] "Raptr"="c:\progra~1\Raptr\raptrstub.exe" [2014-10-17 55568] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" [2014-09-15 748256] "Avira Systray"="c:\program files\Avira\My Avira\Avira.OE.Systray.exe" [2014-09-23 165168] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-10-01 703736] . c:\users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Curse.lnk - c:\users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe /startup [2014-8-29 6060808] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring] 2014-09-26 14:04 4811032 ----a-w- c:\program files\CCleaner\CCleaner.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr] 2014-10-17 18:24 55568 ----a-w- c:\progra~1\Raptr\raptrstub.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray] 2013-07-25 09:19 5624784 ----a-w- c:\program files\Spybot - Search & Destroy 2\SDTray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify] 2013-12-05 15:12 5951488 ----a-w- c:\users\jan\AppData\Roaming\Spotify\spotify.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper] 2013-12-05 15:12 1168896 ----a-w- c:\users\jan\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] 2014-08-13 22:34 1937600 ----a-w- c:\program files\Steam\Steam.exe . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2013-10-17 23040] R3 HtcVCom32;HTC Diagnostic Port;c:\windows\system32\DRIVERS\HtcVComV32.sys [2009-10-27 105984] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-09-19 108032] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2014-05-15 3191392] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-08-23 24064] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 vtany;vtany;c:\windows\vtany.sys [x] R3 xhunter1;xhunter1;c:\windows\xhunter1.sys [x] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2014-10-01 994552] S0 amdkmafd;AMD Audio Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmafd.sys [2013-07-16 15968] S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys [2013-07-16 22144] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-11-26 37352] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-05-03 243128] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2014-09-15 208896] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 276992] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2014-10-01 431920] S2 AODDriver4.3;AODDriver4.3;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400] S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-09-23 160560] S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files\Hi-Rez Studios\HiPatchService.exe [2014-08-22 9216] S2 HTCMonitorService;HTCMonitorService;c:\program files\HTC\HTC Sync Manager\HSMServiceEntry.exe [2014-08-04 87368] S2 MBAMScheduler;MBAMScheduler;c:\program files\ Malwarebytes Anti-Malware \mbamscheduler.exe [2014-10-01 1871160] S2 MBAMService;MBAMService;c:\program files\ Malwarebytes Anti-Malware \mbamservice.exe [2014-10-01 968504] S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2012-07-13 769432] S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2013-10-17 166912] S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560] S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928] S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2013-07-16 27768] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2014-06-21 77824] S3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys [2012-10-11 34432] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-10-01 23256] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-10-23 114904] S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-10-01 51928] S3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv.sys [2013-01-31 22656] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2013-07-16 1846448] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - MBAMSWISSARMY *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-10-17 22:53 1089352 ----a-w- c:\program files\Google\Chrome\Application\38.0.2125.104\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-16 14:38] . 2014-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-07-16 14:52] . 2014-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-07-16 14:52] . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = <local> IE: An OneNote s&enden - c:\progra~1\MICROS~3\Office15\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office15\EXCEL.EXE/3000 Trusted Zone: aeriagames.com Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Notify-SDWinLogon - SDWinLogon.dll MSConfigStartUp-Aeria Ignite - c:\program files\Aeria Games\Ignite\aeriaignite.exe AddRemove-swtor_swtor - c:\programdata\BitRaider\brwc.exe AddRemove-Zanzarah - c:\windows\IsUn0407.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,7a,9a,22,ff,72,33,49,a6,3b,5a,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,7a,9a,22,ff,72,33,49,a6,3b,5a,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\windows\system32\atieclxx.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\taskhost.exe c:\program files\ Malwarebytes Anti-Malware \mbam.exe c:\program files\HTC\HTC Sync Manager\HTC Sync\adb.exe c:\windows\system32\conhost.exe c:\program files\Google\Update\\GoogleCrashHandler.exe c:\users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\progra~1\Raptr\raptr.exe c:\progra~1\Raptr\raptr_im.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-10-23 20:33:10 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-10-23 18:33 . Vor Suchlauf: 18 Verzeichnis(se), Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 157.081.559.040 Bytes frei . - - End Of File - - 8808C874373BF50A7FC7E7B293BE41B4 A36C5E4F47E84449FF07ED3517B43A31 |
![]() | #6 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! |
![]() | #7 |
| ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Hey schrauber ^-^ Am 20.10, also vor 5 Tagen, begann dieses Problem. Bevor ich mich also hier meldete, hatte ich leider vorher schon ein mal meinen Computer mit Mbam gescannt und der Log hatte einige Funde, ich werde die beiden Logs posten, einen vom 25. (Heute) und den vom 20. 25.10 Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 25.10.2014 Suchlauf-Zeit: 21:16:48 Logdatei: mbam25-10.txt Administrator: Ja Version: Malware Datenbank: v2014.10.25.05 Rootkit Datenbank: v2014.10.22.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: jan Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 335239 Verstrichene Zeit: 15 Min, 50 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 1 PUP.Optional.OpenCandy, C:\Users\jan\Desktop\Programme\Daemon Tools Lite\DTLite4471-0333.exe, In Quarantäne, [ead7997e88f4b87e9d19ce844cb91ce4], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 20.10.2014 Suchlauf-Zeit: 22:38:51 Logdatei: mbam20-10.txt Administrator: Ja Version: Malware Datenbank: v2014.03.04.09 Rootkit Datenbank: v2014.10.17.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: jan Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 230195 Verstrichene Zeit: 13 Min, 11 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 1 PUP.Optional.VMNToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}, In Quarantäne, [4684bf56d3a9a393e8b0ef86fd05f60a], Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 3 PUP.Optional.OpenCandy, C:\Users\jan\Desktop\Programme\Daemon Tools Lite\DTLite4471-0333.exe, Keine Aktion durch Benutzer, [15b51df83f3dae88ce182e2307fd9967], PUP.Optional.MyStartTB.A, C:\Users\jan\Downloads\ManyCamSetup.exe, In Quarantäne, [9c2ed1445a22280e00bc196b2ad7b64a], PUP.Optional.Handy.A, C:\Users\jan\Downloads\GotClip_Setup.exe, In Quarantäne, [646643d254283105077da2bbc140c040], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Werde jetzt schon ein mal eine Gaming-Session machen und berichten ob das Problem immernoch vorhanden ist, danke für die Hilfe ^-^ ADWCleaner Code:
ATTFilter # AdwCleaner v4.001 - Bericht erstellt am 25/10/2014 um 21:59:42 # DB v2014-10-23.2 # Aktualisiert 20/10/2014 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits) # Benutzername : jan - JAN-PC # Gestartet von : C:\Users\jan\Desktop\adwcleaner_4.001.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\jan\AppData\Local\CrashRpt ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{06E58E5E-F8CB-4049-991E-A41C03BD419E} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{100EB1FD-D03E-47FD-81F3-EE91287F9465} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{258C9770-1713-4021-8D7E-1F184A2BD754} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{31CF9EBE-5755-4A1D-AC25-2834D952D9B4} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{43D9E6F0-1776-4897-AE14-ECEDECBAFEC0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5A074B29-F830-49DE-A31B-5BB9D7F6B407} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{855F3B16-6D32-4FE6-8A56-BBB695989046} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{C451C08A-EC37-45DF-AAAD-18B51AB5E837} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{DCC70A83-E184-40A3-906B-779AF5E941C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{EF99BD32-C1FB-11D2-892F-0090271D4F88} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17344 -\\ Google Chrome v38.0.2125.104 ************************* AdwCleaner[R0].txt - [1194 octets] - [14/09/2013 20:05:41] AdwCleaner[R1].txt - [912 octets] - [14/09/2013 20:16:22] AdwCleaner[R2].txt - [971 octets] - [14/09/2013 20:24:17] AdwCleaner[R3].txt - [2392 octets] - [20/10/2014 23:03:48] AdwCleaner[R4].txt - [3668 octets] - [21/10/2014 18:18:33] AdwCleaner[R5].txt - [3774 octets] - [25/10/2014 21:57:34] AdwCleaner[S0].txt - [1259 octets] - [14/09/2013 20:13:03] AdwCleaner[S1].txt - [2445 octets] - [20/10/2014 23:07:08] AdwCleaner[S2].txt - [3687 octets] - [25/10/2014 21:59:42] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3747 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.3 (10.21.2014:1) OS: Windows 7 Ultimate x86 Ran by jan on 25.10.2014 at 22:09:57,18 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 25.10.2014 at 22:11:43,68 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frisches FRST Log FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-10-2014 Ran by jan (administrator) on JAN-PC on 25-10-2014 22:13:09 Running from C:\Users\jan\Desktop Loaded Profile: jan (Available profiles: jan) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe (Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\System32\PnkBstrA.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe () C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe (Google Inc.) C:\Program Files\Google\Update\\GoogleCrashHandler.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe (Curse, Inc) C:\Users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Raptr, Inc) C:\Program Files\Raptr\raptr.exe (Raptr, Inc) C:\Program Files\Raptr\raptr_im.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-09-15] (Advanced Micro Devices, Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Akamai NetSession Interface] => C:\Users\jan\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55568 2014-10-17] (Raptr, Inc) Startup: C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk ShortcutTarget: Curse.lnk -> C:\Users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) Handler: AutorunsDisabled\skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll (OGPlanet) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) Chrome: ======= CHR StartupUrls: Default -> "hxxp://jappy.de/" CHR Profile: C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-16] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (Turn Off the Lights) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-07-16] CHR Extension: (YouTube) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-16] CHR Extension: (TV) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-05-04] CHR Extension: (Tanki Online) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chnamgoimgnbgkabfjkikldbfdhhfhdo [2014-08-18] CHR Extension: (Google-Suche) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-16] CHR Extension: (Tampermonkey) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-08-04] CHR Extension: (Realm of the Mad God) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp [2014-07-18] CHR Extension: (RAD Soldiers) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkiahcckehgdocgonfdickeagmoembpe [2014-07-17] CHR Extension: (Rush Team) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2014-05-04] CHR Extension: (Avira SafeSearch) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2014-08-08] CHR Extension: (Freefall Tournament) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2014-05-04] CHR Extension: (Polycraft) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopfmbpfhhfnklgmjpoehcjaajhpbhbl [2014-07-27] CHR Extension: (Avira Browser Safety) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-10] CHR Extension: (Heroes & Generals) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2014-05-20] CHR Extension: (WarChiefs - Tiberium Alliances Combat Simulator) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggiejiffgcdcfogfcgdebmbafcfndpgd [2013-08-04] CHR Extension: (AdBlock) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-16] CHR Extension: (Speed Test) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2014-08-18] CHR Extension: (Red Crucible 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iechpocbkaimjmlpfinoahkolenfdmig [2014-08-17] CHR Extension: (Cut the Rope) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2014-08-03] CHR Extension: (Plug+) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jflocljnfndnnnlmfaamgbkbibnfmlkf [2013-07-16] CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2013-08-05] CHR Extension: (Verdun Game) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\khdppkcpilejlgahecofelpoidcnjbdg [2014-07-18] CHR Extension: (Sand 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\klicmgamjpclmbhppmdeamffedflmkcn [2014-10-16] CHR Extension: (Artillery Tower Protector) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgcejmkikbadghamaadggncnbfekdik [2014-08-03] CHR Extension: (Fieldrunners) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2014-05-04] CHR Extension: (Regen-Alarm) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-08-18] CHR Extension: (Spelunky HTML5) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhagnkphcmpkmabhocgimoncfaihkpof [2014-10-01] CHR Extension: (DSL speedtest) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj [2014-08-18] CHR Extension: (Apple Shooter) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbhfnlipcinfjmjplgegncjlmpnihecg [2014-08-18] CHR Extension: (Google Wallet) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Batterfield Map) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\npjmhhanmmlmpcnonlcgplgfnngboodf [2014-09-05] CHR Extension: (Sand) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdknckljjbdpkhgmcokoahffbdinafbo [2014-09-12] CHR Extension: (Reditr - The Best Reddit Client) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmfcbbijgnhoebddbjpmlikabnbnddgb [2014-10-01] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG) R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed] R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-08-04] (Nero AG) S2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG) S3 npggsvc; C:\Windows\system32\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-07-19] () R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2013-07-16] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [15968 2013-07-16] (Advanced Micro Devices, Inc.) R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [22144 2013-07-16] (Advanced Micro Devices, Inc.) R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-03] (Disc Soft Ltd) S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1846448 2013-07-16] (VIA Technologies, Inc.) S3 catchme; \??\C:\Users\jan\AppData\Local\Temp\catchme.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 vtany; \??\C:\Windows\vtany.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-25 22:11 - 2014-10-25 22:11 - 00000781 _____ () C:\Users\jan\Desktop\FRST - Verknüpfung.lnk 2014-10-25 22:11 - 2014-10-25 22:11 - 00000689 _____ () C:\Users\jan\Desktop\JRT.txt 2014-10-25 22:08 - 2014-10-25 22:08 - 00000000 ____D () C:\Users\jan\Desktop\FRST-OlderVersion 2014-10-25 22:07 - 2014-10-21 20:25 - 01706144 _____ (Thisisu) C:\Users\jan\Desktop\JRT_NEW.exe 2014-10-25 22:05 - 2014-10-25 21:59 - 00003827 _____ () C:\Users\jan\Desktop\AdwCleaner[S2].txt 2014-10-25 21:50 - 2014-10-25 21:50 - 00001309 _____ () C:\Users\jan\Desktop\mbam25-10.txt 2014-10-25 21:49 - 2014-10-25 21:53 - 00001706 _____ () C:\Users\jan\Desktop\mbam20-10.txt 2014-10-23 20:33 - 2014-10-23 20:33 - 00019058 _____ () C:\ComboFix.txt 2014-10-23 20:06 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-10-23 20:06 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-10-23 20:06 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-10-23 20:06 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-10-23 20:06 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-10-23 20:06 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-10-23 20:06 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-10-23 20:06 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-10-23 20:04 - 2014-10-23 20:33 - 00000000 ____D () C:\Qoobox 2014-10-23 20:04 - 2014-10-23 20:30 - 00000000 ____D () C:\Windows\erdnt 2014-10-23 19:58 - 2014-10-23 19:59 - 05584933 ____R (Swearware) C:\Users\jan\Desktop\ComboFix.exe 2014-10-22 13:17 - 2014-10-22 13:42 - 00037130 _____ () C:\Users\jan\Desktop\Addition.txt 2014-10-22 13:15 - 2014-10-25 22:13 - 00016849 _____ () C:\Users\jan\Desktop\FRST.txt 2014-10-22 13:14 - 2014-10-25 22:13 - 00000000 ____D () C:\FRST 2014-10-22 13:13 - 2014-10-25 22:08 - 01104384 _____ (Farbar) C:\Users\jan\Desktop\FRST.exe 2014-10-22 03:11 - 2014-10-22 03:17 - 00009897 _____ () C:\Users\jan\Desktop\hijackthis.log 2014-10-22 03:08 - 2014-10-22 03:08 - 00002238 _____ () C:\Users\jan\Downloads\hijackthis.log 2014-10-22 02:51 - 2014-10-22 02:51 - 00388608 _____ (Trend Micro Inc.) C:\Users\jan\Desktop\HiJackThis204.exe 2014-10-22 00:11 - 2014-10-22 00:11 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-21 23:04 - 2014-10-21 23:04 - 00117912 _____ () C:\Users\jan\AppData\Local\GDIPFONTCACHEV1.DAT 2014-10-21 22:59 - 2014-10-25 22:01 - 00000448 _____ () C:\Windows\setupact.log 2014-10-21 22:59 - 2014-10-25 22:00 - 00003226 _____ () C:\Windows\PFRO.log 2014-10-21 22:59 - 2014-10-21 22:59 - 00460912 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-21 22:59 - 2014-10-21 22:59 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-21 18:50 - 2014-10-21 18:50 - 00143690 _____ () C:\Users\jan\Desktop\cc_20141021_185023.reg 2014-10-21 18:42 - 2014-10-21 18:42 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-10-21 18:42 - 2014-10-21 18:42 - 00000000 ____D () C:\Program Files\CCleaner 2014-10-21 18:36 - 2014-10-21 18:27 - 03239099 _____ () C:\Users\jan\Desktop\CBS.log 2014-10-21 18:33 - 2014-10-21 18:33 - 00030992 _____ () C:\sfcdetails.txt 2014-10-21 18:17 - 2014-10-21 18:17 - 01962496 _____ () C:\Users\jan\Desktop\adwcleaner_4.001.exe 2014-10-20 23:11 - 2014-10-20 23:11 - 00000000 ____D () C:\Windows\ERUNT 2014-10-20 22:10 - 2014-10-25 22:02 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-10-20 22:10 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-20 22:10 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-20 22:04 - 2014-10-20 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-10-20 22:04 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-17 14:47 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-17 14:47 - 2014-09-29 02:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-17 14:47 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-17 14:47 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-17 14:47 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-17 14:47 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-17 14:47 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-17 14:47 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-17 14:47 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-17 14:47 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-17 14:47 - 2014-09-19 03:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-10-17 14:47 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-17 14:47 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-17 14:47 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-10-17 14:47 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-10-17 14:47 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-17 14:47 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-17 14:47 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-17 14:47 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-17 14:47 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-17 14:47 - 2014-09-19 02:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-10-17 14:47 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-10-17 14:47 - 2014-09-19 02:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-10-17 14:47 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-10-17 14:47 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-17 14:47 - 2014-09-19 02:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-17 14:47 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-17 14:47 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-10-17 14:47 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-17 14:47 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-17 14:47 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-10-17 14:47 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-17 14:47 - 2014-08-29 03:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-10-17 14:47 - 2014-08-29 03:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-10-17 14:47 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-17 14:47 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-17 14:47 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-17 14:47 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-17 14:47 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-17 14:47 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-17 14:47 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-17 14:47 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-17 14:46 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-17 14:46 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 20:45 - 2014-10-16 20:45 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-10-16 20:43 - 2014-10-16 20:43 - 00638888 _____ (Oracle Corporation) C:\Users\jan\Downloads\chromeinstall-8u25.exe 2014-10-13 22:45 - 2014-10-13 22:45 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-10-13 21:11 - 2014-10-13 22:07 - 00001957 _____ () C:\Users\jan\Desktop\Engel Englisch.txt 2014-10-01 14:31 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-09-30 15:30 - 2014-09-30 15:30 - 00060300 _____ () C:\Windows\system32\CCCInstall_201409301530165576.log 2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\ProgramData\ATI 2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\Program Files\AMD AVT 2014-09-30 15:29 - 2014-09-30 15:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-09-30 15:15 - 2014-09-30 15:17 - 210974816 _____ (AMD Inc.) C:\Users\jan\Downloads\amd-catalyst-14-9-win7-win8.1-32bit-dd-ccc-whql.exe 2014-09-25 16:04 - 2014-09-25 16:06 - 00000104 _____ () C:\Users\jan\Desktop\Notizen.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-25 22:08 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-25 22:08 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-25 22:07 - 2013-07-16 16:52 - 00000000 ____D () C:\Users\jan\Desktop\Anti-Vir 2014-10-25 22:05 - 2013-07-16 16:44 - 01955897 _____ () C:\Windows\WindowsUpdate.log 2014-10-25 22:03 - 2014-08-17 21:07 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Raptr 2014-10-25 22:01 - 2014-09-18 18:05 - 00000000 ____D () C:\Users\jan\AppData\Local\HTC MediaHub 2014-10-25 22:01 - 2013-07-16 16:52 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-25 22:01 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-25 21:59 - 2013-09-14 14:51 - 00000000 ____D () C:\AdwCleaner 2014-10-25 21:58 - 2013-07-16 16:52 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-25 21:38 - 2013-07-17 00:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-23 20:33 - 2013-08-27 20:30 - 00000000 ____D () C:\Users\Spiele & Programme von Jan 2014-10-23 20:33 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default 2014-10-23 20:33 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public 2014-10-23 20:22 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini 2014-10-23 20:14 - 2013-11-17 02:20 - 00000000 ____D () C:\ProgramData\Temp 2014-10-21 19:38 - 2013-10-03 00:11 - 00000000 ____D () C:\Users\jan\Desktop\Musik 2014-10-21 19:12 - 2013-07-18 01:50 - 00000000 ____D () C:\Program Files\Steam 2014-10-21 19:08 - 2013-08-17 01:58 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Ubisoft 2014-10-21 19:08 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-10-21 19:06 - 2014-07-30 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon 2014-10-21 19:06 - 2014-07-30 23:25 - 00000000 ____D () C:\Nexon 2014-10-21 18:59 - 2013-07-17 00:17 - 00000000 ____D () C:\Program Files\Java 2014-10-21 18:49 - 2013-08-26 04:56 - 00000000 ____D () C:\Users\jan\AppData\Roaming\uTorrent 2014-10-21 18:49 - 2013-07-28 00:36 - 00000000 ____D () C:\Users\jan\AppData\Roaming\DAEMON Tools Lite 2014-10-21 18:49 - 2013-07-25 00:40 - 00000000 ____D () C:\Users\jan\AppData\Roaming\TS3Client 2014-10-21 18:48 - 2013-10-09 04:16 - 00000000 ____D () C:\Windows\Minidump 2014-10-21 18:48 - 2013-08-17 15:27 - 00000000 ___RD () C:\Users\jan\Desktop\Games 2014-10-21 18:48 - 2013-07-25 21:26 - 00000000 ____D () C:\Users\jan\Desktop\Programme 2014-10-21 18:48 - 2013-07-16 17:40 - 00000000 ____D () C:\Windows\Panther 2014-10-20 22:55 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Help 2014-10-20 22:13 - 2013-09-22 17:47 - 00000000 ____D () C:\Users\jan\Desktop\Schule 2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Malwarebytes 2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-19 23:21 - 2014-05-03 22:59 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-10-19 23:21 - 2014-05-03 22:55 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-19 03:21 - 2013-08-17 02:27 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-19 03:01 - 2013-07-16 19:20 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-18 14:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-10-18 14:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-10-18 13:30 - 2014-08-17 21:07 - 00000000 ____D () C:\Program Files\Raptr 2014-10-18 13:19 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-10-18 03:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-10-18 03:08 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini 2014-10-18 00:57 - 2013-07-16 16:53 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-10-16 20:45 - 2014-08-11 14:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-16 20:44 - 2014-08-11 14:55 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-10-16 20:44 - 2014-08-11 14:55 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-10-16 20:44 - 2013-10-22 22:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-15 12:17 - 2014-09-10 14:26 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Curse Client 2014-10-13 22:45 - 2013-08-17 13:54 - 00000000 ____D () C:\ProgramData\Package Cache 2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\Program Files\Avira 2014-10-02 15:53 - 2014-03-27 10:02 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-01 14:10 - 2013-07-16 23:08 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-10-01 14:10 - 2013-07-16 17:02 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-01 14:10 - 2013-07-16 17:02 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-09-30 15:30 - 2013-07-16 16:56 - 00000000 ____D () C:\ProgramData\AMD 2014-09-30 15:29 - 2013-07-16 16:55 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-09-30 15:19 - 2013-07-16 16:54 - 00000000 ____D () C:\AMD Files to move or delete: ==================== C:\Users\jan\jagex_cl_runescape_LIVE.dat C:\Users\jan\jagex_cl_runescape_LIVE1.dat C:\Users\jan\random.dat Some content of TEMP: ==================== C:\Users\jan\AppData\Local\temp\avgnt.exe C:\Users\jan\AppData\Local\temp\Quarantine.exe C:\Users\jan\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-17 15:28 ==================== End Of Log ============================ --- --- --- |
![]() | #8 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig!ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #9 |
| ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=1648f742f5ac164fa38f585121f18e42 # engine=20780 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-10-26 01:52:12 # local_time=2014-10-26 02:52:12 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 25815 40301471 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 0 165919523 0 0 # scanned=13352 # found=0 # cleaned=0 # scan_time=2252 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=1648f742f5ac164fa38f585121f18e42 # engine=20780 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-10-26 02:29:34 # local_time=2014-10-26 03:29:34 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 28057 40303713 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 0 165921765 0 0 # scanned=50277 # found=0 # cleaned=0 # scan_time=2065 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=1648f742f5ac164fa38f585121f18e42 # engine=20780 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-10-26 06:36:12 # local_time=2014-10-26 07:36:12 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 42855 40318511 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 0 165936563 0 0 # scanned=331602 # found=3 # cleaned=0 # scan_time=7621 sh=D1F0FD084A0C4BF7DD0B710573E06A17222D55C4 ft=1 fh=787d4ad607d79e1d vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jan\Downloads\OpenOffice - CHIP-Downloader.exe" sh=3D1FDED56D9DF9D1D5F07D8FA5F903C9CA308B3B ft=1 fh=029a8e2c3fd8a9aa vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jan\Downloads\PDF24 Creator - CHIP-Downloader.exe" sh=DA928C6FE9145CDFEC3212376F85E7051798FC79 ft=1 fh=1d985872365bc2cd vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jan\Downloads\rpc412_setup.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.89 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy CCleaner Java 8 Update 25 Java version out of Date! Adobe Flash Player Google Chrome 37.0.2062.124 Google Chrome 38.0.2125.104 ````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled! Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-10-2014 Ran by jan (administrator) on JAN-PC on 26-10-2014 16:53:59 Running from C:\Users\jan\Desktop Loaded Profile: jan (Available profiles: jan) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe (Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\System32\PnkBstrA.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe () C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe (Google Inc.) C:\Program Files\Google\Update\\GoogleCrashHandler.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-09-15] (Advanced Micro Devices, Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Akamai NetSession Interface] => C:\Users\jan\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55568 2014-10-17] (Raptr, Inc) Startup: C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk ShortcutTarget: Curse.lnk -> C:\Users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) Handler: AutorunsDisabled\skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll (OGPlanet) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) Chrome: ======= CHR StartupUrls: Default -> "hxxp://jappy.de/" CHR Profile: C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-16] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (Turn Off the Lights) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-07-16] CHR Extension: (YouTube) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-16] CHR Extension: (TV) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-05-04] CHR Extension: (Tanki Online) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chnamgoimgnbgkabfjkikldbfdhhfhdo [2014-08-18] CHR Extension: (Google-Suche) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-16] CHR Extension: (Tampermonkey) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-08-04] CHR Extension: (Realm of the Mad God) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp [2014-07-17] CHR Extension: (RAD Soldiers) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkiahcckehgdocgonfdickeagmoembpe [2014-07-17] CHR Extension: (Rush Team) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2014-05-04] CHR Extension: (Avira SafeSearch) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2014-08-08] CHR Extension: (Freefall Tournament) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2014-05-04] CHR Extension: (Polycraft) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopfmbpfhhfnklgmjpoehcjaajhpbhbl [2014-07-27] CHR Extension: (Avira Browser Safety) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-10] CHR Extension: (Heroes & Generals) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2014-05-20] CHR Extension: (WarChiefs - Tiberium Alliances Combat Simulator) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggiejiffgcdcfogfcgdebmbafcfndpgd [2013-08-04] CHR Extension: (AdBlock) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-16] CHR Extension: (Speed Test) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2014-08-18] CHR Extension: (Red Crucible 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iechpocbkaimjmlpfinoahkolenfdmig [2014-08-17] CHR Extension: (Cut the Rope) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2014-08-03] CHR Extension: (Plug+) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jflocljnfndnnnlmfaamgbkbibnfmlkf [2013-07-16] CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2013-08-05] CHR Extension: (Verdun Game) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\khdppkcpilejlgahecofelpoidcnjbdg [2014-07-17] CHR Extension: (Sand 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\klicmgamjpclmbhppmdeamffedflmkcn [2014-10-16] CHR Extension: (Artillery Tower Protector) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgcejmkikbadghamaadggncnbfekdik [2014-08-03] CHR Extension: (Fieldrunners) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2014-05-04] CHR Extension: (Regen-Alarm) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-08-18] CHR Extension: (Spelunky HTML5) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhagnkphcmpkmabhocgimoncfaihkpof [2014-10-01] CHR Extension: (DSL speedtest) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj [2014-08-18] CHR Extension: (Apple Shooter) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbhfnlipcinfjmjplgegncjlmpnihecg [2014-08-18] CHR Extension: (Google Wallet) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Batterfield Map) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\npjmhhanmmlmpcnonlcgplgfnngboodf [2014-09-05] CHR Extension: (Sand) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdknckljjbdpkhgmcokoahffbdinafbo [2014-09-12] CHR Extension: (Reditr - The Best Reddit Client) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmfcbbijgnhoebddbjpmlikabnbnddgb [2014-10-01] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG) R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed] R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-08-04] (Nero AG) S2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG) S3 npggsvc; C:\Windows\system32\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-07-19] () R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2013-07-16] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [15968 2013-07-16] (Advanced Micro Devices, Inc.) R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [22144 2013-07-16] (Advanced Micro Devices, Inc.) R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-03] (Disc Soft Ltd) S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1846448 2013-07-16] (VIA Technologies, Inc.) S3 catchme; \??\C:\Users\jan\AppData\Local\Temp\catchme.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 vtany; \??\C:\Windows\vtany.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-26 16:53 - 2014-10-26 16:54 - 00017303 _____ () C:\Users\jan\Desktop\FRST.txt 2014-10-26 16:53 - 2014-10-26 16:53 - 00000000 ____D () C:\Users\jan\Desktop\FRST-OlderVersion 2014-10-26 16:43 - 2014-10-26 16:43 - 00854448 _____ () C:\Users\jan\Desktop\SecurityCheck.exe 2014-10-26 16:17 - 2014-10-26 16:30 - 00000429 _____ () C:\Users\jan\Desktop\eset.txt 2014-10-26 02:11 - 2014-10-26 02:11 - 00000000 ____D () C:\Program Files\ESET 2014-10-26 02:09 - 2014-10-26 02:10 - 02347384 _____ (ESET) C:\Users\jan\Desktop\esetsmartinstaller_deu.exe 2014-10-25 21:07 - 2014-10-21 19:25 - 01706144 _____ (Thisisu) C:\Users\jan\Desktop\JRT_NEW.exe 2014-10-23 19:33 - 2014-10-23 19:33 - 00019058 _____ () C:\ComboFix.txt 2014-10-23 19:06 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-10-23 19:06 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-10-23 19:06 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-10-23 19:06 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-10-23 19:06 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-10-23 19:06 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-10-23 19:06 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-10-23 19:06 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-10-23 19:04 - 2014-10-23 19:33 - 00000000 ____D () C:\Qoobox 2014-10-23 19:04 - 2014-10-23 19:30 - 00000000 ____D () C:\Windows\erdnt 2014-10-23 18:58 - 2014-10-23 18:59 - 05584933 ____R (Swearware) C:\Users\jan\Desktop\ComboFix.exe 2014-10-22 12:14 - 2014-10-26 16:54 - 00000000 ____D () C:\FRST 2014-10-22 12:13 - 2014-10-26 16:53 - 01104896 _____ (Farbar) C:\Users\jan\Desktop\FRST.exe 2014-10-22 02:08 - 2014-10-22 02:08 - 00002238 _____ () C:\Users\jan\Downloads\hijackthis.log 2014-10-22 01:51 - 2014-10-22 01:51 - 00388608 _____ (Trend Micro Inc.) C:\Users\jan\Desktop\HiJackThis204.exe 2014-10-21 23:11 - 2014-10-21 23:11 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-21 22:04 - 2014-10-21 22:04 - 00117912 _____ () C:\Users\jan\AppData\Local\GDIPFONTCACHEV1.DAT 2014-10-21 21:59 - 2014-10-26 04:31 - 00000504 _____ () C:\Windows\setupact.log 2014-10-21 21:59 - 2014-10-25 21:00 - 00003226 _____ () C:\Windows\PFRO.log 2014-10-21 21:59 - 2014-10-21 21:59 - 00460912 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-21 21:59 - 2014-10-21 21:59 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-21 17:50 - 2014-10-21 17:50 - 00143690 _____ () C:\Users\jan\Desktop\cc_20141021_185023.reg 2014-10-21 17:42 - 2014-10-21 17:42 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-10-21 17:42 - 2014-10-21 17:42 - 00000000 ____D () C:\Program Files\CCleaner 2014-10-21 17:36 - 2014-10-21 17:27 - 03239099 _____ () C:\Users\jan\Desktop\CBS.log 2014-10-21 17:33 - 2014-10-21 17:33 - 00030992 _____ () C:\sfcdetails.txt 2014-10-21 17:17 - 2014-10-21 17:17 - 01962496 _____ () C:\Users\jan\Desktop\adwcleaner_4.001.exe 2014-10-20 22:11 - 2014-10-20 22:11 - 00000000 ____D () C:\Windows\ERUNT 2014-10-20 21:10 - 2014-10-26 04:35 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-20 21:10 - 2014-10-21 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-20 21:10 - 2014-10-21 23:11 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-10-20 21:10 - 2014-10-01 10:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-20 21:10 - 2014-10-01 10:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-20 21:04 - 2014-10-20 21:10 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-10-20 21:04 - 2014-10-01 10:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-17 13:47 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-17 13:47 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-17 13:47 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-17 13:47 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-17 13:47 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-17 13:47 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-17 13:47 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-17 13:47 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-17 13:47 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-17 13:47 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-17 13:47 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-10-17 13:47 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-17 13:47 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-17 13:47 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-10-17 13:47 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-10-17 13:47 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-17 13:47 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-17 13:47 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-17 13:47 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-17 13:47 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-17 13:47 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-10-17 13:47 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-10-17 13:47 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-10-17 13:47 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-10-17 13:47 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-17 13:47 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-17 13:47 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-17 13:47 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-10-17 13:47 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-17 13:47 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-17 13:47 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-10-17 13:47 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-17 13:47 - 2014-08-29 02:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-17 13:47 - 2014-08-29 02:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-10-17 13:47 - 2014-08-29 02:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-17 13:47 - 2014-08-29 02:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-10-17 13:47 - 2014-08-29 02:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-10-17 13:47 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-17 13:47 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-17 13:47 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-17 13:47 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-17 13:47 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-17 13:47 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-17 13:47 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-17 13:47 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-17 13:47 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-17 13:47 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-17 13:47 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-17 13:46 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-17 13:46 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 19:45 - 2014-10-16 19:45 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-10-16 19:43 - 2014-10-16 19:43 - 00638888 _____ (Oracle Corporation) C:\Users\jan\Downloads\chromeinstall-8u25.exe 2014-10-13 21:45 - 2014-10-13 21:45 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-10-13 20:11 - 2014-10-13 21:07 - 00001957 _____ () C:\Users\jan\Desktop\Engel Englisch.txt 2014-10-01 13:31 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-09-30 14:30 - 2014-09-30 14:30 - 00060300 _____ () C:\Windows\system32\CCCInstall_201409301530165576.log 2014-09-30 14:30 - 2014-09-30 14:30 - 00000000 ____D () C:\ProgramData\ATI 2014-09-30 14:30 - 2014-09-30 14:30 - 00000000 ____D () C:\Program Files\AMD AVT 2014-09-30 14:29 - 2014-09-30 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-09-30 14:15 - 2014-09-30 14:17 - 210974816 _____ (AMD Inc.) C:\Users\jan\Downloads\amd-catalyst-14-9-win7-win8.1-32bit-dd-ccc-whql.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-26 16:38 - 2013-07-16 23:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-26 15:58 - 2013-07-16 15:52 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-26 15:58 - 2013-07-16 15:52 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-26 04:40 - 2009-07-14 05:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-26 04:40 - 2009-07-14 05:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-26 04:38 - 2010-11-20 22:01 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-26 04:33 - 2014-08-17 20:07 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Raptr 2014-10-26 04:32 - 2014-09-18 17:05 - 00000000 ____D () C:\Users\jan\AppData\Local\HTC MediaHub 2014-10-26 04:32 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-26 04:30 - 2013-07-16 15:44 - 01989518 _____ () C:\Windows\WindowsUpdate.log 2014-10-26 02:54 - 2013-07-16 18:53 - 00000000 ____D () C:\Games 2014-10-25 21:07 - 2013-07-16 15:52 - 00000000 ____D () C:\Users\jan\Desktop\Anti-Vir 2014-10-25 20:59 - 2013-09-14 13:51 - 00000000 ____D () C:\AdwCleaner 2014-10-23 19:33 - 2013-08-27 19:30 - 00000000 ____D () C:\Users\Spiele & Programme von Jan 2014-10-23 19:33 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default 2014-10-23 19:33 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-10-23 19:22 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2014-10-23 19:14 - 2013-11-17 01:20 - 00000000 ____D () C:\ProgramData\Temp 2014-10-21 18:38 - 2013-10-02 23:11 - 00000000 ____D () C:\Users\jan\Desktop\Musik 2014-10-21 18:12 - 2013-07-18 00:50 - 00000000 ____D () C:\Program Files\Steam 2014-10-21 18:08 - 2013-08-17 00:58 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Ubisoft 2014-10-21 18:08 - 2009-07-14 05:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-10-21 18:06 - 2014-07-30 22:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon 2014-10-21 17:59 - 2013-07-16 23:17 - 00000000 ____D () C:\Program Files\Java 2014-10-21 17:49 - 2013-08-26 03:56 - 00000000 ____D () C:\Users\jan\AppData\Roaming\uTorrent 2014-10-21 17:49 - 2013-07-27 23:36 - 00000000 ____D () C:\Users\jan\AppData\Roaming\DAEMON Tools Lite 2014-10-21 17:49 - 2013-07-24 23:40 - 00000000 ____D () C:\Users\jan\AppData\Roaming\TS3Client 2014-10-21 17:48 - 2013-10-09 03:16 - 00000000 ____D () C:\Windows\Minidump 2014-10-21 17:48 - 2013-08-17 14:27 - 00000000 ___RD () C:\Users\jan\Desktop\Games 2014-10-21 17:48 - 2013-07-25 20:26 - 00000000 ____D () C:\Users\jan\Desktop\Programme 2014-10-21 17:48 - 2013-07-16 16:40 - 00000000 ____D () C:\Windows\Panther 2014-10-20 21:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help 2014-10-20 21:13 - 2013-09-22 16:47 - 00000000 ____D () C:\Users\jan\Desktop\Schule 2014-10-20 21:10 - 2013-09-16 21:24 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Malwarebytes 2014-10-20 21:10 - 2013-09-16 21:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-19 22:21 - 2014-05-03 21:59 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-10-19 22:21 - 2014-05-03 21:55 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-19 02:21 - 2013-08-17 01:27 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-19 02:01 - 2013-07-16 18:20 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-18 13:35 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-10-18 13:04 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-10-18 12:30 - 2014-08-17 20:07 - 00000000 ____D () C:\Program Files\Raptr 2014-10-18 12:19 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-10-18 02:39 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-10-18 02:08 - 2009-07-14 03:04 - 00000478 _____ () C:\Windows\win.ini 2014-10-17 23:57 - 2013-07-16 15:53 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-10-16 19:45 - 2014-08-11 13:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-16 19:44 - 2014-08-11 13:55 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-10-16 19:44 - 2014-08-11 13:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-10-16 19:44 - 2014-08-11 13:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-10-16 19:44 - 2014-08-11 13:55 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-10-16 19:44 - 2013-10-22 21:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-15 11:17 - 2014-09-10 13:26 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Curse Client 2014-10-13 21:45 - 2013-08-17 12:54 - 00000000 ____D () C:\ProgramData\Package Cache 2014-10-13 21:45 - 2013-07-16 16:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-10-13 21:45 - 2013-07-16 16:02 - 00000000 ____D () C:\Program Files\Avira 2014-10-02 14:53 - 2014-03-27 09:02 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-01 13:10 - 2013-07-16 22:08 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-10-01 13:10 - 2013-07-16 16:02 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-01 13:10 - 2013-07-16 16:02 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-09-30 14:30 - 2013-07-16 15:56 - 00000000 ____D () C:\ProgramData\AMD 2014-09-30 14:29 - 2013-07-16 15:55 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-09-30 14:19 - 2013-07-16 15:54 - 00000000 ____D () C:\AMD Files to move or delete: ==================== C:\Users\jan\jagex_cl_runescape_LIVE.dat C:\Users\jan\jagex_cl_runescape_LIVE1.dat C:\Users\jan\random.dat Some content of TEMP: ==================== C:\Users\jan\AppData\Local\temp\avgnt.exe C:\Users\jan\AppData\Local\temp\Quarantine.exe C:\Users\jan\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-26 08:02 ==================== End Of Log ============================ Im moment öffnet sich der Arbeitsplatz nicht mehr, jedoch bin ich mir immer noch unsicher, ich werde noch ein paar runden spielen und bescheid geben ![]() Danke für die Hilfe Schrauber! ![]() |
![]() | #10 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Adobe updaten. Fertig ![]() Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun ![]() Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #11 |
| ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Hallo Schrauber, das problem mit dem Arbeitsplatz ist mittlerweile seit anderthalb oder 2 Tagen nicht mehr aufgetreten und ich danke dir herzlichst ! Ich habe mittlerweile meinen Computer aufgeräumt und ältere Sachen runter geschmissen, mein Computer läuft mittlerweile auch ein wenig schneller und sieht netter aus. Ich danke dir und sobald sich ein neues Problem oder das mit dem Arbeitsplatz wieder melden sollte, wende ich mich wieder an dich ![]() Danke! MfG ![]() |
![]() | #12 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! Gern Geschehen ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
Themen zu [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! |
fehlercode 0x5, fehlercode 0xc0000005, fehlercode windows, pup.optional.handy.a, pup.optional.mystarttb.a, pup.optional.opencandy, pup.optional.vmntoolbar.a, win32/downloadsponsor.a, win32/downware.l |