Blumenbeet | 10.08.2013 16:18 | Code:
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok ich war während des scans nicht am pc. als ich wiederkam, hat er neu gestartet (?) habe nur obiges log gefunden. da ich jetzt nicht wusste, ob alles ordnungsgemäß verlaufen ist (habe nicht finish gedrückt,...), habe ich nochmal gescant:
log folgt, scant noch
so auch der 2. scan wurde irgendwie abgebrochen. der bildschirm wurde schwarz und es kamen etliche meldungen (zb windows destroy,...) dann hat der pc einen neustart alleine vollzogen. ich konnte wieder nicht finishen. auch der log ist nicht vorhanden, nur jener, der schon oben gepostet wurde. leider.
avira habe ich wieder aktiviert und firewall auch.
werde jetzt den 2. schritt ausführen.
pc ist immer noch gleich langsam.
was mache ich mit den verknüpfungen/downloads auf meinem desktop? Code:
Results of screen317's Security Check version 0.99.71
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10 ``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
SpywareBlaster 5.0
Secunia PSI (3.0.0.7009)
Malwarebytes Anti-Malware Version 1.75.0.1300
Adobe Flash Player 11.8.800.94
Adobe Reader XI
Mozilla Firefox (23.0) ````````Process Check: objlist.exe by Laurent````````
WinPatrol winpatrol.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
BillP Studios WinPatrol WinPatrol.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-08-2013
Ran by biba (administrator) on 10-08-2013 17:15:44
Running from C:\Users\biba\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
() C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(ASUS) C:\Windows\AsScrPro.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
() C:\Users\biba\Downloads\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Farbar) C:\Users\biba\Downloads\FRST64(4).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [16336416 2009-08-15] (NVIDIA Corporation)
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323072 2009-08-12] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2184520 2009-07-27] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-03-18] (CANON INC.)
HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [423144 2013-04-27] (BillP Studios)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-20] (ASUS)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-02] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKU\Gast\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-04-05] (Apple Inc.)
HKU\Gast\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-04-05] (Apple Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\biba\AppData\Roaming\Mozilla\Firefox\Profiles\ey1g4ovd.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\biba\AppData\Roaming\Mozilla\Extensions\{SbX-136198-9783706830751-stu10}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-02] (Avira Operations GmbH & Co. KG)
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia)
==================== Drivers (Whitelisted) ====================
R2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
R2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-01] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-04-18] (Secunia)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-05-20] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U3 tmlwf;
U3 tmwfp;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-10 17:12 - 2013-08-10 17:13 - 00891098 _____ C:\Users\biba\Downloads\SecurityCheck.exe
2013-08-10 15:50 - 2013-08-10 15:50 - 02347384 _____ (ESET) C:\Users\biba\Downloads\esetsmartinstaller_enu(1).exe
2013-08-10 12:40 - 2013-08-10 12:40 - 02347384 _____ (ESET) C:\Users\biba\Downloads\esetsmartinstaller_enu.exe
2013-08-10 11:09 - 2013-08-10 17:05 - 00000168 _____ C:\Windows\setupact.log
2013-08-10 11:09 - 2013-08-10 11:09 - 00000000 _____ C:\Windows\setuperr.log
2013-08-10 11:06 - 2013-08-10 11:06 - 04429440 _____ (Piriform Ltd) C:\Users\biba\Downloads\ccsetup404.exe
2013-08-10 10:55 - 2013-08-10 10:55 - 01790633 _____ (Farbar) C:\Users\biba\Downloads\FRST64(3).exe
2013-08-10 10:51 - 2013-08-10 10:51 - 01790633 _____ (Farbar) C:\Users\biba\Downloads\FRST64(2).exe
2013-08-10 10:47 - 2013-08-10 10:47 - 01790633 _____ (Farbar) C:\Users\biba\Downloads\FRST64(1).exe
2013-08-10 10:34 - 2013-08-10 10:34 - 00958418 _____ (Oleg N. Scherbakov) C:\Users\biba\Desktop\JRT.exe
2013-08-10 10:21 - 2013-08-10 10:21 - 00001209 _____ C:\AdwCleaner[S1].txt
2013-08-10 10:20 - 2013-08-10 10:20 - 00666633 _____ C:\Users\biba\Desktop\adwcleaner(1).exe
2013-08-10 10:19 - 2013-08-10 10:20 - 00666633 _____ C:\Users\biba\Downloads\adwcleaner.exe
2013-08-09 12:09 - 2013-08-09 12:09 - 00025053 _____ C:\ComboFix.txt
2013-08-09 11:59 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-09 11:59 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-09 11:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-09 11:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-09 11:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-09 11:59 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-09 11:59 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-09 11:59 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-09 11:58 - 2013-08-09 12:09 - 00000000 ____D C:\Qoobox
2013-08-09 11:58 - 2013-08-09 12:07 - 00000000 ____D C:\Windows\erdnt
2013-08-09 11:55 - 2013-08-09 11:56 - 05100713 ____R (Swearware) C:\Users\biba\Desktop\ComboFix.exe
2013-08-09 09:27 - 2013-08-09 09:28 - 00014052 _____ C:\Users\biba\Downloads\Addition.txt
2013-08-09 09:27 - 2013-08-09 09:27 - 00000000 ____D C:\FRST
2013-08-09 09:25 - 2013-08-09 09:26 - 01790169 _____ (Farbar) C:\Users\biba\Downloads\FRST64.exe
2013-07-12 22:58 - 2013-07-12 23:00 - 00000000 ____D C:\Windows\system32\MRT
2013-07-11 12:12 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-11 12:12 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-11 12:12 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-11 12:12 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-11 12:12 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-11 12:12 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-11 12:12 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-11 12:12 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-11 12:12 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-11 12:12 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-11 12:12 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-11 12:12 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-11 12:12 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-11 12:12 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 12:12 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 12:12 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-11 12:12 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 12:12 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-11 12:12 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-11 12:12 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-11 12:12 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 12:12 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 12:00 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 12:00 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 12:00 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 12:00 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 12:00 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-11 11:59 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 11:59 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
==================== One Month Modified Files and Folders =======
2013-08-10 17:15 - 2013-08-10 17:15 - 01790633 _____ (Farbar) C:\Users\biba\Downloads\FRST64(4).exe
2013-08-10 17:13 - 2013-08-10 17:12 - 00891098 _____ C:\Users\biba\Downloads\SecurityCheck.exe
2013-08-10 17:10 - 2013-07-02 10:49 - 01454881 _____ C:\Windows\WindowsUpdate.log
2013-08-10 17:06 - 2013-06-14 09:44 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl
2013-08-10 17:06 - 2012-05-13 11:48 - 00003094 _____ C:\Windows\System32\Tasks\WC3
2013-08-10 17:05 - 2013-08-10 11:09 - 00000168 _____ C:\Windows\setupact.log
2013-08-10 17:05 - 2011-11-30 09:19 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-10 17:05 - 2011-11-24 07:05 - 00000080 _____ C:\Windows\system32\Defrag.ini
2013-08-10 17:05 - 2011-11-24 07:05 - 00000020 _____ C:\Windows\system32\BootTime.ini
2013-08-10 17:05 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-10 16:41 - 2013-06-01 14:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-10 16:22 - 2011-11-30 09:19 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-10 15:50 - 2013-08-10 15:50 - 02347384 _____ (ESET) C:\Users\biba\Downloads\esetsmartinstaller_enu(1).exe
2013-08-10 14:08 - 2009-07-14 06:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-10 14:08 - 2009-07-14 06:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-10 12:40 - 2013-08-10 12:40 - 02347384 _____ (ESET) C:\Users\biba\Downloads\esetsmartinstaller_enu.exe
2013-08-10 11:09 - 2013-08-10 11:09 - 00000000 _____ C:\Windows\setuperr.log
2013-08-10 11:08 - 2011-11-24 09:50 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-08-10 11:07 - 2012-12-07 15:01 - 00000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-10 11:07 - 2012-12-07 15:01 - 00000000 ____D C:\Program Files\CCleaner
2013-08-10 11:06 - 2013-08-10 11:06 - 04429440 _____ (Piriform Ltd) C:\Users\biba\Downloads\ccsetup404.exe
2013-08-10 10:55 - 2013-08-10 10:55 - 01790633 _____ (Farbar) C:\Users\biba\Downloads\FRST64(3).exe
2013-08-10 10:51 - 2013-08-10 10:51 - 01790633 _____ (Farbar) C:\Users\biba\Downloads\FRST64(2).exe
2013-08-10 10:47 - 2013-08-10 10:47 - 01790633 _____ (Farbar) C:\Users\biba\Downloads\FRST64(1).exe
2013-08-10 10:36 - 2013-06-01 14:31 - 00000000 ____D C:\Windows\ERUNT
2013-08-10 10:34 - 2013-08-10 10:34 - 00958418 _____ (Oleg N. Scherbakov) C:\Users\biba\Desktop\JRT.exe
2013-08-10 10:21 - 2013-08-10 10:21 - 00001209 _____ C:\AdwCleaner[S1].txt
2013-08-10 10:20 - 2013-08-10 10:20 - 00666633 _____ C:\Users\biba\Desktop\adwcleaner(1).exe
2013-08-10 10:20 - 2013-08-10 10:19 - 00666633 _____ C:\Users\biba\Downloads\adwcleaner.exe
2013-08-09 12:09 - 2013-08-09 12:09 - 00025053 _____ C:\ComboFix.txt
2013-08-09 12:09 - 2013-08-09 11:58 - 00000000 ____D C:\Qoobox
2013-08-09 12:07 - 2013-08-09 11:58 - 00000000 ____D C:\Windows\erdnt
2013-08-09 12:07 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-09 11:56 - 2013-08-09 11:55 - 05100713 ____R (Swearware) C:\Users\biba\Desktop\ComboFix.exe
2013-08-09 09:28 - 2013-08-09 09:27 - 00014052 _____ C:\Users\biba\Downloads\Addition.txt
2013-08-09 09:27 - 2013-08-09 09:27 - 00000000 ____D C:\FRST
2013-08-09 09:26 - 2013-08-09 09:25 - 01790169 _____ (Farbar) C:\Users\biba\Downloads\FRST64.exe
2013-08-09 08:58 - 2013-05-09 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-08 14:03 - 2013-05-17 16:00 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-08 14:02 - 2013-06-27 22:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-08 08:40 - 2013-06-01 14:50 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-08-02 17:50 - 2012-12-30 10:29 - 00000000 ____D C:\Users\biba\Desktop\Schreiben
2013-07-12 23:00 - 2013-07-12 22:58 - 00000000 ____D C:\Windows\system32\MRT
2013-07-12 20:17 - 2011-11-30 09:19 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-12 20:17 - 2011-11-30 09:19 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-11 13:13 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther
2013-07-11 12:29 - 2009-07-14 06:45 - 00311104 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 12:26 - 2009-07-14 09:45 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 12:26 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-11 12:26 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-11 12:23 - 2009-08-04 11:51 - 00654400 _____ C:\Windows\system32\perfh007.dat
2013-07-11 12:23 - 2009-08-04 11:51 - 00130240 _____ C:\Windows\system32\perfc007.dat
2013-07-11 12:23 - 2009-07-14 07:13 - 01520734 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-11 12:02 - 2011-11-24 00:00 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-11 11:58 - 2013-06-01 14:47 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-11 11:58 - 2013-02-15 09:19 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-11 11:58 - 2013-02-15 09:19 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-02 09:24
==================== End Of Log ============================ --- --- ---
--- --- --- |