Hallo cosinus,
Adwcleaner hat nur Kleinigkeiten gefunden: Code:
# AdwCleaner v3.018 - Bericht erstellt am 07/02/2014 um 11:38:41
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Gideon - HOME
# Gestartet von : C:\Users\Gideon\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\boost_interprocess
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Google Chrome v32.0.1700.107
[ Datei : C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2129 octets] - [29/12/2013 01:48:57]
AdwCleaner[R1].txt - [963 octets] - [06/01/2014 01:19:03]
AdwCleaner[R2].txt - [1090 octets] - [07/02/2014 11:36:58]
AdwCleaner[S0].txt - [2100 octets] - [29/12/2013 01:52:14]
AdwCleaner[S1].txt - [1023 octets] - [06/01/2014 01:20:50]
AdwCleaner[S2].txt - [1016 octets] - [07/02/2014 11:38:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1076 octets] ########## Und JRT hat überhapt nix gefunden: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows 8 x64
Ran by Gideon on 07.02.2014 at 11:46:09,61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.02.2014 at 11:52:24,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Frisches FRST Log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-02-2014
Ran by Gideon (administrator) on HOME on 07-02-2014 11:55:00
Running from C:\Users\Gideon\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\mcafee\AppStats\MfeASUM.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\mcsvchost\McSvHost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-22] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13519432 2013-04-09] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor)
HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-06-03] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2058586743-3979093847-619797469-1001\...\Run: [Spotify Web Helper] - C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1193176 2013-09-28] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKCU - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Chrome:
=======
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
CHR Extension: (Google Docs) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-25]
CHR Extension: (Google Drive) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-25]
CHR Extension: (YouTube) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-25]
CHR Extension: (Google-Suche) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-25]
CHR Extension: (SiteAdvisor) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-12-29]
CHR Extension: (AdBlock) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-25]
CHR Extension: (Google Wallet) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-25]
CHR Extension: (Google Mail) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-25]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-12-28]
==================== Services (Whitelisted) =================
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227968 2013-02-28] (Qualcomm Atheros Commnucations)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2013-04-22] (ELAN Microelectronics Corp.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-04-26] (Acer Incorporate)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [121616 2013-10-02] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178048 2013-11-28] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [334760 2012-12-21] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 MfeASUM; C:\Program Files\McAfee\AppStats\MfeASUM.exe [335216 2013-12-26] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025232 2013-12-11] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-12-05] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [184800 2013-12-05] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
S3 NOBU; No ImagePath
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation)
R3 AthrSdSrv; C:\Windows\system32\DRIVERS\athrsd.sys [43520 2013-03-12] (Qualcomm Atheros, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98744 2013-04-23] (Advanced Micro Devices)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-02-28] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-12-05] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-12-05] (McAfee, Inc.)
R1 MfeASKM; C:\Program Files\McAfee\AppStats\MfeASKM.sys [31408 2013-12-26] (McAfee, Inc.)
R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-12-05] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69344 2013-12-05] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-12-05] (McAfee, Inc.)
R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782616 2013-12-05] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [411944 2013-11-26] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96112 2013-11-26] (McAfee, Inc.)
R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-12-05] (McAfee, Inc.)
S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-21] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-07 11:55 - 2014-02-07 11:55 - 00016451 _____ () C:\Users\Gideon\Desktop\FRST.txt
2014-02-07 11:54 - 2014-02-07 11:54 - 02079744 _____ (Farbar) C:\Users\Gideon\Desktop\FRST64.exe
2014-02-07 11:54 - 2014-02-07 11:54 - 00000000 ____D () C:\Users\Gideon\Desktop\FRST-OlderVersion
2014-02-07 11:52 - 2014-02-07 11:52 - 00000613 _____ () C:\Users\Gideon\Desktop\JRT.txt
2014-02-07 11:46 - 2014-02-07 11:46 - 00000000 ____D () C:\Windows\ERUNT
2014-02-07 11:45 - 2014-02-07 11:45 - 01037530 _____ (Thisisu) C:\Users\Gideon\Downloads\JRT.exe
2014-02-07 11:45 - 2014-02-07 11:45 - 01037530 _____ (Thisisu) C:\Users\Gideon\Desktop\JRT.exe
2014-02-07 11:27 - 2014-02-07 11:27 - 01166132 _____ () C:\Users\Gideon\Desktop\adwcleaner.exe
2014-02-06 23:27 - 2014-02-06 23:27 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-02-05 13:34 - 2014-02-05 13:45 - 163606685 _____ () C:\Users\Gideon\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2014-02-05 07:44 - 2014-02-05 07:46 - 00000000 ____D () C:\Users\Gideon\AppData\Local\Adobe
2014-02-04 13:37 - 2014-02-04 13:38 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu (1).exe
2014-02-04 13:33 - 2014-02-04 13:33 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-02-04 13:32 - 2014-02-04 13:32 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu.exe
2014-02-03 13:05 - 2014-02-03 13:05 - 00000000 ___RD () C:\Users\Gideon\Documents\Notes
2014-02-01 19:07 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-02-01 09:11 - 2014-02-01 09:11 - 00777528 _____ () C:\Windows\Minidump\020114-44429-01.dmp
2014-02-01 09:10 - 2014-02-01 09:10 - 339248834 _____ () C:\Windows\MEMORY.DMP
2014-01-26 13:44 - 2014-02-06 23:50 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-01-26 13:39 - 2014-02-06 23:50 - 00000000 ____D () C:\Users\Gideon\Desktop\mbar
2014-01-26 13:39 - 2014-02-06 23:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-01-26 13:36 - 2014-01-26 13:39 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Gideon\Desktop\mbar-1.07.0.1009.exe
2014-01-25 20:18 - 2014-01-25 20:19 - 02181948 _____ () C:\Users\Gideon\Downloads\LineApp.xlsm
2014-01-24 18:27 - 2014-01-24 18:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-01-23 21:58 - 2014-01-23 21:58 - 00000000 ____D () C:\Users\Gideon\PicStream
2014-01-23 21:57 - 2014-01-23 22:42 - 00000000 ____D () C:\Users\Gideon\AppData\Local\clear.fi
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Public\OEM
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\Documents\clear.fi
2014-01-22 14:18 - 2014-01-22 14:18 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-20 14:59 - 2014-01-20 14:59 - 00000000 ___HD () C:\Users\Gideon\Desktop\.updtmp
2014-01-19 16:11 - 2014-01-19 16:11 - 00000000 ____D () C:\Users\Gideon\AppData\Local\fabi.me
2014-01-19 16:10 - 2013-09-24 11:14 - 00179200 _____ (fabi.me) C:\Users\Gideon\Desktop\SpeedAutoClicker.exe
2014-01-19 16:09 - 2014-01-19 16:09 - 00094899 _____ () C:\Users\Gideon\Downloads\SpeedAutoClicker.zip
2014-01-15 16:56 - 2013-12-07 07:37 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-01-15 16:56 - 2013-12-07 07:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 16:56 - 2013-12-07 06:15 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-01-15 16:56 - 2013-12-07 06:15 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 16:56 - 2013-10-31 06:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2014-01-15 16:56 - 2013-10-31 06:56 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2014-01-15 16:56 - 2013-10-31 05:01 - 00550400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2014-01-15 16:56 - 2013-10-31 04:42 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2014-01-15 16:56 - 2013-10-28 06:50 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-01-15 16:56 - 2013-10-28 05:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-01-15 16:56 - 2013-10-13 21:49 - 00100696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2014-01-15 16:56 - 2013-08-27 06:21 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-01-15 16:56 - 2013-08-27 06:19 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-01-15 16:56 - 2013-08-26 23:29 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-01-15 16:56 - 2013-08-26 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-01-10 21:53 - 2014-01-19 13:48 - 00004535 _____ () C:\Users\Gideon\Desktop\Neues Textdokument (2).txt
2014-01-10 20:55 - 2014-01-10 20:56 - 00000178 _____ () C:\Users\Gideon\Desktop\Logfiles Combofix.zip.zip
2014-01-10 20:41 - 2014-02-07 11:40 - 00012986 _____ () C:\Windows\PFRO.log
2014-01-10 20:35 - 2014-01-10 20:35 - 00131944 _____ () C:\ComboFix.txt
2014-01-10 20:22 - 2014-01-10 20:35 - 00000000 ____D () C:\Qoobox
2014-01-10 20:22 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-01-10 20:22 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-01-10 20:22 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-01-10 20:21 - 2014-01-10 20:32 - 00000000 ____D () C:\Windows\erdnt
2014-01-09 16:06 - 2014-01-09 16:08 - 00023994 _____ () C:\Users\Gideon\Downloads\Addition.txt
2014-01-09 16:02 - 2014-02-07 11:54 - 00000000 ____D () C:\FRST
2014-01-09 16:02 - 2014-02-06 16:22 - 00031562 _____ () C:\Users\Gideon\Downloads\FRST.txt
2014-01-09 16:00 - 2014-01-09 16:00 - 01931770 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64.exe
2014-01-08 18:25 - 2014-01-08 18:26 - 00001211 _____ () C:\Users\Gideon\Downloads\SHK.bat
==================== One Month Modified Files and Folders =======
2014-02-07 11:55 - 2014-02-07 11:55 - 00016451 _____ () C:\Users\Gideon\Desktop\FRST.txt
2014-02-07 11:55 - 2014-01-09 16:02 - 00000000 ____D () C:\FRST
2014-02-07 11:54 - 2014-02-07 11:54 - 02079744 _____ (Farbar) C:\Users\Gideon\Desktop\FRST64.exe
2014-02-07 11:54 - 2014-02-07 11:54 - 00000000 ____D () C:\Users\Gideon\Desktop\FRST-OlderVersion
2014-02-07 11:52 - 2014-02-07 11:52 - 00000613 _____ () C:\Users\Gideon\Desktop\JRT.txt
2014-02-07 11:46 - 2014-02-07 11:46 - 00000000 ____D () C:\Windows\ERUNT
2014-02-07 11:45 - 2014-02-07 11:45 - 01037530 _____ (Thisisu) C:\Users\Gideon\Downloads\JRT.exe
2014-02-07 11:45 - 2014-02-07 11:45 - 01037530 _____ (Thisisu) C:\Users\Gideon\Desktop\JRT.exe
2014-02-07 11:45 - 2013-09-29 05:32 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-02-07 11:45 - 2013-09-29 05:32 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-02-07 11:45 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-07 11:41 - 2014-01-06 21:14 - 01613883 _____ () C:\Windows\WindowsUpdate.log
2014-02-07 11:41 - 2013-12-25 20:26 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-07 11:40 - 2014-01-10 20:41 - 00012986 _____ () C:\Windows\PFRO.log
2014-02-07 11:40 - 2013-08-02 16:58 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-02-07 11:40 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-07 11:40 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-02-07 11:38 - 2013-12-29 01:48 - 00000000 ____D () C:\AdwCleaner
2014-02-07 11:37 - 2013-12-25 20:26 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-07 11:27 - 2014-02-07 11:27 - 01166132 _____ () C:\Users\Gideon\Desktop\adwcleaner.exe
2014-02-07 11:21 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru
2014-02-06 23:50 - 2014-01-26 13:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-02-06 23:50 - 2014-01-26 13:39 - 00000000 ____D () C:\Users\Gideon\Desktop\mbar
2014-02-06 23:27 - 2014-02-06 23:27 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-02-06 23:26 - 2014-01-26 13:39 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-02-06 16:22 - 2014-01-09 16:02 - 00031562 _____ () C:\Users\Gideon\Downloads\FRST.txt
2014-02-06 13:10 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-05 15:15 - 2013-12-25 20:13 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2058586743-3979093847-619797469-1001
2014-02-05 13:45 - 2014-02-05 13:34 - 163606685 _____ () C:\Users\Gideon\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2014-02-05 07:46 - 2014-02-05 07:44 - 00000000 ____D () C:\Users\Gideon\AppData\Local\Adobe
2014-02-04 13:41 - 2013-12-25 20:29 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-04 13:38 - 2014-02-04 13:37 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu (1).exe
2014-02-04 13:33 - 2014-02-04 13:33 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-02-04 13:32 - 2014-02-04 13:32 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu.exe
2014-02-04 08:09 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-02-03 13:05 - 2014-02-03 13:05 - 00000000 ___RD () C:\Users\Gideon\Documents\Notes
2014-02-01 20:32 - 2013-12-26 00:56 - 00000000 ____D () C:\Users\Gideon\AppData\Roaming\.minecraft
2014-02-01 19:01 - 2013-08-02 16:58 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-02-01 19:01 - 2012-07-26 09:12 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-02-01 19:00 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-02-01 09:11 - 2014-02-01 09:11 - 00777528 _____ () C:\Windows\Minidump\020114-44429-01.dmp
2014-02-01 09:11 - 2014-01-05 12:30 - 00000000 ____D () C:\Windows\Minidump
2014-02-01 09:10 - 2014-02-01 09:10 - 339248834 _____ () C:\Windows\MEMORY.DMP
2014-01-30 22:10 - 2013-12-29 00:18 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-30 22:10 - 2013-12-29 00:18 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-26 13:39 - 2014-01-26 13:36 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Gideon\Desktop\mbar-1.07.0.1009.exe
2014-01-25 20:19 - 2014-01-25 20:18 - 02181948 _____ () C:\Users\Gideon\Downloads\LineApp.xlsm
2014-01-24 19:14 - 2013-12-29 00:46 - 00000000 ____D () C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-24 19:11 - 2013-09-28 20:26 - 00000000 ____D () C:\ProgramData\Symantec
2014-01-24 19:01 - 2013-09-28 20:25 - 00000000 ____D () C:\Program Files (x86)\Norton Online Backup ARA
2014-01-24 18:27 - 2014-01-24 18:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-01-23 22:42 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\AppData\Local\clear.fi
2014-01-23 21:58 - 2014-01-23 21:58 - 00000000 ____D () C:\Users\Gideon\PicStream
2014-01-23 21:58 - 2013-12-25 20:05 - 00000000 ____D () C:\Users\Gideon
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Public\OEM
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\Documents\clear.fi
2014-01-22 14:18 - 2014-01-22 14:18 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-22 14:18 - 2014-01-06 18:02 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-20 14:59 - 2014-01-20 14:59 - 00000000 ___HD () C:\Users\Gideon\Desktop\.updtmp
2014-01-19 16:11 - 2014-01-19 16:11 - 00000000 ____D () C:\Users\Gideon\AppData\Local\fabi.me
2014-01-19 16:09 - 2014-01-19 16:09 - 00094899 _____ () C:\Users\Gideon\Downloads\SpeedAutoClicker.zip
2014-01-19 13:48 - 2014-01-10 21:53 - 00004535 _____ () C:\Users\Gideon\Desktop\Neues Textdokument (2).txt
2014-01-18 19:17 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache
2014-01-18 17:54 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\WinStore
2014-01-15 17:50 - 2013-12-27 13:23 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 17:47 - 2013-12-27 13:23 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-10 20:56 - 2014-01-10 20:55 - 00000178 _____ () C:\Users\Gideon\Desktop\Logfiles Combofix.zip.zip
2014-01-10 20:42 - 2014-01-05 12:30 - 00283416 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-10 20:35 - 2014-01-10 20:35 - 00131944 _____ () C:\ComboFix.txt
2014-01-10 20:35 - 2014-01-10 20:22 - 00000000 ____D () C:\Qoobox
2014-01-10 20:32 - 2014-01-10 20:21 - 00000000 ____D () C:\Windows\erdnt
2014-01-10 20:31 - 2012-07-26 06:26 - 00000215 _____ () C:\Windows\system.ini
2014-01-09 16:08 - 2014-01-09 16:06 - 00023994 _____ () C:\Users\Gideon\Downloads\Addition.txt
2014-01-09 16:00 - 2014-01-09 16:00 - 01931770 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64.exe
2014-01-08 18:26 - 2014-01-08 18:25 - 00001211 _____ () C:\Users\Gideon\Downloads\SHK.bat
Some content of TEMP:
====================
C:\Users\Gideon\AppData\Local\temp\Quarantine.exe
C:\Users\Gideon\AppData\Local\temp\SCC.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-27 11:53
==================== End Of Log ============================ --- --- ---
Sieht gut aus, oder? |