Sorry, dass es was lange gedauert hat aber ich hab jetzt alles. Zuerst noch danke für die Hilfe!
Ich weiß, dass auch sie sehr beschäftigt sind und schätze es deshalb umso mehr mir wegen meines Problemes zuhelfen. Bringen wir die Sache zu Ende:
Malware Antivirus Bericht:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 21.04.2014 15:36:27, SYSTEM, LAPTOP, Protection, Malware Protection, Starting,
Protection, 21.04.2014 15:36:27, SYSTEM, LAPTOP, Protection, Malware Protection, Started,
Protection, 21.04.2014 15:36:27, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Starting,
Protection, 21.04.2014 15:36:28, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Started,
Update, 21.04.2014 15:37:30, SYSTEM, LAPTOP, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 21.04.2014 15:40:26, SYSTEM, LAPTOP, Manual, Malware Database, 2014.3.4.9, 2014.4.21.4,
Protection, 21.04.2014 15:40:29, SYSTEM, LAPTOP, Protection, Refresh, Starting,
Protection, 21.04.2014 15:40:29, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Stopping,
Protection, 21.04.2014 15:40:29, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Stopped,
Protection, 21.04.2014 15:40:34, SYSTEM, LAPTOP, Protection, Refresh, Success,
Protection, 21.04.2014 15:40:34, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Starting,
Protection, 21.04.2014 15:40:34, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Started,
Protection, 21.04.2014 16:05:28, SYSTEM, LAPTOP, Protection, Malware Protection, Starting,
Protection, 21.04.2014 16:05:28, SYSTEM, LAPTOP, Protection, Malware Protection, Started,
Protection, 21.04.2014 16:05:28, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Starting,
Protection, 21.04.2014 16:05:28, SYSTEM, LAPTOP, Protection, Malicious Website Protection, Started,
(end)
Nun der adw-Cleaner Bericht:AdwCleaner Logfile:
Code:
# AdwCleaner v3.102 - Bericht erstellt am 21/04/2014 um 18:05:22
# Aktualisiert 21/04/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Krauss - LAPTOP
Jetzt der JRT-Bericht:
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Krauss on 21.04.2014 at 18:14:02,14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.04.2014 at 18:22:48,13
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# Gestartet von : C:\Users\Krauss\Downloads\AdwCleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\WINDOWS\SysWOW64\AI_RecycleBin
Ordner Gelöscht : C:\Users\Administrator\Documents\Youcam
Ordner Gelöscht : C:\Users\Krauss\.android
Ordner Gelöscht : C:\Users\Krauss\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\Krauss\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Krauss\Documents\Youcam
Datei Gelöscht : C:\Users\Krauss\daemonprocess.txt
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16384
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Krauss\AppData\Roaming\Mozilla\Firefox\Profiles\kx8o5kwo.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [1142 octets] - [21/04/2014 17:51:24]
AdwCleaner[S0].txt - [1075 octets] - [21/04/2014 18:05:22]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1135 octets] ##########
--- --- ---
Und zu guter letzt noch der gewünschte frische FRST-Log
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-04-2014 01
Ran by Krauss (administrator) on LAPTOP on 21-04-2014 18:34:55
Running from C:\Users\Krauss\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
() C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\MyWiMax.exe
() C:\Program Files (x86)\PHotkey\POSD.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Krauss\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [11577216 2012-08-27] (Motorola Solutions, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-30] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-17] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917176 2012-09-05] (Synaptics Incorporated)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-20] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [258576 2012-07-30] (CyberLink Corp.)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2014-04-20] (Kaspersky Lab ZAO)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
SearchScopes: HKCU - {9A75080D-DABD-46BD-B1EA-4D8E6FE61A1D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Krauss\AppData\Roaming\Mozilla\Firefox\Profiles\kx8o5kwo.default
FF Homepage: https://www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2012-09-22]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2012-09-22]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2012-09-22]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2012-09-22]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2012-09-22]
==================== Services (Whitelisted) =================
R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-18] ()
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2014-04-20] (Kaspersky Lab ZAO)
R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-13] (CyberLink)
R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-13] (CyberLink)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [156672 2011-10-13] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [15440 2012-07-26] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [121728 2012-08-27] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-04-21] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2014-04-21] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625760 2014-04-21] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2014-04-21] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-04-21] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2014-04-21] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2014-04-21] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2014-04-21] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4293672 2012-09-13] (Intel Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-21 18:28 - 2014-04-21 18:31 - 02163712 _____ (Farbar) C:\Users\Krauss\Downloads\FRST64(1).exe
2014-04-21 18:22 - 2014-04-21 18:22 - 00000613 _____ () C:\Users\Krauss\Desktop\JRT.txt
2014-04-21 18:13 - 2014-04-21 18:13 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-21 18:11 - 2014-04-21 18:13 - 01016261 _____ (Thisisu) C:\Users\Krauss\Downloads\JRT.exe
2014-04-21 18:09 - 2014-04-21 18:09 - 00000000 ____D () C:\Users\Krauss\Documents\Youcam
2014-04-21 18:08 - 2014-04-21 18:08 - 00000117 _____ () C:\WINDOWS\system32\netcfg-153937.txt
2014-04-21 18:05 - 2014-04-21 18:05 - 00000117 _____ () C:\WINDOWS\system32\netcfg-7274593.txt
2014-04-21 17:50 - 2014-04-21 18:05 - 00000000 ____D () C:\AdwCleaner
2014-04-21 17:48 - 2014-04-21 17:49 - 01322687 _____ () C:\Users\Krauss\Downloads\AdwCleaner.exe
2014-04-21 17:48 - 2014-04-21 17:48 - 00001610 _____ () C:\Users\Krauss\Desktop\mbam.txt
2014-04-21 15:36 - 2014-04-21 18:08 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-21 15:36 - 2014-04-21 15:36 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-21 15:36 - 2014-04-21 15:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-21 15:36 - 2014-04-21 15:36 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-21 15:36 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-21 15:36 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-04-21 15:36 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-21 15:31 - 2014-04-21 15:34 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Krauss\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-21 15:26 - 2014-04-21 15:26 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-21 15:25 - 2014-04-21 15:26 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Krauss\Downloads\revosetup95.exe
2014-04-21 15:12 - 2014-04-21 15:12 - 00001348 _____ () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013.lnk
2014-04-21 15:12 - 2014-04-21 15:12 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\LolClient
2014-04-21 14:30 - 2014-04-21 14:30 - 00001613 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-04-21 14:30 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2014-04-21 14:30 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2014-04-21 14:30 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2014-04-21 14:30 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2014-04-21 14:30 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2014-04-21 13:52 - 2014-04-21 13:52 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-04-21 13:51 - 2014-04-21 14:30 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Riot Games
2014-04-21 13:48 - 2014-04-21 13:51 - 34888568 _____ (Riot Games) C:\Users\Krauss\Downloads\LeagueofLegends_EUW_Installer_06_12_13(2).exe
2014-04-21 12:44 - 2014-04-21 12:44 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Macromedia
2014-04-21 12:03 - 2014-04-21 18:33 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-04-21 12:03 - 2014-04-21 12:03 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-04-21 12:03 - 2014-04-21 12:03 - 00000000 ____D () C:\ProgramData\McAfee
2014-04-21 12:01 - 2014-04-21 12:04 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Adobe
2014-04-21 11:54 - 2014-04-21 11:54 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Mozilla
2014-04-21 11:54 - 2014-04-21 11:54 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Mozilla
2014-04-21 11:53 - 2014-04-21 11:53 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-21 11:53 - 2014-04-21 11:53 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-21 11:53 - 2014-04-21 11:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-21 11:53 - 2014-04-21 11:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-21 11:50 - 2014-04-21 11:50 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Macromedia
2014-04-21 01:01 - 2014-04-21 01:01 - 00000117 _____ () C:\WINDOWS\system32\netcfg-6611421.txt
2014-04-21 01:01 - 2014-04-21 01:01 - 00000117 _____ () C:\WINDOWS\system32\netcfg-6611296.txt
2014-04-21 00:25 - 2014-04-21 15:59 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3863069283-2814587192-1313183951-1001
2014-04-21 00:20 - 2014-04-21 00:20 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Power2Go8
2014-04-21 00:20 - 2014-04-21 00:20 - 00000000 ____D () C:\Users\Krauss\AppData\Local\CyberLink
2014-04-21 00:19 - 2014-04-21 00:19 - 00001446 _____ () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ___RD () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ___RD () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ____D () C:\WINDOWS\System32\Tasks\WPD
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Adobe
2014-04-21 00:19 - 2012-08-11 06:24 - 00001217 _____ () C:\Users\Default\Desktop\ALDI Foto.lnk
2014-04-21 00:19 - 2012-08-11 06:22 - 00001275 _____ () C:\Users\Default\Desktop\Medion Services.lnk
2014-04-21 00:19 - 2012-08-05 14:12 - 00001809 _____ () C:\Users\Default\Desktop\ALDI Talk.lnk
2014-04-21 00:19 - 2012-08-05 14:11 - 00001153 _____ () C:\Users\Default\Desktop\ALDI Süd Reisen.lnk
2014-04-21 00:19 - 2012-08-05 14:11 - 00001025 _____ () C:\Users\Default\Desktop\ALDI Süd Startseite.lnk
2014-04-21 00:19 - 2012-08-05 14:10 - 00001895 _____ () C:\Users\Default\Desktop\ALDI Süd Blumen Service.lnk
2014-04-21 00:18 - 2014-04-21 00:19 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Packages
2014-04-21 00:18 - 2014-04-21 00:18 - 00000020 ___SH () C:\Users\Krauss\ntuser.ini
2014-04-21 00:18 - 2014-04-21 00:18 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Intel
2014-04-21 00:18 - 2014-04-21 00:18 - 00000000 ____D () C:\Users\Krauss\AppData\Local\VirtualStore
2014-04-21 00:17 - 2014-04-21 18:23 - 01157095 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-21 00:17 - 2014-04-21 00:17 - 00000117 _____ () C:\WINDOWS\system32\netcfg-4001468.txt
2014-04-21 00:17 - 2014-04-21 00:17 - 00000117 _____ () C:\WINDOWS\system32\netcfg-4000906.txt
2014-04-21 00:15 - 2014-04-21 00:16 - 00000117 _____ () C:\WINDOWS\system32\netcfg-3903609.txt
2014-04-21 00:15 - 2014-04-21 00:15 - 00000117 _____ () C:\WINDOWS\system32\netcfg-3903390.txt
2014-04-21 00:04 - 2014-04-21 00:35 - 00000000 ____D () C:\Windows.old
2014-04-21 00:03 - 2014-04-21 00:03 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-04-20 23:45 - 2014-04-20 23:45 - 00000000 ____D () C:\$WINDOWS.~BT
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-218984.txt
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-218906.txt
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-217812.txt
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-211984.txt
2014-04-20 23:12 - 2014-04-21 18:05 - 00000000 ____D () C:\Users\Krauss
2014-04-20 23:12 - 2014-04-20 23:14 - 00017148 _____ () C:\WINDOWS\diagwrn.xml
2014-04-20 23:12 - 2014-04-20 23:14 - 00017148 _____ () C:\WINDOWS\diagerr.xml
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Vorlagen
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Startmenü
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Netzwerkumgebung
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Lokale Einstellungen
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Eigene Dateien
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Druckumgebung
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Documents\Eigene Musik
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Documents\Eigene Bilder
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\AppData\Local\Verlauf
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\AppData\Local\Anwendungsdaten
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Anwendungsdaten
2014-04-20 23:12 - 2012-07-26 10:13 - 00000000 ___RD () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-04-20 23:12 - 2012-07-26 10:13 - 00000000 ___RD () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-20 23:12 - 2012-07-26 10:13 - 00000000 ___RD () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-04-20 23:12 - 2012-07-26 10:13 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-04-20 23:06 - 2014-04-20 23:06 - 00002306 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3863069283-2814587192-1313183951-500
2014-04-20 23:06 - 2014-04-20 23:06 - 00001139 _____ () C:\WINDOWS\system32\netcfg-107234.txt
2014-04-20 23:06 - 2014-04-20 23:06 - 00000109 _____ () C:\WINDOWS\system32\netcfg-80843.txt
2014-04-20 17:19 - 2014-04-21 00:29 - 00000000 ___HD () C:\$SysReset
2014-04-18 19:34 - 2014-04-21 18:34 - 00013884 _____ () C:\Users\Krauss\Downloads\FRST.txt
2014-04-18 19:34 - 2014-04-18 19:35 - 00026955 _____ () C:\Users\Krauss\Downloads\Addition.txt
2014-04-18 19:33 - 2014-04-21 18:34 - 00000000 ____D () C:\FRST
2014-04-18 19:30 - 2014-04-18 19:32 - 02158592 _____ (Farbar) C:\Users\Krauss\Downloads\FRST64.exe
2014-04-18 19:29 - 2014-04-18 19:29 - 01146880 _____ (Farbar) C:\Users\Krauss\Downloads\FRST.exe
==================== One Month Modified Files and Folders =======
2014-04-21 18:35 - 2014-04-18 19:34 - 00013884 _____ () C:\Users\Krauss\Downloads\FRST.txt
2014-04-21 18:34 - 2014-04-18 19:33 - 00000000 ____D () C:\FRST
2014-04-21 18:33 - 2014-04-21 12:03 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-04-21 18:33 - 2014-04-21 00:17 - 01157095 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-21 18:31 - 2014-04-21 18:28 - 02163712 _____ (Farbar) C:\Users\Krauss\Downloads\FRST64(1).exe
2014-04-21 18:22 - 2014-04-21 18:22 - 00000613 _____ () C:\Users\Krauss\Desktop\JRT.txt
2014-04-21 18:13 - 2014-04-21 18:13 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-21 18:13 - 2014-04-21 18:11 - 01016261 _____ (Thisisu) C:\Users\Krauss\Downloads\JRT.exe
2014-04-21 18:13 - 2012-09-21 16:58 - 00754172 _____ () C:\WINDOWS\system32\perfh007.dat
2014-04-21 18:13 - 2012-09-21 16:58 - 00156362 _____ () C:\WINDOWS\system32\perfc007.dat
2014-04-21 18:13 - 2012-07-26 09:28 - 01748838 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-21 18:10 - 2012-09-22 06:42 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-04-21 18:10 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2014-04-21 18:09 - 2014-04-21 18:09 - 00000000 ____D () C:\Users\Krauss\Documents\Youcam
2014-04-21 18:08 - 2014-04-21 18:08 - 00000117 _____ () C:\WINDOWS\system32\netcfg-153937.txt
2014-04-21 18:08 - 2014-04-21 15:36 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-21 18:06 - 2012-07-26 09:22 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-21 18:06 - 2012-07-26 07:26 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-04-21 18:05 - 2014-04-21 18:05 - 00000117 _____ () C:\WINDOWS\system32\netcfg-7274593.txt
2014-04-21 18:05 - 2014-04-21 17:50 - 00000000 ____D () C:\AdwCleaner
2014-04-21 18:05 - 2014-04-20 23:12 - 00000000 ____D () C:\Users\Krauss
2014-04-21 18:00 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-04-21 17:49 - 2014-04-21 17:48 - 01322687 _____ () C:\Users\Krauss\Downloads\AdwCleaner.exe
2014-04-21 17:48 - 2014-04-21 17:48 - 00001610 _____ () C:\Users\Krauss\Desktop\mbam.txt
2014-04-21 16:48 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\rescache
2014-04-21 16:46 - 2012-07-26 11:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-04-21 16:46 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\WinStore
2014-04-21 16:46 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-04-21 16:46 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-04-21 16:46 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-04-21 16:46 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-04-21 16:46 - 2012-07-26 07:37 - 00000000 ____D () C:\WINDOWS\servicing
2014-04-21 16:45 - 2012-07-26 10:12 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-04-21 16:45 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
2014-04-21 16:45 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\SysWOW64\Com
2014-04-21 16:45 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\migwiz
2014-04-21 16:45 - 2012-07-26 07:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\oobe
2014-04-21 16:45 - 2012-07-26 07:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism
2014-04-21 16:45 - 2012-07-26 07:38 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2014-04-21 16:45 - 2012-07-26 07:38 - 00000000 ____D () C:\WINDOWS\system32\oobe
2014-04-21 16:45 - 2012-07-26 07:38 - 00000000 ____D () C:\WINDOWS\system32\Dism
2014-04-21 16:43 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\SystemResetPlatform
2014-04-21 16:43 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\Com
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\SysWOW64\winrm
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\SysWOW64\slmgr
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\system32\winrm
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\system32\slmgr
2014-04-21 16:40 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\en-GB
2014-04-21 16:40 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI
2014-04-21 16:40 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\SysWOW64\en-GB
2014-04-21 16:40 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\en-GB
2014-04-21 16:40 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-04-21 16:40 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\System
2014-04-21 16:38 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\system32\WCN
2014-04-21 16:38 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\MUI
2014-04-21 16:37 - 2012-07-26 11:43 - 00000000 ____D () C:\WINDOWS\system32\Printing_Admin_Scripts
2014-04-21 16:33 - 2012-09-21 16:48 - 00000000 ____D () C:\WINDOWS\SysWOW64\XPSViewer
2014-04-21 16:20 - 2012-09-21 18:30 - 00000000 ___DC () C:\WINDOWS\Panther
2014-04-21 16:04 - 2012-09-21 17:30 - 00002046 _____ () C:\WINDOWS\PFRO.log
2014-04-21 16:03 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\addins
2014-04-21 15:59 - 2014-04-21 00:25 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3863069283-2814587192-1313183951-1001
2014-04-21 15:36 - 2014-04-21 15:36 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-21 15:36 - 2014-04-21 15:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-21 15:36 - 2014-04-21 15:36 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-21 15:34 - 2014-04-21 15:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Krauss\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-21 15:26 - 2014-04-21 15:26 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-21 15:26 - 2014-04-21 15:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Krauss\Downloads\revosetup95.exe
2014-04-21 15:12 - 2014-04-21 15:12 - 00001348 _____ () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013.lnk
2014-04-21 15:12 - 2014-04-21 15:12 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\LolClient
2014-04-21 14:30 - 2014-04-21 14:30 - 00001613 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-04-21 14:30 - 2014-04-21 13:51 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Riot Games
2014-04-21 13:52 - 2014-04-21 13:52 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-04-21 13:51 - 2014-04-21 13:48 - 34888568 _____ (Riot Games) C:\Users\Krauss\Downloads\LeagueofLegends_EUW_Installer_06_12_13(2).exe
2014-04-21 12:44 - 2014-04-21 12:44 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Macromedia
2014-04-21 12:06 - 2012-09-22 05:23 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-21 12:05 - 2012-09-22 05:24 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2014-04-21 12:04 - 2014-04-21 12:01 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Adobe
2014-04-21 12:03 - 2014-04-21 12:03 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-04-21 12:03 - 2014-04-21 12:03 - 00000000 ____D () C:\ProgramData\McAfee
2014-04-21 12:03 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\restore
2014-04-21 11:54 - 2014-04-21 11:54 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Mozilla
2014-04-21 11:54 - 2014-04-21 11:54 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Mozilla
2014-04-21 11:53 - 2014-04-21 11:53 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-21 11:53 - 2014-04-21 11:53 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-21 11:53 - 2014-04-21 11:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-21 11:53 - 2014-04-21 11:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-21 11:50 - 2014-04-21 11:50 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Macromedia
2014-04-21 01:01 - 2014-04-21 01:01 - 00000117 _____ () C:\WINDOWS\system32\netcfg-6611421.txt
2014-04-21 01:01 - 2014-04-21 01:01 - 00000117 _____ () C:\WINDOWS\system32\netcfg-6611296.txt
2014-04-21 00:35 - 2014-04-21 00:04 - 00000000 ____D () C:\Windows.old
2014-04-21 00:29 - 2014-04-20 17:19 - 00000000 ___HD () C:\$SysReset
2014-04-21 00:27 - 2012-09-22 06:41 - 00625760 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys
2014-04-21 00:27 - 2012-09-22 06:41 - 00090208 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys
2014-04-21 00:27 - 2012-08-13 16:49 - 00178448 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kneps.sys
2014-04-21 00:27 - 2012-08-03 15:55 - 00050448 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klwfp.sys
2014-04-21 00:27 - 2012-08-02 15:09 - 00030304 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klim6.sys
2014-04-21 00:27 - 2012-07-25 14:53 - 00029280 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klmouflt.sys
2014-04-21 00:27 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kl1.sys
2014-04-21 00:27 - 2012-05-25 19:38 - 00029280 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2014-04-21 00:20 - 2014-04-21 00:20 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Power2Go8
2014-04-21 00:20 - 2014-04-21 00:20 - 00000000 ____D () C:\Users\Krauss\AppData\Local\CyberLink
2014-04-21 00:19 - 2014-04-21 00:19 - 00001446 _____ () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ___RD () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ___RD () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ____D () C:\WINDOWS\System32\Tasks\WPD
2014-04-21 00:19 - 2014-04-21 00:19 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Adobe
2014-04-21 00:19 - 2014-04-21 00:18 - 00000000 ____D () C:\Users\Krauss\AppData\Local\Packages
2014-04-21 00:19 - 2012-07-26 09:20 - 00000000 ____D () C:\WINDOWS\Setup
2014-04-21 00:18 - 2014-04-21 00:18 - 00000020 ___SH () C:\Users\Krauss\ntuser.ini
2014-04-21 00:18 - 2014-04-21 00:18 - 00000000 ____D () C:\Users\Krauss\AppData\Roaming\Intel
2014-04-21 00:18 - 2014-04-21 00:18 - 00000000 ____D () C:\Users\Krauss\AppData\Local\VirtualStore
2014-04-21 00:17 - 2014-04-21 00:17 - 00000117 _____ () C:\WINDOWS\system32\netcfg-4001468.txt
2014-04-21 00:17 - 2014-04-21 00:17 - 00000117 _____ () C:\WINDOWS\system32\netcfg-4000906.txt
2014-04-21 00:16 - 2014-04-21 00:15 - 00000117 _____ () C:\WINDOWS\system32\netcfg-3903609.txt
2014-04-21 00:15 - 2014-04-21 00:15 - 00000117 _____ () C:\WINDOWS\system32\netcfg-3903390.txt
2014-04-21 00:04 - 2012-07-26 10:13 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template
2014-04-21 00:03 - 2014-04-21 00:03 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-04-20 23:45 - 2014-04-20 23:45 - 00000000 ____D () C:\$WINDOWS.~BT
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-04-20 23:15 - 2014-04-20 23:15 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-04-20 23:15 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows NT
2014-04-20 23:15 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-218984.txt
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-218906.txt
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-217812.txt
2014-04-20 23:14 - 2014-04-20 23:14 - 00000117 _____ () C:\WINDOWS\system32\netcfg-211984.txt
2014-04-20 23:14 - 2014-04-20 23:12 - 00017148 _____ () C:\WINDOWS\diagwrn.xml
2014-04-20 23:14 - 2014-04-20 23:12 - 00017148 _____ () C:\WINDOWS\diagerr.xml
2014-04-20 23:14 - 2012-07-26 10:12 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-20 23:14 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\Recovery
2014-04-20 23:14 - 2012-07-26 09:21 - 00021704 _____ () C:\WINDOWS\setupact.log
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Vorlagen
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Startmenü
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Netzwerkumgebung
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Lokale Einstellungen
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Eigene Dateien
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Druckumgebung
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Documents\Eigene Musik
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Documents\Eigene Bilder
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\AppData\Local\Verlauf
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\AppData\Local\Anwendungsdaten
2014-04-20 23:12 - 2014-04-20 23:12 - 00000000 _SHDL () C:\Users\Krauss\Anwendungsdaten
2014-04-20 23:11 - 2012-09-22 05:49 - 00303464 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-04-20 23:10 - 2012-07-26 10:13 - 00003608 _____ () C:\WINDOWS\DtcInstall.log
2014-04-20 23:06 - 2014-04-20 23:06 - 00002306 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3863069283-2814587192-1313183951-500
2014-04-20 23:06 - 2014-04-20 23:06 - 00001139 _____ () C:\WINDOWS\system32\netcfg-107234.txt
2014-04-20 23:06 - 2014-04-20 23:06 - 00000109 _____ () C:\WINDOWS\system32\netcfg-80843.txt
2014-04-18 19:35 - 2014-04-18 19:34 - 00026955 _____ () C:\Users\Krauss\Downloads\Addition.txt
2014-04-18 19:32 - 2014-04-18 19:30 - 02158592 _____ (Farbar) C:\Users\Krauss\Downloads\FRST64.exe
2014-04-18 19:29 - 2014-04-18 19:29 - 01146880 _____ (Farbar) C:\Users\Krauss\Downloads\FRST.exe
2014-04-03 09:51 - 2014-04-21 15:36 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-21 15:36 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-21 15:36 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
Some content of TEMP:
====================
C:\Users\Krauss\AppData\Local\Temp\Quarantine.exe
C:\Users\Krauss\AppData\Local\Temp\swt-win32-3349.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-09-21 17:30
==================== End Of Log ============================
--- --- ---
--- --- ---
Danke freue mich schon auf eine baldige Antwort
Gruß joni_k
Wundert mich jetzt aber der JRT-Bericht und der ADW-Cleaner Bericht wurden im selben Textfeld notiert