Eset lief ziemlich lange (gefühlt 18 Stunden), hier das Log: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=46bf4094da185a47b378200a4053bd63
# engine=19352
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-25 08:10:59
# local_time=2014-07-25 10:10:59 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 66 85 19168203 157948909 0 0
# scanned=35192
# found=16
# cleaned=0
# scan_time=1963
sh=5273994A8CF50EF89AFCF3B67D9EB7A079A3B69F ft=1 fh=9303b344bca1e78e vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-3882204627-1061545298-3667153872-1001\$RWWO2US.exe"
sh=CCD90EE6E9B1ADFF9657E8F2C126BC6CB5C2EB24 ft=1 fh=91473923cd86549e vn="Variante von Win32/SProtector.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash.dll.vir"
sh=08FF41709DB8A9CCE36FD2996CC4FD2649FE1BFD ft=1 fh=8f3c051ef20a108b vn="Variante von Win64/SProtector.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll.vir"
sh=C5828B700B9EF61FA1534D5D18482BF12F591CBF ft=1 fh=0404da55e35b3671 vn="Variante von Win32/AdWare.SpeedingUpMyPC.D Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProLauncher.exe.vir"
sh=DDD2974F59F7DBB2C99557C05FB33787C7B27748 ft=1 fh=b62022df389e395a vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe.vir"
sh=AAEA2D2C15813161F9E114E6E1708CE545D5C8CA ft=1 fh=0022d452663e533e vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSense\SaveSenseUpdateVer.exe.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe.vir"
sh=10903598F769E2AC5F1E2372E90F6722A3A860B7 ft=1 fh=89560075533c3d40 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll.vir"
sh=88482528CE4F67A1004B50BA93282CEACCEDE534 ft=1 fh=e40b702402e604d5 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe.vir"
sh=70D49B9ABA391E6976DAB5C4BEA63733459B3F1C ft=1 fh=0b76a05977e7722a vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe.vir"
sh=F09B9B9B1D16D1539D23CC6ACDE0DC7BC983DF59 ft=1 fh=2dbadf99ca2df2d7 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe.vir"
sh=8563F21B965879AE572840082BB2E9E5990F8A45 ft=1 fh=0aef99ed940fde6b vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Patrick\AppData\Roaming\OpenCandy\8572FC2A50CC4DEEB8700199290B1341\sas.exe.vir"
sh=7B722A85CE6450E5D2B061C6D55BD6C7C82B3838 ft=1 fh=4b4dd648bb3da366 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Patrick\AppData\Roaming\OpenCandy\8572FC2A50CC4DEEB8700199290B1341\SaveSense_p1v2.exe.vir"
sh=AAEA2D2C15813161F9E114E6E1708CE545D5C8CA ft=1 fh=0022d452663e533e vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Patrick\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=46bf4094da185a47b378200a4053bd63
# engine=19370
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-28 07:17:56
# local_time=2014-07-28 09:17:56 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 66 85 19381020 158161726 0 0
# scanned=385317
# found=81
# cleaned=0
# scan_time=50414
sh=CCD90EE6E9B1ADFF9657E8F2C126BC6CB5C2EB24 ft=1 fh=91473923cd86549e vn="Variante von Win32/SProtector.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash.dll.vir"
sh=08FF41709DB8A9CCE36FD2996CC4FD2649FE1BFD ft=1 fh=8f3c051ef20a108b vn="Variante von Win64/SProtector.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll.vir"
sh=C5828B700B9EF61FA1534D5D18482BF12F591CBF ft=1 fh=0404da55e35b3671 vn="Variante von Win32/AdWare.SpeedingUpMyPC.D Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProLauncher.exe.vir"
sh=DDD2974F59F7DBB2C99557C05FB33787C7B27748 ft=1 fh=b62022df389e395a vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe.vir"
sh=AAEA2D2C15813161F9E114E6E1708CE545D5C8CA ft=1 fh=0022d452663e533e vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSense\SaveSenseUpdateVer.exe.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe.vir"
sh=10903598F769E2AC5F1E2372E90F6722A3A860B7 ft=1 fh=89560075533c3d40 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll.vir"
sh=88482528CE4F67A1004B50BA93282CEACCEDE534 ft=1 fh=e40b702402e604d5 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe.vir"
sh=70D49B9ABA391E6976DAB5C4BEA63733459B3F1C ft=1 fh=0b76a05977e7722a vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe.vir"
sh=F09B9B9B1D16D1539D23CC6ACDE0DC7BC983DF59 ft=1 fh=2dbadf99ca2df2d7 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe.vir"
sh=8563F21B965879AE572840082BB2E9E5990F8A45 ft=1 fh=0aef99ed940fde6b vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Patrick\AppData\Roaming\OpenCandy\8572FC2A50CC4DEEB8700199290B1341\sas.exe.vir"
sh=7B722A85CE6450E5D2B061C6D55BD6C7C82B3838 ft=1 fh=4b4dd648bb3da366 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Patrick\AppData\Roaming\OpenCandy\8572FC2A50CC4DEEB8700199290B1341\SaveSense_p1v2.exe.vir"
sh=AAEA2D2C15813161F9E114E6E1708CE545D5C8CA ft=1 fh=0022d452663e533e vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Patrick\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe.vir"
sh=D01F9F59BF6CA6E3FE60231CC8808C1A4FEA4530 ft=1 fh=e23161741f42185f vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Setup_31FreeVideoConverter.exe"
sh=08A0459CAF9820F6E4FC020095791995CFC989AB ft=0 fh=0000000000000000 vn="Variante von Generik.BOICCES Trojaner" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\$RECYCLE.BIN\S-1-5-21-3605044430-831468403-406832244-1002\$R4LZWRC\unzip\Alte Zip\Tool\afcad140.zip"
sh=B84EDE50FED81BD01F6F9698E71C949E2E60A092 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2011-03-20 190006\Backup Files 2011-04-03 190014\Backup files 1.zip"
sh=27E34FBD61DDCD28B0465E292FD78B33E409EA8E ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2011-04-10 190006\Backup Files 2011-04-10 190006\Backup files 1.zip"
sh=5CFD5DDE4E9E0130126E727013C508BC7A530438 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2011-05-22 190012\Backup Files 2011-05-22 190012\Backup files 1.zip"
sh=6BDC2371555F49F704EB42AF922EB81F69A205A9 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2011-07-24 203318\Backup Files 2011-07-24 203318\Backup files 1.zip"
sh=B8A4A757D397D9E89F15578ABA437C835A1203A0 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2012-02-06 191309\Backup Files 2012-02-06 191309\Backup files 1.zip"
sh=8F46135D3CB759FA3197A09BF9E8F20D532D31AE ft=0 fh=0000000000000000 vn="Variante von Win32/Speedchecker.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2012-02-06 191309\Backup Files 2012-02-06 191309\Backup files 2.zip"
sh=FA1B4FCDF3F02748AFC48484AE43E5BEF9CCE0A2 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2013-08-13 005231\Backup Files 2013-08-13 005231\Backup files 1.zip"
sh=5239FC50ED6151D6116FA1F5BBF237E9EFBED8DD ft=0 fh=0000000000000000 vn="Variante von Win32/Speedchecker.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2013-08-13 005231\Backup Files 2013-08-13 005231\Backup files 2.zip"
sh=F8139660C9EE0FCC5F88E897FEBE33984EA37DC8 ft=0 fh=0000000000000000 vn="Android/Exploit.Lotoor.AT Trojaner" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2013-08-13 005231\Backup Files 2013-09-25 181155\Backup files 1.zip"
sh=84C220E2E71D543DD06509783D08A9100C1EB8F2 ft=0 fh=0000000000000000 vn="Android/Exploit.Lotoor.AT Trojaner" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2013-08-13 005231\Backup Files 2013-09-25 181155\Backup files 3.zip"
sh=1A036F5546C0207C6823C8EBCB07C58E11163630 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Widgi.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2013-08-13 005231\Backup Files 2013-10-20 195247\Backup files 2.zip"
sh=3258F2625073191633D314A63DAA2E3ECE2C1DE6 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.SearchSuite.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\BUMBLEBEE\Backup Set 2013-08-13 005231\Backup Files 2013-11-10 202239\Backup files 1.zip"
sh=876F488054FCBFFC6343F84B1FCEB5DBF243A068 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-04-28 190003\Backup Files 2013-05-05 190004\Backup files 1.zip"
sh=2C809EC3A751BEE6F61F887928AC2B7FC2697DDF ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-05-19 191546\Backup Files 2013-05-19 191546\Backup files 2.zip"
sh=A3C399395FE7CECD373021F14544E203BAECF7B6 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-05-19 191546\Backup Files 2013-05-19 191546\Backup files 5.zip"
sh=3A3F1F1F48B4B3E6639484CDFAEA5343B51B3A32 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-05-19 191546\Backup Files 2013-05-26 190008\Backup files 1.zip"
sh=B78579220B6FB58921FCFD17C66AC48F6EE7C6BF ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-05-19 191546\Backup Files 2013-06-02 190001\Backup files 1.zip"
sh=87F85F9513A45E91B156D11BF5CC9B333DFDECDB ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-05-19 191546\Backup Files 2013-06-10 030331\Backup files 1.zip"
sh=4D42A30C81200CFAD49E9B60C6BF2406F8925D88 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-06-23 190004\Backup Files 2013-06-23 190004\Backup files 2.zip"
sh=60186CAB03D5F64D4D05DC05269F7B5DD8B06AB9 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-06-23 190004\Backup Files 2013-06-23 190004\Backup files 5.zip"
sh=C80739034164FF93BE07CC0409877C04B878D979 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-06-23 190004\Backup Files 2013-07-07 190006\Backup files 1.zip"
sh=5A83EC4862E6BFFF5616BD104F23BD3C18FCD95A ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-06-23 190004\Backup Files 2013-07-14 224257\Backup files 1.zip"
sh=9E25C31733DECA8E30A89AD78B290E66595EF735 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-06-23 190004\Backup Files 2013-07-21 212712\Backup files 1.zip"
sh=10187E15D92B73635523D901A3A4D32C52A688DF ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-07-29 234447\Backup Files 2013-07-29 234447\Backup files 2.zip"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDYGONZALEZ\Backup Set 2013-07-29 234447\Backup Files 2013-09-17 183937\Backup files 1.zip"
sh=7A3728E7405F69131C8EF6DC3CDD742935D2F9ED ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDY_GO\Backup Set 2013-12-16 013818\Backup Files 2013-12-23 173519\Backup files 1.zip"
sh=91F8DD6B7C15D385FFBF7243F3EB1CFECA4D07DF ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Patrick\Desktop\Testdisk\testdisk-6.14\Rettung\SPEEDY_GO\Backup Set 2014-01-12 190000\Backup Files 2014-01-12 190000\Backup files 1.zip"
sh=B92CEFCB1BEBAC04CEB57C202AD1248F95A5D4F9 ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1.zip"
sh=7967678757DD61AB5665E2CF546A14D9CE6AA70D ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1217.zip"
sh=0353AFA8DC0E92CC153A5118FC7E7C4669C261B5 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1218.zip"
sh=585CA7A87F46059174647C576AD37ABA8DFB8671 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1229.zip"
sh=BF4CEDE7B6457F9ACA603E980F36AC0E8058C12D ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1289.zip"
sh=AF3D46D6BE4E7C8D7250465D3F323897C0E98D7D ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1348.zip"
sh=0860FFF2758C0AB9A885618E002E11913879B8AE ft=0 fh=0000000000000000 vn="Variante von Win32/Speedchecker.A evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1359.zip"
sh=FC2D4D4E5983F4E0F56D9CDC29C633EEE7791665 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1417.zip"
sh=2CAE16142F3D99E8DD59070069CEF48B3C232758 ft=0 fh=0000000000000000 vn="Variante von Win32/Speedchecker.A evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1428.zip"
sh=7F2B827AD4B4ED47C41524F1C280001D0052DE26 ft=0 fh=0000000000000000 vn="Android/Exploit.Lotoor.AT Trojaner" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1467.zip"
sh=C4AE80C0C8BCFADB49551E193A9B8A350C13AFBE ft=0 fh=0000000000000000 vn="Android/Exploit.Lotoor.AT Trojaner" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1469.zip"
sh=544A91FDFF18ADDF3149418C04DE11443509F7C2 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Widgi.B evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1487.zip"
sh=16CB7512DF8444FF7877178E94B15B8D68453132 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.SearchSuite.L evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 1490.zip"
sh=0C29C2239BB2E42520D1C1283D9EFAE675314549 ft=0 fh=0000000000000000 vn="Variante von Generik.BOICCES Trojaner" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-17 105246\Backup files 758.zip"
sh=50908E26DCB99C1A8A4C67EABD23F84FAA3D68EF ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 107.zip"
sh=6BB724608AB901F7ED0CF225CB6C3550EAEE529C ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 108.zip"
sh=C1CFC02CCD8E5CBA612FFD6C105B3DC69F26CD70 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 109.zip"
sh=6AA797ACBCCE80109F323BDD4652255EE9E40AA7 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 115.zip"
sh=4EED9986493E320F3D0EC15E49D8E23A5AB3FEE9 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 138.zip"
sh=513F5C32BF4EC604A84D002B85DBD735A36BD804 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 140.zip"
sh=23A1EF2D64EDCC8CC3028CCC75C3F1CD458279E4 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 141.zip"
sh=6189C3BF051ABB31A052D90EA30BC4751320024C ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 143.zip"
sh=2641050639C295102767F718DD537398FC9916AB ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 144.zip"
sh=CE669F74378A868BA022C204EB27D51F0BF1B041 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 146.zip"
sh=26BFFFCF938F9C2062FED7A254F022181D248A87 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 165.zip"
sh=6241DA7F5A3D5AB8BA9858F13A5E27EE0F6DE18D ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 17.zip"
sh=F8F36B738CFDA2DD531C45627CEAEF6ECCCD83F3 ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 176.zip"
sh=FF5C41B76891EBDBEACC96A0094257A16812531A ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 181.zip"
sh=00857E69F7C4AA23B08626FB427A63077AC356E1 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 27.zip"
sh=4E8BE8F2FBFE6F597853B66A03B2A2900351278E ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 52.zip"
sh=298F39C608B8A90B96F1459CA48BFED501F6FF0A ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 56.zip"
sh=399D48B4A8A0874F8B58633992128B3A904C1372 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 60.zip"
sh=487699AF833EDD89137CCE55F6AA49C2790B7B4A ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 64.zip"
sh=5D64D262119324BF9FEB3CC18AD0367BF6FC3D07 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 71.zip"
sh=E9A16C5EE5D750DDE2363C5DA1DC31319ECE68F2 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-02-23 221955\Backup files 95.zip"
sh=5EA4FA1A23F8B3F060A5FD747E36229D2ACA446A ft=0 fh=0000000000000000 vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-06-10 205531\Backup files 2.zip"
sh=0883375B7198EB1CC8F4B930B9207370A872FE53 ft=0 fh=0000000000000000 vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="K:\SPEEDY_GO\Backup Set 2014-02-17 105246\Backup Files 2014-07-27 191323\Backup files 2.zip" Wenn man das so liest, wird einem ganz anders...
Hier das Security Checkup Log: Code:
Results of screen317's Security Check version 0.99.85
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
McAfee Anti-Virus und Anti-Spyware
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 65
Java version out of Date!
Adobe Flash Player 14.0.0.145
Adobe Reader XI
Mozilla Firefox (30.0)
Mozilla Thunderbird (24.1.1)
Google Chrome 35.0.1916.153
Google Chrome 36.0.1985.125 ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamscheduler.exe
Symantec Norton Online Backup NOBuAgent.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Und das aktuelle FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-07-2014 01
Ran by Patrick (administrator) on SPEEDY_GO on 28-07-2014 18:39:48
Running from C:\Users\Patrick\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Malwarebytes Corporation) D:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(TeamViewer GmbH) D:\Programme\TeamViewer\Version9\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() D:\Program Files (x86)\WISO\Steuer 2014\mshaktuell.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard Development Co. L.P.) C:\Program Files (x86)\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe
(Disc Soft Ltd) D:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
() C:\Program Files (x86)\Opera\23.0.1522.60\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.60\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11464296 2010-09-03] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [MDS_Menu] => C:\Program Files (x86)\Acer Arcade Deluxe\MediaEspresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe [419112 2010-12-01] (CyberLink Corp.)
HKLM-x32\...\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [618600 2010-12-03] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5537136 2013-08-14] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [TrayServer] => D:\Programme\MAGIX\Video_deluxe_MX_Premium_Sonderedition\TrayServer_de.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> D:\Program Files (x86)\WISO\Steuer 2014\mshaktuell.exe ()
ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll (Egis Technology Inc.)
ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll (Egis Technology Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xa9y2lcc.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @videolan.org/vlc,version=2.1.1 - D:\Programme\VLC Media Player\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - D:\Programme\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Amazon-Icon - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xa9y2lcc.default\Extensions\amazon-icon@giga.de [2014-06-06]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-12-15]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-12-18]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2013-12-15]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-02]
CHR Extension: (Google Drive) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-02]
CHR Extension: (YouTube) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-02]
CHR Extension: (Google-Suche) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-02]
CHR Extension: (SiteAdvisor) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2014-05-02]
CHR Extension: (Google Wallet) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-02]
CHR Extension: (Google Mail) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-02]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 MBAMScheduler; D:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; D:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-03-18] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-04-03] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-04-03] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S4 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 TeamViewer9; D:\Programme\TeamViewer\Version9\TeamViewer_Service.exe [5024576 2014-04-25] (TeamViewer GmbH)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270704 2013-08-14] (Western Digital Technologies, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70592 2014-04-03] (McAfee, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-18] (Disc Soft Ltd)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R2 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-28] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [177544 2014-04-03] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311856 2014-04-03] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [522360 2014-04-03] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [784760 2014-04-03] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [441264 2014-03-18] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-03-18] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [346760 2014-04-03] (McAfee, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-28 18:38 - 2014-07-28 18:39 - 00022307 _____ () C:\Users\Patrick\Desktop\FRST.txt
2014-07-28 18:38 - 2014-07-25 22:11 - 02093568 _____ (Farbar) C:\Users\Patrick\Desktop\FRST64.exe
2014-07-28 18:36 - 2014-07-28 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-07-28 18:21 - 2014-07-28 18:22 - 00001078 _____ () C:\Users\Patrick\Desktop\checkup.txt
2014-07-28 09:47 - 2014-07-28 09:47 - 00854390 _____ () C:\Users\Patrick\Desktop\SecurityCheck.exe
2014-07-28 01:55 - 2014-07-12 12:31 - 2836504208 _____ () C:\Users\Patrick\Downloads\Zwiebeljack räumt auf.mkv
2014-07-27 19:15 - 2014-07-25 21:33 - 02347384 _____ (ESET) C:\Users\Patrick\Desktop\esetsmartinstaller_deu (1).exe
2014-07-27 13:14 - 2014-07-28 18:20 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\avidemux
2014-07-27 13:14 - 2014-07-27 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64bits)
2014-07-27 13:08 - 2014-07-27 13:09 - 16456460 _____ () C:\Users\Patrick\Desktop\avidemux_2.6.8_win64_v2.exe
2014-07-27 13:07 - 2014-07-27 13:07 - 00000707 _____ () C:\Users\Patrick\Desktop\JRT.txt
2014-07-27 12:57 - 2014-07-27 12:57 - 00000000 ____D () C:\Windows\ERUNT
2014-07-26 22:19 - 2014-07-27 02:03 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\FreeVideoConverter
2014-07-26 22:19 - 2014-07-26 22:19 - 00001149 _____ () C:\Users\Patrick\Desktop\Free Video Converter.lnk
2014-07-26 22:19 - 2014-07-26 22:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Converter
2014-07-26 22:08 - 2014-07-26 22:08 - 00445592 _____ (Bandoo Media Inc) C:\Users\Patrick\Desktop\Setup_31FreeVideoConverter.exe
2014-07-26 20:38 - 2014-07-26 20:38 - 00021956 _____ () C:\ComboFix.txt
2014-07-26 20:26 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-26 20:26 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-26 20:26 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-26 20:26 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-26 20:26 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-26 20:26 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-26 20:26 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-26 20:26 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-26 20:25 - 2014-07-26 20:38 - 00000000 ____D () C:\Qoobox
2014-07-26 20:25 - 2014-07-26 20:37 - 00000000 ____D () C:\Windows\erdnt
2014-07-26 20:16 - 2014-07-26 20:16 - 00003172 _____ () C:\Windows\System32\Tasks\{04769C88-1E2D-4212-A6A0-324194CA06B2}
2014-07-26 20:12 - 2014-07-26 20:12 - 00000728 _____ () C:\Users\Patrick\Desktop\Revo Uninstaller.lnk
2014-07-26 14:27 - 2014-07-26 14:27 - 00275464 _____ () C:\Windows\Minidump\072614-28672-01.dmp
2014-07-25 23:35 - 2014-07-25 23:35 - 00024136 _____ () C:\Users\Patrick\Desktop\logs.zip
2014-07-25 22:29 - 2014-07-25 22:29 - 00003261 _____ () C:\Users\Patrick\Desktop\gmer.log
2014-07-25 22:21 - 2014-07-25 22:21 - 00181378 _____ () C:\Users\Patrick\Desktop\Addition_old.txt
2014-07-25 22:20 - 2014-07-28 18:39 - 00000000 ____D () C:\FRST
2014-07-25 22:20 - 2014-07-27 13:09 - 00055028 _____ () C:\Users\Patrick\Desktop\FRST_2.txt
2014-07-25 22:19 - 2014-07-27 13:24 - 00000476 _____ () C:\Users\Patrick\Desktop\defogger_disable.log
2014-07-25 22:19 - 2014-07-25 22:19 - 00000168 _____ () C:\Users\Patrick\defogger_reenable
2014-07-25 22:11 - 2014-07-25 22:11 - 00050477 _____ () C:\Users\Patrick\Desktop\Defogger.exe
2014-07-25 21:34 - 2014-07-25 21:34 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-25 21:17 - 2014-07-28 18:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-25 21:16 - 2014-07-25 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-25 21:16 - 2014-07-25 21:16 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-25 21:16 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-25 21:16 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-25 21:16 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-25 21:02 - 2014-07-25 21:02 - 00004347 _____ () C:\Users\Patrick\Desktop\gmer (1).log
2014-07-25 20:45 - 2014-07-25 20:45 - 00000000 __SHD () C:\Users\Patrick\AppData\Local\EmieUserList
2014-07-25 20:45 - 2014-07-25 20:45 - 00000000 __SHD () C:\Users\Patrick\AppData\Local\EmieSiteList
2014-07-25 20:37 - 2014-07-25 20:37 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-24 22:20 - 2014-07-24 22:20 - 00002567 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Excel Viewer.lnk
2014-07-24 22:16 - 2014-07-24 22:17 - 53634800 _____ (Microsoft Corporation) C:\Users\Patrick\Downloads\ExcelViewer.exe
2014-07-24 21:32 - 2014-07-24 21:32 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Avg2014
2014-07-21 13:18 - 2014-07-21 13:18 - 00000000 ____D () C:\Windows\Sun
2014-07-21 13:17 - 2014-07-21 13:17 - 00004669 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-21 13:17 - 2014-07-11 03:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-21 13:17 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-21 13:17 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-21 13:17 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-16 03:00 - 2014-07-16 03:00 - 00264498 _____ () C:\Windows\msxml4-KB2758694-enu.LOG
2014-07-14 13:26 - 2014-07-14 13:26 - 00000000 ____D () C:\Users\Patrick\Documents\MAGIX
2014-07-14 12:54 - 2014-07-14 13:26 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\MAGIX
2014-07-14 12:54 - 2014-07-14 12:54 - 00000000 ____D () C:\Users\Patrick\Documents\MAGIX_MusicEditor
2014-07-14 12:54 - 2014-07-14 12:54 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Xara
2014-07-14 12:44 - 2014-07-14 12:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-07-14 12:44 - 2014-07-14 12:44 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-07-14 12:43 - 2014-07-14 13:26 - 00000000 ____D () C:\ProgramData\MAGIX
2014-07-14 12:43 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-07-14 12:43 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-07-13 12:58 - 2014-07-13 12:58 - 00000000 ____D () C:\ProgramData\RELOADED
2014-07-13 12:48 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2014-07-13 12:48 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-07-13 12:48 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2014-07-13 12:48 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2014-07-13 12:48 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-07-13 12:48 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-07-13 12:48 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2014-07-13 12:31 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-07-13 12:30 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-07-13 12:30 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-07-13 12:30 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-07-13 12:30 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-07-13 12:30 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-07-13 12:30 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-07-13 12:30 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-07-13 12:30 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-07-13 12:30 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-07-13 12:30 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-07-13 12:30 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-07-13 12:30 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-07-13 12:30 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-07-13 12:30 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-07-13 12:30 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-07-13 12:30 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-07-13 12:30 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-07-11 12:50 - 2014-07-13 12:45 - 00000507 _____ () C:\Users\Public\Desktop\Metro Last Light.lnk
2014-07-11 12:50 - 2014-07-13 12:45 - 00000507 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metro Last Light.lnk
2014-07-10 11:46 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-10 11:46 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-10 11:46 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 11:46 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-10 11:46 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 11:46 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 11:46 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 11:46 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 11:46 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 11:46 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 11:46 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 11:46 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 11:46 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 11:46 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 11:46 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 11:46 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 11:46 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 11:46 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 11:46 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 11:46 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 11:46 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 11:46 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 11:46 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 11:46 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 11:46 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 11:46 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 11:46 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 11:46 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 11:46 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 11:46 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 11:46 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 11:46 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-10 11:46 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 11:46 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 11:46 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 11:46 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 11:46 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 11:46 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 11:46 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 11:46 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 11:46 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 11:46 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 11:46 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 11:46 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 11:46 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 11:46 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 11:46 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 11:46 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 11:46 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 11:46 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 11:46 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 11:46 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 11:46 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 11:46 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 11:46 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 11:46 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 11:46 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 11:46 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 11:46 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 11:46 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 11:46 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 11:46 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 11:46 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 11:46 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 11:46 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 11:46 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 11:46 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 11:46 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 11:46 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 11:46 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 11:46 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-10 11:46 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-10 11:46 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-10 11:46 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-10 11:46 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-10 11:46 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-10 11:46 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-10 11:46 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 11:45 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 11:45 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 11:45 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-04 12:41 - 2014-07-04 12:41 - 00001621 _____ () C:\Users\Patrick\AppData\Local\recently-used.xbel
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-28 18:40 - 2014-07-28 18:38 - 00022307 _____ () C:\Users\Patrick\Desktop\FRST.txt
2014-07-28 18:39 - 2014-07-25 22:20 - 00000000 ____D () C:\FRST
2014-07-28 18:36 - 2014-07-28 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-07-28 18:36 - 2014-05-09 16:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-28 18:36 - 2013-12-15 21:51 - 00001848 _____ () C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk
2014-07-28 18:31 - 2014-05-02 12:25 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-28 18:30 - 2013-12-16 02:38 - 00007239 _____ () C:\Windows\setupact.log
2014-07-28 18:30 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-28 18:27 - 2013-12-15 18:21 - 01271368 _____ () C:\Windows\WindowsUpdate.log
2014-07-28 18:22 - 2014-07-28 18:21 - 00001078 _____ () C:\Users\Patrick\Desktop\checkup.txt
2014-07-28 18:20 - 2014-07-27 13:14 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\avidemux
2014-07-28 18:20 - 2014-07-25 21:17 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-28 18:20 - 2014-05-02 12:25 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-28 09:47 - 2014-07-28 09:47 - 00854390 _____ () C:\Users\Patrick\Desktop\SecurityCheck.exe
2014-07-28 01:54 - 2013-12-20 02:46 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\vlc
2014-07-27 13:24 - 2014-07-25 22:19 - 00000476 _____ () C:\Users\Patrick\Desktop\defogger_disable.log
2014-07-27 13:14 - 2014-07-27 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64bits)
2014-07-27 13:09 - 2014-07-27 13:08 - 16456460 _____ () C:\Users\Patrick\Desktop\avidemux_2.6.8_win64_v2.exe
2014-07-27 13:09 - 2014-07-25 22:20 - 00055028 _____ () C:\Users\Patrick\Desktop\FRST_2.txt
2014-07-27 13:07 - 2014-07-27 13:07 - 00000707 _____ () C:\Users\Patrick\Desktop\JRT.txt
2014-07-27 12:59 - 2009-07-14 06:45 - 00018848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-27 12:59 - 2009-07-14 06:45 - 00018848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-27 12:57 - 2014-07-27 12:57 - 00000000 ____D () C:\Windows\ERUNT
2014-07-27 12:51 - 2013-12-15 18:16 - 00214048 _____ () C:\Windows\PFRO.log
2014-07-27 12:50 - 2014-05-02 13:17 - 00000000 ____D () C:\AdwCleaner
2014-07-27 02:03 - 2014-07-26 22:19 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\FreeVideoConverter
2014-07-26 22:19 - 2014-07-26 22:19 - 00001149 _____ () C:\Users\Patrick\Desktop\Free Video Converter.lnk
2014-07-26 22:19 - 2014-07-26 22:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Converter
2014-07-26 22:19 - 2009-07-14 04:34 - 00000596 _____ () C:\Windows\win.ini
2014-07-26 22:08 - 2014-07-26 22:08 - 00445592 _____ (Bandoo Media Inc) C:\Users\Patrick\Desktop\Setup_31FreeVideoConverter.exe
2014-07-26 21:52 - 2013-12-16 03:13 - 00699080 _____ () C:\Windows\system32\perfh007.dat
2014-07-26 21:52 - 2013-12-16 03:13 - 00149220 _____ () C:\Windows\system32\perfc007.dat
2014-07-26 21:52 - 2009-07-14 07:13 - 01619224 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-26 20:38 - 2014-07-26 20:38 - 00021956 _____ () C:\ComboFix.txt
2014-07-26 20:38 - 2014-07-26 20:25 - 00000000 ____D () C:\Qoobox
2014-07-26 20:37 - 2014-07-26 20:25 - 00000000 ____D () C:\Windows\erdnt
2014-07-26 20:36 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-26 20:21 - 2013-12-20 01:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II Hero Editor
2014-07-26 20:18 - 2013-12-18 13:36 - 00000000 ____D () C:\Program Files (x86)\Yahoo!
2014-07-26 20:16 - 2014-07-26 20:16 - 00003172 _____ () C:\Windows\System32\Tasks\{04769C88-1E2D-4212-A6A0-324194CA06B2}
2014-07-26 20:12 - 2014-07-26 20:12 - 00000728 _____ () C:\Users\Patrick\Desktop\Revo Uninstaller.lnk
2014-07-26 14:27 - 2014-07-26 14:27 - 00275464 _____ () C:\Windows\Minidump\072614-28672-01.dmp
2014-07-26 14:27 - 2014-06-10 21:06 - 1243866252 _____ () C:\Windows\MEMORY.DMP
2014-07-26 14:27 - 2014-06-10 21:06 - 00000000 ____D () C:\Windows\Minidump
2014-07-25 23:36 - 2014-05-09 16:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-25 23:36 - 2013-12-16 03:06 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-25 23:36 - 2013-12-16 03:06 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-25 23:35 - 2014-07-25 23:35 - 00024136 _____ () C:\Users\Patrick\Desktop\logs.zip
2014-07-25 23:33 - 2013-12-23 19:21 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-07-25 23:33 - 2013-12-23 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-07-25 22:29 - 2014-07-25 22:29 - 00003261 _____ () C:\Users\Patrick\Desktop\gmer.log
2014-07-25 22:21 - 2014-07-25 22:21 - 00181378 _____ () C:\Users\Patrick\Desktop\Addition_old.txt
2014-07-25 22:19 - 2014-07-25 22:19 - 00000168 _____ () C:\Users\Patrick\defogger_reenable
2014-07-25 22:19 - 2013-12-15 19:21 - 00000000 ____D () C:\Users\Patrick
2014-07-25 22:11 - 2014-07-28 18:38 - 02093568 _____ (Farbar) C:\Users\Patrick\Desktop\FRST64.exe
2014-07-25 22:11 - 2014-07-25 22:11 - 00050477 _____ () C:\Users\Patrick\Desktop\Defogger.exe
2014-07-25 21:47 - 2014-05-02 12:25 - 00004118 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-07-25 21:47 - 2014-05-02 12:25 - 00003866 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-07-25 21:47 - 2014-01-19 15:31 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-07-25 21:47 - 2013-12-19 00:16 - 00003676 _____ () C:\Windows\System32\Tasks\HP-Online-Aktualisierungsprogramm
2014-07-25 21:34 - 2014-07-25 21:34 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-25 21:33 - 2014-07-27 19:15 - 02347384 _____ (ESET) C:\Users\Patrick\Desktop\esetsmartinstaller_deu (1).exe
2014-07-25 21:18 - 2014-05-12 11:37 - 00000000 ____D () C:\Users\Patrick\AppData\Local\CrashDumps
2014-07-25 21:16 - 2014-07-25 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-25 21:16 - 2014-07-25 21:16 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-25 21:02 - 2014-07-25 21:02 - 00004347 _____ () C:\Users\Patrick\Desktop\gmer (1).log
2014-07-25 20:45 - 2014-07-25 20:45 - 00000000 __SHD () C:\Users\Patrick\AppData\Local\EmieUserList
2014-07-25 20:45 - 2014-07-25 20:45 - 00000000 __SHD () C:\Users\Patrick\AppData\Local\EmieSiteList
2014-07-25 20:37 - 2014-07-25 20:37 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-25 20:29 - 2013-12-15 21:50 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-07-24 22:20 - 2014-07-24 22:20 - 00002567 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Excel Viewer.lnk
2014-07-24 22:19 - 2013-12-20 14:35 - 00000000 ____D () C:\Program Files (x86)\MSECache
2014-07-24 22:17 - 2014-07-24 22:16 - 53634800 _____ (Microsoft Corporation) C:\Users\Patrick\Downloads\ExcelViewer.exe
2014-07-24 21:32 - 2014-07-24 21:32 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Avg2014
2014-07-22 14:54 - 2014-06-13 12:21 - 00003852 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1387134862
2014-07-22 14:54 - 2013-12-15 21:14 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-07-21 13:18 - 2014-07-21 13:18 - 00000000 ____D () C:\Windows\Sun
2014-07-21 13:18 - 2014-05-05 10:20 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-21 13:17 - 2014-07-21 13:17 - 00004669 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-21 13:17 - 2014-01-28 11:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-16 03:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-16 03:16 - 2009-07-14 06:45 - 00392560 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-16 03:00 - 2014-07-16 03:00 - 00264498 _____ () C:\Windows\msxml4-KB2758694-enu.LOG
2014-07-14 13:29 - 2013-12-15 19:23 - 00108680 _____ () C:\Users\Patrick\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-14 13:26 - 2014-07-14 13:26 - 00000000 ____D () C:\Users\Patrick\Documents\MAGIX
2014-07-14 13:26 - 2014-07-14 12:54 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\MAGIX
2014-07-14 13:26 - 2014-07-14 12:43 - 00000000 ____D () C:\ProgramData\MAGIX
2014-07-14 12:54 - 2014-07-14 12:54 - 00000000 ____D () C:\Users\Patrick\Documents\MAGIX_MusicEditor
2014-07-14 12:54 - 2014-07-14 12:54 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Xara
2014-07-14 12:54 - 2014-07-14 12:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-07-14 12:44 - 2014-07-14 12:44 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-07-14 12:43 - 2013-12-15 21:54 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-07-14 03:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\spool
2014-07-14 03:17 - 2014-05-07 10:28 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-14 03:17 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-14 03:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-14 03:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-13 13:10 - 2014-06-12 14:14 - 00000000 ____D () C:\Users\Patrick\Documents\4A Games
2014-07-13 13:03 - 2014-06-12 14:12 - 00000000 ____D () C:\Users\Patrick\AppData\Local\4A Games
2014-07-13 12:58 - 2014-07-13 12:58 - 00000000 ____D () C:\ProgramData\RELOADED
2014-07-13 12:47 - 2013-12-15 19:05 - 00066095 _____ () C:\Windows\DirectX.log
2014-07-13 12:45 - 2014-07-11 12:50 - 00000507 _____ () C:\Users\Public\Desktop\Metro Last Light.lnk
2014-07-13 12:45 - 2014-07-11 12:50 - 00000507 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metro Last Light.lnk
2014-07-12 12:31 - 2014-07-28 01:55 - 2836504208 _____ () C:\Users\Patrick\Downloads\Zwiebeljack räumt auf.mkv
2014-07-11 03:02 - 2014-07-21 13:17 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-11 02:56 - 2014-07-21 13:17 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-11 02:56 - 2014-07-21 13:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-11 02:55 - 2014-07-21 13:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-10 20:35 - 2013-12-15 20:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 20:34 - 2013-12-15 20:00 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-04 12:41 - 2014-07-04 12:41 - 00001621 _____ () C:\Users\Patrick\AppData\Local\recently-used.xbel
2014-07-04 12:41 - 2014-05-12 00:47 - 00000000 ____D () C:\Users\Patrick\AppData\Local\gtk-2.0
2014-07-04 12:32 - 2014-05-12 00:36 - 00000000 ____D () C:\Users\Patrick\.gimp-2.8
2014-06-30 04:09 - 2014-07-10 11:46 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-10 11:46 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
Some content of TEMP:
====================
C:\Users\Patrick\AppData\Local\Temp\-wuvu-iq.dll
C:\Users\Patrick\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-18 13:02
==================== End Of Log ============================ --- --- ---
Ob ich noch Probleme habe? Mir scheint erst jetzt, dass ich überhaupt richtige Probleme habe ... |