ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43
# engine=14047
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-11 05:10:54
# local_time=2013-06-11 07:10:54 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 11566108 122600504 0 0
# scanned=100248
# found=0
# cleaned=0
# scan_time=16116
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43
# engine=14049
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-11 06:48:10
# local_time=2013-06-11 08:48:10 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 11571944 122606340 0 0
# scanned=142381
# found=0
# cleaned=0
# scan_time=5483
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43
# engine=16000
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-11-23 04:39:14
# local_time=2013-11-23 05:39:14 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 11686084 136854604 0 0
# scanned=159582
# found=0
# cleaned=0
# scan_time=17331
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43
# engine=16505
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-03 10:19:00
# local_time=2014-01-03 11:19:00 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 15248870 140417390 0 0
# scanned=172179
# found=0
# cleaned=0
# scan_time=14092
Results of screen317's Security Check version 0.99.78
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 45
Adobe Reader 10.1.8
Adobe Reader out of Date!
Google Chrome 31.0.1650.57
Google Chrome 31.0.1650.63
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
WinPatrol winpatrol.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
BillP Studios WinPatrol WinPatrol.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
und zu guter letzt
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-01-2014
Ran by Besitzer (administrator) on LAPTOPJULIAN on 03-01-2014 23:57:14
Running from C:\Users\Besitzer\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Spotify Ltd) C:\Users\Besitzer\AppData\Roaming\Spotify\spotify.exe
(Spotify Ltd) C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
(Overwolf) C:\Program Files (x86)\Overwolf\Overwolf.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper.exe
(Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper64.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [LoadFUJ02E3] - C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED)
HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [205168 2011-10-03] (FUJITSU LIMITED)
HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [158024 2011-09-30] (FUJITSU LIMITED)
HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [23368 2011-09-30] (FUJITSU LIMITED)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [MouseDriver] - C:\Windows\System32\TiltWheelMouse.exe [241152 2012-12-19] (Pixart Imaging Inc)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-06] (Intel Corporation)
HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [255208 2012-03-21] (CyberLink Corp.)
HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-29] (FUJITSU LIMITED)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-01] ()
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [Spotify] - C:\Users\Besitzer\AppData\Roaming\Spotify\spotify.exe [5951488 2013-12-07] (Spotify Ltd)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-07] (Spotify Ltd)
HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [456768 2013-10-19] (BillP Studios)
HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF71A0D7D9D00CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR Extension: (Adblock Plus) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0
CHR Extension: (Google Wallet) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
==================== Services (Whitelisted) =================
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc)
R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf)
R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2013-11-22] ()
R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63856 2011-10-03] (FUJITSU LIMITED)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED)
R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED)
R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-09] (Intel Corporation)
S3 iaStorS; C:\Windows\system32\drivers\iaStorS.sys [638896 2012-03-09] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [51280 2010-11-02] (LSI Corporation)
S3 megasr1; C:\Windows\system32\drivers\megasr1.sys [806696 2012-02-08] (LSI Corporation, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8217064 2012-01-02] (Realtek Semiconductor Corp.)
R3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U4 losvaiin;
U4 lrmykkgu;
U4 X6va012;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-03 23:56 - 2014-01-03 23:56 - 01931750 _____ (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe
2014-01-03 23:47 - 2014-01-03 23:47 - 00987410 _____ C:\Users\Besitzer\Downloads\SecurityCheck (1).exe
2014-01-03 18:53 - 2014-01-03 18:53 - 02347384 _____ (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (2).exe
2014-01-02 23:00 - 2014-01-02 23:00 - 00002138 _____ C:\Users\Public\Desktop\Rise Of Nations.lnk
2014-01-02 15:33 - 2014-01-02 15:33 - 00000628 _____ C:\Users\Besitzer\Desktop\JRT.txt
2014-01-02 15:27 - 2014-01-02 15:27 - 01036305 _____ (Thisisu) C:\Users\Besitzer\Downloads\JRT (1).exe
2014-01-02 15:09 - 2014-01-02 15:09 - 00000000 __SHD C:\found.000
2014-01-02 15:01 - 2014-01-02 15:01 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (3).exe
2014-01-02 14:41 - 2014-01-02 14:42 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup-1.75.0.1300 (1).exe
2014-01-01 13:28 - 2014-01-01 13:28 - 00000546 _____ C:\Windows\PFRO.log
2014-01-01 13:18 - 2014-01-01 13:18 - 00023546 _____ C:\ComboFix.txt
2014-01-01 13:09 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-01 13:09 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-01 13:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-01 13:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-01 13:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-01 13:09 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-01 13:09 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-01 13:09 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-01 13:08 - 2014-01-01 13:18 - 00000000 ____D C:\Qoobox
2014-01-01 13:06 - 2014-01-01 13:07 - 05160176 ____R (Swearware) C:\Users\Besitzer\Downloads\ComboFix.exe
2013-12-30 14:47 - 2014-01-03 13:52 - 00000560 _____ C:\Windows\setupact.log
2013-12-30 14:47 - 2013-12-30 14:47 - 00000000 _____ C:\Windows\setuperr.log
2013-12-30 14:45 - 2013-12-30 14:45 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (2).exe
2013-12-30 14:34 - 2013-12-30 14:34 - 00096108 _____ C:\Users\Besitzer\Documents\6.reg
2013-12-30 14:33 - 2013-12-30 14:33 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-30 14:31 - 2013-12-30 14:32 - 04645232 _____ (Piriform Ltd) C:\Users\Besitzer\Downloads\ccsetup409.exe
2013-12-27 23:08 - 2013-12-27 23:08 - 00000000 ____D C:\Program Files (x86)\LucasArts
2013-12-22 21:20 - 2013-12-22 21:20 - 00000000 ____D C:\Users\Besitzer\Desktop\Spiele
2013-12-14 12:26 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-14 12:26 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-14 12:26 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-14 12:26 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-14 12:24 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-14 12:24 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-14 12:24 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-14 12:24 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-14 12:24 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-14 12:24 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-14 12:24 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-14 12:24 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-14 12:24 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-14 12:24 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-14 12:24 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-14 12:24 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-14 12:24 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-14 12:24 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-14 12:24 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-14 12:24 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-14 12:24 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-14 12:24 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-14 12:24 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-14 12:24 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-14 12:24 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-14 12:24 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-14 12:24 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-14 12:24 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-14 12:24 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-14 12:24 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-14 12:24 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-14 12:24 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-14 12:24 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-14 12:24 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-14 12:24 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-13 23:25 - 2013-12-30 14:21 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2013-12-13 23:25 - 2013-12-13 23:25 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-12-13 23:22 - 2014-01-03 18:50 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Overwolf
2013-12-13 22:00 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-13 22:00 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-13 22:00 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-13 21:59 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-13 21:59 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-13 21:59 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-13 21:59 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-13 21:57 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-13 21:57 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-13 21:56 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-13 21:56 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-13 21:56 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-13 21:56 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-13 21:56 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-13 21:56 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-13 21:56 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-13 21:56 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-13 21:56 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-13 21:56 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-08 16:26 - 2013-12-08 16:25 - 00103736 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-07 13:04 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-07 12:59 - 2013-12-07 12:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-07 12:59 - 2013-12-07 12:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-07 12:59 - 2013-12-07 12:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-07 12:59 - 2013-12-07 12:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-07 12:59 - 2013-12-07 12:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
==================== One Month Modified Files and Folders =======
2014-01-03 23:57 - 2013-11-16 15:17 - 00013559 _____ C:\Users\Besitzer\Downloads\FRST.txt
2014-01-03 23:56 - 2014-01-03 23:56 - 01931750 _____ (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe
2014-01-03 23:50 - 2013-04-13 16:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Skype
2014-01-03 23:49 - 2013-02-01 18:00 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-03 23:47 - 2014-01-03 23:47 - 00987410 _____ C:\Users\Besitzer\Downloads\SecurityCheck (1).exe
2014-01-03 23:33 - 2013-09-28 22:16 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Spotify
2014-01-03 22:53 - 2009-07-14 05:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 22:53 - 2009-07-14 05:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 22:49 - 2013-05-25 18:25 - 01355624 _____ C:\Windows\WindowsUpdate.log
2014-01-03 19:16 - 2013-02-01 18:31 - 00000000 ____D C:\Users\Besitzer\AppData\Local\PMB Files
2014-01-03 19:15 - 2013-02-01 18:31 - 00000000 ____D C:\ProgramData\PMB Files
2014-01-03 18:53 - 2014-01-03 18:53 - 02347384 _____ (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (2).exe
2014-01-03 18:51 - 2013-01-28 12:07 - 00000000 ____D C:\Users\Besitzer\Documents\Youcam
2014-01-03 18:50 - 2013-12-13 23:22 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Overwolf
2014-01-03 18:50 - 2013-09-28 22:18 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Spotify
2014-01-03 18:50 - 2013-02-01 18:00 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-03 18:50 - 2013-01-28 11:57 - 00062864 _____ C:\Users\Besitzer\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-03 13:57 - 2013-01-28 21:22 - 01515692 _____ C:\Windows\system32\perfh007.dat
2014-01-03 13:57 - 2013-01-28 21:22 - 00406602 _____ C:\Windows\system32\perfc007.dat
2014-01-03 13:57 - 2009-07-14 06:13 - 00005414 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 13:52 - 2013-12-30 14:47 - 00000560 _____ C:\Windows\setupact.log
2014-01-03 13:52 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 13:52 - 2009-07-14 05:45 - 00292360 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-02 23:00 - 2014-01-02 23:00 - 00002138 _____ C:\Users\Public\Desktop\Rise Of Nations.lnk
2014-01-02 22:56 - 2013-04-04 23:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2014-01-02 15:45 - 2013-02-17 17:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\TS3Client
2014-01-02 15:33 - 2014-01-02 15:33 - 00000628 _____ C:\Users\Besitzer\Desktop\JRT.txt
2014-01-02 15:27 - 2014-01-02 15:27 - 01036305 _____ (Thisisu) C:\Users\Besitzer\Downloads\JRT (1).exe
2014-01-02 15:09 - 2014-01-02 15:09 - 00000000 __SHD C:\found.000
2014-01-02 15:04 - 2013-11-17 13:47 - 00000000 ____D C:\AdwCleaner
2014-01-02 15:01 - 2014-01-02 15:01 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (3).exe
2014-01-02 14:42 - 2014-01-02 14:41 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup-1.75.0.1300 (1).exe
2014-01-01 13:28 - 2014-01-01 13:28 - 00000546 _____ C:\Windows\PFRO.log
2014-01-01 13:18 - 2014-01-01 13:18 - 00023546 _____ C:\ComboFix.txt
2014-01-01 13:18 - 2014-01-01 13:08 - 00000000 ____D C:\Qoobox
2014-01-01 13:17 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-01 13:07 - 2014-01-01 13:06 - 05160176 ____R (Swearware) C:\Users\Besitzer\Downloads\ComboFix.exe
2014-01-01 13:07 - 2013-06-10 12:47 - 00000000 ____D C:\Windows\erdnt
2013-12-31 20:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-12-31 20:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-31 18:22 - 2013-11-16 15:18 - 00027785 _____ C:\Users\Besitzer\Downloads\Addition.txt
2013-12-31 16:30 - 2013-11-01 12:34 - 00021840 ____T C:\Windows\SysWOW64\SIntfNT.dll
2013-12-31 16:30 - 2013-11-01 12:34 - 00017212 ____T C:\Windows\SysWOW64\SIntf32.dll
2013-12-31 16:30 - 2013-11-01 12:34 - 00012067 ____T C:\Windows\SysWOW64\SIntf16.dll
2013-12-31 01:23 - 2013-04-04 14:39 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-30 14:47 - 2013-12-30 14:47 - 00000000 _____ C:\Windows\setuperr.log
2013-12-30 14:45 - 2013-12-30 14:45 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (2).exe
2013-12-30 14:34 - 2013-12-30 14:34 - 00096108 _____ C:\Users\Besitzer\Documents\6.reg
2013-12-30 14:33 - 2013-12-30 14:33 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-30 14:33 - 2013-02-01 18:04 - 00000000 ____D C:\Program Files\CCleaner
2013-12-30 14:32 - 2013-12-30 14:31 - 04645232 _____ (Piriform Ltd) C:\Users\Besitzer\Downloads\ccsetup409.exe
2013-12-30 14:21 - 2013-12-13 23:25 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2013-12-30 14:21 - 2013-01-28 11:32 - 00000000 ____D C:\Users\Besitzer
2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat
2013-12-30 14:20 - 2013-01-28 11:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-30 13:58 - 2013-01-28 21:23 - 00000000 ____D C:\Windows\panther
2013-12-27 23:08 - 2013-12-27 23:08 - 00000000 ____D C:\Program Files (x86)\LucasArts
2013-12-26 11:03 - 2013-05-05 12:08 - 00000000 ____D C:\Users\Besitzer\Desktop\Musik
2013-12-24 22:05 - 2013-04-05 20:00 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-24 12:08 - 2013-04-13 16:49 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-24 12:08 - 2013-04-13 16:49 - 00000000 ____D C:\ProgramData\Skype
2013-12-22 21:23 - 2013-05-05 12:10 - 00000000 ___RD C:\Users\Besitzer\Desktop\Anwendungen
2013-12-22 21:21 - 2013-05-05 12:08 - 00000000 ____D C:\Users\Besitzer\Desktop\Bilder
2013-12-22 21:21 - 2013-05-05 12:07 - 00000000 ____D C:\Users\Besitzer\Desktop\Dokumente
2013-12-22 21:20 - 2013-12-22 21:20 - 00000000 ____D C:\Users\Besitzer\Desktop\Spiele
2013-12-15 18:26 - 2013-08-16 22:42 - 00000000 ____D C:\Windows\system32\MRT
2013-12-15 18:24 - 2013-06-09 15:45 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-15 12:34 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-13 23:25 - 2013-12-13 23:25 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-12-08 16:53 - 2013-12-01 13:59 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Xfire
2013-12-08 16:25 - 2013-12-08 16:26 - 00103736 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-08 12:44 - 2013-02-01 18:00 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 12:44 - 2013-02-01 18:00 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-08 12:22 - 2013-12-01 13:58 - 00000000 ____D C:\ProgramData\Xfire
2013-12-08 12:20 - 2013-01-28 11:32 - 00001433 _____ C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-07 23:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-07 12:59 - 2013-12-07 12:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-07 12:59 - 2013-12-07 12:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-07 12:59 - 2013-12-07 12:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-07 12:59 - 2013-12-07 12:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-07 12:59 - 2013-12-07 12:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-07 12:59 - 2013-12-07 12:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-07 12:59 - 2013-12-07 12:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-06 20:46 - 2013-02-01 18:01 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-06 20:35 - 2013-01-28 11:32 - 00000000 ____D C:\Users\Besitzer\AppData\Local\VirtualStore
Some content of TEMP:
====================
C:\Users\Besitzer\AppData\Local\Temp\EBU20CB.DLL
C:\Users\Besitzer\AppData\Local\Temp\EBU703.EXE
C:\Users\Besitzer\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-31 20:03
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
Ja leider habe ich immer noch die gleichen Probleme wie oben beschrieben