Hallo cosinus,
lieben Dank für das Willkommenheißen und Deine Hilfe! Ich verzweifle hier langsam D:
Wow, dass Avira so skrupellos ist, wusste Ich nicht. Danke für die Info. :pfui:
Ich habe vorübergehend AVG installiert, weil Ich merkte, dass beim beim Wiederinstallieren von Avira wieder Probleme entstanden also habe Ich es gleich einmal gelassen. Welche Software Ich nun nehmen soll, weiß ich nicht, bin offen für Empfehlungen ....
Ich poste mal vorhergehende malwarebytes logs MIT FUNDEN Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.02.07.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Neslihan :: NESLIHAN-PC [Administrator]
11.02.2014 23:09:12
mbam-log-2014-02-11 (23-09-12).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 616718
Laufzeit: 43 Minute(n), 4 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 4
C:\Users\Neslihan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M60PQH7Y\Setup[1].exe (PUP.Optional.Glindorus.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Neslihan\Local Settings\Application Data\Bundled software uninstaller\biclient.exe (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows.old\Users\Neslihan\Desktop\office2010\WLX\mini-KMS Activator v1.1 FiNAL.exe (Riskware.Crk) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\$RECYCLE.BIN\S-1-5-21-4071366543-1694281726-3121886136-1000\$RME60RU.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.02.07.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Neslihan :: NESLIHAN-PC [Administrator]
07.02.2014 22:57:09
mbam-log-2014-02-07 (22-57-09).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 213945
Laufzeit: 2 Minute(n), 7 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 2
HKCU\Software\InstalledBrowserExtensions\Crossrider (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Vittalia\AxtanInstaller (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.01.23.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Neslihan :: NESLIHAN-PC [Administrator]
23.01.2014 23:36:39
mbam-log-2014-01-23 (23-36-39).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 212154
Laufzeit: 2 Minute(n), 6 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 2
HKCU\Software\AppDataLow\Software\Crossrider (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\SMARTBAR (PUP.Optional.SnapDo.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 1
HKCU\Software\Smartbar|Publisher (PUP.Optional.SnapDo.A) -> Daten: SnapdoGOblidooYB -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
Das geht also bis zum 23.1. zurück - ältere lass Ich mal? FARBAR'S
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2014
Ran by Neslihan (administrator) on NESLIHAN-PC on 12-02-2014 23:06:57
Running from C:\Users\Neslihan\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) D:\Programme\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Wacom Technology, Corp.) C:\Windows\system32\Pen_Tablet.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(xwidget.com) D:\Programme\XWidget\xwidget.exe
(Spotify Ltd) C:\Users\Neslihan\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVG Technologies CZ, s.r.o.) D:\Programme\AVG\AVG2014\avgui.exe
(Wacom Technology, Corp.) C:\Windows\system32\WTablet\Pen_TabletUser.exe
(Wacom Technology, Corp.) C:\Windows\system32\Pen_Tablet.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\sysWow64\SearchProtocolHost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-03-12] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291128 2013-03-06] (Intel Corporation)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-23] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-10-17] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_UI] - D:\Programme\AVG\AVG2014\avgui.exe [4962320 2014-01-22] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\S-1-5-21-2549670680-3362463661-2922105165-1000\...\Run: [xwidget] - D:\Programme\XWidget\xwidget.exe [1811968 2013-06-09] (xwidget.com)
HKU\S-1-5-21-2549670680-3362463661-2922105165-1000\...\Run: [Spotify Web Helper] - C:\Users\Neslihan\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-22] (Spotify Ltd)
HKU\S-1-5-21-2549670680-3362463661-2922105165-1000\...\MountPoints2: {333018b2-1035-11e3-ad86-806e6f6e6963} - E:\ASRSetup.exe
AppInit_DLLs: C:\PROGRA~2\MOVIES~1\SAFETY~1\x64\SAFETY~2.DLL => File Not Found
AppInit_DLLs-x32: c:\progra~2\movies~1\safety~1\safety~2.dll => File Not Found
Startup: C:\Users\Neslihan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
==================== Internet (Whitelisted) ====================
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Neslihan\AppData\Roaming\Mozilla\Firefox\Profiles\y4ljwfsl.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - D:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @onlive.com/OnLiveGameClientDetector,version=1.0.0 - C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll (OnLive)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Neslihan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Neslihan\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Plugin HKCU: LWAPlugin15.8 - C:\Users\Neslihan\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Neslihan\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Extension: FireFTP - C:\Users\Neslihan\AppData\Roaming\Mozilla\Firefox\Profiles\y4ljwfsl.default\Extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}.xpi [2013-12-23]
FF Extension: Adblock Plus - C:\Users\Neslihan\AppData\Roaming\Mozilla\Firefox\Profiles\y4ljwfsl.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-12]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2013-09-12]
FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Firefox\firefox.exe
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll No File
CHR Plugin: ( "name": "",) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: ( "name": "",) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (OnLive Game Client Detector) - C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll (OnLive)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Unity Player) - C:\Users\Neslihan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Users\Neslihan\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
CHR Plugin: (Microsoft Lync Web App Plug-in) - C:\Users\Neslihan\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
CHR Plugin: (Microsoft Office 2010) - D:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - D:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Extension: (Adblock Plus) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-15]
CHR Extension: (No Name) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\clhambhgmoihmhbfjmmaciggnfcfkflo [2013-12-15]
CHR Extension: (Adobe Acrobat – PDF-Datei erstellen) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2013-09-13]
CHR Extension: (XKit) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfgeeomkfdefkckijiabdbogjkdaecd [2013-11-04]
CHR Extension: (AdBlock) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-04]
CHR Extension: (FabCam) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejilffmihldhlfocnabcgndjjpgadfl [2013-12-15]
CHR Extension: (ProxMate - Proxy on steroids!) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifalmiidchkjjmkkbkoaibpmoeichmki [2013-11-04]
CHR Extension: (No Name) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jklljiahjgoglchglekebfljnmbaleig [2013-12-15]
CHR Extension: (Chat Undetected) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\llmfehnfojojfamjjijjciopbjimcffa [2013-11-04]
CHR Extension: (Google Wallet) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (No Name) - C:\Users\Neslihan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojcflmmmcfpacggndoaaflkmcoblhnbh [2013-12-15]
CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Neslihan\AppData\Local\foxtab_speeddial.crx [2013-10-26]
CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Neslihan\AppData\Local\foxtab_speeddial.crx [2013-10-26]
CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Neslihan\AppData\Local\foxtab_speeddial.crx [2013-10-26]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-12-21]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-01-27] (Adobe Systems)
S2 AVGIDSAgent; D:\Programme\AVG\AVG2014\avgidsagent.exe [3788816 2014-01-22] (AVG Technologies CZ, s.r.o.)
R2 avgwd; D:\Programme\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
S4 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
S4 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-12] (Intel Corporation)
S4 intelsba; C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [48832 2013-01-28] (Intel Corporation)
S4 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [182248 2013-03-14] ()
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
S3 Microsoft SharePoint Workspace Audit Service; D:\Programme\Microsoft Office\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation)
S4 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [239176 2013-02-19] (Realtek Semiconductor)
S2 AntiVirSchedulerService; "D:\Programme\Avira\AntiVir Desktop\sched.exe" [X]
S2 AntiVirService; "D:\Programme\Avira\AntiVir Desktop\avguard.exe" [X]
S4 AntiVirWebService; "D:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]
==================== Drivers (Whitelisted) ====================
S3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2013-09-10] (ASRock Incorporation)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [34640 2012-08-09] (ASRock Inc.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [496400 2013-02-26] (Intel Corporation)
S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2013-09-08] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2013-08-29] (FNet Co., Ltd.)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-22] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21048 2013-03-14] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21048 2013-03-14] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-03-14] ()
R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2011-04-08] (Realtek Semiconductor Corporation )
S3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-09-18] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-12 23:06 - 2014-02-12 23:07 - 00021706 _____ () C:\Users\Neslihan\Desktop\FRST.txt
2014-02-12 23:06 - 2014-02-12 23:06 - 00000000 ____D () C:\FRST
2014-02-12 23:05 - 2014-02-12 23:05 - 00001992 _____ () C:\Users\Neslihan\Desktop\JRT.txt
2014-02-12 23:02 - 2014-02-12 23:02 - 00000000 ____D () C:\Windows\ERUNT
2014-02-12 23:01 - 2014-02-12 23:02 - 02152448 _____ (Farbar) C:\Users\Neslihan\Desktop\FRST64.exe
2014-02-12 23:01 - 2014-02-12 23:01 - 01037530 _____ (Thisisu) C:\Users\Neslihan\Desktop\JRT.exe
2014-02-12 22:59 - 2014-02-12 22:59 - 00000056 _____ () C:\Windows\setupact.log
2014-02-12 22:59 - 2014-02-12 22:59 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-12 22:58 - 2014-02-12 22:58 - 00002738 _____ () C:\Windows\PFRO.log
2014-02-12 22:56 - 2014-02-12 22:57 - 00000000 ____D () C:\AdwCleaner
2014-02-12 22:55 - 2014-02-12 22:55 - 01166132 _____ () C:\Users\Neslihan\Desktop\adwcleaner.exe
2014-02-12 22:46 - 2014-02-12 22:46 - 00009478 _____ () C:\cc_20140212_224637_2.reg
2014-02-12 22:37 - 2014-02-12 22:37 - 00088546 _____ () C:\cc_20140212_223727.reg
2014-02-12 22:36 - 2014-02-12 22:36 - 00000674 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-02-12 22:07 - 2014-02-12 22:07 - 00614792 _____ (Chip Digital GmbH) C:\Users\Neslihan\Downloads\CCleaner - CHIP-Downloader.exe
2014-02-12 21:42 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 21:42 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 21:42 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-12 21:42 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-12 19:39 - 2014-02-12 19:39 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\AVG2014
2014-02-12 19:38 - 2014-02-12 19:38 - 00000734 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-02-12 19:38 - 2014-02-12 19:38 - 00000000 ___HD () C:\$AVG
2014-02-12 19:38 - 2014-02-12 19:38 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\TuneUp Software
2014-02-12 19:38 - 2014-02-12 19:38 - 00000000 ____D () C:\ProgramData\AVG2014
2014-02-12 17:50 - 2014-02-12 21:28 - 00000000 ____D () C:\ProgramData\MFAData
2014-02-12 17:50 - 2014-02-12 21:16 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\Avg2014
2014-02-12 17:50 - 2014-02-12 17:50 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\MFAData
2014-02-12 17:48 - 2014-02-12 17:49 - 04435328 _____ (AVG Technologies) C:\Users\Neslihan\Downloads\avg_avct_stb_all_2014_4158_futuretest2.exe
2014-02-12 17:29 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-12 17:29 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-12 17:29 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-12 17:29 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-12 17:29 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-12 17:29 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-12 17:29 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-12 17:29 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-12 17:29 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-12 17:29 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-12 17:29 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-12 17:29 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-12 17:29 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-12 17:29 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-12 17:29 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-12 17:29 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-12 17:29 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-12 17:29 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-12 17:29 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-12 17:29 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-12 17:29 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-12 17:29 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-12 17:29 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-12 17:29 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-12 17:29 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-12 17:29 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-12 17:29 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-12 17:29 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-12 17:29 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-12 17:29 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-12 17:29 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-12 17:29 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-12 17:29 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-12 17:29 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-12 17:29 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-12 17:29 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-12 17:29 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-12 17:29 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-12 17:29 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-12 17:15 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-12 17:15 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-12 17:14 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 17:14 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 17:14 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-12 17:14 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 17:14 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-12 17:14 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-12 17:14 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-12 17:14 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-12 17:14 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-12 17:14 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-12 17:14 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-12 17:14 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-12 17:14 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-12 17:14 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-12 17:14 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-12 17:14 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-12 17:14 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-12 17:14 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-12 17:14 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-12 17:14 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-12 17:14 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-12 17:14 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-12 17:08 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-12 17:08 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-12 15:21 - 2014-02-12 15:21 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Avira
2014-02-12 14:40 - 2014-02-12 17:03 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-12 14:40 - 2014-02-12 15:16 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-02-12 14:32 - 2014-02-12 14:32 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-01-31 13:32 - 2014-01-31 13:32 - 00001271 _____ () C:\Users\Neslihan\Desktop\DC Universe Online PSG.lnk
2014-01-27 19:03 - 2014-01-27 19:03 - 00000000 ____D () C:\Users\Neslihan\Documents\Updater
2014-01-27 17:57 - 2014-01-27 17:57 - 00000000 ____D () C:\Users\Public\Documents\Adobe PDF
2014-01-27 17:56 - 2014-01-27 17:56 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-01-27 17:56 - 2004-08-17 02:40 - 00016384 _____ () C:\Windows\SysWOW64\FileOps.exe
2014-01-15 14:42 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:42 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:42 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:42 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:42 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:42 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:42 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:42 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:42 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-14 23:48 - 2014-01-14 23:55 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Notepad++
2014-01-14 23:48 - 2014-01-14 23:48 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
==================== One Month Modified Files and Folders =======
2014-02-12 23:07 - 2014-02-12 23:06 - 00021706 _____ () C:\Users\Neslihan\Desktop\FRST.txt
2014-02-12 23:06 - 2014-02-12 23:06 - 00000000 ____D () C:\FRST
2014-02-12 23:06 - 2011-04-12 08:43 - 00658476 _____ () C:\Windows\system32\perfh007.dat
2014-02-12 23:06 - 2011-04-12 08:43 - 00131346 _____ () C:\Windows\system32\perfc007.dat
2014-02-12 23:06 - 2009-07-14 06:13 - 01510528 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-12 23:05 - 2014-02-12 23:05 - 00001992 _____ () C:\Users\Neslihan\Desktop\JRT.txt
2014-02-12 23:03 - 2013-08-29 00:00 - 02075137 _____ () C:\Windows\WindowsUpdate.log
2014-02-12 23:02 - 2014-02-12 23:02 - 00000000 ____D () C:\Windows\ERUNT
2014-02-12 23:02 - 2014-02-12 23:01 - 02152448 _____ (Farbar) C:\Users\Neslihan\Desktop\FRST64.exe
2014-02-12 23:02 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-12 23:02 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-12 23:01 - 2014-02-12 23:01 - 01037530 _____ (Thisisu) C:\Users\Neslihan\Desktop\JRT.exe
2014-02-12 23:00 - 2013-10-17 22:27 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\WTablet
2014-02-12 23:00 - 2013-08-29 08:05 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-12 22:59 - 2014-02-12 22:59 - 00000056 _____ () C:\Windows\setupact.log
2014-02-12 22:59 - 2014-02-12 22:59 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-12 22:59 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-12 22:58 - 2014-02-12 22:58 - 00002738 _____ () C:\Windows\PFRO.log
2014-02-12 22:57 - 2014-02-12 22:56 - 00000000 ____D () C:\AdwCleaner
2014-02-12 22:55 - 2014-02-12 22:55 - 01166132 _____ () C:\Users\Neslihan\Desktop\adwcleaner.exe
2014-02-12 22:48 - 2013-08-29 09:37 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-12 22:46 - 2014-02-12 22:46 - 00009478 _____ () C:\cc_20140212_224637_2.reg
2014-02-12 22:38 - 2013-10-21 23:01 - 00000000 ____D () C:\Program Files (x86)\360
2014-02-12 22:38 - 2013-08-29 08:05 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-12 22:37 - 2014-02-12 22:37 - 00088546 _____ () C:\cc_20140212_223727.reg
2014-02-12 22:36 - 2014-02-12 22:36 - 00000674 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-02-12 22:36 - 2013-10-28 00:12 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\FileZilla
2014-02-12 22:36 - 2013-09-17 12:56 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-02-12 22:36 - 2013-09-08 19:37 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\CrashDumps
2014-02-12 22:36 - 2013-08-29 10:11 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Winamp
2014-02-12 22:36 - 2013-08-29 00:50 - 00000000 ____D () C:\Windows\Panther
2014-02-12 22:36 - 2013-08-28 23:57 - 00000000 ____D () C:\Windows\Minidump
2014-02-12 22:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-12 22:07 - 2014-02-12 22:07 - 00614792 _____ (Chip Digital GmbH) C:\Users\Neslihan\Downloads\CCleaner - CHIP-Downloader.exe
2014-02-12 21:28 - 2014-02-12 17:50 - 00000000 ____D () C:\ProgramData\MFAData
2014-02-12 21:16 - 2014-02-12 17:50 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\Avg2014
2014-02-12 19:39 - 2014-02-12 19:39 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\AVG2014
2014-02-12 19:38 - 2014-02-12 19:38 - 00000734 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-02-12 19:38 - 2014-02-12 19:38 - 00000000 ___HD () C:\$AVG
2014-02-12 19:38 - 2014-02-12 19:38 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\TuneUp Software
2014-02-12 19:38 - 2014-02-12 19:38 - 00000000 ____D () C:\ProgramData\AVG2014
2014-02-12 18:17 - 2013-09-07 21:29 - 00001456 _____ () C:\Users\Neslihan\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2014-02-12 17:50 - 2014-02-12 17:50 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\MFAData
2014-02-12 17:49 - 2014-02-12 17:48 - 04435328 _____ (AVG Technologies) C:\Users\Neslihan\Downloads\avg_avct_stb_all_2014_4158_futuretest2.exe
2014-02-12 17:33 - 2013-09-09 20:29 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-12 17:29 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini
2014-02-12 17:09 - 2013-08-29 09:48 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-12 17:08 - 2013-08-29 09:48 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-12 17:03 - 2014-02-12 14:40 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-12 17:03 - 2013-09-29 22:08 - 00000000 ____D () C:\Users\Neslihan\Documents\xwidget
2014-02-12 17:03 - 2013-09-10 15:33 - 00000000 __RHD () C:\MSOCache
2014-02-12 17:03 - 2013-09-07 23:53 - 00000000 ____D () C:\ProgramData\Avira
2014-02-12 17:03 - 2013-09-07 11:48 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-02-12 17:03 - 2013-08-29 09:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-12 17:03 - 2013-08-29 08:05 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\Google
2014-02-12 17:03 - 2013-08-29 08:05 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-12 17:03 - 2013-08-29 00:06 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\TP-LINK
2014-02-12 17:03 - 2013-08-29 00:00 - 00000000 ____D () C:\Users\Neslihan
2014-02-12 17:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-02-12 17:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-02-12 17:02 - 2013-08-29 00:08 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\Last.fm
2014-02-12 15:21 - 2014-02-12 15:21 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Avira
2014-02-12 15:16 - 2014-02-12 14:40 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-02-12 14:32 - 2014-02-12 14:32 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-02-11 23:06 - 2013-10-26 22:30 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\SoulseekQt
2014-02-06 13:16 - 2014-02-12 17:29 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-12 17:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-12 17:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-12 17:29 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-12 17:29 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-12 17:29 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-12 17:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-12 17:29 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-12 17:29 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-12 17:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-12 17:29 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-12 17:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-12 17:29 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-12 17:29 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-12 17:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-12 17:29 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-12 17:29 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-12 17:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-12 17:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-12 17:29 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-12 17:29 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-12 17:29 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-12 17:29 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-12 17:29 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-12 17:29 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-12 17:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-12 17:29 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-12 17:29 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-12 17:29 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-12 17:29 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-12 17:29 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-12 17:29 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-12 17:29 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-12 17:29 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-12 17:29 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-12 17:29 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-12 17:29 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-12 17:29 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-12 17:29 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-01-31 13:32 - 2014-01-31 13:32 - 00001271 _____ () C:\Users\Neslihan\Desktop\DC Universe Online PSG.lnk
2014-01-29 11:59 - 2009-07-14 05:45 - 05172624 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-28 18:10 - 2013-08-29 07:58 - 00125888 _____ () C:\Users\Neslihan\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-27 19:03 - 2014-01-27 19:03 - 00000000 ____D () C:\Users\Neslihan\Documents\Updater
2014-01-27 19:03 - 2013-08-29 08:08 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Adobe
2014-01-27 19:02 - 2013-08-29 09:36 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\Adobe
2014-01-27 17:57 - 2014-01-27 17:57 - 00000000 ____D () C:\Users\Public\Documents\Adobe PDF
2014-01-27 17:57 - 2013-08-29 08:08 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-01-27 17:57 - 2013-08-29 00:01 - 00000000 ___RD () C:\Users\Neslihan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-27 17:56 - 2014-01-27 17:56 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-01-27 17:56 - 2013-08-29 08:08 - 00000000 ____D () C:\ProgramData\Adobe
2014-01-24 00:02 - 2013-12-19 00:02 - 00000103 _____ () C:\Users\Neslihan\AppData\Roaming\WB.CFG
2014-01-23 22:49 - 2013-09-07 23:38 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Mozilla
2014-01-23 11:19 - 2013-08-29 09:37 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-23 11:19 - 2013-08-29 09:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-23 11:19 - 2013-08-29 09:37 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-22 20:46 - 2013-09-07 17:39 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Spotify
2014-01-22 18:08 - 2013-09-07 17:40 - 00000000 ____D () C:\Users\Neslihan\AppData\Local\Spotify
2014-01-22 12:29 - 2013-09-07 17:40 - 00001768 _____ () C:\Users\Neslihan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-01-15 13:57 - 2013-11-17 12:00 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Skype
2014-01-14 23:55 - 2014-01-14 23:48 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Notepad++
2014-01-14 23:48 - 2014-01-14 23:48 - 00000000 ____D () C:\Users\Neslihan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
Some content of TEMP:
====================
C:\Users\Neslihan\AppData\Local\Temp\4E954E.dll
C:\Users\Neslihan\AppData\Local\Temp\5CBD5C.dll
C:\Users\Neslihan\AppData\Local\Temp\807A80.dll
C:\Users\Neslihan\AppData\Local\Temp\941894.dll
C:\Users\Neslihan\AppData\Local\Temp\AC47AC.dll
C:\Users\Neslihan\AppData\Local\Temp\BC17BC.dll
C:\Users\Neslihan\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 01:13
==================== End Of Log ============================ --- --- ---
--- --- ---
Übrigens dauert es nun auch länger, bis Windows hochfährt. Sonst war er in 4 Sekunden hochgefahren, nun ist es deutlich länger bis zum Loginfenster schwarz.
^ habe den obigen Beitrag editiert, bitte refresh falls nicht schon geschehen
übrigens, beim Versuch die Reste von Avira zu entfernen passiert folgendes: http://i.imgur.com/T6xhlFj.png |