Na Ihr seid ja gründlich, das muss ich schon sagen.
;)
Leider ist gestern wieder ein Popup (kann nicht abgespielt werden, neuer Videoplayer ist notwendig bla, Flashfake wird wieder angeboten - diesmal in der Optik identisch mit dem Original aber im Text immer noch leichtere Übersetzungsfehler) aufgetreten. Ein schneller Scan auf eigene Faust (darf ich das während ich hier in "Behandlung" bin?) mit Adw brachte einige Dateien, die genau da liegen, wo (das nun zum dritten Mal installlierte) Classic-Shell liegt. Das kann doch aber schlecht sein - von offizieller Seite runtergezogen, millionenfach verwendet usw.. Möglicherweise verhält sich Classic-Shell wie ein Trojaner?
Ich habe also erstmal nix über AdwCleaner gelöscht, weil das ständige Neuinstallieren von Classic-Shell nervt (und ich ohne es nicht arbeiten kann - es gab jedoch vorher ein Jahr lang keine Bedrohung mit Classicshell und der zweite Rechner (XP) hat exakt die selben Popups auch ohne Classic-Shell).
adw14.txt:
Code:
# AdwCleaner v3.205 - Bericht erstellt am 05/05/2014 um 21:20:13
# Aktualisiert 28/04/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Papa - SIEMI
# Gestartet von : C:\Users\Papa\Desktop\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gefunden : C:\Users\Papa\AppData\Local\Temp\OCS ###########(Anmerkung Aaron666 hier liegt Classic Shell drinne)##########
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\OCS
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
*************************
AdwCleaner[R0].txt - [10615 octets] - [26/04/2014 20:10:30]
AdwCleaner[R10].txt - [1480 octets] - [29/04/2014 19:49:22]
AdwCleaner[R11].txt - [1541 octets] - [01/05/2014 00:03:11]
AdwCleaner[R12].txt - [1602 octets] - [03/05/2014 13:05:21]
AdwCleaner[R13].txt - [1663 octets] - [03/05/2014 13:08:10]
AdwCleaner[R14].txt - [943 octets] - [05/05/2014 21:20:13]
AdwCleaner[R1].txt - [893 octets] - [26/04/2014 20:15:59]
AdwCleaner[R2].txt - [1011 octets] - [26/04/2014 20:20:31]
AdwCleaner[R3].txt - [1033 octets] - [26/04/2014 20:25:43]
AdwCleaner[R4].txt - [1057 octets] - [26/04/2014 20:34:08]
AdwCleaner[R5].txt - [1118 octets] - [26/04/2014 20:37:50]
AdwCleaner[R6].txt - [1274 octets] - [26/04/2014 20:58:08]
AdwCleaner[R7].txt - [1298 octets] - [26/04/2014 21:01:56]
AdwCleaner[R8].txt - [1358 octets] - [26/04/2014 21:07:41]
AdwCleaner[R9].txt - [1419 octets] - [29/04/2014 00:32:06]
AdwCleaner[S0].txt - [8383 octets] - [26/04/2014 20:12:41]
AdwCleaner[S1].txt - [953 octets] - [26/04/2014 20:17:15]
AdwCleaner[S2].txt - [1043 octets] - [26/04/2014 20:28:15]
AdwCleaner[S3].txt - [1285 octets] - [26/04/2014 21:00:01]
AdwCleaner[S4].txt - [1724 octets] - [03/05/2014 13:08:47]
########## EOF - C:\AdwCleaner\AdwCleaner[R14].txt - [1841 octets] ##########
Ich hatte nun einige Tage Ruhe mit Popups. War das Zufall? Ist das ein Rückfall oder immer noch das selbe Problem? Kommt mir auch so vor, als wenn ich mir die Popups immer wieder auf der gleichen Seite hole (hxxp://minecraft-de.gamepedia.com/Minecraft_Wiki) auf der die gesamte Family momentan häufig surft. Dort kommen dann immer wieder diese lästigen Popups, kann aber auch daran liegen, dass wir uns dort oft aufhalten und es eben deswegen da auffällt. Nur komisch, dass es jetzt ein paar Tage ruhiger war. Irgendetwas wurde "gefühlt" wieder aktiviert. Kann ich irgendwo im browser sonst auch diese Verschlimmbesserungspopups ausschalten, falls das Prob nur rein optisch ist?
Danach startete ich also einigermaßen besorgt mit Eset.
Das Problem ist, dass Eset-Onlinescaner nach einem Abend und einer Nacht nur bei etwa 15% der Platte(-n + eine externe + ein Stick) ist. Sollte der Energiesparmodus vielleicht abgeschaltet werden? Immerhin bin ich ohne Firewall online etc. und der Rechner möchte ja auch mal seine Ruhe. Allein jetzt während ich hier schreibe, schaffte er den Sprung von 15 auf 20%. Das riecht mir doch sehr nach "ich arbeite nur, solange man mich aktiv hält".
Hab den Verdacht, dass er nach ein paar Minuten immer nix mehr tut, denn die Platte rödelt dann nicht mehr (keine Geräusche, keine Lichtblitze an der Decke des Schlafzimmers mehr etc. wie am Anfang, wenn man grad am PC nachschaute ;)). Kann doch net sein, dass es so lange dauert oder?? Dann brauche ich ja drei Tage....
Musste abbrechen gestern und einen zweiten Scan starten, weil ich dran arbeiten wollte.
Edit heute morgen:
Energiesparmodus musste definitiv ausgeschaltet werden, erst dann klappte es - war eben in ca. 40 Minuten mit den letzten 80% durch. Das sollte man vielleicht als Tip an alle "Win8 mit Energiesparmodus"-User ausgeben. ;)
log.txt (neu) nach über 8h letzter Scan/ 12h insgesamter (ineffektiver) und davon etwa 50 Minuten effektiver Scanarbeit insgesamt:
CODE]ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=09340e7865fcb4439dadaab9167d943e
# engine=18141
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-05 04:07:51
# local_time=2014-05-05 06:07:51 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=5893 16776573 100 94 3550 16652000 0 0
# scanned=8409
# found=0
# cleaned=0
# scan_time=2933
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=09340e7865fcb4439dadaab9167d943e
# engine=18144
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-06 04:59:35
# local_time=2014-05-06 06:59:35 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=5893 16776573 100 94 35350 16698304 0 0
# scanned=226227
# found=2
# cleaned=0
# scan_time=30391
sh=1FE4C40BD300B7B6873115CD82EA4A4DACC1BED7 ft=0 fh=0000000000000000 vn="SWF/Exploit.CVE-2014-0322.A Trojaner" ac=I fn="C:\Users\Papa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6VEOQV9S\Q0THwdn-WaGBXZ8K2VrirA-3Z1T4lgg1fz1o6HQqkr3bSH-XIUXoa2_5JEgukrR4V-61oD6v3ao=[1].htm"
sh=D26C110E5A9524AED73C2BB3579CB79A7E4F3AC4 ft=0 fh=0000000000000000 vn="JS/Exploit.Agent.NGQ Trojaner" ac=I fn="C:\Users\Papa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DI1ZPYDR\g2t281qxcj[1].htm"
[/CODE]
Also da wurden zwei Dateien gefunden. Da ich sie nicht bereinigen sollten, müssten sie ja noch drauf sein. Warum sollte ich sie eigentlich nicht entfernen? Kommt das im nächsten Schritt?
Habe nun alles wieder deinstalliert wie beschrieben.
Dann Checkup ausgeführt.
ckeckup.txt
Code:
Results of screen317's Security Check version 0.99.82
x64 (UAC is enabled)
Internet Explorer 10 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Defender
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 55
Adobe Reader XI
````````Process Check: objlist.exe by Laurent````````
Windows Defender MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
Der Windoof Smartscreen wollte FRST verhindern, musste es ein paar mal versuchen und erzwingen. Warum trat das Problem eigentlich nicht bei den dreiundachtzig vorhergehenden FRST-Scans auf? FRST von Filepony solte doch aber sauber sein oder?
FRST.txt
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2014
Ran by Papa (administrator) on SIEMI on 06-05-2014 07:25:41
Running from C:\Users\Papa\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-07-02] (Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {643D121D-A3A5-4688-889C-D2D7CF18C4DB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM - {643D121D-A3A5-4688-889C-D2D7CF18C4DB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - DefaultScope {643D121D-A3A5-4688-889C-D2D7CF18C4DB} URL =
SearchScopes: HKCU - {643D121D-A3A5-4688-889C-D2D7CF18C4DB} URL =
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
==================== Services (Whitelisted) =================
R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-04-29] (CyberGhost S.R.L)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [659600 2012-08-01] (Acer Incorporated)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-07-19] (Intel Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
S2 0085951363511697mcinstcleanup; C:\Users\Papa\AppData\Local\Temp\008595~1.EXE -cleanup -nolog [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R3 e1cexpress; C:\Windows\system32\DRIVERS\e1c63x64.sys [498032 2012-07-12] (Intel Corporation)
S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-02-26] (LogMeIn Inc.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S4 nvpciflt; \SystemRoot\system32\DRIVERS\nvpciflt.sys [X]
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-06 07:25 - 2014-05-06 07:25 - 00008412 _____ () C:\Users\Papa\Desktop\FRST.txt
2014-05-06 07:24 - 2014-05-06 07:24 - 02063872 _____ (Farbar) C:\Users\Papa\Desktop\FRST64.exe
2014-05-06 07:20 - 2014-05-06 07:20 - 00855379 _____ () C:\Users\Papa\Desktop\SecurityCheck.exe
2014-05-05 21:49 - 2014-05-05 21:49 - 00001926 _____ () C:\Users\Papa\Desktop\AdwCleaner[R14].txt
2014-05-05 17:12 - 2014-05-05 17:12 - 02347384 _____ (ESET) C:\Users\Papa\Desktop\esetsmartinstaller_deu.exe
2014-05-03 13:49 - 2014-05-03 13:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-05-03 13:18 - 2014-05-03 13:18 - 00000000 ____D () C:\Windows\ERUNT
2014-05-03 13:04 - 2014-05-03 13:04 - 01310621 _____ () C:\Users\Papa\Desktop\adwcleaner.exe
2014-05-03 12:48 - 2014-05-03 13:02 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-03 12:48 - 2014-05-03 12:48 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-03 12:48 - 2014-05-03 12:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-03 12:47 - 2014-05-03 12:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-03 12:47 - 2014-05-03 12:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-03 12:47 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-03 12:47 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-03 12:47 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-02 20:22 - 2014-04-29 16:14 - 19275264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-02 20:22 - 2014-04-29 14:47 - 14357504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-02 20:22 - 2014-04-29 14:36 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-02 20:22 - 2014-04-29 14:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 20:26 - 2014-05-06 07:17 - 00000000 ____D () C:\Users\Papa\AppData\Roaming\ClassicShell
2014-05-01 20:26 - 2014-05-01 20:26 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-05-01 19:53 - 2014-05-01 19:53 - 00001256 _____ () C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ClassicStartMenu.lnk
2014-05-01 19:39 - 2014-05-01 19:48 - 00000000 ____D () C:\Qoobox
2014-05-01 19:39 - 2014-05-01 19:47 - 00000000 ____D () C:\Windows\erdnt
2014-05-01 19:39 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-01 19:39 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-01 19:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-01 19:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-01 19:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-01 19:39 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-05-01 19:39 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-01 19:39 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-01 19:39 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-30 22:53 - 2014-04-30 23:03 - 00000000 ____D () C:\Users\Papa\AppData\Local\CyberGhost
2014-04-30 22:52 - 2014-04-30 23:03 - 00000000 ____D () C:\Program Files\CyberGhost 5
2014-04-30 22:52 - 2014-04-30 22:53 - 00000000 ____D () C:\Program Files\TAP-Windows
2014-04-30 22:52 - 2014-04-30 22:52 - 00001732 _____ () C:\Users\Papa\Desktop\CyberGhost 5.lnk
2014-04-30 22:52 - 2014-04-30 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
2014-04-30 21:49 - 2014-04-30 21:49 - 00009728 ___SH () C:\Users\Papa\Desktop\Thumbs.db
2014-04-30 21:31 - 2014-05-06 07:25 - 00000000 ____D () C:\FRST
2014-04-28 21:18 - 2014-04-28 21:18 - 00675988 _____ () C:\Users\Papa\Desktop\Minecraft.exe
2014-04-26 21:38 - 2014-04-26 21:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-26 21:38 - 2014-04-26 21:37 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-26 21:38 - 2014-04-26 21:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-26 21:38 - 2014-04-26 21:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-26 21:37 - 2014-04-26 21:37 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-26 20:53 - 2014-04-29 00:26 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-26 20:10 - 2014-05-05 21:20 - 00000000 ____D () C:\AdwCleaner
2014-04-26 19:04 - 2014-04-26 20:12 - 00001064 _____ () C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-04-20 10:17 - 2014-04-20 10:17 - 00284864 _____ (IvoSoft) C:\Windows\system32\StartMenuHelper64.dll
2014-04-20 10:17 - 2014-04-20 10:17 - 00244928 _____ (IvoSoft) C:\Windows\SysWOW64\StartMenuHelper32.dll
2014-04-19 17:29 - 2014-04-19 17:29 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-13 00:28 - 2014-04-13 00:28 - 00000000 ____D () C:\Users\Papa\AppData\Local\LogMeIn
2014-04-13 00:28 - 2014-04-13 00:28 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-04-12 23:41 - 2014-04-26 21:38 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-12 23:37 - 2014-04-12 23:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-12 08:36 - 2014-03-07 02:48 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-12 08:36 - 2014-03-07 02:48 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-12 08:36 - 2014-03-07 02:47 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-12 08:36 - 2014-03-07 02:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-12 08:36 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-12 08:36 - 2014-03-07 02:08 - 02240000 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-12 08:36 - 2014-03-07 02:08 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-12 08:36 - 2014-03-07 02:08 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-12 08:36 - 2014-03-07 02:08 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-12 08:36 - 2014-02-04 01:56 - 00332632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-12 08:36 - 2014-02-04 01:56 - 00278872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-12 08:36 - 2014-01-31 05:55 - 00209712 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-04-12 08:36 - 2014-01-31 02:48 - 00564736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-04-12 08:36 - 2014-01-31 02:48 - 00485888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSDApi.dll
2014-04-12 08:36 - 2014-01-31 02:48 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2014-04-12 08:36 - 2014-01-31 02:48 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-12 08:36 - 2014-01-31 02:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-04-12 08:36 - 2014-01-31 02:06 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2014-04-12 08:36 - 2014-01-31 02:06 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-12 08:36 - 2014-01-27 05:42 - 02232664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-04-12 08:36 - 2014-01-27 05:39 - 01939288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-12 08:36 - 2014-01-27 02:52 - 17561088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-04-12 08:36 - 2014-01-27 02:31 - 19752448 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-04-12 08:36 - 2014-01-27 01:17 - 00386722 _____ () C:\Windows\system32\ApnDatabase.xml
2014-04-12 08:36 - 2014-01-16 01:42 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-04-12 08:36 - 2014-01-11 08:48 - 05979648 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-04-12 08:36 - 2014-01-11 07:06 - 05092352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-04-12 08:36 - 2014-01-03 01:35 - 00365568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-04-12 08:36 - 2014-01-03 01:32 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-04-12 08:36 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-04-12 08:36 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-04-12 08:36 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-04-12 08:36 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-12 08:36 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-12 08:36 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-12 08:36 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-04-12 08:36 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-12 08:36 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-12 08:36 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-12 08:35 - 2014-03-07 02:47 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-12 08:35 - 2014-03-07 02:47 - 02049536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-12 08:35 - 2014-03-07 02:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-04-12 08:35 - 2014-03-07 02:08 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-12 08:35 - 2014-03-07 02:08 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-12 08:35 - 2014-03-07 02:08 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-12 08:35 - 2014-03-07 02:08 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-04-12 08:35 - 2014-03-07 02:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-12 08:35 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-04-12 08:35 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-10 17:27 - 2014-02-06 01:41 - 01257984 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 17:27 - 2014-02-06 01:41 - 00978432 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-04-10 17:27 - 2014-02-06 01:26 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-04-10 17:27 - 2014-02-06 01:19 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-07 20:07 - 2014-04-07 20:07 - 00000146 _____ () C:\Users\Papa\Desktop\Für Antje.lnk
==================== One Month Modified Files and Folders =======
2014-05-06 07:25 - 2014-05-06 07:25 - 00008412 _____ () C:\Users\Papa\Desktop\FRST.txt
2014-05-06 07:25 - 2014-04-30 21:31 - 00000000 ____D () C:\FRST
2014-05-06 07:24 - 2014-05-06 07:24 - 02063872 _____ (Farbar) C:\Users\Papa\Desktop\FRST64.exe
2014-05-06 07:20 - 2014-05-06 07:20 - 00855379 _____ () C:\Users\Papa\Desktop\SecurityCheck.exe
2014-05-06 07:17 - 2014-05-01 20:26 - 00000000 ____D () C:\Users\Papa\AppData\Roaming\ClassicShell
2014-05-06 07:12 - 2012-12-15 14:15 - 01174813 _____ () C:\Windows\WindowsUpdate.log
2014-05-06 07:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-05-05 21:51 - 2013-06-02 14:06 - 00000000 ____D () C:\Users\Papa\AppData\Roaming\.minecraft
2014-05-05 21:49 - 2014-05-05 21:49 - 00001926 _____ () C:\Users\Papa\Desktop\AdwCleaner[R14].txt
2014-05-05 21:20 - 2014-04-26 20:10 - 00000000 ____D () C:\AdwCleaner
2014-05-05 17:12 - 2014-05-05 17:12 - 02347384 _____ (ESET) C:\Users\Papa\Desktop\esetsmartinstaller_deu.exe
2014-05-05 17:11 - 2012-09-08 10:06 - 00751892 _____ () C:\Windows\system32\perfh007.dat
2014-05-05 17:11 - 2012-09-08 10:06 - 00155620 _____ () C:\Windows\system32\perfc007.dat
2014-05-05 17:11 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-04 13:31 - 2012-12-28 20:58 - 00000000 ____D () C:\Users\Papa\AppData\Local\CrashDumps
2014-05-03 13:50 - 2014-05-03 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-05-03 13:50 - 2013-06-08 18:40 - 00000000 ____D () C:\Program Files\Classic Shell
2014-05-03 13:46 - 2013-12-10 21:38 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-03 13:46 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-03 13:18 - 2014-05-03 13:18 - 00000000 ____D () C:\Windows\ERUNT
2014-05-03 13:09 - 2012-08-02 17:04 - 00050264 _____ () C:\Windows\PFRO.log
2014-05-03 13:04 - 2014-05-03 13:04 - 01310621 _____ () C:\Users\Papa\Desktop\adwcleaner.exe
2014-05-03 13:02 - 2014-05-03 12:48 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-03 12:48 - 2014-05-03 12:48 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-03 12:48 - 2014-05-03 12:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-03 12:48 - 2014-05-03 12:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-03 12:47 - 2014-05-03 12:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-01 20:26 - 2014-05-01 20:26 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-05-01 19:53 - 2014-05-01 19:53 - 00001256 _____ () C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ClassicStartMenu.lnk
2014-05-01 19:48 - 2014-05-01 19:39 - 00000000 ____D () C:\Qoobox
2014-05-01 19:48 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-05-01 19:47 - 2014-05-01 19:39 - 00000000 ____D () C:\Windows\erdnt
2014-05-01 19:46 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-05-01 19:44 - 2012-07-26 07:26 - 57671680 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-05-01 19:44 - 2012-07-26 07:26 - 12320768 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-05-01 19:44 - 2012-07-26 07:26 - 00786432 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-05-01 19:44 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-05-01 19:44 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-05-01 19:43 - 2012-07-26 10:08 - 04866048 _____ () C:\Windows\system32\config\DRIVERS.bak
2014-05-01 09:56 - 2012-12-15 14:23 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-768443793-1239807132-3807941381-1002
2014-04-30 23:03 - 2014-04-30 22:53 - 00000000 ____D () C:\Users\Papa\AppData\Local\CyberGhost
2014-04-30 23:03 - 2014-04-30 22:52 - 00000000 ____D () C:\Program Files\CyberGhost 5
2014-04-30 22:53 - 2014-04-30 22:52 - 00000000 ____D () C:\Program Files\TAP-Windows
2014-04-30 22:52 - 2014-04-30 22:52 - 00001732 _____ () C:\Users\Papa\Desktop\CyberGhost 5.lnk
2014-04-30 22:52 - 2014-04-30 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
2014-04-30 21:49 - 2014-04-30 21:49 - 00009728 ___SH () C:\Users\Papa\Desktop\Thumbs.db
2014-04-29 16:14 - 2014-05-02 20:22 - 19275264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 14:47 - 2014-05-02 20:22 - 14357504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:36 - 2014-05-02 20:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:25 - 2014-05-02 20:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-29 00:26 - 2014-04-26 20:53 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-28 21:21 - 2012-12-15 18:33 - 00004250 _____ () C:\Users\Papa\Desktop\Neues Textdokument.txt
2014-04-28 21:18 - 2014-04-28 21:18 - 00675988 _____ () C:\Users\Papa\Desktop\Minecraft.exe
2014-04-27 18:11 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-04-27 17:44 - 2012-07-26 09:21 - 00034103 _____ () C:\Windows\setupact.log
2014-04-26 21:38 - 2014-04-12 23:41 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-26 21:37 - 2014-04-26 21:38 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-26 21:37 - 2014-04-26 21:38 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-26 21:37 - 2014-04-26 21:38 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-26 21:37 - 2014-04-26 21:38 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-26 21:37 - 2014-04-26 21:37 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-26 20:17 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-04-26 20:15 - 2012-12-15 14:18 - 00000000 ___RD () C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-26 20:15 - 2012-12-15 14:18 - 00000000 ___RD () C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-26 20:13 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-04-26 20:13 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-04-26 20:12 - 2014-04-26 19:04 - 00001064 _____ () C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-04-23 01:47 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-23 01:47 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-20 10:17 - 2014-04-20 10:17 - 00284864 _____ (IvoSoft) C:\Windows\system32\StartMenuHelper64.dll
2014-04-20 10:17 - 2014-04-20 10:17 - 00244928 _____ (IvoSoft) C:\Windows\SysWOW64\StartMenuHelper32.dll
2014-04-19 17:29 - 2014-04-19 17:29 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-19 17:28 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-04-13 00:28 - 2014-04-13 00:28 - 00000000 ____D () C:\Users\Papa\AppData\Local\LogMeIn
2014-04-13 00:28 - 2014-04-13 00:28 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-04-12 23:37 - 2014-04-12 23:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-12 21:24 - 2012-12-15 14:33 - 00000000 ____D () C:\Games
2014-04-10 17:41 - 2013-08-09 21:33 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 17:40 - 2012-12-18 09:33 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-07 20:07 - 2014-04-07 20:07 - 00000146 _____ () C:\Users\Papa\Desktop\Für Antje.lnk
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-27 18:01
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
Wie geht es weiter?
*Ehrgeiz geweckt ist*