Hallo Schrauber,
hier die neuen Daten:
ESETSmartInstaller@High as downloader log:
Can not read file from internet.ESETSmartInstaller@High as downloader log:
Can not read file from internet.# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=16c5317d8ce322408ef161bb173b523f
# engine=18519
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-06-03 04:56:09
# local_time=2014-06-03 06:56:09 (+0100, Mitteleuropäische Sommerzeit )
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 85208 267191059 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 243874 153401219 0 0
# scanned=205725
# found=7
# cleaned=0
# scan_time=3577
sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\apnic.dll"
sh=1A3F14C0A66F9AF050D1F34FBACBAADC31751A07 ft=1 fh=2704a03a0f47b728 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\apntoolbarinstaller.exe"
sh=4B553651EF610C0614F8393D6C25ABA0A8F09ECA ft=1 fh=92ef1bb072edf568 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\Offercast_AVIRAV7_.exe"
sh=6EDA4285A495C1A690CDD9A93BD440DCB275C970 ft=1 fh=6cd9e736b83741ee vn="Variante von Win32/InstallCore.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\PDFCreator\message.exe"
sh=6B6105C0BF9C8942B523C7BC6279BF1D241909BA ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\temp\InstallFilter64.msi"
sh=377B57B27B3C7265A888FBD6244FA1D1554C869A ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.OHY Trojaner" ac=I fn="C:\Users\Jule\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\2cbfa542-3a83fd02"
sh=EE9717AD935A15AB07DD2E226398C2D9082D8E82 ft=1 fh=b775fe24c08839c1 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Users\Jule\Downloads\avira_free_antivirus_de.exe"
Results of screen317's Security Check version 0.99.83
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java version out of Date!
Adobe Flash Player 13.0.0.214
Adobe Reader 10.1.9
Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Jule (administrator) on PC-JULE on 04-06-2014 07:16:01
Running from C:\Users\Jule\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
() C:\Windows\SysWOW64\DptfParticipantProcessorService.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
() C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
() C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\System32\SnippingTool.exe
(Opera Software) C:\Program Files (x86)\Opera\opera.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\SysWOW64\DptfPolicyLpmServiceHelper.exe
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90832 2012-06-07] (ASUS)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-26] (Intel Corporation)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-05-31] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-05-31] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321584 2012-04-28] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [ASUS Screen Saver Protector] => C:\Windows\AsScrPro.exe [3058304 2012-08-08] (ASUS)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-567887733-519607453-4259938690-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21445248 2014-05-08] (Skype Technologies S.A.)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [215400 2012-06-10] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\Users\Jule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Jule\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Jule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE8D652EF9376CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
SearchScopes: HKCU - URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3320326&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=2&UP=SPB8CA358D-B10A-4803-A5BD-E32782904A97&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120929223739.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120929223739.dll No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101714.dll (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [{2eb5e925-e6f3-498b-b388-aa7afcd1c865}] - C:\Program Files (x86)\best-markit-soft\157.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 DptfParticipantProcessorService; C:\Windows\SysWOW64\DptfParticipantProcessorService.exe [18944 2012-02-20] ()
R2 DptfPolicyConfigTDPService; C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe [19968 2012-02-20] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-05-10] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-11] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2014-03-25] (soft Xpansion)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 DptfDevDram; C:\Windows\System32\DRIVERS\DptfDevDram.sys [107288 2012-02-20] (Intel Corporation)
R3 DptfDevFan; C:\Windows\System32\DRIVERS\DptfDevFan.sys [42776 2012-02-20] (Intel Corporation)
R3 DptfDevGen; C:\Windows\System32\DRIVERS\DptfDevGen.sys [64792 2012-02-20] (Intel Corporation)
R3 DptfDevPch; C:\Windows\System32\DRIVERS\DptfDevPch.sys [96024 2012-02-20] (Intel Corporation)
R3 DptfDevProc; C:\Windows\System32\DRIVERS\DptfDevProc.sys [220952 2012-02-20] (Intel Corporation)
R3 DptfManager; C:\Windows\System32\DRIVERS\DptfManager.sys [357656 2012-02-20] (Intel Corporation)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-04] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz136; \??\C:\Users\Jule\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-04 07:16 - 2014-06-04 07:16 - 00018466 _____ () C:\Users\Jule\Desktop\FRST.txt
2014-06-04 07:14 - 2014-06-04 07:14 - 02068992 _____ (Farbar) C:\Users\Jule\Desktop\FRST64.exe
2014-06-04 00:33 - 2014-06-04 00:33 - 00000960 _____ () C:\Users\Jule\Desktop\SC.txt
2014-06-04 00:29 - 2014-06-04 00:29 - 00854367 _____ () C:\Users\Jule\Desktop\SecurityCheck.exe
2014-06-03 23:59 - 2014-06-03 23:59 - 00002275 _____ () C:\Users\Jule\Desktop\eset.txt
2014-06-02 17:07 - 2014-06-02 17:12 - 02347384 _____ (ESET) C:\Users\Jule\Desktop\esetsmartinstaller_deu.exe
2014-06-02 16:50 - 2008-01-09 12:08 - 695973888 _____ () C:\Users\Jule\Desktop\Keinohrhasen.avi
2014-05-30 21:00 - 2014-05-30 21:00 - 00000624 _____ () C:\Users\Jule\Desktop\JRT.txt
2014-05-30 20:52 - 2014-05-30 20:52 - 01016261 _____ (Thisisu) C:\Users\Jule\Desktop\JRT.exe
2014-05-30 20:46 - 2014-05-30 20:46 - 00001056 _____ () C:\Users\Jule\Desktop\AdwCleaner[S0].txt
2014-05-30 20:41 - 2014-05-30 20:42 - 00000000 ____D () C:\AdwCleaner
2014-05-30 20:39 - 2014-05-30 20:39 - 01327971 _____ () C:\Users\Jule\Desktop\adwcleaner_3.211.exe
2014-05-30 20:38 - 2014-05-30 20:38 - 00001154 _____ () C:\Users\Jule\Desktop\mbam.txt
2014-05-30 20:25 - 2014-06-04 03:02 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-30 20:25 - 2014-05-30 20:25 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-30 20:25 - 2014-05-30 20:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-30 20:25 - 2014-05-30 20:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-30 20:25 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-30 20:25 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-30 20:25 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-30 20:23 - 2014-05-30 20:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Jule\Desktop\mbam-setup-2.0.2.1012.exe
2014-05-27 08:05 - 2014-06-03 07:15 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-05-27 08:05 - 2014-05-27 08:05 - 00027216 _____ () C:\ComboFix.txt
2014-05-27 08:05 - 2014-05-27 08:05 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-27 08:05 - 2014-05-27 08:05 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-27 08:05 - 2014-05-27 08:05 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-27 07:24 - 2014-05-27 08:05 - 00000000 ____D () C:\Qoobox
2014-05-27 07:24 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-27 07:24 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-27 07:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-27 07:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-27 07:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-27 07:24 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-27 07:24 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-27 07:24 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-27 07:23 - 2014-05-27 08:01 - 00000000 ____D () C:\Windows\erdnt
2014-05-27 07:17 - 2014-05-27 07:17 - 05202211 ____R (Swearware) C:\Users\Jule\Desktop\ComboFix.exe
2014-05-25 19:22 - 2014-06-04 07:16 - 00000000 ____D () C:\FRST
2014-05-25 10:49 - 2014-05-25 10:49 - 00009135 _____ () C:\Users\Jule\Desktop\Madagaskarreiseplanung.odt
2014-05-24 18:40 - 2014-05-25 17:28 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\GlarySoft
2014-05-23 22:54 - 2014-05-23 22:54 - 00000000 ____D () C:\Windows\ERUNT
2014-05-23 11:43 - 2014-05-23 11:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-23 11:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-20 17:21 - 2014-05-20 17:21 - 00000000 __SHD () C:\Users\Jule\AppData\Local\EmieUserList
2014-05-20 17:21 - 2014-05-20 17:21 - 00000000 __SHD () C:\Users\Jule\AppData\Local\EmieSiteList
2014-05-19 20:07 - 2014-05-30 17:41 - 00000000 ____D () C:\Users\Jule\Desktop\156CANON
2014-05-19 17:30 - 2014-05-19 17:31 - 01017552 _____ () C:\Windows\Minidump\051914-22152-01.dmp
2014-05-17 21:14 - 2014-05-17 21:14 - 00241011 _____ () C:\Users\Jule\Desktop\received_m_mid_1400311351244_ba1c121899eff31453_0.jpeg
2014-05-16 21:33 - 2014-05-25 15:59 - 00000000 ____D () C:\Users\Jule\Desktop\Fotos für zu Hause
2014-05-16 16:43 - 2014-05-16 18:53 - 00000000 ____D () C:\Users\Jule\Desktop\LEO-Bewerbungen
2014-05-15 23:34 - 2014-03-31 09:35 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-05-15 23:31 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 23:31 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 23:31 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 23:31 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 23:31 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 23:31 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 21:28 - 2014-05-15 21:29 - 00000000 ____D () C:\Users\Jule\Desktop\Fotobüchlein
2014-05-15 17:47 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 17:47 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 17:47 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 17:47 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 17:47 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 17:47 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 17:47 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 17:47 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 17:47 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 17:47 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 17:47 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 17:47 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 17:47 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 17:47 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 17:47 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 17:47 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 17:47 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 17:47 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 17:47 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 17:47 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 17:47 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 17:47 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 17:47 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 17:47 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 17:47 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 17:47 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 17:47 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 17:47 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 17:47 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 17:47 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-15 17:46 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 17:46 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 17:41 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 17:41 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 23:54 - 2014-05-15 19:38 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-12 16:21 - 2014-05-12 16:21 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-12 16:21 - 2014-05-12 16:21 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\Apple Computer
2014-05-12 16:21 - 2014-05-12 16:21 - 00000000 ____D () C:\Users\Jule\AppData\Local\Apple Computer
2014-05-12 16:21 - 2014-05-12 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-12 16:20 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-05-12 16:19 - 2014-05-12 16:20 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-12 16:19 - 2014-05-12 16:20 - 00000000 ____D () C:\Program Files\iTunes
2014-05-12 16:19 - 2014-05-12 16:20 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-12 16:19 - 2014-05-12 16:19 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-05-12 16:19 - 2014-05-12 16:19 - 00000000 ____D () C:\Program Files\iPod
2014-05-12 16:17 - 2014-05-12 16:17 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Users\Jule\AppData\Local\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\ProgramData\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files\Bonjour
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-05-12 16:00 - 2014-05-29 18:33 - 00001017 _____ () C:\Users\Jule\Desktop\Dropbox.lnk
2014-05-12 15:57 - 2014-06-02 16:56 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\DropboxMaster
2014-05-12 15:56 - 2014-05-29 18:33 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-12 15:52 - 2014-05-21 07:14 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-05-12 15:52 - 2014-05-12 15:52 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-05-12 15:52 - 2014-05-12 15:52 - 00000000 ____D () C:\Users\Jule\AppData\Local\Skype
2014-05-12 15:52 - 2014-05-12 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-05-12 15:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-12 15:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-12 15:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-12 15:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-12 15:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-12 15:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-12 15:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-12 15:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-12 15:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-12 15:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-12 15:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-12 15:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-12 15:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-12 15:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-12 15:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-12 15:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-12 15:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-12 15:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-12 15:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-12 15:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-12 15:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-12 15:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-12 15:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-12 15:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-12 15:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-12 15:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-12 15:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-12 15:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-12 15:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-12 15:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-12 15:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-12 15:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-12 15:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-12 15:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-12 15:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-12 15:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-12 15:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-12 15:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-12 15:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-12 15:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-12 15:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-12 15:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-12 15:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-12 15:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
==================== One Month Modified Files and Folders =======
2014-06-04 07:16 - 2014-06-04 07:16 - 00018466 _____ () C:\Users\Jule\Desktop\FRST.txt
2014-06-04 07:16 - 2014-05-25 19:22 - 00000000 ____D () C:\FRST
2014-06-04 07:16 - 2012-09-29 17:20 - 00000000 ____D () C:\Users\Jule\AppData\Local\Temp
2014-06-04 07:14 - 2014-06-04 07:14 - 02068992 _____ (Farbar) C:\Users\Jule\Desktop\FRST64.exe
2014-06-04 07:05 - 2012-09-29 20:26 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\Skype
2014-06-04 06:18 - 2012-10-02 07:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-04 03:02 - 2014-05-30 20:25 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-04 02:19 - 2012-08-08 12:06 - 02053232 _____ () C:\Windows\WindowsUpdate.log
2014-06-04 00:33 - 2014-06-04 00:33 - 00000960 _____ () C:\Users\Jule\Desktop\SC.txt
2014-06-04 00:29 - 2014-06-04 00:29 - 00854367 _____ () C:\Users\Jule\Desktop\SecurityCheck.exe
2014-06-03 23:59 - 2014-06-03 23:59 - 00002275 _____ () C:\Users\Jule\Desktop\eset.txt
2014-06-03 23:49 - 2013-09-12 21:37 - 00000000 ___RD () C:\Users\Jule\Dropbox
2014-06-03 11:42 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-03 11:42 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-03 11:31 - 2012-08-08 12:11 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-06-03 10:07 - 2013-03-28 13:38 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-03 10:07 - 2013-03-28 13:38 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-03 07:15 - 2014-05-27 08:05 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-06-03 02:09 - 2012-09-30 04:43 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\Dropbox
2014-06-02 23:11 - 2012-09-30 08:13 - 00017408 _____ () C:\Windows\system32\rpcnetp.exe
2014-06-02 23:11 - 2012-09-29 17:23 - 00000387 _____ () C:\Users\Jule\AppData\Roaming\sp_data.sys
2014-06-02 20:17 - 2009-07-14 06:51 - 00122714 _____ () C:\Windows\setupact.log
2014-06-02 17:12 - 2014-06-02 17:07 - 02347384 _____ (ESET) C:\Users\Jule\Desktop\esetsmartinstaller_deu.exe
2014-06-02 16:56 - 2014-05-12 15:57 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\DropboxMaster
2014-06-02 16:46 - 2012-09-29 20:08 - 00058288 _____ (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll
2014-06-02 16:46 - 2012-08-08 12:11 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-06-02 16:46 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-02 16:42 - 2011-02-19 06:24 - 00707736 _____ () C:\Windows\system32\perfh007.dat
2014-06-02 16:42 - 2011-02-19 06:24 - 00153104 _____ () C:\Windows\system32\perfc007.dat
2014-06-02 16:42 - 2009-07-14 07:13 - 01622228 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-02 16:00 - 2014-03-25 21:20 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-06-01 19:12 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-01 01:07 - 2012-09-30 04:23 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\SoftGrid Client
2014-05-30 21:00 - 2014-05-30 21:00 - 00000624 _____ () C:\Users\Jule\Desktop\JRT.txt
2014-05-30 20:52 - 2014-05-30 20:52 - 01016261 _____ (Thisisu) C:\Users\Jule\Desktop\JRT.exe
2014-05-30 20:46 - 2014-05-30 20:46 - 00001056 _____ () C:\Users\Jule\Desktop\AdwCleaner[S0].txt
2014-05-30 20:43 - 2012-02-24 03:34 - 00267506 _____ () C:\Windows\PFRO.log
2014-05-30 20:42 - 2014-05-30 20:41 - 00000000 ____D () C:\AdwCleaner
2014-05-30 20:39 - 2014-05-30 20:39 - 01327971 _____ () C:\Users\Jule\Desktop\adwcleaner_3.211.exe
2014-05-30 20:38 - 2014-05-30 20:38 - 00001154 _____ () C:\Users\Jule\Desktop\mbam.txt
2014-05-30 20:25 - 2014-05-30 20:25 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-30 20:25 - 2014-05-30 20:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-30 20:25 - 2014-05-30 20:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-30 20:23 - 2014-05-30 20:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Jule\Desktop\mbam-setup-2.0.2.1012.exe
2014-05-30 17:41 - 2014-05-19 20:07 - 00000000 ____D () C:\Users\Jule\Desktop\156CANON
2014-05-29 18:34 - 2012-09-29 17:21 - 00000000 ___RD () C:\Users\Jule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-29 18:33 - 2014-05-12 16:00 - 00001017 _____ () C:\Users\Jule\Desktop\Dropbox.lnk
2014-05-29 18:33 - 2014-05-12 15:56 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-29 06:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-27 08:05 - 2014-05-27 08:05 - 00027216 _____ () C:\ComboFix.txt
2014-05-27 08:05 - 2014-05-27 08:05 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-27 08:05 - 2014-05-27 08:05 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-27 08:05 - 2014-05-27 08:05 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-27 08:05 - 2014-05-27 07:24 - 00000000 ____D () C:\Qoobox
2014-05-27 08:05 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-05-27 08:01 - 2014-05-27 07:23 - 00000000 ____D () C:\Windows\erdnt
2014-05-27 08:00 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-27 07:59 - 2012-09-29 17:20 - 00000000 ____D () C:\Users\Jule
2014-05-27 07:17 - 2014-05-27 07:17 - 05202211 ____R (Swearware) C:\Users\Jule\Desktop\ComboFix.exe
2014-05-25 17:28 - 2014-05-24 18:40 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\GlarySoft
2014-05-25 16:51 - 2014-03-25 21:21 - 00000000 ____D () C:\temp
2014-05-25 15:59 - 2014-05-16 21:33 - 00000000 ____D () C:\Users\Jule\Desktop\Fotos für zu Hause
2014-05-25 12:51 - 2012-02-24 04:33 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-05-25 12:35 - 2012-02-24 04:33 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2014-05-25 10:49 - 2014-05-25 10:49 - 00009135 _____ () C:\Users\Jule\Desktop\Madagaskarreiseplanung.odt
2014-05-23 22:54 - 2014-05-23 22:54 - 00000000 ____D () C:\Windows\ERUNT
2014-05-23 17:02 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther
2014-05-23 11:43 - 2014-05-23 11:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-23 11:17 - 2014-03-25 21:21 - 78981650 _____ () C:\Windows\system32\SavingsBullFilterService.log
2014-05-21 07:14 - 2014-05-12 15:52 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-05-21 07:14 - 2012-09-29 20:25 - 00000000 ____D () C:\ProgramData\Skype
2014-05-20 17:21 - 2014-05-20 17:21 - 00000000 __SHD () C:\Users\Jule\AppData\Local\EmieUserList
2014-05-20 17:21 - 2014-05-20 17:21 - 00000000 __SHD () C:\Users\Jule\AppData\Local\EmieSiteList
2014-05-19 20:20 - 2012-10-02 07:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-19 20:20 - 2012-09-29 21:58 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-19 20:20 - 2012-09-29 21:58 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-19 17:31 - 2014-05-19 17:30 - 01017552 _____ () C:\Windows\Minidump\051914-22152-01.dmp
2014-05-19 17:30 - 2013-04-25 21:15 - 795579603 _____ () C:\Windows\MEMORY.DMP
2014-05-19 17:30 - 2013-04-25 21:15 - 00000000 ____D () C:\Windows\Minidump
2014-05-17 21:14 - 2014-05-17 21:14 - 00241011 _____ () C:\Users\Jule\Desktop\received_m_mid_1400311351244_ba1c121899eff31453_0.jpeg
2014-05-16 20:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-16 18:53 - 2014-05-16 16:43 - 00000000 ____D () C:\Users\Jule\Desktop\LEO-Bewerbungen
2014-05-15 21:29 - 2014-05-15 21:28 - 00000000 ____D () C:\Users\Jule\Desktop\Fotobüchlein
2014-05-15 19:42 - 2012-09-29 17:21 - 00000000 ___RD () C:\Users\Jule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 19:41 - 2012-09-30 08:18 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.dll
2014-05-15 19:39 - 2012-09-30 08:13 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.exe
2014-05-15 19:38 - 2014-05-13 23:54 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-15 19:30 - 2013-09-03 06:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:29 - 2012-10-01 09:19 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-12 16:21 - 2014-05-12 16:21 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-12 16:21 - 2014-05-12 16:21 - 00000000 ____D () C:\Users\Jule\AppData\Roaming\Apple Computer
2014-05-12 16:21 - 2014-05-12 16:21 - 00000000 ____D () C:\Users\Jule\AppData\Local\Apple Computer
2014-05-12 16:21 - 2014-05-12 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-12 16:20 - 2014-05-12 16:19 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-12 16:20 - 2014-05-12 16:19 - 00000000 ____D () C:\Program Files\iTunes
2014-05-12 16:20 - 2014-05-12 16:19 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-12 16:19 - 2014-05-12 16:19 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-05-12 16:19 - 2014-05-12 16:19 - 00000000 ____D () C:\Program Files\iPod
2014-05-12 16:17 - 2014-05-12 16:17 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Users\Jule\AppData\Local\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\ProgramData\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files\Bonjour
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-05-12 16:17 - 2014-05-12 16:17 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-05-12 16:05 - 2012-10-01 11:38 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-05-12 15:52 - 2014-05-12 15:52 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-05-12 15:52 - 2014-05-12 15:52 - 00000000 ____D () C:\Users\Jule\AppData\Local\Skype
2014-05-12 15:52 - 2014-05-12 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-05-12 15:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-12 07:26 - 2014-05-30 20:25 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-30 20:25 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-30 20:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-09 08:14 - 2014-05-15 17:46 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 17:46 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-09 07:55 - 2013-08-21 12:20 - 00032346 _____ () C:\Users\Public\Desktop\BurnInTest.htm
2014-05-09 07:36 - 2009-07-14 04:34 - 00000597 _____ () C:\Windows\win.ini
2014-05-06 06:40 - 2014-05-15 23:31 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 23:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 23:31 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 23:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 23:31 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 23:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
Some content of TEMP:
====================
C:\Users\Jule\AppData\Local\Temp\avgnt.exe
C:\Users\Jule\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpi43bov.dll
C:\Users\Jule\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-29 18:49
==================== End Of Log ============================
--- --- ---
Die Dateien, die ESET gefunden hat, sind doch jetzt noch auf meinem PC, weil ich den Haken bei "Entdeckte Bedrohungen entfernen" entfernt habe, oder?
Weiterhin vielen Dank!
Julia