ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=3c73c2e77cda494682f6c3b3267b8fbe
# engine=14089
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-17 10:14:40
# local_time=2013-06-17 12:14:40 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5122 16777213 100 90 8757710 120246676 0 0
# compatibility_mode=5893 16776574 100 94 35421109 123093930 0 0
# scanned=153377
# found=0
# cleaned=0
# scan_time=20175
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=3c73c2e77cda494682f6c3b3267b8fbe
# engine=19058
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-07-07 06:14:27
# local_time=2014-07-07 08:14:27 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 31484 23331625 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 29454744 156386717 0 0
# scanned=333001
# found=34
# cleaned=0
# scan_time=17102
sh=B2AC265EEC4EED9029B2971C4B42A3CA0117CE3B ft=1 fh=c9e1d0648e2c6dec vn="Variante von MSIL/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir"
sh=CD050DC163422C58EED7FA8F8942D861BD9ED6B5 ft=1 fh=73cadc4c7328be1d vn="Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir"
sh=6AFD48E209016E5B0928DA35A0F383206629542E ft=1 fh=800e2df4756163bc vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll. vir"
sh=9D6A05550D4EDAAE21426963E1D7E29B1128E6A3 ft=1 fh=03f53be6abe181a5 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_25.dll. vir"
sh=359650C7CEBE8C147CC3A52B9746AB33F546D259 ft=1 fh=bc065b51744671b9 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll. vir"
sh=AF8E4B402FDD1252B8AD1A6F392E01CE017FCC2D ft=1 fh=1b562d08d2c329d2 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll. vir"
sh=2900AFF2E6279E11CFA1C94202C993EF0999F8E9 ft=1 fh=05be29e2431ae2cc vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll. vir"
sh=ADC5A8D352C6B68C69F1999C71B39F546E0B6A59 ft=1 fh=6a51156b8cffa57a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll. vir"
sh=97C98A20388FD894B92FD8325545966CA945BCFB ft=1 fh=6121d07ea56d1649 vn="Win32/Toolbar.Montiera.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Roaming\OpenCandy\494390F3F45046D08BB65199FB589AE3\Setupsft_chr_p1v7.exe.vir"
sh=29E42A61A6BE387A24C035693D509D873C02D916 ft=1 fh=b326822ef8b4edbf vn="Win32/SpeedUpMyPC.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Roaming\OpenCandy\4E48BBBCBC804BB1BB68B6C2A062FC58\speedupmypcDE.exe.vir"
sh=19DC837674578FA95327EE2C06C906BDFB64C440 ft=1 fh=84d2bf3110b45a14 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Dominik\AppData\Roaming\OpenCandy\D852E17B51F04BA4A77521583625B8D3\Installer.exe.vir"
sh=4B553651EF610C0614F8393D6C25ABA0A8F09ECA ft=1 fh=92ef1bb072edf568 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\offercast_avirav7_.exe"
sh=6AFD48E209016E5B0928DA35A0F383206629542E ft=1 fh=800e2df4756163bc vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default\extensions\{ce7136d5-daf7-d779-42ad-beaf51ba5a0f}\components\SmartbarFireFoxRemotePlugin_24.dll"
sh=9D6A05550D4EDAAE21426963E1D7E29B1128E6A3 ft=1 fh=03f53be6abe181a5 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default\extensions\{ce7136d5-daf7-d779-42ad-beaf51ba5a0f}\components\SmartbarFireFoxRemotePlugin_25.dll"
sh=359650C7CEBE8C147CC3A52B9746AB33F546D259 ft=1 fh=bc065b51744671b9 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default\extensions\{ce7136d5-daf7-d779-42ad-beaf51ba5a0f}\components\SmartbarFireFoxRemotePlugin_26.dll"
sh=AF8E4B402FDD1252B8AD1A6F392E01CE017FCC2D ft=1 fh=1b562d08d2c329d2 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default\extensions\{ce7136d5-daf7-d779-42ad-beaf51ba5a0f}\components\SmartbarFireFoxRemotePlugin_27.dll"
sh=2900AFF2E6279E11CFA1C94202C993EF0999F8E9 ft=1 fh=05be29e2431ae2cc vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default\extensions\{ce7136d5-daf7-d779-42ad-beaf51ba5a0f}\components\SmartbarFireFoxRemotePlugin_28.dll"
sh=ADC5A8D352C6B68C69F1999C71B39F546E0B6A59 ft=1 fh=6a51156b8cffa57a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default\extensions\{ce7136d5-daf7-d779-42ad-beaf51ba5a0f}\components\SmartbarFireFoxRemotePlugin_29.dll"
sh=1ECEAF181DC0006EE76B299E90CC808A55797637 ft=1 fh=32d2465f103c3ca2 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\avira_free_antivirus_de.exe"
sh=F7C72C5EC5334C58465B8A4257978531B19C4098 ft=1 fh=0ab1d01b6bb0271d vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeDownload (1).exe"
sh=897FD37A4F97BA9BBC92108AA1FB16C970EACBF0 ft=1 fh=58662848aaacab1c vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeDownload.exe"
sh=A0D77630EACAFB761BCEAC35F37C218B7F6438C5 ft=1 fh=350d51f8f122a327 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeDownload3131706.exe"
sh=74652BB55B35EAF701B7776753E34D36835EEC6E ft=1 fh=6b672c3a89b6e08f vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeToMP3Converter (1).exe"
sh=F096F3F9B71BD6B746586D3F24F18553BE891AB5 ft=1 fh=fc198236fb3ac7f2 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeToMP3Converter (2).exe"
sh=F096F3F9B71BD6B746586D3F24F18553BE891AB5 ft=1 fh=fc198236fb3ac7f2 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeToMP3Converter (3).exe"
sh=3DF621DDBF63ABE9E8632D73EA87FDED137D71FB ft=1 fh=1c88a728f9455b03 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeToMP3Converter (4).exe"
sh=F7260CE69E39008609AC6570C2013A39315C46F5 ft=1 fh=c8129b0266621a88 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeToMP3Converter.exe"
sh=F7260CE69E39008609AC6570C2013A39315C46F5 ft=1 fh=c8129b0266621a88 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\Downloads\FreeYouTubeToMP3Converter_3.12.1.320.exe"
sh=011C6AC3C584E4650D6FA5FECF6D2E32C50A9457 ft=1 fh=5f9bc7bf4fd4339a vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\m4a-to-mp3-70converter.exe"
sh=F74DEFC00820BA00880E018936AD16226C301A4E ft=1 fh=af16ef21883d2d4c vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Users\Dominik\Downloads\m4a-to-mp3-converter_7.2.exe"
sh=0D2A62F795981098A82524EC17A3D50FAB773246 ft=1 fh=76f1a6e7285ff2db vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\Downloads\OpenOffice - CHIP-Installer.exe"
sh=75157F0BFB6C826800D5B8E27DAC0B240A1DFF69 ft=1 fh=6e3c7280487fb52d vn="MSIL/AdvancedSystemProtector.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\Downloads\rcpsetup_softonic_new_de_pd_new.exe"
sh=40C4AD77BA85766B0B209842E9FD90846F311A87 ft=1 fh=0080ea933fa27dfc vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Dominik\Downloads\SoftonicDownloader_fuer_vlc-media-player.exe"
sh=5DE3C90FFD48803B4E3924FF37DC7EB6E5FC3285 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\5e1604c.msi"
Results of screen317's Security Check version 0.99.85
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
JavaFX 2.1.1
Java 7 Update 55
Java version out of Date!
Adobe Flash Player 13.0.0.214
Flash Player out of Date!
Adobe Reader 10.1.10
Adobe Reader out of Date!
Mozilla Firefox 18.0.2
Firefox out of Date!
Google Chrome 35.0.1916.114
Google Chrome 35.0.1916.153
````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Symantec Norton Online Backup NOBuAgent.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01
Ran by Dominik (administrator) on NICKBUCHBINDER on 07-07-2014 21:00:26
Running from C:\Users\Dominik\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Google Inc.) C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2723624 2011-03-28] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296984 2012-01-05] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-12] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-10-27] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [185896 2013-10-28] (Geek Software GmbH)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-3362895703-2964763858-2143014042-1000\...\Run: [Google Update] => C:\Users\Dominik\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-23] (Google Inc.)
HKU\S-1-5-21-3362895703-2964763858-2143014042-1000\...\Run: [GoogleChromeAutoLaunch_66F8C29980E8EAA9103CEBF5E167BC0C] => C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe [860488 2014-06-05] (Google Inc.)
==================== Internet (Whitelisted) ====================
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 132.199.1.163 132.199.1.2
FireFox:
========
FF ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Dominik\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Dominik\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Snap.Do - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\ajlshcgy.default\Extensions\{ce7136d5-daf7-d779-42ad-beaf51ba5a0f} [2014-05-26]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2013-11-28]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Plugin: (Shockwave Flash) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.225\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Dominik\AppData\Local\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Dominik\AppData\Local\Google\Chrome\Application\35.0.1916.153\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\Dominik\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (AdBlock) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-09-13]
CHR Extension: (Google Wallet) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30]
CHR StartMenuInternet: Google Chrome - C:\Users\Dominik\AppData\Local\Google\Chrome\Application\chrome.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-25] (Avira Operations GmbH & Co. KG)
S3 OXSDIDRV_x64; C:\Windows\System32\DRIVERS\OXSDIDRV_x64.sys [51760 2009-09-28] ()
S3 OXUDIDRV; C:\Windows\system32\Drivers\OXUDIDRV_X64.sys [31280 2010-05-25] ()
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-07 20:59 - 2014-07-07 20:59 - 00000000 ____D () C:\Users\Dominik\Downloads\FRST-OlderVersion
2014-07-07 20:50 - 2014-07-07 20:50 - 00854390 _____ () C:\Users\Dominik\Downloads\SecurityCheck.exe
2014-07-07 15:25 - 2014-07-07 15:25 - 02347384 _____ (ESET) C:\Users\Dominik\Downloads\esetsmartinstaller_deu.exe
2014-07-06 22:33 - 2014-07-06 22:33 - 00001027 _____ () C:\Users\Dominik\Desktop\JRT.txt
2014-07-06 22:14 - 2014-07-06 22:15 - 01016261 _____ (Thisisu) C:\Users\Dominik\Downloads\JRT (1).exe
2014-07-06 22:08 - 2014-07-06 22:08 - 00653808 _____ () C:\Windows\Minidump\070614-30934-01.dmp
2014-07-06 20:33 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-06 20:32 - 2014-07-06 22:03 - 00000000 ____D () C:\AdwCleaner
2014-07-06 20:32 - 2014-07-06 20:32 - 01346519 _____ () C:\Users\Dominik\Downloads\adwcleaner_3.214.exe
2014-07-06 10:27 - 2014-07-06 10:27 - 00656744 _____ () C:\Windows\Minidump\070614-39905-01.dmp
2014-07-05 19:44 - 2014-07-05 19:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (4).exe
2014-07-03 14:26 - 2014-07-05 19:45 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-03 14:26 - 2014-07-05 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 14:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-03 14:26 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-03 14:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-03 14:25 - 2014-07-03 14:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (3).exe
2014-07-03 14:24 - 2014-07-03 14:24 - 00003278 _____ () C:\Windows\System32\Tasks\{8BEF405A-C21B-4900-AB07-984EDAA3600D}
2014-07-03 14:16 - 2014-07-03 14:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-07-03 14:10 - 2014-07-03 14:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-07-03 14:07 - 2014-07-03 14:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Dominik\Downloads\revosetup95.exe
2014-07-03 14:07 - 2014-07-03 14:07 - 00001272 _____ () C:\Users\Dominik\Desktop\Revo Uninstaller.lnk
2014-07-03 14:07 - 2014-07-03 14:07 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-02 22:48 - 2014-07-02 22:50 - 00041406 _____ () C:\Users\Dominik\Downloads\Addition.txt
2014-07-02 22:46 - 2014-07-07 21:00 - 00015148 _____ () C:\Users\Dominik\Downloads\FRST.txt
2014-07-02 22:45 - 2014-07-07 21:00 - 00000000 ____D () C:\FRST
2014-07-02 22:44 - 2014-07-07 20:59 - 02084352 _____ (Farbar) C:\Users\Dominik\Downloads\FRST64.exe
2014-06-27 14:29 - 2014-06-27 14:29 - 00516552 _____ () C:\Windows\Minidump\062714-31590-01.dmp
2014-06-26 14:32 - 2014-06-30 07:10 - 00000000 ____D () C:\Users\Dominik\Desktop\Kunstgeschichte
2014-06-26 10:43 - 2014-06-26 10:43 - 00961360 _____ (Chip Digital GmbH) C:\Users\Dominik\Downloads\OpenOffice - CHIP-Installer.exe
2014-06-22 00:25 - 2014-07-06 22:08 - 414976486 _____ () C:\Windows\MEMORY.DMP
2014-06-22 00:25 - 2014-06-22 00:25 - 00707168 _____ () C:\Windows\Minidump\062214-21496-01.dmp
2014-06-13 12:51 - 2014-06-13 12:51 - 00114073 _____ () C:\Users\Dominik\Desktop\10bf9ac543514ee
2014-06-11 20:12 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 20:12 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-11 20:12 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 20:12 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 20:12 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-11 20:12 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-11 20:12 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 20:12 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 20:12 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 20:12 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 20:12 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-11 20:12 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-11 20:12 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 20:12 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 20:12 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 20:12 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-11 20:12 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-11 20:12 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 20:12 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-11 20:12 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 20:12 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 20:12 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-11 20:12 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 20:12 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 20:12 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 20:12 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 20:12 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 20:12 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 20:12 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 20:12 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 20:12 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 20:12 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 20:12 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 20:12 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 20:12 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 20:12 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 20:12 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 20:12 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 20:12 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 20:12 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 20:12 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-11 20:11 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 20:11 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-11 20:11 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 20:11 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 20:11 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 20:11 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 20:11 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 20:11 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 20:11 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-11 20:11 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-11 20:11 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 20:11 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 20:11 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 20:11 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-11 20:11 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 20:11 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-11 20:11 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-11 20:11 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-11 20:11 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 20:11 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 20:11 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-11 20:11 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 20:11 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 20:11 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-11 20:11 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
==================== One Month Modified Files and Folders =======
2014-07-07 21:00 - 2014-07-02 22:46 - 00015148 _____ () C:\Users\Dominik\Downloads\FRST.txt
2014-07-07 21:00 - 2014-07-02 22:45 - 00000000 ____D () C:\FRST
2014-07-07 20:59 - 2014-07-07 20:59 - 00000000 ____D () C:\Users\Dominik\Downloads\FRST-OlderVersion
2014-07-07 20:59 - 2014-07-02 22:44 - 02084352 _____ (Farbar) C:\Users\Dominik\Downloads\FRST64.exe
2014-07-07 20:50 - 2014-07-07 20:50 - 00854390 _____ () C:\Users\Dominik\Downloads\SecurityCheck.exe
2014-07-07 20:38 - 2012-03-22 14:46 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-07 20:05 - 2012-07-23 20:24 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3362895703-2964763858-2143014042-1000UA.job
2014-07-07 20:05 - 2012-07-23 20:24 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3362895703-2964763858-2143014042-1000Core.job
2014-07-07 18:26 - 2012-05-03 03:20 - 01603739 _____ () C:\Windows\WindowsUpdate.log
2014-07-07 15:25 - 2014-07-07 15:25 - 02347384 _____ (ESET) C:\Users\Dominik\Downloads\esetsmartinstaller_deu.exe
2014-07-07 11:28 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-07 11:28 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-07 11:23 - 2012-07-23 19:11 - 00000000 ____D () C:\ProgramData\clear.fi
2014-07-07 11:20 - 2014-05-27 20:56 - 00006117 _____ () C:\Windows\setupact.log
2014-07-07 11:20 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-06 23:00 - 2014-05-24 21:46 - 00000000 ____D () C:\Users\Dominik\Desktop\Dokumente
2014-07-06 22:33 - 2014-07-06 22:33 - 00001027 _____ () C:\Users\Dominik\Desktop\JRT.txt
2014-07-06 22:15 - 2014-07-06 22:14 - 01016261 _____ (Thisisu) C:\Users\Dominik\Downloads\JRT (1).exe
2014-07-06 22:08 - 2014-07-06 22:08 - 00653808 _____ () C:\Windows\Minidump\070614-30934-01.dmp
2014-07-06 22:08 - 2014-06-22 00:25 - 414976486 _____ () C:\Windows\MEMORY.DMP
2014-07-06 22:08 - 2012-10-23 10:23 - 00000000 ____D () C:\Windows\Minidump
2014-07-06 22:07 - 2014-05-26 15:18 - 00001405 _____ () C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-06 22:05 - 2013-03-18 02:12 - 00253928 _____ () C:\Windows\PFRO.log
2014-07-06 22:03 - 2014-07-06 20:32 - 00000000 ____D () C:\AdwCleaner
2014-07-06 20:32 - 2014-07-06 20:32 - 01346519 _____ () C:\Users\Dominik\Downloads\adwcleaner_3.214.exe
2014-07-06 10:27 - 2014-07-06 10:27 - 00656744 _____ () C:\Windows\Minidump\070614-39905-01.dmp
2014-07-05 19:45 - 2014-07-03 14:26 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-05 19:45 - 2014-07-03 14:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-05 19:45 - 2014-05-29 22:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-05 19:44 - 2014-07-05 19:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (4).exe
2014-07-03 14:25 - 2014-07-03 14:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (3).exe
2014-07-03 14:24 - 2014-07-03 14:24 - 00003278 _____ () C:\Windows\System32\Tasks\{8BEF405A-C21B-4900-AB07-984EDAA3600D}
2014-07-03 14:16 - 2014-07-03 14:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-07-03 14:10 - 2014-07-03 14:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dominik\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-07-03 14:07 - 2014-07-03 14:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Dominik\Downloads\revosetup95.exe
2014-07-03 14:07 - 2014-07-03 14:07 - 00001272 _____ () C:\Users\Dominik\Desktop\Revo Uninstaller.lnk
2014-07-03 14:07 - 2014-07-03 14:07 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-02 22:50 - 2014-07-02 22:48 - 00041406 _____ () C:\Users\Dominik\Downloads\Addition.txt
2014-06-30 07:10 - 2014-06-26 14:32 - 00000000 ____D () C:\Users\Dominik\Desktop\Kunstgeschichte
2014-06-27 14:29 - 2014-06-27 14:29 - 00516552 _____ () C:\Windows\Minidump\062714-31590-01.dmp
2014-06-26 11:26 - 2012-08-07 19:35 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-06-26 10:43 - 2014-06-26 10:43 - 00961360 _____ (Chip Digital GmbH) C:\Users\Dominik\Downloads\OpenOffice - CHIP-Installer.exe
2014-06-25 20:00 - 2012-07-23 20:24 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3362895703-2964763858-2143014042-1000UA
2014-06-25 20:00 - 2012-07-23 20:24 - 00003706 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3362895703-2964763858-2143014042-1000Core
2014-06-24 13:53 - 2013-10-18 07:39 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-22 00:25 - 2014-06-22 00:25 - 00707168 _____ () C:\Windows\Minidump\062214-21496-01.dmp
2014-06-13 12:51 - 2014-06-13 12:51 - 00114073 _____ () C:\Users\Dominik\Desktop\10bf9ac543514ee
2014-06-12 11:00 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-12 01:45 - 2013-08-16 00:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 01:42 - 2012-08-03 01:07 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 01:39 - 2014-05-07 23:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-08 11:13 - 2014-06-11 20:11 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-11 20:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
Some content of TEMP:
====================
C:\Users\Dominik\AppData\Local\Temp\avgnt.exe
C:\Users\Dominik\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-30 07:28
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
So, alle Scans durch, muss jetzt mal testen, ob wieder alles funktioniert.