Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: [Windows7] Computer (Arbeitsplatz) öffnet sich ständig!

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 22.10.2014, 02:31   #1
Ridertsen
 
[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Guten Abend!,

Mein Computer bzw. Arbeitsplatz öffnet sich ständig (Das ploppt dann einfach auf), manchmal mit Pause zwischendurch und manchmal einfach un-unterbrochen.

Meistens auch während ich spiele (Schmeißt mich dann auf den Desktop und der Arbeitsplatz/Computer ist geöffnet).

Wäre nett wenn ihr mir weiterhelfen könntet, denn ich erkenne rein gar nichts >.< .. hoffe mal dass das nicht so schlimm aussieht :P

MfG

HiJackthis Logfile:
Code:
ATTFilter
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 03:11:15, on 22.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\***\Downloads\HiJackThis204.exe
C:\Users\***\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\***\Desktop\HiJackThis204.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\jan\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Raptr] C:\PROGRA~1\Raptr\raptrstub.exe --startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - Startup: Curse.lnk = C:\Users\***\AppData\Roaming\Curse Client\Bin\Curse.exe
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~3\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~3\Office15\EXCEL.EXE/3000
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: hxxp://*.aeriagames.com
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Echtzeit-Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files\Hi-Rez Studios\HiPatchService.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - VIA Technologies, Inc. - C:\Windows\system32\viakaraokesrv.exe

--
End of file - 9896 bytes
         
--- --- ---

Alt 22.10.2014, 06:21   #2
schrauber
/// the machine
/// TB-Ausbilder
 

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 22.10.2014, 12:44   #3
Ridertsen
 
[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Hey Schrauber,
erst ein mal schönen dank das du mir hilfst ^-^

habe nun den Scan wie gewünscht vom Desktop aus ausgeführt.

Hier ein mal FRST.


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-10-2014
Ran by *** (administrator) on ***-PC on 22-10-2014 13:15:16
Running from C:\Users\***\Desktop
Loaded Profile: *** (Available profiles: ***)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe
(Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\System32\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe
() C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.5\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Akamai Technologies, Inc.) C:\Users\***\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\***\AppData\Local\Akamai\netsession_win.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Raptr, Inc) C:\Program Files\Raptr\raptr.exe
(Raptr, Inc) C:\Program Files\Raptr\raptr_im.exe
(Curse, Inc) C:\Users\***\AppData\Roaming\Curse Client\Bin\Curse.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-09-15] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Akamai NetSession Interface] => C:\Users\***\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55568 2014-10-17] (Raptr, Inc)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: G - G:\autorun.exe
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: H - H:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {296507c7-d2d6-11e3-995a-002522f73538} - G:\autorun.exe
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {58054721-f6e6-11e2-a340-002522f73538} - G:\autorun.exe
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {84f78f5f-3f33-11e4-93ac-002522f73538} - H:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {9f3a83cc-5cf2-11e3-b313-002522f73538} - H:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\MountPoints2: {c6f0e310-0b33-11e3-86c7-806e6f6e6963} - F:\Setup.exe
Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk
ShortcutTarget: Curse.lnk -> C:\Users\***\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Handler: AutorunsDisabled\skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll (OGPlanet)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\***\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://jappy.de/"
CHR Profile: C:\Users\***\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27]
CHR Extension: (Turn Off the Lights) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-07-16]
CHR Extension: (YouTube) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-16]
CHR Extension: (TV) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-05-04]
CHR Extension: (Tanki Online) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\chnamgoimgnbgkabfjkikldbfdhhfhdo [2014-08-18]
CHR Extension: (Google-Suche) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-16]
CHR Extension: (Tampermonkey) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-08-04]
CHR Extension: (Realm of the Mad God) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp [2014-07-18]
CHR Extension: (RAD Soldiers) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkiahcckehgdocgonfdickeagmoembpe [2014-07-17]
CHR Extension: (Rush Team) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2014-05-04]
CHR Extension: (Avira SafeSearch) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2014-08-08]
CHR Extension: (Freefall Tournament) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2014-05-04]
CHR Extension: (Polycraft) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopfmbpfhhfnklgmjpoehcjaajhpbhbl [2014-07-27]
CHR Extension: (Avira Browser Safety) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-10]
CHR Extension: (Heroes & Generals) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2014-05-20]
CHR Extension: (WarChiefs - Tiberium Alliances Combat Simulator) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggiejiffgcdcfogfcgdebmbafcfndpgd [2013-08-04]
CHR Extension: (AdBlock) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-16]
CHR Extension: (Speed Test) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2014-08-18]
CHR Extension: (Red Crucible 2) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\iechpocbkaimjmlpfinoahkolenfdmig [2014-08-17]
CHR Extension: (Cut the Rope) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2014-08-03]
CHR Extension: (Plug+) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jflocljnfndnnnlmfaamgbkbibnfmlkf [2013-07-16]
CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2013-08-05]
CHR Extension: (Verdun Game) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\khdppkcpilejlgahecofelpoidcnjbdg [2014-07-18]
CHR Extension: (Sand 2) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\klicmgamjpclmbhppmdeamffedflmkcn [2014-10-16]
CHR Extension: (Artillery Tower Protector) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgcejmkikbadghamaadggncnbfekdik [2014-08-03]
CHR Extension: (Fieldrunners) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2014-05-04]
CHR Extension: (Regen-Alarm) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-08-18]
CHR Extension: (Spelunky HTML5) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhagnkphcmpkmabhocgimoncfaihkpof [2014-10-01]
CHR Extension: (DSL speedtest) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj [2014-08-18]
CHR Extension: (Apple Shooter) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbhfnlipcinfjmjplgegncjlmpnihecg [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Batterfield Map) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\npjmhhanmmlmpcnonlcgplgfnngboodf [2014-09-05]
CHR Extension: (Sand) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdknckljjbdpkhgmcokoahffbdinafbo [2014-09-12]
CHR Extension: (Reditr - The Best Reddit Client) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmfcbbijgnhoebddbjpmlikabnbnddgb [2014-10-01]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed]
R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-08-04] (Nero AG)
R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG)
S3 npggsvc; C:\Windows\system32\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-07-19] ()
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2013-07-16] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [15968 2013-07-16] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [22144 2013-07-16] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-03] (Disc Soft Ltd)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated)
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [114904 2014-10-22] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1846448 2013-07-16] (VIA Technologies, Inc.)
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vtany; \??\C:\Windows\vtany.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-22 13:15 - 2014-10-22 13:16 - 00018527 _____ () C:\Users\***\Desktop\FRST.txt
2014-10-22 13:14 - 2014-10-22 13:15 - 00000000 ____D () C:\FRST
2014-10-22 13:13 - 2014-10-22 13:13 - 01102336 _____ (Farbar) C:\Users\***\Desktop\FRST.exe
2014-10-22 03:11 - 2014-10-22 03:17 - 00009897 _____ () C:\Users\***\Desktop\hijackthis.log
2014-10-22 03:08 - 2014-10-22 03:08 - 00002238 _____ () C:\Users\***\Downloads\hijackthis.log
2014-10-22 02:51 - 2014-10-22 02:51 - 00388608 _____ (Trend Micro Inc.) C:\Users\***\Desktop\HiJackThis204.exe
2014-10-22 00:11 - 2014-10-22 00:11 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-21 23:04 - 2014-10-21 23:04 - 00117912 _____ () C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-21 22:59 - 2014-10-22 13:07 - 00000112 _____ () C:\Windows\setupact.log
2014-10-21 22:59 - 2014-10-21 22:59 - 00460912 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-21 22:59 - 2014-10-21 22:59 - 00001718 _____ () C:\Windows\PFRO.log
2014-10-21 22:59 - 2014-10-21 22:59 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-21 18:53 - 2014-10-21 18:53 - 00000000 __SHD () C:\Windows\system32\AI_RecycleBin
2014-10-21 18:50 - 2014-10-21 18:50 - 00143690 _____ () C:\Users\***\Desktop\cc_20141021_185023.reg
2014-10-21 18:42 - 2014-10-21 18:42 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-21 18:42 - 2014-10-21 18:42 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-21 18:36 - 2014-10-21 18:27 - 03239099 _____ () C:\Users\***\Desktop\CBS.log
2014-10-21 18:33 - 2014-10-21 18:33 - 00030992 _____ () C:\sfcdetails.txt
2014-10-20 23:13 - 2014-10-20 23:13 - 00000689 _____ () C:\Users\***\Desktop\JRT.txt
2014-10-20 23:11 - 2014-10-20 23:11 - 00000000 ____D () C:\Windows\ERUNT
2014-10-20 22:10 - 2014-10-22 13:08 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2014-10-20 22:10 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-20 22:10 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-20 22:04 - 2014-10-20 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-10-20 22:04 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-17 14:47 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-17 14:47 - 2014-09-29 02:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-17 14:47 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-17 14:47 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-17 14:47 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-17 14:47 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-17 14:47 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-17 14:47 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-17 14:47 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-17 14:47 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-17 14:47 - 2014-09-19 03:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-17 14:47 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-17 14:47 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-17 14:47 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-17 14:47 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-17 14:47 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-17 14:47 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-17 14:47 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-17 14:47 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-17 14:47 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-17 14:47 - 2014-09-19 02:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-17 14:47 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-17 14:47 - 2014-09-19 02:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-17 14:47 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-17 14:47 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-17 14:47 - 2014-09-19 02:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-17 14:47 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-17 14:47 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-17 14:47 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-17 14:47 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-17 14:47 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-17 14:47 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-17 14:47 - 2014-08-29 03:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-10-17 14:47 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-17 14:47 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-17 14:47 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-17 14:47 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-17 14:47 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-17 14:47 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-17 14:47 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-17 14:46 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-17 14:46 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-16 20:45 - 2014-10-16 20:45 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-10-16 20:43 - 2014-10-16 20:43 - 00638888 _____ (Oracle Corporation) C:\Users\***\Downloads\chromeinstall-8u25.exe
2014-10-13 22:45 - 2014-10-13 22:45 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-13 21:11 - 2014-10-13 22:07 - 00001957 _____ () C:\Users\***\Desktop\Engel Englisch.txt
2014-10-01 14:31 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-30 15:30 - 2014-09-30 15:30 - 00060300 _____ () C:\Windows\system32\CCCInstall_201409301530165576.log
2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\ProgramData\ATI
2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\Program Files\AMD AVT
2014-09-30 15:29 - 2014-09-30 15:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-09-30 15:15 - 2014-09-30 15:17 - 210974816 _____ (AMD Inc.) C:\Users\***\Downloads\amd-catalyst-14-9-win7-win8.1-32bit-dd-ccc-whql.exe
2014-09-25 16:04 - 2014-09-25 16:06 - 00000104 _____ () C:\Users\***\Desktop\Notizen.txt
2014-09-24 12:29 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 19:47 - 2014-09-23 19:47 - 00000000 ____D () C:\Users\***\AppData\Roaming\LolClient
2014-09-23 18:28 - 2014-09-23 18:28 - 00000000 ____D () C:\ProgramData\Riot Games
2014-09-23 18:26 - 2014-09-23 18:26 - 00001613 _____ () C:\Users\Public\Desktop\League of Legends.lnk
2014-09-23 18:26 - 2014-09-23 18:26 - 00000000 ____D () C:\Riot Games
2014-09-23 18:26 - 2014-09-23 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-09-23 18:26 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2014-09-23 18:26 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2014-09-23 18:26 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2014-09-23 18:17 - 2014-09-23 18:26 - 00000000 ____D () C:\Users\***\AppData\Roaming\Riot Games
2014-09-23 17:55 - 2014-09-23 17:56 - 30668968 _____ (Riot Games) C:\Users\***\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-22 13:15 - 2013-07-16 16:44 - 01834631 _____ () C:\Windows\WindowsUpdate.log
2014-10-22 13:15 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-22 13:15 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-22 13:09 - 2014-08-17 21:07 - 00000000 ____D () C:\Users\***\AppData\Roaming\Raptr
2014-10-22 13:08 - 2014-09-18 18:05 - 00000000 ____D () C:\Users\***\AppData\Local\HTC MediaHub
2014-10-22 13:08 - 2013-07-16 16:52 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-22 13:07 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-22 03:38 - 2013-07-17 00:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-22 02:58 - 2013-07-16 16:52 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-21 19:38 - 2013-10-03 00:11 - 00000000 ____D () C:\Users\***\Desktop\Musik
2014-10-21 19:12 - 2013-07-18 01:50 - 00000000 ____D () C:\Program Files\Steam
2014-10-21 19:08 - 2013-08-17 01:58 - 00000000 ____D () C:\Users\***\AppData\Roaming\Ubisoft
2014-10-21 19:08 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-21 19:06 - 2014-07-30 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
2014-10-21 19:06 - 2014-07-30 23:25 - 00000000 ____D () C:\Nexon
2014-10-21 18:59 - 2013-07-17 00:17 - 00000000 ____D () C:\Program Files\Java
2014-10-21 18:49 - 2013-08-26 04:56 - 00000000 ____D () C:\Users\***\AppData\Roaming\uTorrent
2014-10-21 18:49 - 2013-07-28 00:36 - 00000000 ____D () C:\Users\***\AppData\Roaming\DAEMON Tools Lite
2014-10-21 18:49 - 2013-07-25 00:40 - 00000000 ____D () C:\Users\***\AppData\Roaming\TS3Client
2014-10-21 18:48 - 2013-10-09 04:16 - 00000000 ____D () C:\Windows\Minidump
2014-10-21 18:48 - 2013-08-17 15:27 - 00000000 ___RD () C:\Users\***\Desktop\Games
2014-10-21 18:48 - 2013-07-25 21:26 - 00000000 ____D () C:\Users\***\Desktop\Programme
2014-10-21 18:48 - 2013-07-16 17:40 - 00000000 ____D () C:\Windows\Panther
2014-10-21 18:22 - 2013-09-14 14:51 - 00000000 ____D () C:\AdwCleaner
2014-10-21 18:17 - 2013-07-16 16:52 - 00000000 ____D () C:\Users\***\Desktop\Anti-Vir
2014-10-20 22:55 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Help
2014-10-20 22:13 - 2013-09-22 17:47 - 00000000 ____D () C:\Users\***\Desktop\Schule
2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\Users\***\AppData\Roaming\Malwarebytes
2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-19 23:21 - 2014-05-03 22:59 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-10-19 23:21 - 2014-05-03 22:55 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-19 03:21 - 2013-08-17 02:27 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-19 03:01 - 2013-07-16 19:20 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-18 14:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-10-18 14:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-18 13:30 - 2014-08-17 21:07 - 00000000 ____D () C:\Program Files\Raptr
2014-10-18 13:19 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-18 03:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-10-18 03:08 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2014-10-18 00:57 - 2013-07-16 16:53 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-16 20:45 - 2014-08-11 14:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-16 20:44 - 2014-08-11 14:55 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-10-16 20:44 - 2014-08-11 14:55 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-10-16 20:44 - 2013-10-22 22:55 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-15 12:17 - 2014-09-10 14:26 - 00000000 ____D () C:\Users\***\AppData\Roaming\Curse Client
2014-10-13 22:45 - 2013-08-17 13:54 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\Program Files\Avira
2014-10-02 15:53 - 2014-03-27 10:02 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-01 14:10 - 2013-07-16 23:08 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-01 14:10 - 2013-07-16 17:02 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-01 14:10 - 2013-07-16 17:02 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-09-30 15:30 - 2013-07-16 16:56 - 00000000 ____D () C:\ProgramData\AMD
2014-09-30 15:29 - 2013-07-16 16:55 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-09-30 15:19 - 2013-07-16 16:54 - 00000000 ____D () C:\AMD
2014-09-24 16:38 - 2013-07-17 00:45 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-24 16:38 - 2013-07-16 19:51 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl

Files to move or delete:
====================
C:\Users\***\jagex_cl_runescape_LIVE.dat
C:\Users\***\jagex_cl_runescape_LIVE1.dat
C:\Users\***\random.dat


Some content of TEMP:
====================
C:\Users\***\AppData\Local\Temp\avgnt.exe
C:\Users\***\AppData\Local\Temp\BRSVC_10390836_hlp.exe
C:\Users\***\AppData\Local\Temp\Quarantine.exe
C:\Users\***\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-17 15:28

==================== End Of Log ============================
         
--- --- ---

--- --- ---




und hier ein mal die Additions.

FRST Additions Logfile:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-10-2014
Ran by *** at 2014-10-22 13:17:00
Running from C:\Users\***\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKCU\...\uTorrent) (Version: 3.3.1.30017 - BitTorrent Inc.)
7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKCU\...\Akamai) (Version:  - Akamai Technologies, Inc)
Algebrator 4.0 (HKLM\...\Algebrator_is1) (Version:  - SoftMath Inc)
AMD Accelerated Video Transcoding (Version: 13.30.100.40915 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (Version: 2014.0915.1813.30937 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{319271B3-E2AA-F623-928E-245C9EBF16F7}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2014.0915.1813.30937 - Ihr Firmenname) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden
Arx Fatalis (HKLM\...\{96443F45-13E2-11D6-AC87-00D0B7A9E540}) (Version: 1.0.0 - JoWood)
Arx Fatalis Version 1.21 (HKLM\...\{171251E0-4EED-4EA1-A46D-3213A226F2B3}_is1) (Version: 1.21 - Arkane Studios)
Arx Libertatis (HKLM\...\ArxLibertatis) (Version: 1.1.1.0 - )
Avira (HKLM\...\{9bd9b85e-7792-483b-a318-cc51ff0877ed}) (Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.306 - Avira)
BC Kings (HKLM\...\Steam App 12460) (Version:  - Mascot Entertainment)
BOSS (HKLM\...\BOSS) (Version: 2.1.1 - BOSS Development Team)
Catalyst Control Center - Branding (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (Version: 2014.0915.1812.30937 - Advanced Micro Devices, Inc.) Hidden
ccc-utility (Version: 2014.0915.1813.30937 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
Command & Conquer Renegade (HKLM\...\Renegade) (Version:  - )
Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM\...\Steam App 240) (Version:  - Valve)
Curse (HKLM\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Curse)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dawngate (HKLM\...\{E20BD715-3CAF-4A6C-A7F5-8F2216710B90}) (Version: 174.83.27.0 - Electronic Arts, Inc.)
Dota 2 (HKLM\...\Steam App 570) (Version:  - Valve)
Drakensang Online (HKLM\...\Drakensang Online) (Version:  - )
Dungeon Defenders (HKLM\...\Steam App 65800) (Version:  - Trendy Entertainment)
F.E.A.R. Online (HKLM\...\F.E.A.R. Online) (Version:  - )
Foxit Reader (HKLM\...\Foxit Reader) (Version:  - )
Google Chrome (HKLM\...\Google Chrome) (Version: 38.0.2125.104 - Google Inc.)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.5 - Google Inc.) Hidden
Hi-Rez Studios Authenticate and Update Service (HKLM\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HTC Driver Installer (HKLM\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.13.0.003 - HTC Corporation)
HTC Sync Manager (HKLM\...\{231D0C79-98A6-4693-A366-36DE7D7346EC}) (Version: 3.1.24.5 - HTC)
HxD Hex Editor Version 1.7.7.0 (HKLM\...\HxD Hex Editor_is1) (Version: 1.7.7.0 - Maël Hörz)
InfiniteCrisis_6EDD581C692E (HKLM\...\InfiniteCrisis_6EDD581C692E) (Version:  - Turbine, Inc)
IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java Auto Updater (Version: 2.8.25.18 - Oracle Corporation) Hidden
Killing Floor (HKLM\...\Steam App 1250) (Version:  - Tripwire Interactive)
League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (Version: 3.0.1 - Riot Games ) Hidden
LTspice IV (HKLM\...\LTspice IV) (Version:  - )
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
ManyCam 3.1.62 (HKLM\...\ManyCam) (Version: 3.1.62 - ManyCam LLC)
Marvel Heroes Game (HKLM\...\{ca6069b5-fc6b-4ce8-a03e-2304143706b7}_is1) (Version: 1.0 - Gazillion Entertainment)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{887868A2-D6DE-3255-AA92-AA0B5A59B874}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
mIRC (HKLM\...\mIRC) (Version: 7.32 - mIRC Co. Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Mumble 1.2.4 (HKLM\...\{AF348C2E-7596-481B-92E0-B211836AB949}) (Version: 1.2.4 - Thorvald Natvig)
Nero Burning ROM (Version: 12.5.5001 - Nero AG) Hidden
Nero Burning ROM Help (CHM) (Version: 12.0.3000 - Nero AG) Hidden
Nero BurningROM 12 (HKLM\...\{DCF34348-8673-4E60-97E5-1CBC0D7293AC}) (Version: 12.5.01100 - Nero AG)
Nero ControlCenter (Version: 11.0.15600 - Nero AG) Hidden
Nero ControlCenter Help (CHM) (Version: 12.0.12000 - Nero AG) Hidden
Nero Core Components (Version: 11.0.20200 - Nero AG) Hidden
Nero SharedVideoCodecs (Version: 1.0.12100.2.0 - Nero AG) Hidden
Nero Update (Version: 11.0.11800.31.0 - Nero AG) Hidden
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.47.3 - Black Tree Gaming)
Nosgoth (HKLM\...\Steam App 200110) (Version: 140722.89040 - Square Enix Ltd)
Notepad++ (HKLM\...\Notepad++) (Version: 6.4.2 - Notepad++ Team)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA PhysX (HKLM\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
OGPlanet Game Launcher (HKLM\...\OGPlanet Game Launcher) (Version: 3.0.0 - OGPlanet, Inc.)
OpenAL (HKLM\...\OpenAL) (Version:  - )
OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Path of Exile (HKLM\...\Steam App 238960) (Version:  - Grinding Gear Games)
PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PlanetSide 2 (HKLM\...\Steam App 218230) (Version:  - Sony Online Entertainment)
Prerequisite installer (Version: 12.0.0003 - Nero AG) Hidden
PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.)
Raptr (HKLM\...\Raptr) (Version:  - )
Robocraft (HKLM\...\Steam App 301520) (Version:  - Freejam)
RuneScape Launcher 1.2.3 (HKLM\...\{FAE99C85-0732-4C58-9C6B-10B5B12FA2E9}) (Version: 1.2.3 - Jagex Ltd)
Sanctum 2 (HKLM\...\Steam App 210770) (Version:  - Coffee Stain Studios)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (Version:  - Microsoft) Hidden
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Smite (HKLM\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 1.0.2348.1 - Hi-Rez Studios)
Special Force 2  1.0 (HKLM\...\Special Force 2 Beta_is1) (Version:  - )
Spotify (HKCU\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.1.21 - Safer-Networking Ltd.)
SSIII Solo Ultratus 1.2 (HKLM\...\SSIII Solo Ultratus) (Version: 1.2 - 3RDsense)
Star Wars The Old Republic (HKLM\...\swtor_swtor) (Version: 7.0.0.2 - Bioware/EA)
Star Wars: The Old Republic (HKLM\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Strife (HKLM\...\Strife) (Version:  - S2 Games)
Stronghold Kingdoms (HKLM\...\{D1D632A2-E249-466D-A094-B1B934D37645}_is1) (Version: 1.17 - Firefly Studios)
Stronghold Kingdoms (HKLM\...\Steam App 47410) (Version:  - FireFly Studios)
Tactical Intervention (HKLM\...\Steam App 51100) (Version:  - FIX Korea)
Team Fortress 2 (HKLM\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Terraria (HKLM\...\Steam App 105600) (Version:  - Re-Logic)
The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Mighty Quest For Epic Loot Version 1.234953 (HKLM\...\The Mighty Quest For Epic Loot_is1) (Version: 1.234953 - )
Torchlight (HKLM\...\Torchlight_is1) (Version:  - GOG.com)
Transformers Universe (HKLM\...\{EAB5ACD3-43C0-4B3E-931A-CA61520934AD}) (Version: 1.0.0.0 - Jagex Ltd)
UE Explorer (HKLM\...\{235A9BC7-9489-43ED-85A7-695667B91AEA}) (Version: 1.1.0 - Eliot)
Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unreal Development Kit: 2013-07 (HKLM\...\UDK-7b92612f-6630-4e3b-a11a-2b4acce44976) (Version:  - Epic Games, Inc.)
Unturned (HKLM\...\Steam App 304930) (Version:  - Nelson Sexton)
VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN)
Westwood Shared Internet Components (HKLM\...\WOLAPI) (Version:  - )
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinZip 17.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DA}) (Version: 17.5.10480 - WinZip Computing, S.L. )
World of Warplanes (HKLM\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C813EU}_is1) (Version:  - Wargaming.net)
Zanzarah - Das verborgene Portal (HKLM\...\Zanzarah) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-871497826-143411075-1366273650-1001_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\jan\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)

==================== Restore Points  =========================

17-10-2014 12:31:37 Windows Update
18-10-2014 01:00:25 Windows Update
18-10-2014 01:25:01 Windows Update
19-10-2014 01:00:17 Windows Update
19-10-2014 21:18:28 Windows Update
21-10-2014 16:53:23 Removed Aeria Ignite
21-10-2014 16:58:18 Removed Java 7 Update 67

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {175703BD-2AF2-4C6C-8097-6FD4E49B36F2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated)
Task: {1CD6C84E-547F-4F6D-B525-E12DDB9E83C8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {2AF223C4-AED9-40A0-B799-1696B16D903E} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {41BDC262-7BDD-4A66-AC56-228FB62E8AF0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-16] (Google Inc.)
Task: {434DD5EB-F3E5-4849-966E-9807D1B6472A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {44D70773-546C-403A-B6BD-7864E68A8254} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd)
Task: {57DB51E6-1190-4A9F-90D1-26D18732B5E3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {6D68D594-1871-4448-9705-53CD7812CD90} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {9BFEDE87-1525-49C5-8B52-D10A4EB236EF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-16] (Google Inc.)
Task: {FF903288-0E8B-4B85-B5CA-E5783D8C11DE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search &amp; Destroy 2\SDScan.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-08-06 13:40 - 2014-08-06 13:40 - 00031080 _____ () C:\Program Files\HTC\HTC Sync Manager\DbAccess.dll
2014-08-06 13:41 - 2014-08-06 13:41 - 00607376 _____ () C:\Program Files\HTC\HTC Sync Manager\sqlite3.dll
2014-08-06 13:41 - 2014-08-06 13:41 - 00059752 _____ () C:\Program Files\HTC\HTC Sync Manager\NAdvLog.dll
2014-08-06 13:41 - 2014-08-06 13:41 - 00036216 _____ () C:\Program Files\HTC\HTC Sync Manager\NFileCacheDBAccess.dll
2014-08-06 13:42 - 2014-08-06 13:42 - 00080248 _____ () C:\Program Files\HTC\HTC Sync Manager\ninstallerhelper.dll
2014-08-06 13:44 - 2014-08-06 13:44 - 00129376 _____ () C:\Program Files\HTC\HTC Sync Manager\zlib1.dll
2014-08-06 13:46 - 2014-08-06 13:46 - 00223592 _____ () C:\Program Files\HTC\HTC Sync Manager\DevConnMon.dll
2013-10-17 15:27 - 2013-10-17 15:27 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2013-07-19 18:47 - 2013-07-19 19:15 - 00076888 _____ () C:\Windows\system32\PnkBstrA.exe
2013-09-14 20:34 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-09-14 20:34 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2013-09-14 20:34 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-09-14 20:34 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
2013-09-14 20:34 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2014-08-06 13:42 - 2014-08-06 13:42 - 00821600 _____ () C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
2014-09-15 18:13 - 2014-09-15 18:13 - 00095744 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-10-23 06:31 - 2013-10-23 06:31 - 01241088 _____ () C:\Program Files\ManyCam\Bin\opencv_imgproc220.dll
2013-10-23 06:31 - 2013-10-23 06:31 - 02010624 _____ () C:\Program Files\ManyCam\Bin\opencv_core220.dll
2010-11-23 00:56 - 2010-11-23 00:56 - 00087040 _____ () C:\Program Files\Raptr\_ctypes.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00043008 _____ () C:\Program Files\Raptr\_socket.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00805376 _____ () C:\Program Files\Raptr\_ssl.pyd
2014-05-14 01:26 - 2014-05-14 01:26 - 05812736 _____ () C:\Program Files\Raptr\PyQt4.QtGui.pyd
2014-05-14 01:26 - 2014-05-14 01:26 - 00067584 _____ () C:\Program Files\Raptr\sip.pyd
2014-05-14 01:26 - 2014-05-14 01:26 - 01662464 _____ () C:\Program Files\Raptr\PyQt4.QtCore.pyd
2014-05-14 01:26 - 2014-05-14 01:26 - 00494592 _____ () C:\Program Files\Raptr\PyQt4.QtNetwork.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00096256 _____ () C:\Program Files\Raptr\win32api.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00110592 _____ () C:\Program Files\Raptr\pywintypes26.dll
2010-11-23 00:56 - 2010-11-23 00:56 - 00010240 _____ () C:\Program Files\Raptr\select.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00356864 _____ () C:\Program Files\Raptr\_hashlib.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00036352 _____ () C:\Program Files\Raptr\win32process.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00111104 _____ () C:\Program Files\Raptr\win32file.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00044544 _____ () C:\Program Files\Raptr\_sqlite3.pyd
2011-02-15 20:17 - 2011-02-15 20:17 - 00417501 _____ () C:\Program Files\Raptr\sqlite3.dll
2010-11-23 00:57 - 2010-11-23 00:57 - 00167936 _____ () C:\Program Files\Raptr\win32gui.pyd
2014-05-14 01:26 - 2014-05-14 01:26 - 00313856 _____ () C:\Program Files\Raptr\PyQt4.QtWebKit.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00127488 _____ () C:\Program Files\Raptr\pyexpat.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00009216 _____ () C:\Program Files\Raptr\winsound.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00354304 _____ () C:\Program Files\Raptr\pythoncom26.dll
2010-11-23 00:57 - 2010-11-23 00:57 - 00016384 _____ () C:\Program Files\Raptr\win32trace.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00583680 _____ () C:\Program Files\Raptr\unicodedata.pyd
2011-11-21 04:20 - 2011-11-21 04:20 - 01949696 _____ () C:\Program Files\Raptr\libtorrent.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00263168 _____ () C:\Program Files\Raptr\win32com.shell.shell.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00324608 _____ () C:\Program Files\Raptr\PIL._imaging.pyd
2013-11-21 02:05 - 2013-11-21 02:05 - 00256000 _____ () C:\Program Files\Raptr\amd_ags.dll
2010-11-23 00:57 - 2010-11-23 00:57 - 00141312 _____ () C:\Program Files\Raptr\gobject._gobject.pyd
2014-06-18 02:56 - 2014-06-18 02:56 - 02717595 _____ () C:\Program Files\Raptr\heliotrope._purple.pyd
2011-02-15 20:17 - 2011-02-15 20:17 - 01213633 _____ () C:\Program Files\Raptr\libxml2-2.dll
2010-11-23 01:06 - 2010-11-23 01:06 - 00055808 _____ () C:\Program Files\Raptr\zlib1.dll
2013-05-10 01:52 - 2013-05-10 01:52 - 00495680 _____ () C:\Program Files\Raptr\plugins\libaim.dll
2013-05-10 01:52 - 2013-05-10 01:52 - 01183699 _____ () C:\Program Files\Raptr\liboscar.dll
2013-05-10 01:52 - 2013-05-10 01:52 - 00483306 _____ () C:\Program Files\Raptr\plugins\libicq.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00655356 _____ () C:\Program Files\Raptr\plugins\libirc.dll
2013-05-03 20:56 - 2013-05-03 20:56 - 01306387 _____ () C:\Program Files\Raptr\plugins\libmsn.dll
2013-05-03 20:56 - 2013-05-03 20:56 - 00565461 _____ () C:\Program Files\Raptr\plugins\libxmpp.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 01640221 _____ () C:\Program Files\Raptr\libjabber.dll
2013-05-03 20:56 - 2013-05-03 20:56 - 00506276 _____ () C:\Program Files\Raptr\plugins\libyahoo.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 01053730 _____ () C:\Program Files\Raptr\libymsg.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00497782 _____ () C:\Program Files\Raptr\plugins\libyahoojp.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00603326 _____ () C:\Program Files\Raptr\plugins\ssl-nss.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00474199 _____ () C:\Program Files\Raptr\plugins\ssl.dll
2014-05-19 17:04 - 2014-05-19 17:04 - 00307712 _____ () C:\Users\jan\AppData\Roaming\Curse Client\Bin\opus.dll
2014-05-19 17:05 - 2014-05-19 17:05 - 00437248 _____ () C:\Users\jan\AppData\Roaming\Curse Client\Bin\WebRTC_CSharpWrapper.dll
2014-10-18 00:57 - 2014-10-10 04:03 - 01042760 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\libglesv2.dll
2014-10-18 00:57 - 2014-10-10 04:03 - 00211272 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\libegl.dll
2014-10-18 00:57 - 2014-10-10 04:04 - 08910664 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\pdf.dll
2014-10-18 00:57 - 2014-10-10 04:03 - 01681224 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Aeria Ignite => "C:\Program Files\Aeria Games\Ignite\aeriaignite.exe" silent
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: Raptr => C:\PROGRA~1\Raptr\raptrstub.exe --startup
MSCONFIG\startupreg: SDTray => "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: Spotify => "C:\Users\jan\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\jan\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\Steam.exe" -silent

========================= Accounts: ==========================

Administrator (S-1-5-21-871497826-143411075-1366273650-500 - Administrator - Disabled)
Gast (S-1-5-21-871497826-143411075-1366273650-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-871497826-143411075-1366273650-1002 - Limited - Enabled)
*** (S-1-5-21-871497826-143411075-1366273650-1001 - Administrator - Enabled) => C:\Users\***

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/22/2014 01:17:29 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418231

Error: (10/22/2014 01:07:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/22/2014 03:00:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Procmon.exe, Version: 3.5.0.0, Zeitstempel: 0x519b927b
Name des fehlerhaften Moduls: Procmon.exe, Version: 3.5.0.0, Zeitstempel: 0x519b927b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0009bd28
ID des fehlerhaften Prozesses: 0x12e0
Startzeit der fehlerhaften Anwendung: 0xProcmon.exe0
Pfad der fehlerhaften Anwendung: Procmon.exe1
Pfad des fehlerhaften Moduls: Procmon.exe2
Berichtskennung: Procmon.exe3

Error: (10/21/2014 11:00:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: raptr.exe, Version: 4.1.2.0, Zeitstempel: 0x4bbd3163
Name des fehlerhaften Moduls: QtCore4.dll, Version: 4.8.2.0, Zeitstempel: 0x4fa6d505
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000240e4
ID des fehlerhaften Prozesses: 0x1378
Startzeit der fehlerhaften Anwendung: 0xraptr.exe0
Pfad der fehlerhaften Anwendung: raptr.exe1
Pfad des fehlerhaften Moduls: raptr.exe2
Berichtskennung: raptr.exe3

Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Smite.exe, Version: 1.0.2348.1, Zeitstempel: 0x54405f04
Name des fehlerhaften Moduls: ltc_game32-88237.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x543ee9ba
Ausnahmecode: 0xc0000005
Fehleroffset: 0x40e917a0
ID des fehlerhaften Prozesses: 0x13f4
Startzeit der fehlerhaften Anwendung: 0xSmite.exe0
Pfad der fehlerhaften Anwendung: Smite.exe1
Pfad des fehlerhaften Moduls: Smite.exe2
Berichtskennung: Smite.exe3

Error: (10/21/2014 04:58:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Smite.exe, Version: 1.0.2348.1, Zeitstempel: 0x54405f04
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0008a3bc
ID des fehlerhaften Prozesses: 0x13f4
Startzeit der fehlerhaften Anwendung: 0xSmite.exe0
Pfad der fehlerhaften Anwendung: Smite.exe1
Pfad des fehlerhaften Moduls: Smite.exe2
Berichtskennung: Smite.exe3

Error: (10/21/2014 04:58:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Smite.exe, Version: 1.0.2348.1, Zeitstempel: 0x54405f04
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000532ce
ID des fehlerhaften Prozesses: 0x13f4
Startzeit der fehlerhaften Anwendung: 0xSmite.exe0
Pfad der fehlerhaften Anwendung: Smite.exe1
Pfad des fehlerhaften Moduls: Smite.exe2
Berichtskennung: Smite.exe3

Error: (10/21/2014 04:58:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Smite.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: Ausnahmecode c0000005, Ausnahmeadresse 771132CE

Error: (10/21/2014 04:02:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (10/22/2014 01:10:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.

Error: (10/21/2014 10:59:37 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎21.‎10.‎2014 um 19:46:17 unerwartet heruntergefahren.

Error: (10/21/2014 07:44:21 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (10/21/2014 07:44:20 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (10/21/2014 07:44:19 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (10/21/2014 07:44:18 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (10/21/2014 07:44:18 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (10/21/2014 07:44:17 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (10/21/2014 07:44:17 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (10/21/2014 07:44:17 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.


Microsoft Office Sessions:
=========================
Error: (10/22/2014 01:17:29 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418231

Error: (10/22/2014 01:07:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/22/2014 03:00:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Procmon.exe3.5.0.0519b927bProcmon.exe3.5.0.0519b927bc00000050009bd2812e001cfed92b714bf00C:\Users\jan\Desktop\Anti-Vir\ProcessMonitor\Procmon.exeC:\Users\jan\Desktop\Anti-Vir\ProcessMonitor\Procmon.exed862c980-5986-11e4-a2c2-002522f73538

Error: (10/21/2014 11:00:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: raptr.exe4.1.2.04bbd3163QtCore4.dll4.8.2.04fa6d505c0000005000240e4137801cfed37e4837b80C:\PROGRA~1\Raptr\raptr.exeC:\PROGRA~1\Raptr\QtCore4.dllbdd03fc0-5932-11e4-929d-002522f73538

Error: (10/21/2014 04:58:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Smite.exe1.0.2348.154405f04ltc_game32-88237.dll_unloaded0.0.0.0543ee9bac000000540e917a013f401cfed3c4f875e70C:\Program Files\Hi-Rez Studios\HiRezGames\smite\binaries\Win32\Smite.exeltc_game32-88237.dllbd83cd70-5932-11e4-929d-002522f73538

Error: (10/21/2014 04:58:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Smite.exe1.0.2348.154405f04ntdll.dll6.1.7601.18247521ea91cc00000050008a3bc13f401cfed3c4f875e70C:\Program Files\Hi-Rez Studios\HiRezGames\smite\binaries\Win32\Smite.exeC:\Windows\SYSTEM32\ntdll.dllbc0543c0-5932-11e4-929d-002522f73538

Error: (10/21/2014 04:58:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Smite.exe1.0.2348.154405f04ntdll.dll6.1.7601.18247521ea91cc0000005000532ce13f401cfed3c4f875e70C:\Program Files\Hi-Rez Studios\HiRezGames\smite\binaries\Win32\Smite.exeC:\Windows\SYSTEM32\ntdll.dllb6f5cb20-5932-11e4-929d-002522f73538

Error: (10/21/2014 04:58:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Smite.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: Ausnahmecode c0000005, Ausnahmeadresse 771132CE

Error: (10/21/2014 04:02:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info =========================== 

Processor: AMD Athlon(tm) II X2 250 Processor
Percentage of memory in use: 57%
Total physical RAM: 3583.3 MB
Available physical RAM: 1531.65 MB
Total Pagefile: 7164.9 MB
Available Pagefile: 4233.02 MB
Total Virtual: 2599.88 MB
Available Virtual: 2441.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:147.29 GB) NTFS
Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: () (Fixed) (Total:465.66 GB) (Free:443.66 GB) NTFS
Drive g: (Renegade Data) (CDROM) (Total:0.37 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 11571157)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 41291E63)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
--- --- ---


ps: ich bin heute ab 17 Uhr leider nicht mehr erreichbar, ich bin ab morgen Abend wieder da.
__________________

Geändert von Ridertsen (22.10.2014 um 13:00 Uhr)

Alt 22.10.2014, 19:17   #4
schrauber
/// the machine
/// TB-Ausbilder
 

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.10.2014, 22:12   #5
Ridertsen
 
[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Kam mir ein wenig komisch vor, denn Combofix löschte etwas von meinem Avira ?

Aber hier ein mal Combofix

Code:
ATTFilter
ComboFix 14-10-21.01 - jan 23.10.2014  20:08:59.1.2 - x86
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.49.1031.18.3583.2615 [GMT 2:00]
ausgeführt von:: c:\users\jan\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\jan\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\IsUn0407.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-09-23 bis 2014-10-23  ))))))))))))))))))))))))))))))
.
.
2014-10-23 18:19 . 2014-10-23 18:19	62576	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D85FBAE-D72B-4041-8993-E96AE5D96F1A}\offreg.dll
2014-10-23 18:18 . 2014-10-23 18:23	--------	d-----w-	c:\users\jan\AppData\Local\temp
2014-10-23 18:18 . 2014-10-23 18:18	--------	d-----w-	c:\users\hedev\AppData\Local\temp
2014-10-23 18:18 . 2014-10-23 18:18	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-10-22 11:14 . 2014-10-22 11:17	--------	d-----w-	C:\FRST
2014-10-22 11:14 . 2014-10-20 01:37	8901368	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D85FBAE-D72B-4041-8993-E96AE5D96F1A}\mpengine.dll
2014-10-21 16:53 . 2014-10-21 16:53	--------	d-sh--w-	c:\windows\system32\AI_RecycleBin
2014-10-21 16:42 . 2014-10-21 16:42	--------	d-----w-	c:\program files\CCleaner
2014-10-20 21:11 . 2014-10-20 21:11	--------	d-----w-	c:\windows\ERUNT
2014-10-20 20:10 . 2014-10-23 18:22	114904	----a-w-	c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-10-20 20:10 . 2014-10-21 22:11	--------	d-----w-	c:\program files\ Malwarebytes Anti-Malware 
2014-10-20 20:10 . 2014-10-01 09:11	51928	----a-w-	c:\windows\system32\drivers\mwac.sys
2014-10-20 20:10 . 2014-10-01 09:11	75480	----a-w-	c:\windows\system32\drivers\mbamchameleon.sys
2014-10-20 20:04 . 2014-10-20 20:10	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2014-10-20 20:04 . 2014-10-01 09:11	23256	----a-w-	c:\windows\system32\drivers\mbam.sys
2014-10-17 12:46 . 2014-09-18 01:32	2363904	----a-w-	c:\windows\system32\msi.dll
2014-10-17 12:46 . 2014-09-13 01:40	67072	----a-w-	c:\windows\system32\packager.dll
2014-10-16 18:45 . 2014-10-16 18:45	--------	d-----w-	c:\program files\Common Files\Java
2014-10-01 12:31 . 2014-09-25 01:40	519680	----a-w-	c:\windows\system32\qdvd.dll
2014-09-30 13:30 . 2014-09-30 13:30	--------	d-----w-	c:\programdata\ATI
2014-09-30 13:30 . 2014-09-30 13:30	--------	d-----w-	c:\program files\AMD AVT
2014-09-28 06:27 . 2014-09-28 06:27	2970808	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\1031\MSOINTL.DLL
2014-09-25 11:30 . 2014-09-25 11:30	81383096	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL
2014-09-25 11:30 . 2014-09-25 11:30	5646032	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe
2014-09-25 11:30 . 2014-09-25 11:30	550064	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE
2014-09-25 11:30 . 2014-09-25 11:30	5353664	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\Csi.dll
2014-09-25 11:30 . 2014-09-25 11:30	26345152	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2014-09-24 10:29 . 2014-09-09 21:47	2048	----a-w-	c:\windows\system32\tzres.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-16 18:44 . 2014-08-11 12:55	96680	----a-w-	c:\windows\system32\WindowsAccessBridge.dll
2014-10-02 13:53 . 2014-03-27 08:02	231568	------w-	c:\windows\system32\MpSigStub.exe
2014-10-01 12:10 . 2013-07-16 21:08	37384	----a-w-	c:\windows\system32\drivers\avnetflt.sys
2014-10-01 12:10 . 2013-07-16 15:02	136216	----a-w-	c:\windows\system32\drivers\avipbb.sys
2014-10-01 12:10 . 2013-07-16 15:02	98160	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2014-09-24 14:38 . 2013-07-16 22:45	701104	----a-w-	c:\windows\system32\FlashPlayerApp.exe
2014-09-24 14:38 . 2013-07-16 17:51	71344	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-15 22:31 . 2014-09-15 22:31	71704	----a-w-	c:\windows\system32\atimpc32.dll
2014-09-15 22:31 . 2014-09-15 22:31	71704	----a-w-	c:\windows\system32\amdpcom32.dll
2014-09-15 22:31 . 2014-04-18 02:42	126848	----a-w-	c:\windows\system32\atiuxpag.dll
2014-09-15 22:31 . 2014-04-18 02:42	100032	----a-w-	c:\windows\system32\atiu9pag.dll
2014-09-15 22:31 . 2014-04-18 02:42	1113576	----a-w-	c:\windows\system32\aticfx32.dll
2014-09-15 22:31 . 2014-04-18 02:42	9254184	----a-w-	c:\windows\system32\atidxx32.dll
2014-09-15 22:31 . 2014-04-18 02:42	7207592	----a-w-	c:\windows\system32\atiumdva.dll
2014-09-15 22:31 . 2014-04-18 02:42	7028336	----a-w-	c:\windows\system32\atiumdag.dll
2014-09-15 22:29 . 2014-09-15 22:29	264928	----a-w-	c:\windows\system32\drivers\amdacpksd.sys
2014-09-15 22:25 . 2014-09-15 22:25	14798336	----a-w-	c:\windows\system32\drivers\atikmdag.sys
2014-09-15 22:18 . 2014-09-15 22:18	203776	----a-w-	c:\windows\system32\clinfo.exe
2014-09-15 22:17 . 2014-09-15 22:17	83456	----a-w-	c:\windows\system32\OpenVideo.dll
2014-09-15 22:17 . 2014-09-15 22:17	73216	----a-w-	c:\windows\system32\OVDecode.dll
2014-09-15 22:17 . 2014-09-15 22:17	28770304	----a-w-	c:\windows\system32\amdocl.dll
2014-09-15 22:16 . 2014-09-15 22:16	58880	----a-w-	c:\windows\system32\OpenCL.dll
2014-09-15 22:09 . 2014-09-15 22:09	37888	----a-w-	c:\windows\system32\amdmmcl.dll
2014-09-15 22:09 . 2014-09-15 22:09	113664	----a-w-	c:\windows\system32\mantle32.dll
2014-09-15 22:08 . 2014-09-15 22:08	23375360	----a-w-	c:\windows\system32\atioglxx.dll
2014-09-15 22:07 . 2014-09-15 22:07	367104	----a-w-	c:\windows\system32\atiapfxx.exe
2014-09-15 22:07 . 2014-09-15 22:07	52224	----a-w-	c:\windows\system32\aticalrt.dll
2014-09-15 22:07 . 2014-09-15 22:07	49152	----a-w-	c:\windows\system32\aticalcl.dll
2014-09-15 22:06 . 2014-09-15 22:06	14302208	----a-w-	c:\windows\system32\aticaldd.dll
2014-09-15 22:05 . 2014-09-15 22:05	4480000	----a-w-	c:\windows\system32\amdmantle32.dll
2014-09-15 22:03 . 2014-09-15 22:03	442368	----a-w-	c:\windows\system32\atidemgy.dll
2014-09-15 22:03 . 2014-09-15 22:03	30720	----a-w-	c:\windows\system32\atimuixx.dll
2014-09-15 22:03 . 2014-09-15 22:03	513536	----a-w-	c:\windows\system32\atieclxx.exe
2014-09-15 22:03 . 2014-09-15 22:03	208896	----a-w-	c:\windows\system32\atiesrxx.exe
2014-09-15 22:03 . 2014-09-15 22:03	85504	----a-w-	c:\windows\system32\mantleaxl32.dll
2014-09-15 22:03 . 2014-09-15 22:03	164352	----a-w-	c:\windows\system32\atitmmxx.dll
2014-09-15 21:59 . 2014-09-15 21:59	637952	----a-w-	c:\windows\system32\coinst_14.30.dll
2014-09-15 21:59 . 2014-09-15 21:59	900608	----a-w-	c:\windows\system32\atiadlxx.dll
2014-09-15 21:59 . 2014-09-15 21:59	69632	----a-w-	c:\windows\system32\atiglpxx.dll
2014-09-15 21:59 . 2014-09-15 21:59	133632	----a-w-	c:\windows\system32\atigktxx.dll
2014-09-15 21:59 . 2014-09-15 21:59	463360	----a-w-	c:\windows\system32\drivers\atikmpag.sys
2014-09-15 21:58 . 2014-09-15 21:58	43520	----a-w-	c:\windows\system32\drivers\ati2erec.dll
2014-09-15 16:19 . 2014-09-15 16:19	38912	----a-w-	c:\windows\system32\kdbsdk32.dll
2014-08-23 01:46 . 2014-08-28 13:35	305152	----a-w-	c:\windows\system32\gdi32.dll
2014-08-01 11:35 . 2014-09-11 13:10	793600	----a-w-	c:\windows\system32\TSWorkspace.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-09-16 11:50	1729232	----a-w-	c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-09-16 11:50	1729232	----a-w-	c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-09-16 11:50	1729232	----a-w-	c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\jan\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"Raptr"="c:\progra~1\Raptr\raptrstub.exe" [2014-10-17 55568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" [2014-09-15 748256]
"Avira Systray"="c:\program files\Avira\My Avira\Avira.OE.Systray.exe" [2014-09-23 165168]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-10-01 703736]
.
c:\users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Curse.lnk - c:\users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe /startup [2014-8-29 6060808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
2014-09-26 14:04	4811032	----a-w-	c:\program files\CCleaner\CCleaner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
2014-10-17 18:24	55568	----a-w-	c:\progra~1\Raptr\raptrstub.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2013-07-25 09:19	5624784	----a-w-	c:\program files\Spybot - Search & Destroy 2\SDTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
2013-12-05 15:12	5951488	----a-w-	c:\users\jan\AppData\Roaming\Spotify\spotify.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
2013-12-05 15:12	1168896	----a-w-	c:\users\jan\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2014-08-13 22:34	1937600	----a-w-	c:\program files\Steam\Steam.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2013-10-17 23040]
R3 HtcVCom32;HTC Diagnostic Port;c:\windows\system32\DRIVERS\HtcVComV32.sys [2009-10-27 105984]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-09-19 108032]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2014-05-15 3191392]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-08-23 24064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vtany;vtany;c:\windows\vtany.sys [x]
R3 xhunter1;xhunter1;c:\windows\xhunter1.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2014-10-01 994552]
S0 amdkmafd;AMD Audio Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmafd.sys [2013-07-16 15968]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys [2013-07-16 22144]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-11-26 37352]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-05-03 243128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2014-09-15 208896]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 276992]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2014-10-01 431920]
S2 AODDriver4.3;AODDriver4.3;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-09-23 160560]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files\Hi-Rez Studios\HiPatchService.exe [2014-08-22 9216]
S2 HTCMonitorService;HTCMonitorService;c:\program files\HTC\HTC Sync Manager\HSMServiceEntry.exe [2014-08-04 87368]
S2 MBAMScheduler;MBAMScheduler;c:\program files\ Malwarebytes Anti-Malware \mbamscheduler.exe [2014-10-01 1871160]
S2 MBAMService;MBAMService;c:\program files\ Malwarebytes Anti-Malware \mbamservice.exe [2014-10-01 968504]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2012-07-13 769432]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2013-10-17 166912]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2013-07-16 27768]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2014-06-21 77824]
S3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys [2012-10-11 34432]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-10-01 23256]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-10-23 114904]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-10-01 51928]
S3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv.sys [2013-01-31 22656]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2013-07-16 1846448]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-10-17 22:53	1089352	----a-w-	c:\program files\Google\Chrome\Application\38.0.2125.104\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-16 14:38]
.
2014-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-07-16 14:52]
.
2014-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-07-16 14:52]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = <local>
IE: An OneNote s&enden - c:\progra~1\MICROS~3\Office15\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office15\EXCEL.EXE/3000
Trusted Zone: aeriagames.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.178.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Notify-SDWinLogon - SDWinLogon.dll
MSConfigStartUp-Aeria Ignite - c:\program files\Aeria Games\Ignite\aeriaignite.exe
AddRemove-swtor_swtor - c:\programdata\BitRaider\brwc.exe
AddRemove-Zanzarah - c:\windows\IsUn0407.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,7a,9a,22,ff,72,33,49,a6,3b,5a,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,7a,9a,22,ff,72,33,49,a6,3b,5a,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\atieclxx.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\taskhost.exe
c:\program files\ Malwarebytes Anti-Malware \mbam.exe
c:\program files\HTC\HTC Sync Manager\HTC Sync\adb.exe
c:\windows\system32\conhost.exe
c:\program files\Google\Update\1.3.25.5\GoogleCrashHandler.exe
c:\users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\progra~1\Raptr\raptr.exe
c:\progra~1\Raptr\raptr_im.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-10-23  20:33:10 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2014-10-23 18:33
.
Vor Suchlauf: 18 Verzeichnis(se), 157.246.095.360 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 157.081.559.040 Bytes frei
.
- - End Of File - - 8808C874373BF50A7FC7E7B293BE41B4
A36C5E4F47E84449FF07ED3517B43A31
         


Alt 24.10.2014, 16:43   #6
schrauber
/// the machine
/// TB-Ausbilder
 

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> [Windows7] Computer (Arbeitsplatz) öffnet sich ständig!

Alt 25.10.2014, 21:20   #7
Ridertsen
 
[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Hey schrauber ^-^

Am 20.10, also vor 5 Tagen, begann dieses Problem.
Bevor ich mich also hier meldete, hatte ich leider vorher schon ein mal meinen Computer mit Mbam gescannt und der Log hatte einige Funde, ich werde die beiden Logs posten, einen vom 25. (Heute) und den vom 20.

25.10

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 25.10.2014
Suchlauf-Zeit: 21:16:48
Logdatei: mbam25-10.txt
Administrator: Ja

Version: 2.00.3.1025
Malware Datenbank: v2014.10.25.05
Rootkit Datenbank: v2014.10.22.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: jan

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 335239
Verstrichene Zeit: 15 Min, 50 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente erkannt)

Module: 0
(Keine schädliche Elemente erkannt)

Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)

Registrierungswerte: 0
(Keine schädliche Elemente erkannt)

Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)

Ordner: 0
(Keine schädliche Elemente erkannt)

Dateien: 1
PUP.Optional.OpenCandy, C:\Users\jan\Desktop\Programme\Daemon Tools Lite\DTLite4471-0333.exe, In Quarantäne, [ead7997e88f4b87e9d19ce844cb91ce4], 

Physische Sektoren: 0
(Keine schädliche Elemente erkannt)


(end)
         
und vom 20.10

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 20.10.2014
Suchlauf-Zeit: 22:38:51
Logdatei: mbam20-10.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.03.04.09
Rootkit Datenbank: v2014.10.17.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: jan

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 230195
Verstrichene Zeit: 13 Min, 11 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente erkannt)

Module: 0
(Keine schädliche Elemente erkannt)

Registrierungsschlüssel: 1
PUP.Optional.VMNToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}, In Quarantäne, [4684bf56d3a9a393e8b0ef86fd05f60a], 

Registrierungswerte: 0
(Keine schädliche Elemente erkannt)

Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)

Ordner: 0
(Keine schädliche Elemente erkannt)

Dateien: 3
PUP.Optional.OpenCandy, C:\Users\jan\Desktop\Programme\Daemon Tools Lite\DTLite4471-0333.exe, Keine Aktion durch Benutzer, [15b51df83f3dae88ce182e2307fd9967], 
PUP.Optional.MyStartTB.A, C:\Users\jan\Downloads\ManyCamSetup.exe, In Quarantäne, [9c2ed1445a22280e00bc196b2ad7b64a], 
PUP.Optional.Handy.A, C:\Users\jan\Downloads\GotClip_Setup.exe, In Quarantäne, [646643d254283105077da2bbc140c040], 

Physische Sektoren: 0
(Keine schädliche Elemente erkannt)


(end)
         
nächstes folgt..

Werde jetzt schon ein mal eine Gaming-Session machen und berichten ob das Problem immernoch vorhanden ist, danke für die Hilfe ^-^

ADWCleaner

Code:
ATTFilter
# AdwCleaner v4.001 - Bericht erstellt am 25/10/2014 um 21:59:42
# DB v2014-10-23.2
# Aktualisiert 20/10/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzername : jan - JAN-PC
# Gestartet von : C:\Users\jan\Desktop\adwcleaner_4.001.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Users\jan\AppData\Local\CrashRpt

***** [ Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{06E58E5E-F8CB-4049-991E-A41C03BD419E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{258C9770-1713-4021-8D7E-1F184A2BD754}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{43D9E6F0-1776-4897-AE14-ECEDECBAFEC0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5A074B29-F830-49DE-A31B-5BB9D7F6B407}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{DCC70A83-E184-40A3-906B-779AF5E941C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17344


-\\ Google Chrome v38.0.2125.104


*************************

AdwCleaner[R0].txt - [1194 octets] - [14/09/2013 20:05:41]
AdwCleaner[R1].txt - [912 octets] - [14/09/2013 20:16:22]
AdwCleaner[R2].txt - [971 octets] - [14/09/2013 20:24:17]
AdwCleaner[R3].txt - [2392 octets] - [20/10/2014 23:03:48]
AdwCleaner[R4].txt - [3668 octets] - [21/10/2014 18:18:33]
AdwCleaner[R5].txt - [3774 octets] - [25/10/2014 21:57:34]
AdwCleaner[S0].txt - [1259 octets] - [14/09/2013 20:13:03]
AdwCleaner[S1].txt - [2445 octets] - [20/10/2014 23:07:08]
AdwCleaner[S2].txt - [3687 octets] - [25/10/2014 21:59:42]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3747 octets] ##########
         
JRT

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.21.2014:1)
OS: Windows 7 Ultimate x86
Ran by jan on 25.10.2014 at 22:09:57,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.10.2014 at 22:11:43,68
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

frisches FRST Log


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-10-2014
Ran by jan (administrator) on JAN-PC on 25-10-2014 22:13:09
Running from C:\Users\jan\Desktop
Loaded Profile: jan (Available profiles: jan)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe
(Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\System32\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
() C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.5\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe
(Curse, Inc) C:\Users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Raptr, Inc) C:\Program Files\Raptr\raptr.exe
(Raptr, Inc) C:\Program Files\Raptr\raptr_im.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-09-15] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Akamai NetSession Interface] => C:\Users\jan\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55568 2014-10-17] (Raptr, Inc)
Startup: C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk
ShortcutTarget: Curse.lnk -> C:\Users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Handler: AutorunsDisabled\skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll (OGPlanet)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://jappy.de/"
CHR Profile: C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27]
CHR Extension: (Turn Off the Lights) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-07-16]
CHR Extension: (YouTube) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-16]
CHR Extension: (TV) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-05-04]
CHR Extension: (Tanki Online) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chnamgoimgnbgkabfjkikldbfdhhfhdo [2014-08-18]
CHR Extension: (Google-Suche) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-16]
CHR Extension: (Tampermonkey) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-08-04]
CHR Extension: (Realm of the Mad God) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp [2014-07-18]
CHR Extension: (RAD Soldiers) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkiahcckehgdocgonfdickeagmoembpe [2014-07-17]
CHR Extension: (Rush Team) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2014-05-04]
CHR Extension: (Avira SafeSearch) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2014-08-08]
CHR Extension: (Freefall Tournament) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2014-05-04]
CHR Extension: (Polycraft) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopfmbpfhhfnklgmjpoehcjaajhpbhbl [2014-07-27]
CHR Extension: (Avira Browser Safety) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-10]
CHR Extension: (Heroes & Generals) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2014-05-20]
CHR Extension: (WarChiefs - Tiberium Alliances Combat Simulator) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggiejiffgcdcfogfcgdebmbafcfndpgd [2013-08-04]
CHR Extension: (AdBlock) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-16]
CHR Extension: (Speed Test) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2014-08-18]
CHR Extension: (Red Crucible 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iechpocbkaimjmlpfinoahkolenfdmig [2014-08-17]
CHR Extension: (Cut the Rope) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2014-08-03]
CHR Extension: (Plug+) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jflocljnfndnnnlmfaamgbkbibnfmlkf [2013-07-16]
CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2013-08-05]
CHR Extension: (Verdun Game) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\khdppkcpilejlgahecofelpoidcnjbdg [2014-07-18]
CHR Extension: (Sand 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\klicmgamjpclmbhppmdeamffedflmkcn [2014-10-16]
CHR Extension: (Artillery Tower Protector) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgcejmkikbadghamaadggncnbfekdik [2014-08-03]
CHR Extension: (Fieldrunners) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2014-05-04]
CHR Extension: (Regen-Alarm) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-08-18]
CHR Extension: (Spelunky HTML5) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhagnkphcmpkmabhocgimoncfaihkpof [2014-10-01]
CHR Extension: (DSL speedtest) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj [2014-08-18]
CHR Extension: (Apple Shooter) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbhfnlipcinfjmjplgegncjlmpnihecg [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Batterfield Map) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\npjmhhanmmlmpcnonlcgplgfnngboodf [2014-09-05]
CHR Extension: (Sand) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdknckljjbdpkhgmcokoahffbdinafbo [2014-09-12]
CHR Extension: (Reditr - The Best Reddit Client) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmfcbbijgnhoebddbjpmlikabnbnddgb [2014-10-01]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed]
R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-08-04] (Nero AG)
S2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG)
S3 npggsvc; C:\Windows\system32\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-07-19] ()
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2013-07-16] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [15968 2013-07-16] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [22144 2013-07-16] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-03] (Disc Soft Ltd)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated)
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1846448 2013-07-16] (VIA Technologies, Inc.)
S3 catchme; \??\C:\Users\jan\AppData\Local\Temp\catchme.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vtany; \??\C:\Windows\vtany.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-25 22:11 - 2014-10-25 22:11 - 00000781 _____ () C:\Users\jan\Desktop\FRST - Verknüpfung.lnk
2014-10-25 22:11 - 2014-10-25 22:11 - 00000689 _____ () C:\Users\jan\Desktop\JRT.txt
2014-10-25 22:08 - 2014-10-25 22:08 - 00000000 ____D () C:\Users\jan\Desktop\FRST-OlderVersion
2014-10-25 22:07 - 2014-10-21 20:25 - 01706144 _____ (Thisisu) C:\Users\jan\Desktop\JRT_NEW.exe
2014-10-25 22:05 - 2014-10-25 21:59 - 00003827 _____ () C:\Users\jan\Desktop\AdwCleaner[S2].txt
2014-10-25 21:50 - 2014-10-25 21:50 - 00001309 _____ () C:\Users\jan\Desktop\mbam25-10.txt
2014-10-25 21:49 - 2014-10-25 21:53 - 00001706 _____ () C:\Users\jan\Desktop\mbam20-10.txt
2014-10-23 20:33 - 2014-10-23 20:33 - 00019058 _____ () C:\ComboFix.txt
2014-10-23 20:06 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-23 20:06 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-23 20:06 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-23 20:06 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-23 20:06 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-23 20:06 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-23 20:06 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-23 20:06 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-23 20:04 - 2014-10-23 20:33 - 00000000 ____D () C:\Qoobox
2014-10-23 20:04 - 2014-10-23 20:30 - 00000000 ____D () C:\Windows\erdnt
2014-10-23 19:58 - 2014-10-23 19:59 - 05584933 ____R (Swearware) C:\Users\jan\Desktop\ComboFix.exe
2014-10-22 13:17 - 2014-10-22 13:42 - 00037130 _____ () C:\Users\jan\Desktop\Addition.txt
2014-10-22 13:15 - 2014-10-25 22:13 - 00016849 _____ () C:\Users\jan\Desktop\FRST.txt
2014-10-22 13:14 - 2014-10-25 22:13 - 00000000 ____D () C:\FRST
2014-10-22 13:13 - 2014-10-25 22:08 - 01104384 _____ (Farbar) C:\Users\jan\Desktop\FRST.exe
2014-10-22 03:11 - 2014-10-22 03:17 - 00009897 _____ () C:\Users\jan\Desktop\hijackthis.log
2014-10-22 03:08 - 2014-10-22 03:08 - 00002238 _____ () C:\Users\jan\Downloads\hijackthis.log
2014-10-22 02:51 - 2014-10-22 02:51 - 00388608 _____ (Trend Micro Inc.) C:\Users\jan\Desktop\HiJackThis204.exe
2014-10-22 00:11 - 2014-10-22 00:11 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-21 23:04 - 2014-10-21 23:04 - 00117912 _____ () C:\Users\jan\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-21 22:59 - 2014-10-25 22:01 - 00000448 _____ () C:\Windows\setupact.log
2014-10-21 22:59 - 2014-10-25 22:00 - 00003226 _____ () C:\Windows\PFRO.log
2014-10-21 22:59 - 2014-10-21 22:59 - 00460912 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-21 22:59 - 2014-10-21 22:59 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-21 18:50 - 2014-10-21 18:50 - 00143690 _____ () C:\Users\jan\Desktop\cc_20141021_185023.reg
2014-10-21 18:42 - 2014-10-21 18:42 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-21 18:42 - 2014-10-21 18:42 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-21 18:36 - 2014-10-21 18:27 - 03239099 _____ () C:\Users\jan\Desktop\CBS.log
2014-10-21 18:33 - 2014-10-21 18:33 - 00030992 _____ () C:\sfcdetails.txt
2014-10-21 18:17 - 2014-10-21 18:17 - 01962496 _____ () C:\Users\jan\Desktop\adwcleaner_4.001.exe
2014-10-20 23:11 - 2014-10-20 23:11 - 00000000 ____D () C:\Windows\ERUNT
2014-10-20 22:10 - 2014-10-25 22:02 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-10-20 22:10 - 2014-10-22 00:11 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2014-10-20 22:10 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-20 22:10 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-20 22:04 - 2014-10-20 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-10-20 22:04 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-17 14:47 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-17 14:47 - 2014-09-29 02:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-17 14:47 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-17 14:47 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-17 14:47 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-17 14:47 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-17 14:47 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-17 14:47 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-17 14:47 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-17 14:47 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-17 14:47 - 2014-09-19 03:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-17 14:47 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-17 14:47 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-17 14:47 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-17 14:47 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-17 14:47 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-17 14:47 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-17 14:47 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-17 14:47 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-17 14:47 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-17 14:47 - 2014-09-19 02:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-17 14:47 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-17 14:47 - 2014-09-19 02:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-17 14:47 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-17 14:47 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-17 14:47 - 2014-09-19 02:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-17 14:47 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-17 14:47 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-17 14:47 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-17 14:47 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-17 14:47 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-17 14:47 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-17 14:47 - 2014-08-29 03:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-10-17 14:47 - 2014-08-29 03:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-10-17 14:47 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-17 14:47 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-17 14:47 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-17 14:47 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-17 14:47 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-17 14:47 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-17 14:47 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-17 14:47 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-17 14:46 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-17 14:46 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-16 20:45 - 2014-10-16 20:45 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-10-16 20:43 - 2014-10-16 20:43 - 00638888 _____ (Oracle Corporation) C:\Users\jan\Downloads\chromeinstall-8u25.exe
2014-10-13 22:45 - 2014-10-13 22:45 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-13 21:11 - 2014-10-13 22:07 - 00001957 _____ () C:\Users\jan\Desktop\Engel Englisch.txt
2014-10-01 14:31 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-30 15:30 - 2014-09-30 15:30 - 00060300 _____ () C:\Windows\system32\CCCInstall_201409301530165576.log
2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\ProgramData\ATI
2014-09-30 15:30 - 2014-09-30 15:30 - 00000000 ____D () C:\Program Files\AMD AVT
2014-09-30 15:29 - 2014-09-30 15:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-09-30 15:15 - 2014-09-30 15:17 - 210974816 _____ (AMD Inc.) C:\Users\jan\Downloads\amd-catalyst-14-9-win7-win8.1-32bit-dd-ccc-whql.exe
2014-09-25 16:04 - 2014-09-25 16:06 - 00000104 _____ () C:\Users\jan\Desktop\Notizen.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-25 22:08 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-25 22:08 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-25 22:07 - 2013-07-16 16:52 - 00000000 ____D () C:\Users\jan\Desktop\Anti-Vir
2014-10-25 22:05 - 2013-07-16 16:44 - 01955897 _____ () C:\Windows\WindowsUpdate.log
2014-10-25 22:03 - 2014-08-17 21:07 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Raptr
2014-10-25 22:01 - 2014-09-18 18:05 - 00000000 ____D () C:\Users\jan\AppData\Local\HTC MediaHub
2014-10-25 22:01 - 2013-07-16 16:52 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-25 22:01 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-25 21:59 - 2013-09-14 14:51 - 00000000 ____D () C:\AdwCleaner
2014-10-25 21:58 - 2013-07-16 16:52 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-25 21:38 - 2013-07-17 00:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-23 20:33 - 2013-08-27 20:30 - 00000000 ____D () C:\Users\Spiele & Programme von Jan
2014-10-23 20:33 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-10-23 20:33 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-10-23 20:22 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-10-23 20:14 - 2013-11-17 02:20 - 00000000 ____D () C:\ProgramData\Temp
2014-10-21 19:38 - 2013-10-03 00:11 - 00000000 ____D () C:\Users\jan\Desktop\Musik
2014-10-21 19:12 - 2013-07-18 01:50 - 00000000 ____D () C:\Program Files\Steam
2014-10-21 19:08 - 2013-08-17 01:58 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Ubisoft
2014-10-21 19:08 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-21 19:06 - 2014-07-30 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
2014-10-21 19:06 - 2014-07-30 23:25 - 00000000 ____D () C:\Nexon
2014-10-21 18:59 - 2013-07-17 00:17 - 00000000 ____D () C:\Program Files\Java
2014-10-21 18:49 - 2013-08-26 04:56 - 00000000 ____D () C:\Users\jan\AppData\Roaming\uTorrent
2014-10-21 18:49 - 2013-07-28 00:36 - 00000000 ____D () C:\Users\jan\AppData\Roaming\DAEMON Tools Lite
2014-10-21 18:49 - 2013-07-25 00:40 - 00000000 ____D () C:\Users\jan\AppData\Roaming\TS3Client
2014-10-21 18:48 - 2013-10-09 04:16 - 00000000 ____D () C:\Windows\Minidump
2014-10-21 18:48 - 2013-08-17 15:27 - 00000000 ___RD () C:\Users\jan\Desktop\Games
2014-10-21 18:48 - 2013-07-25 21:26 - 00000000 ____D () C:\Users\jan\Desktop\Programme
2014-10-21 18:48 - 2013-07-16 17:40 - 00000000 ____D () C:\Windows\Panther
2014-10-20 22:55 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Help
2014-10-20 22:13 - 2013-09-22 17:47 - 00000000 ____D () C:\Users\jan\Desktop\Schule
2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Malwarebytes
2014-10-20 22:10 - 2013-09-16 22:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-19 23:21 - 2014-05-03 22:59 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-10-19 23:21 - 2014-05-03 22:55 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-19 03:21 - 2013-08-17 02:27 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-19 03:01 - 2013-07-16 19:20 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-18 14:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-10-18 14:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-18 13:30 - 2014-08-17 21:07 - 00000000 ____D () C:\Program Files\Raptr
2014-10-18 13:19 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-18 03:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-10-18 03:08 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2014-10-18 00:57 - 2013-07-16 16:53 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-16 20:45 - 2014-08-11 14:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-16 20:44 - 2014-08-11 14:55 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-10-16 20:44 - 2014-08-11 14:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-10-16 20:44 - 2014-08-11 14:55 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-10-16 20:44 - 2013-10-22 22:55 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-15 12:17 - 2014-09-10 14:26 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Curse Client
2014-10-13 22:45 - 2013-08-17 13:54 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-13 22:45 - 2013-07-16 17:02 - 00000000 ____D () C:\Program Files\Avira
2014-10-02 15:53 - 2014-03-27 10:02 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-01 14:10 - 2013-07-16 23:08 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-01 14:10 - 2013-07-16 17:02 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-01 14:10 - 2013-07-16 17:02 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-09-30 15:30 - 2013-07-16 16:56 - 00000000 ____D () C:\ProgramData\AMD
2014-09-30 15:29 - 2013-07-16 16:55 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-09-30 15:19 - 2013-07-16 16:54 - 00000000 ____D () C:\AMD

Files to move or delete:
====================
C:\Users\jan\jagex_cl_runescape_LIVE.dat
C:\Users\jan\jagex_cl_runescape_LIVE1.dat
C:\Users\jan\random.dat


Some content of TEMP:
====================
C:\Users\jan\AppData\Local\temp\avgnt.exe
C:\Users\jan\AppData\Local\temp\Quarantine.exe
C:\Users\jan\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-17 15:28

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 26.10.2014, 16:02   #8
schrauber
/// the machine
/// TB-Ausbilder
 

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.10.2014, 17:06   #9
Ridertsen
 
[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



ESET

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=1648f742f5ac164fa38f585121f18e42
# engine=20780
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-10-26 01:52:12
# local_time=2014-10-26 02:52:12 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 25815 40301471 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 0 165919523 0 0
# scanned=13352
# found=0
# cleaned=0
# scan_time=2252
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=1648f742f5ac164fa38f585121f18e42
# engine=20780
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-10-26 02:29:34
# local_time=2014-10-26 03:29:34 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 28057 40303713 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 0 165921765 0 0
# scanned=50277
# found=0
# cleaned=0
# scan_time=2065
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=1648f742f5ac164fa38f585121f18e42
# engine=20780
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-10-26 06:36:12
# local_time=2014-10-26 07:36:12 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 42855 40318511 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 0 165936563 0 0
# scanned=331602
# found=3
# cleaned=0
# scan_time=7621
sh=D1F0FD084A0C4BF7DD0B710573E06A17222D55C4 ft=1 fh=787d4ad607d79e1d vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jan\Downloads\OpenOffice - CHIP-Downloader.exe"
sh=3D1FDED56D9DF9D1D5F07D8FA5F903C9CA308B3B ft=1 fh=029a8e2c3fd8a9aa vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jan\Downloads\PDF24 Creator - CHIP-Downloader.exe"
sh=DA928C6FE9145CDFEC3212376F85E7051798FC79 ft=1 fh=1d985872365bc2cd vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\jan\Downloads\rpc412_setup.exe"
         
Security Check

Code:
ATTFilter
 Results of screen317's Security Check version 0.99.89  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Avira Desktop   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Spybot - Search & Destroy 
 CCleaner     
 Java 8 Update 25  
 Java version out of Date! 
 Adobe Flash Player 	15.0.0.152  
 Google Chrome 37.0.2062.124  
 Google Chrome 38.0.2125.104  
````````Process Check: objlist.exe by Laurent````````  
 Spybot Teatimer.exe is disabled! 
 Avira Antivir avgnt.exe 
 Avira Antivir avguard.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
FRST

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-10-2014
Ran by jan (administrator) on JAN-PC on 26-10-2014 16:53:59
Running from C:\Users\jan\Desktop
Loaded Profile: jan (Available profiles: jan)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe
(Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\System32\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
() C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.5\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Akamai Technologies, Inc.) C:\Users\jan\AppData\Local\Akamai\netsession_win.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-09-15] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Akamai NetSession Interface] => C:\Users\jan\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-871497826-143411075-1366273650-1001\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55568 2014-10-17] (Raptr, Inc)
Startup: C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk
ShortcutTarget: Curse.lnk -> C:\Users\jan\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Handler: AutorunsDisabled\skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll (OGPlanet)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://jappy.de/"
CHR Profile: C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27]
CHR Extension: (Turn Off the Lights) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-07-16]
CHR Extension: (YouTube) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-16]
CHR Extension: (TV) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-05-04]
CHR Extension: (Tanki Online) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chnamgoimgnbgkabfjkikldbfdhhfhdo [2014-08-18]
CHR Extension: (Google-Suche) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-16]
CHR Extension: (Tampermonkey) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-08-04]
CHR Extension: (Realm of the Mad God) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp [2014-07-17]
CHR Extension: (RAD Soldiers) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkiahcckehgdocgonfdickeagmoembpe [2014-07-17]
CHR Extension: (Rush Team) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2014-05-04]
CHR Extension: (Avira SafeSearch) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2014-08-08]
CHR Extension: (Freefall Tournament) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2014-05-04]
CHR Extension: (Polycraft) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopfmbpfhhfnklgmjpoehcjaajhpbhbl [2014-07-27]
CHR Extension: (Avira Browser Safety) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-10]
CHR Extension: (Heroes & Generals) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2014-05-20]
CHR Extension: (WarChiefs - Tiberium Alliances Combat Simulator) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggiejiffgcdcfogfcgdebmbafcfndpgd [2013-08-04]
CHR Extension: (AdBlock) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-16]
CHR Extension: (Speed Test) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2014-08-18]
CHR Extension: (Red Crucible 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iechpocbkaimjmlpfinoahkolenfdmig [2014-08-17]
CHR Extension: (Cut the Rope) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2014-08-03]
CHR Extension: (Plug+) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jflocljnfndnnnlmfaamgbkbibnfmlkf [2013-07-16]
CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2013-08-05]
CHR Extension: (Verdun Game) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\khdppkcpilejlgahecofelpoidcnjbdg [2014-07-17]
CHR Extension: (Sand 2) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\klicmgamjpclmbhppmdeamffedflmkcn [2014-10-16]
CHR Extension: (Artillery Tower Protector) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgcejmkikbadghamaadggncnbfekdik [2014-08-03]
CHR Extension: (Fieldrunners) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2014-05-04]
CHR Extension: (Regen-Alarm) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-08-18]
CHR Extension: (Spelunky HTML5) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhagnkphcmpkmabhocgimoncfaihkpof [2014-10-01]
CHR Extension: (DSL speedtest) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj [2014-08-18]
CHR Extension: (Apple Shooter) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbhfnlipcinfjmjplgegncjlmpnihecg [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Batterfield Map) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\npjmhhanmmlmpcnonlcgplgfnngboodf [2014-09-05]
CHR Extension: (Sand) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdknckljjbdpkhgmcokoahffbdinafbo [2014-09-12]
CHR Extension: (Reditr - The Best Reddit Client) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmfcbbijgnhoebddbjpmlikabnbnddgb [2014-10-01]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed]
R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-08-04] (Nero AG)
S2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG)
S3 npggsvc; C:\Windows\system32\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-07-19] ()
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2013-07-16] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [15968 2013-07-16] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [22144 2013-07-16] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-03] (Disc Soft Ltd)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated)
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1846448 2013-07-16] (VIA Technologies, Inc.)
S3 catchme; \??\C:\Users\jan\AppData\Local\Temp\catchme.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vtany; \??\C:\Windows\vtany.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 16:53 - 2014-10-26 16:54 - 00017303 _____ () C:\Users\jan\Desktop\FRST.txt
2014-10-26 16:53 - 2014-10-26 16:53 - 00000000 ____D () C:\Users\jan\Desktop\FRST-OlderVersion
2014-10-26 16:43 - 2014-10-26 16:43 - 00854448 _____ () C:\Users\jan\Desktop\SecurityCheck.exe
2014-10-26 16:17 - 2014-10-26 16:30 - 00000429 _____ () C:\Users\jan\Desktop\eset.txt
2014-10-26 02:11 - 2014-10-26 02:11 - 00000000 ____D () C:\Program Files\ESET
2014-10-26 02:09 - 2014-10-26 02:10 - 02347384 _____ (ESET) C:\Users\jan\Desktop\esetsmartinstaller_deu.exe
2014-10-25 21:07 - 2014-10-21 19:25 - 01706144 _____ (Thisisu) C:\Users\jan\Desktop\JRT_NEW.exe
2014-10-23 19:33 - 2014-10-23 19:33 - 00019058 _____ () C:\ComboFix.txt
2014-10-23 19:06 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-23 19:06 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-23 19:06 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-23 19:06 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-23 19:06 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-23 19:06 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-23 19:06 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-23 19:06 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-23 19:04 - 2014-10-23 19:33 - 00000000 ____D () C:\Qoobox
2014-10-23 19:04 - 2014-10-23 19:30 - 00000000 ____D () C:\Windows\erdnt
2014-10-23 18:58 - 2014-10-23 18:59 - 05584933 ____R (Swearware) C:\Users\jan\Desktop\ComboFix.exe
2014-10-22 12:14 - 2014-10-26 16:54 - 00000000 ____D () C:\FRST
2014-10-22 12:13 - 2014-10-26 16:53 - 01104896 _____ (Farbar) C:\Users\jan\Desktop\FRST.exe
2014-10-22 02:08 - 2014-10-22 02:08 - 00002238 _____ () C:\Users\jan\Downloads\hijackthis.log
2014-10-22 01:51 - 2014-10-22 01:51 - 00388608 _____ (Trend Micro Inc.) C:\Users\jan\Desktop\HiJackThis204.exe
2014-10-21 23:11 - 2014-10-21 23:11 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-21 22:04 - 2014-10-21 22:04 - 00117912 _____ () C:\Users\jan\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-21 21:59 - 2014-10-26 04:31 - 00000504 _____ () C:\Windows\setupact.log
2014-10-21 21:59 - 2014-10-25 21:00 - 00003226 _____ () C:\Windows\PFRO.log
2014-10-21 21:59 - 2014-10-21 21:59 - 00460912 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-21 21:59 - 2014-10-21 21:59 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-21 17:50 - 2014-10-21 17:50 - 00143690 _____ () C:\Users\jan\Desktop\cc_20141021_185023.reg
2014-10-21 17:42 - 2014-10-21 17:42 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-21 17:42 - 2014-10-21 17:42 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-21 17:36 - 2014-10-21 17:27 - 03239099 _____ () C:\Users\jan\Desktop\CBS.log
2014-10-21 17:33 - 2014-10-21 17:33 - 00030992 _____ () C:\sfcdetails.txt
2014-10-21 17:17 - 2014-10-21 17:17 - 01962496 _____ () C:\Users\jan\Desktop\adwcleaner_4.001.exe
2014-10-20 22:11 - 2014-10-20 22:11 - 00000000 ____D () C:\Windows\ERUNT
2014-10-20 21:10 - 2014-10-26 04:35 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-20 21:10 - 2014-10-21 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-10-20 21:10 - 2014-10-21 23:11 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2014-10-20 21:10 - 2014-10-01 10:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-20 21:10 - 2014-10-01 10:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-20 21:04 - 2014-10-20 21:10 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-10-20 21:04 - 2014-10-01 10:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-17 13:47 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-17 13:47 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-17 13:47 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-17 13:47 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-17 13:47 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-17 13:47 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-17 13:47 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-17 13:47 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-17 13:47 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-17 13:47 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-17 13:47 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-17 13:47 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-17 13:47 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-17 13:47 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-17 13:47 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-17 13:47 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-17 13:47 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-17 13:47 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-17 13:47 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-17 13:47 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-17 13:47 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-17 13:47 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-17 13:47 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-17 13:47 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-17 13:47 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-17 13:47 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-17 13:47 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-17 13:47 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-17 13:47 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-17 13:47 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-17 13:47 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-17 13:47 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-17 13:47 - 2014-08-29 02:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-17 13:47 - 2014-08-29 02:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-17 13:47 - 2014-08-29 02:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-17 13:47 - 2014-08-29 02:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-10-17 13:47 - 2014-08-29 02:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-10-17 13:47 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-17 13:47 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-17 13:47 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-17 13:47 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-17 13:47 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-17 13:47 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-17 13:47 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-17 13:47 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-17 13:47 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-17 13:47 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-17 13:47 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-17 13:46 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-17 13:46 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-16 19:45 - 2014-10-16 19:45 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-10-16 19:43 - 2014-10-16 19:43 - 00638888 _____ (Oracle Corporation) C:\Users\jan\Downloads\chromeinstall-8u25.exe
2014-10-13 21:45 - 2014-10-13 21:45 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-13 20:11 - 2014-10-13 21:07 - 00001957 _____ () C:\Users\jan\Desktop\Engel Englisch.txt
2014-10-01 13:31 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-30 14:30 - 2014-09-30 14:30 - 00060300 _____ () C:\Windows\system32\CCCInstall_201409301530165576.log
2014-09-30 14:30 - 2014-09-30 14:30 - 00000000 ____D () C:\ProgramData\ATI
2014-09-30 14:30 - 2014-09-30 14:30 - 00000000 ____D () C:\Program Files\AMD AVT
2014-09-30 14:29 - 2014-09-30 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-09-30 14:15 - 2014-09-30 14:17 - 210974816 _____ (AMD Inc.) C:\Users\jan\Downloads\amd-catalyst-14-9-win7-win8.1-32bit-dd-ccc-whql.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 16:38 - 2013-07-16 23:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-26 15:58 - 2013-07-16 15:52 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-26 15:58 - 2013-07-16 15:52 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-26 04:40 - 2009-07-14 05:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-26 04:40 - 2009-07-14 05:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-26 04:38 - 2010-11-20 22:01 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-26 04:33 - 2014-08-17 20:07 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Raptr
2014-10-26 04:32 - 2014-09-18 17:05 - 00000000 ____D () C:\Users\jan\AppData\Local\HTC MediaHub
2014-10-26 04:32 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-26 04:30 - 2013-07-16 15:44 - 01989518 _____ () C:\Windows\WindowsUpdate.log
2014-10-26 02:54 - 2013-07-16 18:53 - 00000000 ____D () C:\Games
2014-10-25 21:07 - 2013-07-16 15:52 - 00000000 ____D () C:\Users\jan\Desktop\Anti-Vir
2014-10-25 20:59 - 2013-09-14 13:51 - 00000000 ____D () C:\AdwCleaner
2014-10-23 19:33 - 2013-08-27 19:30 - 00000000 ____D () C:\Users\Spiele & Programme von Jan
2014-10-23 19:33 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2014-10-23 19:33 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-10-23 19:22 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2014-10-23 19:14 - 2013-11-17 01:20 - 00000000 ____D () C:\ProgramData\Temp
2014-10-21 18:38 - 2013-10-02 23:11 - 00000000 ____D () C:\Users\jan\Desktop\Musik
2014-10-21 18:12 - 2013-07-18 00:50 - 00000000 ____D () C:\Program Files\Steam
2014-10-21 18:08 - 2013-08-17 00:58 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Ubisoft
2014-10-21 18:08 - 2009-07-14 05:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-21 18:06 - 2014-07-30 22:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
2014-10-21 17:59 - 2013-07-16 23:17 - 00000000 ____D () C:\Program Files\Java
2014-10-21 17:49 - 2013-08-26 03:56 - 00000000 ____D () C:\Users\jan\AppData\Roaming\uTorrent
2014-10-21 17:49 - 2013-07-27 23:36 - 00000000 ____D () C:\Users\jan\AppData\Roaming\DAEMON Tools Lite
2014-10-21 17:49 - 2013-07-24 23:40 - 00000000 ____D () C:\Users\jan\AppData\Roaming\TS3Client
2014-10-21 17:48 - 2013-10-09 03:16 - 00000000 ____D () C:\Windows\Minidump
2014-10-21 17:48 - 2013-08-17 14:27 - 00000000 ___RD () C:\Users\jan\Desktop\Games
2014-10-21 17:48 - 2013-07-25 20:26 - 00000000 ____D () C:\Users\jan\Desktop\Programme
2014-10-21 17:48 - 2013-07-16 16:40 - 00000000 ____D () C:\Windows\Panther
2014-10-20 21:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help
2014-10-20 21:13 - 2013-09-22 16:47 - 00000000 ____D () C:\Users\jan\Desktop\Schule
2014-10-20 21:10 - 2013-09-16 21:24 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Malwarebytes
2014-10-20 21:10 - 2013-09-16 21:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-19 22:21 - 2014-05-03 21:59 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-10-19 22:21 - 2014-05-03 21:55 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-19 02:21 - 2013-08-17 01:27 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-19 02:01 - 2013-07-16 18:20 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-18 13:35 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-10-18 13:04 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-18 12:30 - 2014-08-17 20:07 - 00000000 ____D () C:\Program Files\Raptr
2014-10-18 12:19 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-18 02:39 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-10-18 02:08 - 2009-07-14 03:04 - 00000478 _____ () C:\Windows\win.ini
2014-10-17 23:57 - 2013-07-16 15:53 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-16 19:45 - 2014-08-11 13:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-16 19:44 - 2014-08-11 13:55 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-10-16 19:44 - 2014-08-11 13:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-10-16 19:44 - 2014-08-11 13:55 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-10-16 19:44 - 2014-08-11 13:55 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-10-16 19:44 - 2013-10-22 21:55 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-15 11:17 - 2014-09-10 13:26 - 00000000 ____D () C:\Users\jan\AppData\Roaming\Curse Client
2014-10-13 21:45 - 2013-08-17 12:54 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-13 21:45 - 2013-07-16 16:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-13 21:45 - 2013-07-16 16:02 - 00000000 ____D () C:\Program Files\Avira
2014-10-02 14:53 - 2014-03-27 09:02 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-01 13:10 - 2013-07-16 22:08 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-01 13:10 - 2013-07-16 16:02 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-01 13:10 - 2013-07-16 16:02 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-09-30 14:30 - 2013-07-16 15:56 - 00000000 ____D () C:\ProgramData\AMD
2014-09-30 14:29 - 2013-07-16 15:55 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-09-30 14:19 - 2013-07-16 15:54 - 00000000 ____D () C:\AMD

Files to move or delete:
====================
C:\Users\jan\jagex_cl_runescape_LIVE.dat
C:\Users\jan\jagex_cl_runescape_LIVE1.dat
C:\Users\jan\random.dat


Some content of TEMP:
====================
C:\Users\jan\AppData\Local\temp\avgnt.exe
C:\Users\jan\AppData\Local\temp\Quarantine.exe
C:\Users\jan\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-26 08:02

==================== End Of Log ============================
         
--- --- ---


Im moment öffnet sich der Arbeitsplatz nicht mehr, jedoch bin ich mir immer noch unsicher, ich werde noch ein paar runden spielen und bescheid geben
Danke für die Hilfe Schrauber!

Alt 27.10.2014, 09:50   #10
schrauber
/// the machine
/// TB-Ausbilder
 

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Adobe updaten.

Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 27.10.2014, 15:35   #11
Ridertsen
 
[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Hallo Schrauber, das problem mit dem Arbeitsplatz ist mittlerweile seit anderthalb oder 2 Tagen nicht mehr aufgetreten und ich danke dir herzlichst !

Ich habe mittlerweile meinen Computer aufgeräumt und ältere Sachen runter geschmissen, mein Computer läuft mittlerweile auch ein wenig schneller und sieht netter aus.

Ich danke dir und sobald sich ein neues Problem oder das mit dem Arbeitsplatz wieder melden sollte, wende ich mich wieder an dich

Danke!
MfG

Alt 28.10.2014, 10:14   #12
schrauber
/// the machine
/// TB-Ausbilder
 

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Standard

[Windows7] Computer (Arbeitsplatz) öffnet sich ständig!



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu [Windows7] Computer (Arbeitsplatz) öffnet sich ständig!
fehlercode 0x5, fehlercode 0xc0000005, fehlercode windows, pup.optional.handy.a, pup.optional.mystarttb.a, pup.optional.opencandy, pup.optional.vmntoolbar.a, win32/downloadsponsor.a, win32/downware.l




Ähnliche Themen: [Windows7] Computer (Arbeitsplatz) öffnet sich ständig!


  1. Windows7 Firefox öffnet ständig neue Tabs mit Werbung
    Log-Analyse und Auswertung - 20.08.2014 (11)
  2. Windows7: bei jedem Klick öffnet sich ein neuer Tab mit Werbung - egal welcher Browser
    Log-Analyse und Auswertung - 26.02.2014 (19)
  3. Windows7: NationZoom.com öffnet sich beim Öffnen eines Browsers
    Log-Analyse und Auswertung - 21.01.2014 (11)
  4. Firefox öffnet ständig neue Seiten...Computer reagiert sehr langsam
    Log-Analyse und Auswertung - 07.08.2013 (42)
  5. Computer/Arbeitsplatz Vista 64 Bit öffnet sich ohne Aufforderung
    Plagegeister aller Art und deren Bekämpfung - 19.04.2013 (2)
  6. Arbeitsplatz öffnet sich einfach automatisch
    Alles rund um Windows - 28.01.2013 (2)
  7. Arbeitsplatz öffnet sich einfach automatisch
    Plagegeister aller Art und deren Bekämpfung - 28.01.2013 (11)
  8. Ad.adserverplus.com öffnet sich ständig
    Plagegeister aller Art und deren Bekämpfung - 02.01.2013 (8)
  9. S.M.A.R.T. Check Windows7 Desktop Schwarz und nurnoch Papierkorb und Arbeitsplatz da
    Log-Analyse und Auswertung - 02.11.2012 (1)
  10. IE Werbung öffnet sich ständig
    Log-Analyse und Auswertung - 10.06.2010 (19)
  11. IE öffnet sich ständig
    Log-Analyse und Auswertung - 19.04.2010 (3)
  12. IE öffnet sich ständig
    Log-Analyse und Auswertung - 15.04.2010 (1)
  13. IE öffnet sich ständig
    Plagegeister aller Art und deren Bekämpfung - 18.06.2008 (1)
  14. iexplorer öffnet sich ständig
    Log-Analyse und Auswertung - 26.12.2007 (3)
  15. computer startet sich ständig neu....
    Plagegeister aller Art und deren Bekämpfung - 03.10.2005 (14)
  16. Trojaner??? IE öffnet sich ständig
    Log-Analyse und Auswertung - 23.04.2005 (1)
  17. Ständig öffnet sich IE - Fenster
    Plagegeister aller Art und deren Bekämpfung - 03.03.2005 (7)

Zum Thema [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! - Guten Abend!, Mein Computer bzw. Arbeitsplatz öffnet sich ständig (Das ploppt dann einfach auf), manchmal mit Pause zwischendurch und manchmal einfach un-unterbrochen. Meistens auch während ich spiele (Schmeißt mich dann - [Windows7] Computer (Arbeitsplatz) öffnet sich ständig!...
Archiv
Du betrachtest: [Windows7] Computer (Arbeitsplatz) öffnet sich ständig! auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.